Vulnerability management software that closes findings, not just lists them.
Sable scans your external attack surface continuously, deduplicates what comes back, ranks it by the risk it actually carries, and gives every finding an owner, a due date, and a retest. The scanner is the easy part. Finishing is the product.
Continuous external scanning · CVSS severity · Owners and due dates · Retest workflow
What is vulnerability management software?
Vulnerability management software is the system that finds weaknesses across your estate, decides which of them matter, drives the fixes, and proves the fixes worked. The scanning half is well solved and largely commoditised. The half that fails is everything after: thousands of raw findings, duplicated across tools, ranked by a severity score that ignores whether anything is actually reachable, and no record of who owns what. Risk-based vulnerability management is the correction — rank by real-world exploitability rather than raw CVSS, and treat every finding as work with an owner rather than a row in an export.
Scan, rank, assign, retest.
One loop, run continuously, inside the same workspace as your risks, controls, and policies.
Continuous external scanning
Scans run continuously against your IPs, ports, and web applications, so exposure surfaces when it appears rather than at the next quarterly review.
Deduplicated findings inbox
The same weakness found three ways collapses into one finding, which is the difference between a queue your team finishes and an export nobody opens.
Ranked by real-world risk
Severity is CVSS-scored and then weighted by what an attacker could realistically reach, so the list you work top-down is the list that matters.
Owners and due dates
Every finding carries a named owner and a due date. Remediation stops being a shared intention and becomes tracked work.
Retest built into the workflow
A finding is not closed because someone said so. It is closed because a retest confirmed it, and the record of that retest is the evidence.
Pentest findings in the same queue
When SubRosa runs a penetration test, the findings land in this queue rather than arriving as a PDF you re-key into a spreadsheet.
A findings queue your team actually finishes.
Findings land prioritised, assigned, and tracked from open to retested, in the same tenant as the risks they feed and the controls they evidence. A closed finding updates your risk register without anyone copying it across.
- CriticalRetestedLog4Shell on an unpatched build serverCVE-2021-44228
- CriticalIn progressVPN appliance two versions behindPerimeter
- HighOpenEDR exclusion covers the whole temp pathEndpoint
- MediumOpenSMB signing disabled across file serversInternal
Ranked by people who exploit these for a living.
Exploitability, not just severity
SubRosa is an offensive security firm. We know which critical-rated findings are unreachable and which medium-rated ones are the way in, and that judgement is what the ranking encodes.
Connected to the rest of the program
A standalone scanner leaves you moving findings into whatever system tracks your risks and controls. In Sable they are already there, so closing a finding moves the register too.
In the trial, not after a procurement cycle
Vulnerability management is included in the free trial with no credit card. Point it at your external estate and see real findings the same day.
See what's exposed before someone else does.
Start a free trial of Sable, scan your external attack surface, and put an owner on everything that comes back.
Common questions
- What is vulnerability management software?
- Vulnerability management software finds weaknesses across your estate, decides which of them matter, drives the fixes, and proves the fixes worked. The scanning half is largely commoditised; the half that fails is everything after it — thousands of raw findings, duplicated across tools, ranked by a severity score that ignores whether anything is actually reachable, and no record of who owns what. Sable is built around that second half.
- What does Sable actually scan?
- Your external attack surface: IPs, open ports, and web applications, scanned continuously rather than on a quarterly cycle. Findings are deduplicated so the same weakness discovered three ways becomes one item, scored with CVSS, then weighted by what an attacker could realistically reach.
- Does Sable replace Tenable, Qualys, or Rapid7?
- For external attack surface management and the remediation workflow around it, yes — and Sable adds the risk register, controls, and evidence those tools leave you to handle elsewhere. For authenticated, agent-based scanning of every internal endpoint and workstation, no. Those platforms go deeper inside the perimeter than Sable does today. If deep internal agent coverage is your requirement, run it alongside Sable and land the findings here; if your gap is knowing what is exposed outside and finishing the work that follows, Sable covers it on its own.
- What is risk-based vulnerability management?
- Ranking findings by the risk they genuinely carry rather than by raw CVSS score. A critical-rated vulnerability on a host nothing can reach matters less than a medium-rated one on your perimeter, and a queue ordered purely by CVSS sends teams to the wrong work first. Sable's ranking is weighted by exploitability, informed by the fact that SubRosa is an offensive security firm and spends its week establishing which findings are actually reachable.
- How does a finding get closed?
- Not by someone marking it done. Every finding carries a named owner and a due date, and closure requires a retest that confirms the fix held. The retest record is what turns remediation into evidence you can hand an auditor or a customer, rather than an assertion.
- Can SubRosa run vulnerability management for us instead?
- Yes. SubRosa delivers vulnerability management as a service for teams without the capacity to run it themselves, and penetration test findings from our team land in the same Sable queue rather than arriving as a PDF you re-key. The platform and the service use one workspace, so moving between them does not mean moving systems.
- Is vulnerability management included in the Sable free trial?
- Yes — it is available in the 14-day free trial with no credit card. Point it at your external estate and you will see real findings the same day.