{
  "kind": "security-atlas-product-research-directory",
  "reviewedAt": "2026-09-19",
  "status": "unassessed",
  "scope": "Representative offerings, not a ranking or a count of unique companies. Capabilities are documented claims; no independent effectiveness scores are assigned.",
  "segments": [
    {
      "name": "Security information & event management",
      "slug": "siem",
      "url": "https://atlasofsecurity.com/landscape/segments/siem/"
    },
    {
      "name": "Endpoint detection & response",
      "slug": "edr",
      "url": "https://atlasofsecurity.com/landscape/segments/edr/"
    },
    {
      "name": "Identity & access management",
      "slug": "iam",
      "url": "https://atlasofsecurity.com/landscape/segments/iam/"
    },
    {
      "name": "Vulnerability & exposure management",
      "slug": "vulnerability-management",
      "url": "https://atlasofsecurity.com/landscape/segments/vulnerability-management/"
    },
    {
      "name": "Cloud & workload security",
      "slug": "cloud-security",
      "url": "https://atlasofsecurity.com/landscape/segments/cloud-security/"
    },
    {
      "name": "Application & software supply-chain security",
      "slug": "application-security",
      "url": "https://atlasofsecurity.com/landscape/segments/application-security/"
    },
    {
      "name": "Data protection & posture",
      "slug": "data-security",
      "url": "https://atlasofsecurity.com/landscape/segments/data-security/"
    },
    {
      "name": "Response orchestration & managed operations",
      "slug": "security-operations",
      "url": "https://atlasofsecurity.com/landscape/segments/security-operations/"
    }
  ],
  "products": [
    {
      "name": "Microsoft Sentinel",
      "company": "Microsoft",
      "segment": "siem",
      "category": "Cloud SIEM",
      "url": "https://atlasofsecurity.com/landscape/vendors/microsoft-sentinel/",
      "description": "Microsoft Sentinel is a cloud SIEM for collecting security records, finding suspicious activity and investigating incidents. A practitioner connects relevant sources and uses queries and analytics rules to turn those records into evidence.",
      "scope": "This profile covers Sentinel analytics and investigation. Data tiers, automation and adjacent Microsoft security products have their own configuration and commercial boundaries; a Microsoft environment alone does not establish that every source or feature is included.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Microsoft Sentinel official overview",
          "url": "https://learn.microsoft.com/en-us/azure/sentinel/sentinel-overview"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Splunk Enterprise Security",
      "company": "Cisco",
      "segment": "siem",
      "category": "SIEM and security analytics",
      "url": "https://atlasofsecurity.com/landscape/vendors/splunk-enterprise-security/",
      "description": "Splunk Enterprise Security adds security detection and investigation workflows to the Splunk platform. Analysts search event data, use risk and entity context, and organize the evidence needed to investigate a case.",
      "scope": "This is the Enterprise Security offering, not every Splunk observability or automation product. Essentials and Premier packaging differ; confirm which analytics, case management and response capabilities belong to the proposed edition.",
      "lifecycle": {
        "status": "current",
        "note": "Cisco completed its acquisition of Splunk on March 18, 2024. The ownership change does not itself establish that separate Cisco or Splunk products share an entitlement or deployment."
      },
      "sources": [
        {
          "title": "Splunk Enterprise Security official overview",
          "url": "https://www.splunk.com/en_us/products/enterprise-security.html"
        },
        {
          "title": "Cisco acquisition of Splunk",
          "url": "https://www.cisco.com/site/us/en/about/corporate-development/acquisitions/splunk/index.html"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Google Security Operations SIEM",
      "company": "Google / Alphabet",
      "segment": "siem",
      "category": "Cloud SIEM",
      "url": "https://atlasofsecurity.com/landscape/vendors/google-security-operations-siem/",
      "description": "Google Security Operations SIEM brings security telemetry into a cloud analytics environment. Its investigation and detection workflows depend on converting incoming records into a useful common representation and preserving the context behind each alert.",
      "scope": "This profile covers the SIEM portion of Google Security Operations, formerly associated with the Chronicle name. SOAR and other suite capabilities need their own scope and entitlement checks; a connector listing does not guarantee complete parsing for every source version.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Google Security Operations SIEM official overview",
          "url": "https://docs.cloud.google.com/chronicle/docs/overview"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Elastic Security",
      "company": "Elastic",
      "segment": "siem",
      "category": "SIEM and search analytics",
      "url": "https://atlasofsecurity.com/landscape/vendors/elastic-security-siem/",
      "description": "Elastic Security provides SIEM investigation and detection over data stored in the Elastic platform. Analysts work with searchable events, rules and entity context; useful results still depend on sound collection and consistent field mappings.",
      "scope": "This page covers the SIEM use case, with Elastic Defend covered separately as an endpoint offering. Cloud and self-managed deployments divide infrastructure responsibilities differently, and advanced security capabilities vary by subscription.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Elastic Security official overview",
          "url": "https://www.elastic.co/security/siem"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Falcon Next-Gen SIEM",
      "company": "CrowdStrike",
      "segment": "siem",
      "category": "Cloud SIEM and platform analytics",
      "url": "https://atlasofsecurity.com/landscape/vendors/crowdstrike-falcon-next-gen-siem/",
      "description": "Falcon Next-Gen SIEM combines security analytics with Falcon context and supported third-party data. The practical question is whether the organization’s required records can be collected, understood and investigated reliably within that workflow.",
      "scope": "This profile concerns the SIEM offering, not the full Falcon endpoint or managed-service portfolio. Third-party parsing, retention and automation need explicit validation; buying a platform does not automatically license all of its modules.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Falcon Next-Gen SIEM official overview",
          "url": "https://www.crowdstrike.com/en-us/platform/next-gen-siem/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Cortex XSIAM",
      "company": "Palo Alto Networks",
      "segment": "siem",
      "category": "Converged SIEM and security operations",
      "url": "https://atlasofsecurity.com/landscape/vendors/palo-alto-cortex-xsiam/",
      "description": "Cortex XSIAM combines SIEM-style analytics with adjacent detection, investigation and automation capabilities. It is best examined as an operations workflow whose components, data dependencies and action permissions need to be understood separately.",
      "scope": "The product crosses SIEM, XDR and automation categories. This profile does not imply that every Cortex component is included or that all existing tools can be replaced; migration and module scope depend on the actual agreement and deployment.",
      "lifecycle": {
        "status": "current",
        "note": "Palo Alto Networks acquired IBM’s QRadar SaaS assets in 2024. Migration offers concern eligible offerings and agreements; that transaction did not retire IBM’s self-managed QRadar SIEM."
      },
      "sources": [
        {
          "title": "Cortex XSIAM official overview",
          "url": "https://www.paloaltonetworks.com/cortex/cortex-xsiam"
        },
        {
          "title": "Palo Alto Networks acquisition of QRadar SaaS assets",
          "url": "https://www.paloaltonetworks.com/company/press/2024/palo-alto-networks--closes-acquisition-of-ibm-s-qradar-saas-assets"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Exabeam New-Scale / LogRhythm SIEM",
      "company": "Exabeam",
      "segment": "siem",
      "category": "Cloud and self-hosted SIEM portfolio",
      "url": "https://atlasofsecurity.com/landscape/vendors/exabeam-logrhythm-siem/",
      "description": "Exabeam’s portfolio includes cloud-oriented New-Scale offerings and the self-hosted LogRhythm SIEM lineage. Both address security analytics, but a practitioner must identify the specific product before comparing architecture, features or operating responsibilities.",
      "scope": "This portfolio page deliberately distinguishes the offerings rather than treating their names as interchangeable editions of one installation. Merger history does not prove that integrations, licenses or migration paths are identical.",
      "lifecycle": {
        "status": "current",
        "note": "Exabeam and LogRhythm completed their merger on July 17, 2024. Their shared corporate context should not be read as proof that all product features or entitlements have converged."
      },
      "sources": [
        {
          "title": "Exabeam and LogRhythm merger announcement",
          "url": "https://www.exabeam.com/press-releases/exabeam-and-logrhythm-complete-merger-and-announce-new-company-details/"
        },
        {
          "title": "Exabeam New-Scale / LogRhythm SIEM official overview",
          "url": "https://www.exabeam.com/capabilities/siem/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Unified Defense SIEM",
      "company": "Securonix",
      "segment": "siem",
      "category": "Cloud SIEM and behavior analytics",
      "url": "https://atlasofsecurity.com/landscape/vendors/securonix-unified-defense-siem/",
      "description": "Securonix Unified Defense SIEM combines cloud security analytics with user and entity behavior context. Its value in practice depends on whether the available identity and event data support an investigation that an analyst can explain.",
      "scope": "This page covers the SIEM offering and its investigation context. Automation, threat intelligence and AI-assisted capabilities should be evaluated within the proposed package; advertised assistance is not evidence that an autonomous decision is correct.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Unified Defense SIEM official overview",
          "url": "https://www.securonix.com/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "IBM QRadar SIEM",
      "company": "IBM",
      "segment": "siem",
      "category": "Self-managed SIEM",
      "url": "https://atlasofsecurity.com/landscape/vendors/ibm-qradar/",
      "description": "IBM QRadar SIEM correlates security records into offenses that analysts investigate using event and asset context. This profile focuses on the continuing IBM self-managed offering and the operating work required to maintain its collection and correlation.",
      "scope": "Do not confuse this product with the acquired QRadar SaaS portfolio. Analytics extensions and other IBM capabilities have separate compatibility and entitlement requirements; an offense still needs investigation before it supports a response decision.",
      "lifecycle": {
        "status": "current",
        "note": "IBM’s self-managed QRadar SIEM remains distinct from the acquired SaaS offerings. IBM lists April 14, 2026 as end of life for QRadar SaaS SIEM/SOAR and August 31, 2026 for SaaS EDR/XDR; those dates do not retire the self-managed product."
      },
      "sources": [
        {
          "title": "IBM QRadar SIEM official overview",
          "url": "https://www.ibm.com/products/qradar-siem"
        },
        {
          "title": "QRadar SaaS portfolio and lifecycle context",
          "url": "https://www.ibm.com/products/qradar/saas"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "OpenText Enterprise Security Manager",
      "company": "OpenText",
      "segment": "siem",
      "category": "Enterprise SIEM and correlation",
      "url": "https://atlasofsecurity.com/landscape/vendors/opentext-arcsight/",
      "description": "OpenText Enterprise Security Manager, known through the ArcSight lineage, provides security event correlation and investigation. It is a useful example of how connector quality, normalized fields and maintained rules determine what an enterprise SIEM can actually detect.",
      "scope": "This profile covers Enterprise Security Manager. Log analytics, automation and other OpenText security products should be scoped separately; a familiar portfolio name does not establish which components or licenses are part of a deployment.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "OpenText Enterprise Security Manager official overview",
          "url": "https://www.opentext.com/products/enterprise-security-manager"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "FortiSIEM",
      "company": "Fortinet",
      "segment": "siem",
      "category": "SIEM with asset and operations context",
      "url": "https://atlasofsecurity.com/landscape/vendors/fortinet-fortisiem/",
      "description": "FortiSIEM combines security event analytics with asset and operational context. It can help an analyst relate an alert to the systems involved, provided collection, discovery and source integration are configured for the actual environment.",
      "scope": "This page covers FortiSIEM rather than the full Fortinet portfolio. Deployment models and behavior analytics or response features require edition checks. An IT/OT use case does not authorize active discovery or containment on operational equipment.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "FortiSIEM official overview",
          "url": "https://www.fortinet.com/products/siem/fortisiem"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "SIEM (InsightIDR)",
      "company": "Rapid7",
      "segment": "siem",
      "category": "Cloud SIEM and detection",
      "url": "https://atlasofsecurity.com/landscape/vendors/rapid7-insightidr/",
      "description": "Rapid7 InsightIDR provides cloud security detection and investigation using collected event data and available endpoint and identity context. Practitioners use its search and alert workflows to connect activity that would be difficult to understand from a single source.",
      "scope": "This profile covers the product, not Rapid7’s managed detection and response service. Collectors, agents, automation and adjacent capabilities need explicit scope checks; a software deployment does not by itself provide around-the-clock analyst coverage.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "SIEM (InsightIDR) official overview",
          "url": "https://docs.rapid7.com/insightidr/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Logpoint SIEM",
      "company": "Logpoint",
      "segment": "siem",
      "category": "SIEM and normalized analytics",
      "url": "https://atlasofsecurity.com/landscape/vendors/logpoint-siem/",
      "description": "Logpoint SIEM collects and normalizes security records for detection and investigation. It illustrates the importance of understanding source coverage and operating responsibilities even when a vendor offers a simpler commercial or deployment model.",
      "scope": "This profile covers SIEM. Cloud and on-premises choices, automation and neighboring capabilities must be confirmed in the proposal. A regional vendor presence does not establish the location or regulatory approval of a specific hosted deployment.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Logpoint SIEM official overview",
          "url": "https://logpoint.com/en/product/siem/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Graylog Security",
      "company": "Graylog",
      "segment": "siem",
      "category": "Security analytics over log management",
      "url": "https://atlasofsecurity.com/landscape/vendors/graylog-security/",
      "description": "Graylog Security adds security detection and investigation capabilities to the Graylog platform. A practitioner can use its log-centric workflow to explore events and develop detections, but must distinguish the licensed security offering from Graylog Open.",
      "scope": "This page covers Graylog Security. Open-source log management availability does not make every security feature free; rule formats, supported content and advanced capabilities should be checked against the selected release and entitlement.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Graylog Security official overview",
          "url": "https://graylog.org/products/security/"
        },
        {
          "title": "Graylog Security documentation",
          "url": "https://docs.graylog.org/docs/graylog-security"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Wazuh",
      "company": "Wazuh Inc.",
      "segment": "siem",
      "category": "Open-source security monitoring",
      "url": "https://atlasofsecurity.com/landscape/vendors/wazuh/",
      "description": "Wazuh is an open-source security monitoring platform combining endpoint agents, central analysis and searchable security data. It gives learners a concrete way to connect collected host activity with rules, alerts and the operational work behind monitoring.",
      "scope": "This profile covers the Wazuh platform rather than a guarantee of equivalent coverage to every commercial SIEM. Self-managed deployments require infrastructure and maintenance; managed cloud services have separate terms. Open-source licensing does not remove operating costs.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Wazuh official overview",
          "url": "https://documentation.wazuh.com/current/getting-started/index.html"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Microsoft Defender for Endpoint Plan 2",
      "company": "Microsoft",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/defender-for-endpoint/",
      "description": "Microsoft Defender for Endpoint Plan 2 combines endpoint detection and response with investigation capabilities in the Defender ecosystem. For a new analyst, its role is to turn supported device activity into alerts, investigation context and authorized response options.",
      "scope": "Plan 2 includes EDR capabilities absent from Plan 1. Defender for Business and server coverage have separate licensing considerations; response functions also differ by operating system.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Microsoft Defender for Endpoint Plan 2 official product documentation",
          "url": "https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint"
        },
        {
          "title": "Microsoft Defender for Endpoint Plan 2 official product documentation",
          "url": "https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-plan-1"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Falcon Insight XDR",
      "company": "CrowdStrike",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/crowdstrike-falcon-insight/",
      "description": "Falcon Insight XDR is CrowdStrike’s endpoint detection and response offering within the Falcon platform. It combines endpoint investigation with supported cross-domain context, giving analysts a way to explore related activity and use licensed response functions during an investigation.",
      "scope": "The endpoint sensor, Insight XDR entitlement and optional hunting or Falcon Complete managed service represent different parts of the purchase. Confirm the licensed capabilities and supported platforms.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Falcon Insight XDR official product documentation",
          "url": "https://www.crowdstrike.com/en-us/platform/endpoint-security/falcon-insight-xdr/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Singularity Endpoint",
      "company": "SentinelOne",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/sentinelone-singularity-endpoint/",
      "description": "Singularity Endpoint combines prevention with endpoint detection and response in SentinelOne’s platform. Its Storyline investigation model connects related activity, while remediation and rollback are advertised response capabilities whose availability must be checked against the chosen package and operating system.",
      "scope": "Evaluate the endpoint package separately from identity, mobile and Wayfinder managed-service offerings. A general rollback claim does not establish recovery coverage for every operating system or workload.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Singularity Endpoint official product documentation",
          "url": "https://www.sentinelone.com/platform/endpoint-security/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Cortex XDR",
      "company": "Palo Alto Networks",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/palo-alto-cortex-xdr/",
      "description": "Cortex XDR connects endpoint detection and response with supported network, cloud, identity and other security signals. The endpoint agent contributes host evidence, while the wider analytics platform helps analysts investigate relationships that would be difficult to see in one isolated alert.",
      "scope": "The endpoint agent and broader XDR analytics have different deployment and licensing considerations. Unit 42 managed detection and response is a separate service, not an automatic part of endpoint software.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Cortex XDR official product documentation",
          "url": "https://www.paloaltonetworks.com/cortex/cortex-xdr"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Sophos EDR",
      "company": "Sophos",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/sophos-endpoint/",
      "description": "Sophos EDR adds investigation and response to Sophos Endpoint protection. It gives analysts endpoint evidence and documented options such as isolation and live shell, while related XDR and managed-service products broaden the portfolio without being interchangeable with the EDR license.",
      "scope": "Confirm the current Sophos Central product and edition instead of relying on older Intercept X packaging. Sophos MDR and the acquired Secureworks portfolio require separate scope and service evaluation.",
      "lifecycle": {
        "status": "current",
        "note": "Sophos completed its acquisition of Secureworks on 3 February 2025. Evaluate current Sophos and Taegis offerings by their individual product and service scopes."
      },
      "sources": [
        {
          "title": "Sophos EDR official product documentation",
          "url": "https://www.sophos.com/en-us/products/endpoint-security/edr"
        },
        {
          "title": "Sophos completes Secureworks acquisition",
          "url": "https://www.sophos.com/en-us/press/press-releases/2025/02/sophos-completes-secureworks-acquisition"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "TrendAI Vision One Endpoint Security",
      "company": "Trend Micro",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/trendai-endpoint-security/",
      "description": "TrendAI Vision One Endpoint Security connects endpoint protection and investigation to the wider Vision One platform. The offering is relevant when analysts need to understand endpoint events alongside supported server, email, cloud or network signals rather than treating every alert in isolation.",
      "scope": "TrendAI is Trend Micro’s enterprise business identity. Verify the endpoint package, integrations and supported operating systems; advertised legacy or IoT coverage does not establish support for industrial controllers.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "TrendAI Vision One Endpoint Security official product documentation",
          "url": "https://www.trendaisecurity.com/en-us/platform/endpoint-security"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Trellix EDR with Forensics",
      "company": "Trellix",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/trellix-edr/",
      "description": "Trellix EDR with Forensics sits within an enterprise endpoint security portfolio with ePolicy Orchestrator management heritage. Its documented emphasis includes continuous monitoring and guided investigation, making it useful to study how endpoint evidence supports a repeatable investigation and evidence-handling process.",
      "scope": "Endpoint prevention, EDR, forensic functions and ePO deployment options need explicit package mapping. Verify current compatibility documentation; the accepted research had limited direct access to some Trellix product material.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Trellix EDR with Forensics official product documentation",
          "url": "https://www.trellix.com/platform/endpoint-security/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "GravityZone EDR",
      "company": "Bitdefender",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/bitdefender-gravityzone/",
      "description": "GravityZone EDR brings endpoint investigation into Bitdefender’s protection platform. Cross-endpoint incident correlation helps analysts connect related activity, while hunting and supported integrations provide ways to investigate beyond a single alert and share evidence with the wider security operations workflow.",
      "scope": "GravityZone EDR, enterprise bundles, XDR extensions and managed response have different entitlements. Confirm supported workstation and server platforms and the protection components included in the proposed package.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "GravityZone EDR official product documentation",
          "url": "https://www.bitdefender.com/en-us/business/products/endpoint-detection-response"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "ESET Inspect",
      "company": "ESET",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/eset-inspect/",
      "description": "ESET Inspect is the detection and response component in the ESET PROTECT ecosystem. It combines behavior and reputation information with investigation capabilities, providing a useful example of how endpoint rules, related activity and analyst judgment contribute to a security decision.",
      "scope": "Inspect is an XDR-enabling module rather than a replacement for every endpoint protection component. Cloud and on-premises options exist; verify the selected deployment, licensing and supported operating-system releases.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "ESET Inspect official product documentation",
          "url": "https://www.eset.com/us/business/solutions/endpoint-detection-and-response/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Elements Endpoint Detection and Response",
      "company": "WithSecure",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/withsecure-elements-edr/",
      "description": "WithSecure Elements Endpoint Detection and Response organizes suspicious endpoint observations into broader investigation context. Guided response and an escalation-to-expert option illustrate a co-managed approach: software supports the investigation while the customer and any contracted specialists retain defined operational responsibilities.",
      "scope": "Elements EDR and endpoint protection packaging should be confirmed together. WithSecure carries the enterprise F-Secure lineage after the business and consumer separation; current platform support requires direct documentation checks.",
      "lifecycle": {
        "status": "current",
        "note": "WithSecure continues the enterprise business lineage associated with F-Secure; the business and consumer offerings separated rather than simply sharing a new product name."
      },
      "sources": [
        {
          "title": "Elements Endpoint Detection and Response official product documentation",
          "url": "https://www.withsecure.com/en/solutions/software-and-services/elements-endpoint-detection-and-response"
        },
        {
          "title": "WithSecure company history",
          "url": "https://www.withsecure.com/en/about-us/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Elastic Defend",
      "company": "Elastic",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/elastic-defend/",
      "description": "Elastic Defend provides endpoint protection and detection within Elastic Security through Elastic Agent and Fleet. It is a useful learning example of how a centrally managed endpoint integration supplies host evidence to a wider search and investigation platform that still requires operational ownership.",
      "scope": "Elastic Defend is the endpoint integration, distinct from the broader Elastic SIEM. Deployment requires the appropriate Elastic Stack or serverless environment, Fleet management and attention to licensed response capabilities.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Elastic Defend official product documentation",
          "url": "https://www.elastic.co/docs/solutions/security/configure-elastic-defend"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Carbon Black Cloud Enterprise EDR",
      "company": "Broadcom",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/carbon-black-enterprise-edr/",
      "description": "Carbon Black Cloud Enterprise EDR focuses on endpoint activity visibility, search and investigation. Its technical overview describes an evidence-oriented workflow in which analysts examine recorded behavior, connect related observations and use queries to investigate questions beyond the alert that started the case.",
      "scope": "Carbon Black is a Broadcom division. Cloud Enterprise EDR and the separate Carbon Black EDR deployment are distinct offerings; endpoint prevention and other cloud modules need explicit package verification.",
      "lifecycle": {
        "status": "current",
        "note": "Carbon Black is part of Broadcom. Cloud Enterprise EDR and the separate Carbon Black EDR product require their own deployment and support checks."
      },
      "sources": [
        {
          "title": "Carbon Black Cloud Enterprise EDR official product documentation",
          "url": "https://docs.broadcom.com/doc/carbon-black-enterprise-edr-technical-overview"
        },
        {
          "title": "Broadcom Carbon Black detection and response",
          "url": "https://www.broadcom.com/products/carbon-black/threat-detection-and-response"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Aurora Endpoint Defense",
      "company": "Arctic Wolf",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/arctic-wolf-aurora-endpoint/",
      "description": "Aurora Endpoint Defense is an endpoint product in Arctic Wolf’s portfolio following its acquisition of Cylance assets. The offering brings prevention, detection and response capabilities into an endpoint technology discussion that should remain distinct from the company’s separately contracted managed security services.",
      "scope": "Confirm the exact Aurora endpoint product, deployment path and operating-system support. Ownership of Cylance assets does not mean endpoint software automatically includes Aurora MDR or a particular response-service commitment.",
      "lifecycle": {
        "status": "current",
        "note": "Arctic Wolf acquired Cylance assets in 2025. Check the exact Aurora endpoint product and any migration requirements separately from MDR service coverage."
      },
      "sources": [
        {
          "title": "Aurora Endpoint Defense official product documentation",
          "url": "https://arcticwolf.com/cylance/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Cisco Secure Endpoint",
      "company": "Cisco",
      "segment": "edr",
      "category": "Endpoint detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/cisco-secure-endpoint/",
      "description": "Cisco Secure Endpoint combines endpoint protection and investigation within Cisco’s security portfolio. Device trajectory is a useful beginner concept: it helps an analyst follow activity associated with a host, while supported isolation and related security integrations provide options for an authorized response.",
      "scope": "Essentials, Advantage and Premier editions have different capabilities. Cisco XDR integration and Talos hunting entitlements need verification; a product license does not automatically establish a managed incident-response commitment.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Cisco Secure Endpoint official product documentation",
          "url": "https://www.cisco.com/site/us/en/products/security/endpoint-security/secure-endpoint/index.html"
        },
        {
          "title": "Cisco Secure Endpoint official product documentation",
          "url": "https://www.cisco.com/c/en/us/products/collateral/security/fireamp-endpoints/datasheet-c78-733181.html"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Microsoft Entra ID",
      "company": "Microsoft",
      "segment": "iam",
      "category": "Workforce IAM",
      "url": "https://atlasofsecurity.com/landscape/vendors/microsoft-entra-id/",
      "description": "Microsoft Entra ID is a cloud identity provider for workforce sign-in, multifactor authentication, and policy-based access to applications and cloud consoles. It issues tokens so employees, contractors, and partners can reach Microsoft 365 and connected software.",
      "scope": "This profile covers Entra ID workforce authentication, Conditional Access, and hybrid directory sync. It does not cover customer identity, identity governance add-ons, or privileged access unless those SKUs are licensed separately.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Microsoft Entra authentication methods overview",
          "url": "https://learn.microsoft.com/en-us/entra/identity/authentication/overview-authentication"
        },
        {
          "title": "Microsoft Entra account recovery overview",
          "url": "https://learn.microsoft.com/en-us/entra/identity/authentication/concept-account-recovery-overview"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Okta Workforce Identity",
      "company": "Okta",
      "segment": "iam",
      "category": "Workforce IAM",
      "url": "https://atlasofsecurity.com/landscape/vendors/okta-workforce-identity/",
      "description": "Okta Workforce Identity is a cloud identity provider for employees, contractors, and partners. It offers single sign-on, adaptive multifactor authentication, a universal directory, and optional lifecycle, governance, and privileged-access modules across a large application catalog.",
      "scope": "This profile covers the workforce identity suite. Auth0 customer identity is a related but separately scoped product. Single sign-on, adaptive multifactor authentication, identity governance, and privileged access are distinct SKUs.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Okta Workforce Identity",
          "url": "https://www.okta.com/products/workforce-identity/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Auth0",
      "company": "Auth0",
      "segment": "iam",
      "category": "Customer identity",
      "url": "https://atlasofsecurity.com/landscape/vendors/auth0/",
      "description": "Auth0 is Okta's customer identity platform for product teams that ship consumer or multi-tenant login. It handles business-to-consumer and business-to-business sign-in, social and enterprise federation, consent, and machine-to-machine client credentials rather than employee single sign-on.",
      "scope": "Auth0 serves customer and application identity separately from Okta Workforce Identity. Scope its authentication, provisioning and authorization offerings explicitly; the application remains responsible for enforcing the authorization decisions it obtains.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Auth0 customer identity",
          "url": "https://auth0.com/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "PingFederate / PingOne",
      "company": "Ping Identity",
      "segment": "iam",
      "category": "Workforce and customer federation",
      "url": "https://atlasofsecurity.com/landscape/vendors/ping-identity/",
      "description": "PingFederate is a federation server for Security Assertion Markup Language, OpenID Connect, OAuth, and WS-Federation, with adapters and a policy editor. PingOne adds cloud multifactor authentication and identity services for hybrid or self-hosted deployments that mix workforce and partner identities.",
      "scope": "Design the PingOne versus PingFederate split explicitly. ForgeRock-origin capabilities appear in Ping's family unless a live contract still names ForgeRock. Government-cloud authorization claims need a current package check, not a brochure.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "PingFederate",
          "url": "https://www.pingidentity.com/en/product/pingfederate.html"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "SailPoint Human Fabric / Identity Security Cloud",
      "company": "SailPoint",
      "segment": "iam",
      "category": "Identity governance",
      "url": "https://atlasofsecurity.com/landscape/vendors/sailpoint-identity-security/",
      "description": "SailPoint Identity Security Cloud is an identity governance platform for discovering, governing, and protecting human access. It focuses on lifecycle, access certifications, and separation of duties rather than login user experience, with modules that extend toward cloud entitlements and non-employee identities.",
      "scope": "Current public naming also uses Human Fabric and describes its relationship to Identity Security Cloud. Existing customer editions and migration requirements still need contract-specific verification. This profile is identity governance, not workforce single sign-on.",
      "lifecycle": {
        "status": "current",
        "note": "Current public pages use Human Fabric alongside Identity Security Cloud. Verify edition and contract details; naming alone does not establish a mandatory migration."
      },
      "sources": [
        {
          "title": "SailPoint Identity Security Cloud",
          "url": "https://www.sailpoint.com/products/identity-security-cloud"
        },
        {
          "title": "SailPoint Human Fabric",
          "url": "https://www.sailpoint.com/products/human-fabric"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Saviynt Identity Cloud",
      "company": "Saviynt",
      "segment": "iam",
      "category": "Identity governance",
      "url": "https://atlasofsecurity.com/landscape/vendors/saviynt-identity-cloud/",
      "description": "Saviynt Identity Cloud is a cloud identity governance platform that spans workforce access, application access governance, non-human identities, and privileged-access adjacency. It is often evaluated where enterprise-resource-planning or electronic-health-record connectors matter as much as single sign-on.",
      "scope": "This profile is identity governance plus some privileged and non-human identity coverage, not a standalone workforce identity provider. Connector inventory and runtime enforcement must be proven per application. AI-agent registration is marketed and needs a lab check.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Saviynt Identity Cloud platform",
          "url": "https://saviynt.com/platform"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Idira Privileged Access Management",
      "company": "CyberArk",
      "segment": "iam",
      "category": "Privileged access",
      "url": "https://atlasofsecurity.com/landscape/vendors/cyberark-idira/",
      "description": "Idira Privileged Access Management is the current public PAM offering associated with CyberArk’s portfolio under Palo Alto Networks. It addresses privileged credentials and human administrative sessions. Adjacent machine and agent identity capabilities require separate product and deployment checks.",
      "scope": "This profile covers privileged access in the CyberArk portfolio under Palo Alto Networks. Machine and agent identity products require separate scoping; do not assume one console or subscription covers the entire portfolio.",
      "lifecycle": {
        "status": "current",
        "note": "Palo Alto Networks completed CyberArk’s acquisition on 11 February 2026. The current PAM page uses Idira; naming and ownership alone do not establish product retirement."
      },
      "sources": [
        {
          "title": "Idira Privileged Access Management",
          "url": "https://www.paloaltonetworks.com/idira/human/privileged-access-management"
        },
        {
          "title": "Palo Alto Networks completes acquisition of CyberArk",
          "url": "https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "BeyondTrust PAM Portfolio",
      "company": "BeyondTrust",
      "segment": "iam",
      "category": "Privileged access",
      "url": "https://atlasofsecurity.com/landscape/vendors/beyondtrust-pam/",
      "description": "BeyondTrust Pathfinder privileged access management combines password safe vaulting, privileged remote access, endpoint privilege management, and just-in-time elevation. It is aimed at least privilege on Windows and Unix, vendor remote access, and jump hosts rather than workforce single sign-on.",
      "scope": "This profile covers privileged account and session management plus endpoint privilege. Cloud entitlement and identity-threat capabilities are adjacent offerings. Confirm the selected module, deployment and target support rather than treating the whole portfolio as one product.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "BeyondTrust modern privileged access management",
          "url": "https://www.beyondtrust.com/solutions/modern-pam"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Delinea Secret Server",
      "company": "Delinea",
      "segment": "iam",
      "category": "Privileged access",
      "url": "https://atlasofsecurity.com/landscape/vendors/delinea-secret-server/",
      "description": "Delinea Secret Server is a credential vault for privileged secrets. It discovers accounts, encrypts stored credentials, supports check-in and check-out with rotation, and can monitor sessions. Platform claims that reach identity governance should be scoped separately from the vault.",
      "scope": "This profile is vault-focused privileged access for human, machine, and described AI credential control. It is not a workforce identity provider. Treat platformization and identity-governance-adjacent features as separate modules to license and test.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Delinea Secret Server",
          "url": "https://delinea.com/products/secret-server"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "IBM Verify",
      "company": "IBM",
      "segment": "iam",
      "category": "Identity fabric",
      "url": "https://atlasofsecurity.com/landscape/vendors/ibm-verify/",
      "description": "IBM Verify is a family of workforce, customer, governance, and privileged-identity products under one brand. It includes multifactor authentication, orchestration, consent, directory, identity governance, privileged identity, and an application gateway for legacy applications, including a government SKU.",
      "scope": "Map which SKU does single sign-on, customer identity, identity governance, or privileged identity before an evaluation. This is a fabric for hybrid IBM, mainframe, and regulated estates, not a single greenfield software-as-a-service identity provider.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "IBM Verify",
          "url": "https://www.ibm.com/products/verify-identity"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Oracle OCI IAM / Identity Governance",
      "company": "Oracle",
      "segment": "iam",
      "category": "Cloud IAM and identity governance",
      "url": "https://atlasofsecurity.com/landscape/vendors/oracle-identity/",
      "description": "Oracle Cloud Infrastructure Identity and Access Management provides identity domains for single sign-on, multifactor authentication, and lifecycle in Oracle Cloud. Oracle Identity Governance remains the adjacent on-premises heritage product for entitlements, with Access Governance for reviews.",
      "scope": "This profile covers native Oracle Cloud identity domains plus adjacent identity governance. It is not a generic customer-identity suite for non-Oracle applications unless those connections are in scope. Confirm identity-domain versus Identity Governance packaging on the quote.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Oracle Cloud Infrastructure Identity and Access Management",
          "url": "https://www.oracle.com/security/cloud-security/identity-cloud/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "JumpCloud Open Directory",
      "company": "JumpCloud",
      "segment": "iam",
      "category": "Workforce directory and device management",
      "url": "https://atlasofsecurity.com/landscape/vendors/jumpcloud/",
      "description": "JumpCloud Open Directory is a cloud directory that combines workforce identity, single sign-on, multifactor authentication, LDAP, RADIUS, and device management for mixed operating systems. It is often evaluated by smaller information-technology teams consolidating directory, single sign-on, and mobile device management.",
      "scope": "This profile is workforce directory and device management, not customer identity or a full identity-governance suite. The cloud-directory pages are the current public path; treat device management as in-scope only when that module is licensed.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "JumpCloud cloud directory",
          "url": "https://jumpcloud.com/platform/cloud-directory"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Cisco Duo",
      "company": "Cisco Duo",
      "segment": "iam",
      "category": "Multifactor authentication overlay",
      "url": "https://atlasofsecurity.com/landscape/vendors/cisco-duo/",
      "description": "Cisco Duo is a multifactor authentication and device-trust overlay that often sits in front of an existing identity provider, virtual private network, or directory. It adds phishing-resistant methods, Duo Push, adaptive policy, and passwordless options without replacing identity governance or customer identity.",
      "scope": "Duo is access security, not a full identity-governance or customer-identity platform. It integrates with Active Directory, virtual private networks, software-as-a-service, and Entra external authentication methods. It does not by itself certify entitlements or vault privileged passwords.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Cisco Duo multifactor authentication",
          "url": "https://duo.com/product/multi-factor-authentication-mfa"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "AWS IAM Identity Center",
      "company": "Amazon Web Services",
      "segment": "iam",
      "category": "Cloud workforce IAM",
      "url": "https://atlasofsecurity.com/landscape/vendors/aws-iam-identity-center/",
      "description": "AWS IAM Identity Center centralizes workforce access to AWS accounts and supported applications. It can connect an external identity provider and provision users through System for Cross-domain Identity Management, while account permission sets give users temporary AWS role credentials.",
      "scope": "Identity Center can use an external identity provider and support customer-managed SAML applications. Scope account access, application assignments and provisioning separately; it is not a complete customer-identity or identity-governance product.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "AWS IAM Identity Center application management",
          "url": "https://docs.aws.amazon.com/singlesignon/latest/userguide/manage-your-applications.html"
        },
        {
          "title": "AWS workforce identity management guidance",
          "url": "https://docs.aws.amazon.com/prescriptive-guidance/latest/security-reference-architecture-identity-management/workforce-identity-management.html"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Google Cloud Identity / Workforce Federation / Identity Platform",
      "company": "Google Cloud",
      "segment": "iam",
      "category": "Cloud workforce and customer identity",
      "url": "https://atlasofsecurity.com/landscape/vendors/google-cloud-identity/",
      "description": "Google publishes three related but separate identity products. Cloud Identity and Workspace issue Google accounts for people. Workforce Identity Federation is a sync-less OpenID Connect and SAML path into Google Cloud. Identity Platform is customer identity for applications you build.",
      "scope": "These are distinct products: Cloud Identity manages Google identities, Workforce Identity Federation maps an external identity provider into Google Cloud, and Identity Platform provides customer identity. Verify the selected product’s requirements separately.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Google Cloud Workforce Identity Federation",
          "url": "https://docs.cloud.google.com/iam/docs/workforce-identity-federation"
        },
        {
          "title": "Google Cloud Identity Platform",
          "url": "https://cloud.google.com/security/products/identity-platform"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Tenable One",
      "company": "Tenable",
      "segment": "vulnerability-management",
      "category": "Exposure management platform",
      "url": "https://atlasofsecurity.com/landscape/vendors/tenable-one/",
      "description": "Tenable One is Tenable's exposure-management family. It gathers vulnerability, web application, identity, cloud, operational technology, and external-surface findings, then adds attack-path context so operators can inspect how weaknesses might combine rather than treating each scanner result as an isolated ticket.",
      "scope": "The family spans information technology, cloud, operational technology, identity, and attack-surface modules plus third-party connectors. Entitlements, connector fidelity, and permissions for automated actions are separate from the platform name.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Tenable One product page",
          "url": "https://www.tenable.com/products/tenable-one"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Qualys VMDR",
      "company": "Qualys",
      "segment": "vulnerability-management",
      "category": "Vulnerability management and TruRisk platform",
      "url": "https://atlasofsecurity.com/landscape/vendors/qualys-vmdr/",
      "description": "Qualys VMDR is a scanner-plus-agent vulnerability workflow on the Enterprise TruRisk Platform. It inventories assets, assesses missing patches and misconfigurations, and adds threat context and patch workflows. Enterprise TruRisk Management is described as aggregating Qualys and third-party findings rather than replacing the assessment layer.",
      "scope": "Cloud agents, passive sensors, and container sensors sit beside network scanning. Assessment coverage and remediation-module entitlements should be treated as separate commercial and operational questions, including how TruRisk relates to KEV and EPSS.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Qualys VMDR",
          "url": "https://www.qualys.com/vmdr"
        },
        {
          "title": "Qualys Enterprise TruRisk Management overview",
          "url": "https://docs.qualys.com/en/etm/latest/introduction/overview.htm"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Rapid7 Exposure Command",
      "company": "Rapid7",
      "segment": "vulnerability-management",
      "category": "Hybrid exposure management",
      "url": "https://atlasofsecurity.com/landscape/vendors/rapid7-exposure-command/",
      "description": "Rapid7 Exposure Command is a hybrid exposure offering that keeps InsightVM as the scanner. Documentation distinguishes Surface Command inventory from vulnerability, cloud, and application findings plus third-party enrichment, so buyers are looking at layered products rather than a single unnamed console.",
      "scope": "InsightVM remains the assessment engine inside the exposure SKU. Package entitlements, InsightVM migration, cloud-workload coverage, and retained evidence need to be confirmed per contract; the family name does not list those contents.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Rapid7 Exposure Command",
          "url": "https://www.rapid7.com/products/command/exposure-management/"
        },
        {
          "title": "Rapid7 Exposure Command documentation",
          "url": "https://docs.rapid7.com/exposure-command/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Microsoft Security Exposure Management",
      "company": "Microsoft",
      "segment": "vulnerability-management",
      "category": "Exposure graph and Defender vulnerability management",
      "url": "https://atlasofsecurity.com/landscape/vendors/microsoft-security-exposure-management/",
      "description": "Microsoft Security Exposure Management provides an exposure graph, attack paths, initiatives, and recommendations across supported endpoints, identities, and cloud signals. Related Defender Vulnerability Management and Defender External Attack Surface Management capabilities have separate requirements, so a Microsoft-heavy estate is still assembling more than one product boundary.",
      "scope": "The vulnerability-management user interface now sits under Exposure Management, while Defender Vulnerability Management and Defender EASM remain related capabilities with their own requirements. License stacking, including Microsoft 365 E5 versus standalone, and government-cloud gaps must be confirmed rather than inferred.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Microsoft Security Exposure Management",
          "url": "https://learn.microsoft.com/en-us/security-exposure-management/microsoft-security-exposure-management"
        },
        {
          "title": "Microsoft Defender EASM discovery",
          "url": "https://learn.microsoft.com/en-us/azure/external-attack-surface-management/what-is-discovery"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "CrowdStrike Falcon Exposure Management",
      "company": "CrowdStrike",
      "segment": "vulnerability-management",
      "category": "Agent-centric exposure management",
      "url": "https://atlasofsecurity.com/landscape/vendors/crowdstrike-falcon-exposure-management/",
      "description": "CrowdStrike Falcon Exposure Management is an agent-centric exposure offering. The vendor describes real-time assessment through the Falcon agent, ExPRT.AI prioritization, attack paths, unmanaged network assessment, and Fusion SOAR playbooks, plus CAASM- and EASM-style inventory around that agent core.",
      "scope": "How much assessment depends on the Falcon agent should be validated on the estate, including unmanaged devices and non-Falcon endpoints. Third-party scanner ingest, operational-technology and Internet of Things claims, and Fusion playbooks need their own authorization and safety review.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "CrowdStrike Falcon Exposure Management",
          "url": "https://www.crowdstrike.com/en-us/platform/exposure-management/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Cisco Vulnerability Management",
      "company": "Cisco",
      "segment": "vulnerability-management",
      "category": "Legacy risk-based vulnerability management",
      "url": "https://atlasofsecurity.com/landscape/vendors/cisco-vulnerability-management/",
      "description": "Cisco Vulnerability Management, formerly Kenna.VM, is a risk-based vulnerability-management product that ingests existing scanner findings, applies threat feeds, and supports service-level tracking by risk. It is in the sample as legacy context: Cisco published end of sale and a last-support date and did not name a replacement in the bulletin.",
      "scope": "This is not a current purchase path. End of sale is 10 March 2026 and last support is 30 June 2028. Remaining work is inventory, export, and successor design on the remaining support term, not new licenses.",
      "lifecycle": {
        "status": "legacy",
        "note": "End of sale 10 March 2026 and last support 30 June 2028. The Cisco end-of-life bulletin does not name a replacement product."
      },
      "sources": [
        {
          "title": "Cisco Vulnerability Management end-of-life bulletin",
          "url": "https://www.cisco.com/c/en/us/products/collateral/security/vulnerability-management/vm-vi-appsec-eol.pdf"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Axonius Cyber Assets and Exposures",
      "company": "Axonius",
      "segment": "vulnerability-management",
      "category": "Cyber asset attack surface management",
      "url": "https://atlasofsecurity.com/landscape/vendors/axonius/",
      "description": "Axonius is a specialist CAASM layer that sits above scanners and other sources. Cyber Assets normalizes and deduplicates many adapters. Exposures unifies vulnerabilities, misconfigurations, identity issues, coverage gaps, and owners so teams can see unscanned, unprotected, or unowned systems rather than only CVE lists.",
      "scope": "The product is an aggregation and ownership plane, not a replacement scanner. Adapter quality for the local stack, configuration-database reconciliation, write-back safety, and the separate Exposures product are the evaluation surface.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Axonius",
          "url": "https://www.axonius.com"
        },
        {
          "title": "Axonius platform overview",
          "url": "https://docs.axonius.com/docs/using-axonius-overview"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "runZero",
      "company": "runZero",
      "segment": "vulnerability-management",
      "category": "Agentless discovery and exposure workflow",
      "url": "https://atlasofsecurity.com/landscape/vendors/runzero/",
      "description": "runZero is an agentless discovery and exposure product for information technology, operational technology, and Internet of Things environments. It combines active, passive, and integration inventory with hosted external engines, query-based vulnerability matching, and a 5.0 verified-remediation workflow. A Community Edition exists.",
      "scope": "The product still publishes as runZero. An 18 June 2026 agreement for Accenture to acquire runZero and NetRise is distinct from a majority investment in Dragos; completion was not established in reviewed sources. Safe operational-technology scanning remains an evaluation item.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "runZero 5 announcement",
          "url": "https://www.runzero.com/blog/runzero-5/"
        },
        {
          "title": "Accenture, Dragos, and runZero agreement",
          "url": "https://www.dragos.com/resources/press-release/dragos-ot-cybersecurity-with-accenture"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Brinqa Platform",
      "company": "Brinqa",
      "segment": "vulnerability-management",
      "category": "Exposure orchestration",
      "url": "https://atlasofsecurity.com/landscape/vendors/brinqa/",
      "description": "Brinqa is an aggregation and orchestration platform rather than another scanner. It uses connectors and a Cyber Risk Graph to deduplicate findings, attribute owners, and apply business context. In August 2026 Brinqa acquired PlexTrac for offensive validation workflow and reporting; that combination is vendor-stated and should be tested rather than assumed mature.",
      "scope": "Connectors, owner inference, and graph correctness are the product surface. PlexTrac integration depth is a separate evaluation after the August 2026 acquisition. Deduplicated tickets still need to match source scanners and exception history.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Brinqa Platform",
          "url": "https://www.brinqa.com/"
        },
        {
          "title": "Brinqa acquires PlexTrac",
          "url": "https://www.brinqa.com/news-room/brinqa-acquires-plextrac-ctem"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "XM Cyber",
      "company": "XM Cyber",
      "segment": "vulnerability-management",
      "category": "Attack-path analysis",
      "url": "https://atlasofsecurity.com/landscape/vendors/xm-cyber/",
      "description": "XM Cyber is an attack-path and choke-point specialist. It builds a digital-twin style graph of CVEs, misconfigurations, and identities across hybrid environments, with vendor-described expansion to cloud and artificial-intelligence related surfaces as of March 2026. The question it answers is how conditions chain toward crown-jewel assets, not how many CVEs exist.",
      "scope": "Graph output is an inference about paths, not proof of a live exploit. Twin fidelity, production safety, and operational-technology or industrial-control path claims must be demonstrated on representative systems. Continuous exposure management here is a graph program, not a scanner replacement.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "XM Cyber",
          "url": "https://xmcyber.com/"
        },
        {
          "title": "XM Cyber continuous exposure management and AI attack surfaces",
          "url": "https://xmcyber.com/press-release/xm-cyber-extends-its-continuous-exposure-management-platform-to-secure-ai-attack-surfaces/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Cymulate Exposure Validation",
      "company": "Cymulate",
      "segment": "vulnerability-management",
      "category": "Breach and attack simulation",
      "url": "https://atlasofsecurity.com/landscape/vendors/cymulate/",
      "description": "Cymulate Exposure Validation is a breach-and-attack-simulation centered product. It runs controlled simulations across attack vectors, supplies threat content, and offers remediation guidance so operators can see whether selected email, web, endpoint, or network controls behave as assumed. It validates controls; it does not inventory every CVE on its own.",
      "scope": "Simulations need payload-safety review, an expected effect on security-operations alert volume, and an honest map of coverage versus the control vendors in place. A simulation that never executes an exploit is not the same proof as an authorized penetration test.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Cymulate breach and attack simulation",
          "url": "https://cymulate.com/breach-and-attack-simulation/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Picus Autonomous Exposure Validation Platform",
      "company": "Picus Security",
      "segment": "vulnerability-management",
      "category": "Exposure validation and breach and attack simulation",
      "url": "https://atlasofsecurity.com/landscape/vendors/picus-security/",
      "description": "Picus offers an Autonomous Exposure Validation Platform that starts from breach-and-attack simulation and adds adjacent exposure, attack-path, and cloud validation modules. A threat library and vendor-specific mitigation content are part of the documented pitch. Module licensing versus need, and the boundary between attack-path validation and BAS, have to be confirmed per package.",
      "scope": "BAS, attack-path validation, and cloud modules are not automatically one entitlement. Security-information-and-event-management and endpoint-detection integrations, mitigation content mapped to specific vendors, and deployment choices should be verified against the package under review.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Picus Autonomous Exposure Validation Platform",
          "url": "https://www.picussecurity.com/autonomous-exposure-validation-platform"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Pentera Platform",
      "company": "Pentera",
      "segment": "vulnerability-management",
      "category": "Automated security validation",
      "url": "https://atlasofsecurity.com/landscape/vendors/pentera/",
      "description": "Pentera is an agentless automated security-validation and automated-penetration-testing platform. Core, Cloud, and Surface assessment modules can attempt broader exploit chains than control simulation, and Resolve is described as remediation orchestration. Because tests may execute, change control, blast-radius limits, and cloud identity-and-access scope are part of the product boundary.",
      "scope": "Each module has its own authority question: network tests, cloud identity scope, and internet-surface assessment against owned properties only. Live exploits and BAS-style simulations both need authorization, change control, and stop conditions; neither is exempt.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Pentera Platform",
          "url": "https://pentera.io/pentera-platform/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Greenbone OPENVAS SCAN",
      "company": "Greenbone",
      "segment": "vulnerability-management",
      "category": "Open-ecosystem vulnerability scanner",
      "url": "https://atlasofsecurity.com/landscape/vendors/greenbone-openvas/",
      "description": "Greenbone OPENVAS SCAN is an open-ecosystem vulnerability scanner from Greenbone AG. Hardware and virtual scanning options exist, with an Enterprise Feed and a Community Feed and Community Edition. The company remains Greenbone AG; OPENVAS is the product brand. It is a useful comparison point for authenticated scanning without treating community coverage as equivalent to enterprise feed coverage.",
      "scope": "Community versus Enterprise feed coverage, authenticated scan quality, distributed management, and support responsibilities sit with the operator. Open-source licensing reduces a license line while leaving hosting, feed maintenance, and triage work. The scanner inventories weaknesses; it is not CTEM or EASM by itself.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Greenbone products",
          "url": "https://www.greenbone.net/en/products/"
        },
        {
          "title": "Greenbone solution comparison",
          "url": "https://www.greenbone.net/wp-content/uploads/solution_comparison_EN.pdf"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "AWS Security Hub and Workload Security",
      "company": "Amazon Web Services",
      "segment": "cloud-security",
      "category": "Native AWS security services",
      "url": "https://atlasofsecurity.com/landscape/vendors/aws-cloud-security/",
      "description": "AWS provides several services for understanding cloud exposure and workload threats. Security Hub CSPM assesses posture; the unified Security Hub correlates selected findings. Inspector examines supported workloads for vulnerabilities, while GuardDuty supplies threat detection. These services cooperate but are not interchangeable switches for complete cloud protection.",
      "scope": "Treat Security Hub, Security Hub CSPM, Inspector and GuardDuty as separately scoped services. Regional enablement, AWS Config dependencies, workload support and paid feature activation affect what is collected and how much the deployment costs.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "AWS Security Hub and Workload Security: official product documentation",
          "url": "https://aws.amazon.com/security-hub/faqs/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Microsoft Defender for Cloud",
      "company": "Microsoft",
      "segment": "cloud-security",
      "category": "Native Azure and multicloud CNAPP",
      "url": "https://atlasofsecurity.com/landscape/vendors/microsoft-defender-for-cloud/",
      "description": "Microsoft Defender for Cloud combines cloud posture, development-related security and workload protection. Its AWS and Google Cloud connectors extend selected capabilities beyond Azure. For a beginner, the key lesson is that connecting a cloud account for configuration visibility does not automatically install or enable every workload protection component.",
      "scope": "Foundational posture, paid Defender CSPM and workload-specific Defender plans have different coverage and billing. Some workload protections need Azure Arc or sensors; other service protections use cloud integrations. Map dependencies separately for each selected plan.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Microsoft Defender for Cloud: official product documentation",
          "url": "https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-cloud-introduction"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Google Security Command Center",
      "company": "Google Cloud",
      "segment": "cloud-security",
      "category": "Native Google Cloud posture and detection",
      "url": "https://atlasofsecurity.com/landscape/vendors/google-security-command-center/",
      "description": "Google Security Command Center collects security findings and supplies posture capabilities for Google Cloud. Posture policies and drift findings help teams compare deployed resources with an intended configuration. Tier and feature choices matter, particularly because published retirement notices affect selected offerings rather than the entire Security Command Center service.",
      "scope": "Confirm organization-level posture availability and the exact tier. Enterprise-specific integrations cannot be assumed in other tiers. Wiz is a separate Google Cloud product; its acquisition does not make all Wiz capabilities native Security Command Center functions.",
      "lifecycle": {
        "status": "transition",
        "note": "Enterprise-tier shutdown is scheduled on or after 21 May 2027, with movement to Premium. SCC DSPM was deprecated on 14 September 2026, with shutdown on or after 1 February 2027. These notices do not retire all SCC tiers."
      },
      "sources": [
        {
          "title": "Google Security Command Center: official product documentation",
          "url": "https://docs.cloud.google.com/security-command-center/docs/security-posture-overview"
        },
        {
          "title": "Google Security Command Center: official supporting source",
          "url": "https://docs.cloud.google.com/security-command-center/docs/deprecations"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Wiz",
      "company": "Wiz",
      "segment": "cloud-security",
      "category": "Multicloud CNAPP",
      "url": "https://atlasofsecurity.com/landscape/vendors/wiz/",
      "description": "Wiz connects cloud inventory, configuration, vulnerability and identity context to help teams understand exposure paths. Its platform includes agentless visibility and separate runtime capabilities. A graph can explain how conditions relate, but observing a process while it runs requires the relevant runtime component and supported deployment.",
      "scope": "This profile covers the Wiz platform and separately scoped Sensor capability. Agentless API or snapshot visibility is not runtime monitoring. Verify cloud, workload and module coverage rather than assuming the same capability exists for every connected account.",
      "lifecycle": {
        "status": "current",
        "note": "Google completed the Wiz acquisition on 11 March 2026. Wiz retains its brand; Google states that its products remain available across multiple clouds."
      },
      "sources": [
        {
          "title": "Wiz: official product documentation",
          "url": "https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/wiz-acquisition/"
        },
        {
          "title": "Wiz: official supporting source",
          "url": "https://www.wiz.io/platform"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Palo Alto Networks Cortex Cloud",
      "company": "Palo Alto Networks",
      "segment": "cloud-security",
      "category": "Application, posture and runtime security",
      "url": "https://atlasofsecurity.com/landscape/vendors/palo-alto-cortex-cloud/",
      "description": "Cortex Cloud brings application security, cloud posture and runtime security into Palo Alto Networks’ cloud portfolio. Prisma Cloud materials remain relevant to its lineage and existing deployments. A practitioner should connect development findings to deployed resources while verifying the precise modules behind the current product name.",
      "scope": "Confirm whether a deployment or quotation refers to Cortex Cloud, Prisma Cloud or particular modules. Naming evolution alone does not prove every customer must migrate. Identity products acquired through CyberArk are separate from CNAPP runtime coverage.",
      "lifecycle": {
        "status": "current",
        "note": "Current pages introduce Cortex Cloud alongside Prisma Cloud materials. Confirm the actual edition and migration requirements; the public naming change alone does not establish a mandatory migration."
      },
      "sources": [
        {
          "title": "Palo Alto Networks Cortex Cloud: official product documentation",
          "url": "https://www.paloaltonetworks.com/cortex/cloud"
        },
        {
          "title": "Palo Alto Networks Cortex Cloud: official supporting source",
          "url": "https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era"
        },
        {
          "title": "Palo Alto Networks Cortex Cloud: official supporting source",
          "url": "https://www.paloaltonetworks.com/prisma/cloud"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Orca Security",
      "company": "Orca Security",
      "segment": "cloud-security",
      "category": "Agentless scanning and runtime CNAPP",
      "url": "https://atlasofsecurity.com/landscape/vendors/orca-security/",
      "description": "Orca Security combines agentless cloud and workload scanning with exposure analysis and separate runtime sensing. Its SideScanning approach examines supported workload state without installing an agent on every scanned workload. That makes the distinction between recorded disk state and live process behavior a useful starting point for evaluation.",
      "scope": "SideScanning and Orca Sensor serve different purposes. Confirm snapshot or disk access, supported workload types and runtime sensor requirements. Agentless assessment should not be described as continuous process prevention merely because it identifies a vulnerable package.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Orca Security: official product documentation",
          "url": "https://orca.security/platform"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "CrowdStrike Falcon Cloud Security",
      "company": "CrowdStrike",
      "segment": "cloud-security",
      "category": "Cloud posture and workload protection",
      "url": "https://atlasofsecurity.com/landscape/vendors/crowdstrike-falcon-cloud-security/",
      "description": "Falcon Cloud Security extends CrowdStrike’s portfolio into cloud posture, workload protection and cloud detection. It combines agentless and sensor-based approaches across documented services. Existing endpoint deployment can simplify some operational familiarity, but it is not evidence that every cloud account, container or entitlement is already assessed.",
      "scope": "Cloud Security, container protection and managed offerings have separate packaging and coverage. Confirm the feature matrix for each cloud and workload; an agentless posture connection does not establish the same protection as a configured workload sensor.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "CrowdStrike Falcon Cloud Security: official product documentation",
          "url": "https://www.crowdstrike.com/en-gb/platform/cloud-security/cnapp/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Sysdig",
      "company": "Sysdig",
      "segment": "cloud-security",
      "category": "Runtime-focused cloud and Kubernetes security",
      "url": "https://atlasofsecurity.com/landscape/vendors/sysdig/",
      "description": "Sysdig uses runtime information to support cloud threat detection and vulnerability prioritization, with a strong Kubernetes and Linux orientation. Knowing a package is present differs from knowing it is used by a running workload. Both kinds of evidence can inform a decision, without making unused software harmless.",
      "scope": "Runtime sensing, posture and Kubernetes assessment have different deployment requirements. Falco and eBPF-related detection require supported instrumentation; an API-only posture connection does not provide the same process visibility. Verify kernel, cluster and workload support before rollout.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Sysdig: official product documentation",
          "url": "https://www.sysdig.com/solutions/cloud-native-application-protection-platform-cnapp"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Fortinet FortiCNAPP",
      "company": "Fortinet",
      "segment": "cloud-security",
      "category": "Posture, workload and development security",
      "url": "https://atlasofsecurity.com/landscape/vendors/fortinet-forticnapp/",
      "description": "FortiCNAPP combines cloud configuration, identity, workload and development-security capabilities with Lacework lineage. Its behavioral analysis can add context to activity, while posture checks examine the configuration itself. The practical goal is to understand which signal supports a finding before deciding who should investigate or change the resource.",
      "scope": "Confirm the current FortiCNAPP edition and the modules retained in any existing Lacework deployment. Agentless control-plane collection and workload agents have different visibility; a shared platform name does not mean every runtime or development function is enabled.",
      "lifecycle": {
        "status": "current",
        "note": "Fortinet completed the Lacework acquisition effective 1 August 2024. Current materials use FortiCNAPP; verify edition and support details rather than inferring retirement from the acquisition."
      },
      "sources": [
        {
          "title": "Fortinet FortiCNAPP: official product documentation",
          "url": "https://investor.fortinet.com/news-releases/news-release-details/fortinet-completes-acquisition-lacework/"
        },
        {
          "title": "Fortinet FortiCNAPP: official supporting source",
          "url": "https://www.fortinet.com/products/forticnapp"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Tenable Cloud Security",
      "company": "Tenable",
      "segment": "cloud-security",
      "category": "Cloud exposure and entitlement management",
      "url": "https://atlasofsecurity.com/landscape/vendors/tenable-cloud-security/",
      "description": "Tenable Cloud Security brings cloud configuration, identity and workload context into an exposure-management portfolio. A learner can use it to examine why an exposed resource matters in its environment, rather than treating every misconfiguration or vulnerability as an isolated record with the same remediation priority.",
      "scope": "This profile covers the documented Cloud Security and Cloud Exposure capability areas. Verify selected modules, cloud connectors and runtime requirements. Existing Tenable vulnerability-management coverage does not automatically establish cloud entitlement, container or runtime visibility.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Tenable Cloud Security: official product documentation",
          "url": "https://www.tenable.com/cloud-security"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Check Point CloudGuard and Wiz CNAPP",
      "company": "Check Point",
      "segment": "cloud-security",
      "category": "CNAPP transition and cloud network security",
      "url": "https://atlasofsecurity.com/landscape/vendors/checkpoint-cloudguard/",
      "description": "Check Point’s current CNAPP path involves its Wiz partnership, while CloudGuard also names cloud network-security products. This is a useful example of why a product family cannot be treated as one lifecycle. A CNAPP transition can affect contracts and workflows without retiring the vendor’s firewall or web-application firewall.",
      "scope": "Scope the existing Check Point CNAPP deployment separately from Cloud Firewall and web-application firewall products. Use the partnership FAQ for migration planning; older CNAPP marketing pages should not be treated as proof that every module remains unchanged.",
      "lifecycle": {
        "status": "transition",
        "note": "Check Point’s FAQ permits existing Check Point CNAPP use through the end of 2026 and identifies Wiz as the only CNAPP option from 2027. Cloud Firewall and WAF are explicitly outside that change."
      },
      "sources": [
        {
          "title": "Check Point CloudGuard and Wiz CNAPP: official product documentation",
          "url": "https://www.checkpoint.com/about-us/check-point-and-wiz-partnership-faq"
        },
        {
          "title": "Check Point CloudGuard and Wiz CNAPP: official supporting source",
          "url": "https://www.checkpoint.com/cloudguard/wiz/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Aqua Security",
      "company": "Aqua Security",
      "segment": "cloud-security",
      "category": "Container and cloud workload security",
      "url": "https://atlasofsecurity.com/landscape/vendors/aqua-security/",
      "description": "Aqua Security connects software and image assessment with cloud posture and runtime controls. Its container-oriented examples help explain the difference between preventing a risky image from entering a pipeline and observing behavior after deployment. Neither stage removes the need to identify who owns the application and its fixes.",
      "scope": "The platform documents several deployment and workload patterns, but coverage must be confirmed for the chosen environment. Image scanning, pipeline controls and runtime enforcement require different integrations; product assurances or authorization claims should not replace a scoped technical evaluation.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Aqua Security: official product documentation",
          "url": "https://www.aquasec.com/products/aqua-cloud-native-security-platform/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "TrendAI Vision One Cloud Security",
      "company": "Trend Micro",
      "segment": "cloud-security",
      "category": "Cloud posture within a broader security platform",
      "url": "https://atlasofsecurity.com/landscape/vendors/trendai-cloud-security/",
      "description": "TrendAI Vision One provides cloud-account connections and security functions within Trend Micro’s wider platform. Supported clouds do not all expose the same features. For a learner, the essential task is reading the feature matrix and distinguishing account posture from image, disk, container and runtime protection.",
      "scope": "Current documentation uses TrendAI Vision One, formerly Trend Vision One. Check the cloud-account comparison for each requested capability, and scope agents, integrations and subscriptions separately. Agentless disk or image scanning is not equivalent to host runtime monitoring.",
      "lifecycle": {
        "status": "current",
        "note": "Official documentation identifies TrendAI Vision One as the current name and Trend Vision One as the former name. Verify product and subscription details separately from branding."
      },
      "sources": [
        {
          "title": "TrendAI Vision One Cloud Security: official product documentation",
          "url": "https://docs.trendmicro.com/en-us/documentation/article/trend-vision-one-cloud-account-comparison"
        },
        {
          "title": "TrendAI Vision One Cloud Security: official supporting source",
          "url": "https://success.trendmicro.com/en-US/solution/KA-0011166"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Upwind",
      "company": "Upwind",
      "segment": "cloud-security",
      "category": "Runtime-focused CNAPP",
      "url": "https://atlasofsecurity.com/landscape/vendors/upwind/",
      "description": "Upwind combines runtime sensing with agentless cloud assessment to provide context about running applications and exposure. Live inventory and process evidence can help a team understand how a workload behaves. They also depend on sensor placement, supported environments and the quality of the signals actually collected.",
      "scope": "This profile covers the documented CNAPP approach, including agentless assessment and separately deployed runtime sensors. Verify platform and workload support in a lab; marketing claims about detection speed or reduced noise are not independent performance evidence.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Upwind: official product documentation",
          "url": "https://docs.upwind.io/public/introduction/concepts/upwind-cnapp"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Black Duck Polaris, Coverity, and SCA",
      "company": "Black Duck",
      "segment": "application-security",
      "category": "Application security testing and software composition analysis",
      "url": "https://atlasofsecurity.com/landscape/vendors/black-duck/",
      "description": "Black Duck is an independent application-security testing and composition-analysis portfolio. The current identity is Black Duck Software, Inc., the former Synopsys Software Integrity Group after the 2024 rebrand. Do not treat Synopsys AppSec as the live product name.",
      "scope": "The broader portfolio includes static, dynamic, interactive, composition, and protocol testing. Confirm language coverage, deployment and data flows, module entitlements, and the current contracting and support entity for an existing agreement.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Black Duck",
          "url": "https://www.blackduck.com/"
        },
        {
          "title": "Black Duck Software independent brand announcement",
          "url": "https://news.blackduck.com/2024-10-01-Introducing-Black-Duck-Software-The-Leader-in-Application-Security-Has-a-New-Name"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Checkmarx One",
      "company": "Checkmarx",
      "segment": "application-security",
      "category": "Application security platform",
      "url": "https://atlasofsecurity.com/landscape/vendors/checkmarx-one/",
      "description": "Checkmarx One is a commercial platform spanning application security testing and posture management. The vendor describes static and dynamic testing, composition analysis, infrastructure as code, containers, secrets, application programming interface checks, malicious-package detection, and ASPM analytics, with Developer Assist for the authoring loop.",
      "scope": "Source-upload versus air-gap deployment, Fusion or hybrid engine accuracy on the local stack, and whether ASPM can land analytics without locking to Checkmarx scanners are buyer tests. Documentation describes ASPM as a landing analytics surface rather than a replacement engine.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Checkmarx One application security platform",
          "url": "https://checkmarx.com/product/application-security-platform/"
        },
        {
          "title": "Checkmarx documentation navigation",
          "url": "https://docs.checkmarx.com/en/34965-196679-navigation-panel.html"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Veracode ARM platform",
      "company": "Veracode",
      "segment": "application-security",
      "category": "Application risk management",
      "url": "https://atlasofsecurity.com/landscape/vendors/veracode/",
      "description": "Veracode's application risk management platform is a binary-analysis and software-as-a-service assurance path. The vendor describes static and dynamic testing, composition analysis, a package firewall after the 2025 Phylum acquisition, container and infrastructure-as-code scanning, Risk Manager after Longbow in 2024, and Fix assistance.",
      "scope": "Binary-only analysis, pipeline-scan latency, and a cloud-only constraint versus regulated on-premises needs are the main boundary tests. Dynamic testing belongs on non-production sites. Package-firewall and Risk Manager modules should be confirmed as entitled rather than assumed from the platform name.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Veracode application security and compliance",
          "url": "https://www.veracode.com/application-security-compliance/"
        },
        {
          "title": "Veracode DAST documentation",
          "url": "https://docs.veracode.com/r/DAST"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Snyk",
      "company": "Snyk",
      "segment": "application-security",
      "category": "Developer-workflow application security",
      "url": "https://atlasofsecurity.com/landscape/vendors/snyk/",
      "description": "Snyk is a developer-workflow suite covering open-source composition analysis, Snyk Code static analysis, secrets, containers, infrastructure as code, and API and web DAST. Official documentation describes editor, command-line, and source-control integrations. Public plan pages exist; regional hosting and enterprise governance still need confirmation.",
      "scope": "Reachability versus raw CVE volume, regional hosting, and trial versus Enterprise governance are the evaluation surface. IDE, CLI, and source-control seating is the intended workflow. DAST remains a running-app test and should stay off production.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "What is Snyk",
          "url": "https://docs.snyk.io/whats-snyk"
        },
        {
          "title": "Snyk plans",
          "url": "https://snyk.io/plans/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "GitHub Code Security and GitHub Secret Protection",
      "company": "GitHub (Microsoft)",
      "segment": "application-security",
      "category": "Source-control native code and secret security",
      "url": "https://atlasofsecurity.com/landscape/vendors/github-advanced-security/",
      "description": "GitHub Code Security and GitHub Secret Protection are separate stock-keeping units in the Advanced Security family. Code Security covers code scanning, dependency review, Dependabot extras, and Copilot Autofix. Secret Protection covers secret scanning, push protection, and custom patterns. Several features remain free on public repositories; private and internal repositories require GitHub Team or Enterprise purchases of the relevant SKU.",
      "scope": "Do not assume one license covers secrets and code. Secret push protection and branch protection are distinct controls. Committer metering and languages outside CodeQL are separate tests. Public-repository entitlements do not automatically apply to private repositories.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "About GitHub Advanced Security",
          "url": "https://docs.github.com/en/get-started/learning-about-github/about-github-advanced-security"
        },
        {
          "title": "GitHub Advanced Security billing",
          "url": "https://docs.github.com/en/billing/concepts/product-billing/github-advanced-security"
        },
        {
          "title": "GitHub supported secret scanning patterns",
          "url": "https://docs.github.com/en/code-security/reference/secret-security/supported-secret-scanning-patterns"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "GitLab SAST and dependency scanning",
      "company": "GitLab",
      "segment": "application-security",
      "category": "Source-control and CI application security",
      "url": "https://atlasofsecurity.com/landscape/vendors/gitlab-application-security/",
      "description": "GitLab integrates application security with source control and continuous integration. Standard SAST analyzers are available across Free, Premium, and Ultimate. Dependency scanning and Advanced SAST require Ultimate under the reviewed documentation. Keep scanner availability distinct from the security views, policies, and vulnerability-management experience included in a tier.",
      "scope": "Confirm each analyzer and reporting feature against the deployed GitLab version and tier. Self-managed hosting changes operational responsibilities; it does not remove license requirements. Use review apps or staging for the dynamic-testing exercise.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "GitLab SAST documentation",
          "url": "https://docs.gitlab.com/user/application_security/sast/"
        },
        {
          "title": "GitLab dependency scanning documentation",
          "url": "https://docs.gitlab.com/user/application_security/dependency_scanning/"
        },
        {
          "title": "GitLab on-demand DAST warning",
          "url": "https://docs.gitlab.com/user/application_security/dast/on-demand_scan/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Semgrep AppSec Platform",
      "company": "Semgrep",
      "segment": "application-security",
      "category": "Custom-rule static analysis and supply-chain platform",
      "url": "https://atlasofsecurity.com/landscape/vendors/semgrep/",
      "description": "Semgrep offers pattern-based static analysis in Community Edition and a commercial AppSec Platform. The platform adds a Pro engine, supply-chain reachability, secrets detection, and SBOM capabilities. Custom rules are the distinctive teaching point: teams can write patterns for local frameworks instead of waiting on a generic rule pack.",
      "scope": "Community Edition versus paid rule quality, lockfile layout for supply-chain results, and interfile analysis on monorepos are the main tests. Community Edition is SAST patterns; composition reachability, secrets, and SBOM are platform features and should not be assumed in the free engine.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Semgrep documentation",
          "url": "https://docs.semgrep.dev/"
        },
        {
          "title": "Semgrep AppSec Platform",
          "url": "https://semgrep.dev/products/semgrep-appsec-platform/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "SonarQube Advanced Security",
      "company": "SonarSource",
      "segment": "application-security",
      "category": "Quality platform with paid software composition analysis",
      "url": "https://atlasofsecurity.com/landscape/vendors/sonarqube-advanced-security/",
      "description": "SonarQube Advanced Security adds paid composition analysis and advanced static analysis to the quality platform. Dependency vulnerability and license-policy checks, SBOM import, and analysis modes have separate boundaries. The reviewed Enterprise-and-above requirement applies to the Advanced Security add-on on SonarQube Server, not to SonarQube Server itself.",
      "scope": "The Advanced Security add-on requires an eligible Server edition and entitlement. Verify documented cloud-analysis and local-parsing data flows before enabling either mode; local parsing is not an air-gap guarantee. Compare its results with existing SCA coverage.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "SonarQube Server Advanced Security dependency analysis",
          "url": "https://docs.sonarsource.com/sonarqube-server/advanced-security/analyzing-projects-for-dependencies"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "HCL AppScan",
      "company": "HCLSoftware",
      "segment": "application-security",
      "category": "Application security testing",
      "url": "https://atlasofsecurity.com/landscape/vendors/hcl-appscan/",
      "description": "HCL AppScan is an IBM-heritage application-security testing family now under HCLSoftware. The vendor describes static, dynamic, and interactive testing, composition analysis, application programming interface checks, secrets, containers, and infrastructure as code, with cloud and self-managed 360° options including air-gap and sovereign deployments.",
      "scope": "Product SKU sprawl is the main teaching hazard: Standard, Enterprise, Source, on Cloud, and 360° are not interchangeable. Correlation of SAST and DAST, and whether self-managed air-gap actually matches the needed engines, must be proven per SKU.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "HCL AppScan",
          "url": "https://www.hcl-software.com/appscan"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "OpenText Fortify Static Code Analyzer",
      "company": "OpenText",
      "segment": "application-security",
      "category": "Static application security testing",
      "url": "https://atlasofsecurity.com/landscape/vendors/opentext-fortify/",
      "description": "OpenText Fortify Static Code Analyzer is a static-testing product known for legacy-language breadth, including COBOL and ABAP. The vendor describes broad language and framework support plus remediation assistance. A broader OpenText Application Security portfolio includes software-as-a-service and self-managed testing around that static core.",
      "scope": "Audit Workbench style review, false-positive handling, and the OpenText versus former Micro Focus contract and support path are operational boundaries. Language-list marketing does not prove the team's compiler and framework are modeled. Self-managed analysis is a reason teams still evaluate Fortify for regulated code.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "OpenText Fortify Static Code Analyzer",
          "url": "https://www.opentext.com/products/fortify-static-code-analyzer"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Mend.io",
      "company": "Mend.io",
      "segment": "application-security",
      "category": "Software composition analysis and developer remediation",
      "url": "https://atlasofsecurity.com/landscape/vendors/mend/",
      "description": "Mend.io provides composition analysis alongside static analysis, container scanning, reachability, and Renovate-based dependency-update workflows. Evaluate each module separately on the codebase: strong dependency results do not establish how a static analyzer models first-party code, and an automated update still needs review and regression checks.",
      "scope": "Renovate merge risk, container coverage, and evidence export are part of the product boundary. Reachability can reduce noise and can also hide shipped components. WhiteSource is a historical name; current brand is Mend.io.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Mend.io",
          "url": "https://www.mend.io/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Endor Labs",
      "company": "Endor Labs",
      "segment": "application-security",
      "category": "Reachability-first composition analysis",
      "url": "https://atlasofsecurity.com/landscape/vendors/endor-labs/",
      "description": "Endor Labs is a reachability-first composition-analysis product with additional vendor-described controls: a package firewall, artificial-intelligence assisted static analysis, secrets, containers, and Model Context Protocol integration into coding agents. The teaching point is call-graph-based reachability plus intake control, not another undifferentiated CVE list.",
      "scope": "Call-graph completeness, Bazel and monorepo support, and the difference between a free Model Context Protocol integration and an enterprise policy plane are buyer tests. Reachability can hide unused-but-shipped components that still belong on an SBOM.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Endor Labs",
          "url": "https://www.endorlabs.com/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Legit Security",
      "company": "Legit Security",
      "segment": "application-security",
      "category": "Application security posture and SDLC discovery",
      "url": "https://atlasofsecurity.com/landscape/vendors/legit-security/",
      "description": "Legit Security is an ASPM and software-development-lifecycle discovery product with vendor-described artificial-intelligence integrated-development-environment guardrails (VibeGuard). It can use native or ingested SAST and SCA, look for secrets beyond git, assess continuous-integration posture, and produce SBOMs. The distinctive choice is discovering the toolchain and correlating it, not replacing every engine.",
      "scope": "Discovery coverage of the actual toolchain, and whether ASPM works without ripping out existing scanners, are the evaluation surface. Secrets beyond git and CI/CD posture checks need authorized access to those systems. VibeGuard is vendor-described until tested in the team's own agentic workflow.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Legit Security",
          "url": "https://www.legitsecurity.com/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Chainguard",
      "company": "Chainguard",
      "segment": "application-security",
      "category": "Hardened rebuilds and provenance",
      "url": "https://atlasofsecurity.com/landscape/vendors/chainguard/",
      "description": "Chainguard supplies hardened open-source containers, libraries, and virtual machines rebuilt with component inventories and build-provenance evidence. Evaluate compatibility and the evidence accompanying each artifact. Replacing a base image still leaves first-party application code and added third-party dependencies for the team to assess.",
      "scope": "Check artifact compatibility, update availability, and provenance policy. Hardened base artifacts do not replace static analysis of first-party application code or composition analysis of the dependencies added by that application. Provenance describes origin and build evidence, not freedom from bugs.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Chainguard",
          "url": "https://www.chainguard.dev/"
        },
        {
          "title": "SLSA",
          "url": "https://slsa.dev/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "JFrog Xray, Advanced Security, and Curation",
      "company": "JFrog",
      "segment": "application-security",
      "category": "Artifact-registry security",
      "url": "https://atlasofsecurity.com/landscape/vendors/jfrog-security/",
      "description": "JFrog centers security on the artifact registry. Xray provides dependency analysis on artifacts already in Artifactory. Advanced Security is a documented add-on with Enterprise X or Enterprise+ that adds contextual analysis, SAST, secrets, and infrastructure as code. Curation addresses package intake. The teaching choice is registry admission and artifact context, not an IDE-first scanner.",
      "scope": "What Artifactory and Xray already cover, Advanced Security add-on entitlements, repository policy latency, and metadata or source handling must be confirmed. Registry policy is not builder isolation, and a signature elsewhere does not replace Xray's artifact analysis.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "JFrog Advanced Security documentation",
          "url": "https://docs.jfrog.com/security/docs/advanced-security"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Microsoft Purview Data Security",
      "company": "Microsoft",
      "segment": "data-security",
      "category": "Classification, DLP and posture",
      "url": "https://atlasofsecurity.com/landscape/vendors/microsoft-purview/",
      "description": "Microsoft Purview brings together tools for finding sensitive information, labeling it, examining exposure, and applying data loss prevention policies. For practitioners, the useful distinction is between identifying a sensitive document and enforcing a rule when someone shares that document.",
      "scope": "This profile covers Information Protection, data loss prevention and data security posture management. Coverage varies by licensed workload and connector; encryption and customer key options are separate decisions, not properties of every label.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Microsoft Purview Data Security: official product evidence",
          "url": "https://learn.microsoft.com/en-us/purview/purview-security"
        },
        {
          "title": "Microsoft Purview Data Security: official supporting evidence",
          "url": "https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Varonis Data Security Platform",
      "company": "Varonis",
      "segment": "data-security",
      "category": "Data posture and access governance",
      "url": "https://atlasofsecurity.com/landscape/vendors/varonis/",
      "description": "Varonis examines sensitive information together with the permissions and activity around it. Its central teaching example is an ordinary file that becomes risky because a broad group or public link can access it, even when the storage service itself is configured correctly.",
      "scope": "This profile centers on discovery, permission analysis and access remediation for supported data stores. Agentless or API-based controls where data resides should not be assumed to block endpoint printing, removable media or every upload path.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Varonis Data Security Platform: official product evidence",
          "url": "https://www.varonis.com/platform/dspm"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Cyera Data Security",
      "company": "Cyera",
      "segment": "data-security",
      "category": "Data posture and DLP orchestration",
      "url": "https://atlasofsecurity.com/landscape/vendors/cyera/",
      "description": "Cyera discovers sensitive data and relates it to exposure across supported cloud, software-as-a-service and other repositories. Its platform also describes DLP orchestration and identity capabilities, so a learner should ask which component finds risk, which changes access, and which inspects actual data movement.",
      "scope": "DSPM, Omni DLP and identity capabilities are distinct coverage areas. The Oasis acquisition adds identity context to the portfolio; it does not establish that every integration is deployed or that posture scanning blocks every transfer.",
      "lifecycle": {
        "status": "current",
        "note": "Cyera announced completion of the Oasis Security acquisition on 3 September 2026. Acquisition alone does not establish the availability of every integration."
      },
      "sources": [
        {
          "title": "Cyera Data Security: official product evidence",
          "url": "https://www.cyera.com/platform/dspm"
        },
        {
          "title": "Cyera Data Security: official supporting evidence",
          "url": "https://www.cyera.com/press-releases/cyera-completes-acquisition-of-oasis-security"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "BigID",
      "company": "BigID",
      "segment": "data-security",
      "category": "Discovery, posture and privacy governance",
      "url": "https://atlasofsecurity.com/landscape/vendors/bigid/",
      "description": "BigID connects security and privacy work through an inventory of sensitive data. Discovery and classification help identify what is stored; posture analysis adds exposure and access context. A shared inventory can support several teams without making privacy workflow and DLP enforcement the same control.",
      "scope": "This profile covers discovery, classification, posture and related data governance. Scope remediation by connector and data store; a listed cloud DLP capability is not evidence that every endpoint or network channel can block a transfer.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "BigID: official product evidence",
          "url": "https://bigid.com/data-security-posture-management"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Securiti AI within Veeam",
      "company": "Securiti AI",
      "segment": "data-security",
      "category": "Data discovery and governance",
      "url": "https://atlasofsecurity.com/landscape/vendors/veeam-securiti/",
      "description": "Securiti AI contributes data discovery, classification, posture and privacy governance to Veeam’s portfolio. These capabilities help explain where sensitive information resides and how it is handled. Their relationship to backup and recovery is useful to study, but a combined corporate portfolio is not automatically one integrated deployment.",
      "scope": "The reviewed completion announcement supports the acquisition and described capability areas. It does not verify every current connector, generally available integration, runtime blocking feature or combined backup and governance workflow; evaluate those explicitly.",
      "lifecycle": {
        "status": "current",
        "note": "Veeam completed the Securiti AI acquisition on 11 December 2025. The reviewed announcement describes strategic direction, not proof that all combined features are generally available."
      },
      "sources": [
        {
          "title": "Securiti AI within Veeam: official product evidence",
          "url": "https://www.veeam.com/company/press-release/veeam-acquires-securiti-ai.html"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Forcepoint DLP",
      "company": "Forcepoint",
      "segment": "data-security",
      "category": "Enterprise DLP across channels",
      "url": "https://atlasofsecurity.com/landscape/vendors/forcepoint-dlp/",
      "description": "Forcepoint DLP applies content policies across documented endpoint, email, web and cloud channels. The practical task is translating a data-handling rule into detection and an appropriate action, while preserving legitimate work. Its separate posture offering can inform that task by identifying sensitive information and exposure.",
      "scope": "Treat Forcepoint DLP and DSPM as complementary products. Deployment and channel coverage depend on the selected components, connectors and subscription; verify disconnected or on-premises operation instead of assuming cloud and local deployments behave identically.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Forcepoint DLP: official product evidence",
          "url": "https://www.forcepoint.com/product/dlp-data-loss-prevention"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Proofpoint Enterprise DLP",
      "company": "Proofpoint",
      "segment": "data-security",
      "category": "Email, cloud and endpoint DLP",
      "url": "https://atlasofsecurity.com/landscape/vendors/proofpoint-dlp/",
      "description": "Proofpoint’s data loss prevention portfolio combines content inspection with user activity and threat context. An email sent to the wrong recipient and a departing employee’s unusual copying behavior illustrate different investigations. The same vendor’s email, cloud, endpoint and posture offerings still need separate coverage decisions.",
      "scope": "This profile covers Enterprise DLP and adjacent information protection capabilities. Confirm each channel and data-store integration; evidence of email detection does not establish endpoint enforcement, complete discovery or automatic posture remediation in every deployment.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Proofpoint Enterprise DLP: official product evidence",
          "url": "https://www.proofpoint.com/us/products/data-loss-prevention"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Symantec Data Loss Prevention",
      "company": "Symantec Enterprise",
      "segment": "data-security",
      "category": "Hybrid enterprise DLP",
      "url": "https://atlasofsecurity.com/landscape/vendors/symantec-dlp/",
      "description": "Symantec Data Loss Prevention, documented by Broadcom, uses a policy and detection architecture for discovering sensitive content and inspecting its movement. Matching a protected customer dataset is different from matching a generic pattern, so the detection method matters as much as the channel carrying the content.",
      "scope": "This is the enterprise DLP product, not consumer security software. Core, Cloud and self-managed components have distinct dependencies. Confirm the supported release, upgrade path and database, management-server and detection-server responsibilities for the chosen deployment.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Symantec Data Loss Prevention: official product evidence",
          "url": "https://techdocs.broadcom.com/us/en/symantec-security-software/information-security/data-loss-prevention/25-1.html"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Netskope One DLP",
      "company": "Netskope",
      "segment": "data-security",
      "category": "Cloud, web and endpoint DLP",
      "url": "https://atlasofsecurity.com/landscape/vendors/netskope-dlp/",
      "description": "Netskope One DLP inspects sensitive information across documented cloud, web and other channels. It can combine inline inspection with API-based examination of SaaS content. These are different observation points: a routed upload, a stored document and an offline endpoint do not have the same enforcement path.",
      "scope": "Endpoint DLP and DSPM require explicit scope and entitlement checks. Routed traffic depends on its inspection path, endpoint enforcement on the applicable client, and SaaS API controls on connector permissions and supported actions rather than network routing alone.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Netskope One DLP: official product evidence",
          "url": "https://www.netskope.com/products/data-loss-prevention"
        },
        {
          "title": "Netskope One DLP: official supporting evidence",
          "url": "https://docs.netskope.com/en/data-loss-prevention/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Zscaler Data Loss Prevention",
      "company": "Zscaler",
      "segment": "data-security",
      "category": "Inline, endpoint and SaaS DLP",
      "url": "https://atlasofsecurity.com/landscape/vendors/zscaler-dlp/",
      "description": "Zscaler DLP applies content policy through cloud inspection, endpoint and supported SaaS controls. A practitioner needs to distinguish inspection of an outbound connection from scanning data already stored in an application. A shared policy interface does not eliminate differences in routing, clients or supported remediation actions.",
      "scope": "This profile covers the documented DLP channels, including Zscaler Internet Access, endpoint and SaaS data at rest. Endpoint functions require the applicable Client Connector configuration; broad database or data-lake inventory is a separate evaluation question.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Zscaler Data Loss Prevention: official product evidence",
          "url": "https://www.zscaler.com/products-and-solutions/data-loss-prevention"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Nightfall AI",
      "company": "Nightfall AI",
      "segment": "data-security",
      "category": "SaaS, browser and AI DLP",
      "url": "https://atlasofsecurity.com/landscape/vendors/nightfall-ai/",
      "description": "Nightfall AI focuses on sensitive information in collaboration tools, browsers and AI workflows. Its useful learning scenario is a developer or analyst pasting synthetic sensitive content into an application. Discovery, classification and prevention depend on how the specific application and device are connected to the product.",
      "scope": "Scope SaaS integrations, browser or device controls, and AI channels separately. Vendor accuracy or cost claims are not independent evidence. This coverage should not be assumed to replace database activity monitoring or every traditional network DLP deployment.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Nightfall AI: official product evidence",
          "url": "https://www.nightfall.ai/home"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Rubrik Security Cloud DSPM",
      "company": "Rubrik",
      "segment": "data-security",
      "category": "Data posture with recovery context",
      "url": "https://atlasofsecurity.com/landscape/vendors/rubrik-dspm/",
      "description": "Rubrik’s data security posture management identifies sensitive information and exposure alongside a broader recovery portfolio. The educational value is connecting data importance to security and recovery decisions. Discovery, permission analysis, channel blocking and restoring a backup are distinct operations, even when one vendor supplies several of them.",
      "scope": "Reviewed integration materials describe DSPM, access governance and related Microsoft 365 protection. Current packaging needs verification: the main product page was inaccessible during research, and documentation does not establish every capability for every storage platform or edition.",
      "lifecycle": {
        "status": "current",
        "note": "Rubrik’s filing confirms the Laminar acquisition in August 2023. Later integration materials support the described DSPM direction; verify current product packaging before evaluation."
      },
      "sources": [
        {
          "title": "Rubrik Security Cloud DSPM: official product evidence",
          "url": "https://www.sec.gov/Archives/edgar/data/1943896/000194389624000018/rbrk-20240731.htm"
        },
        {
          "title": "Rubrik Security Cloud DSPM: official supporting evidence",
          "url": "https://www.rubrik.com/blog/company/25/data-security-posture-management-dspm-integration-with-rubrik-security-cloud-reduces-risk-for-customers"
        },
        {
          "title": "Rubrik Security Cloud DSPM: official supporting evidence",
          "url": "https://www.rubrik.com/solutions/microsoft-365"
        },
        {
          "title": "Rubrik Security Cloud DSPM: official supporting evidence",
          "url": "https://www.rubrik.com/company/newsroom/press-releases/23/rubrik-acquires-dspm-leader-laminar-to-accelerate-cloud-data-security"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "IBM Guardium Data Security",
      "company": "IBM",
      "segment": "data-security",
      "category": "Database activity and data posture",
      "url": "https://atlasofsecurity.com/landscape/vendors/ibm-guardium/",
      "description": "IBM Guardium includes database activity monitoring, data protection and cloud posture products. Monitoring who queries a sensitive table teaches a different control from finding an exposed cloud dataset. The brand spans these jobs, so product names and deployment boundaries are important parts of an evaluation.",
      "scope": "Guardium Data Protection, DSPM and discovery offerings are distinct components. Key lifecycle and cryptography management are adjacent products; buying a database monitor does not automatically provide every posture, encryption or classification capability in the wider family.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "IBM Guardium Data Security: official product evidence",
          "url": "https://www.ibm.com/products/guardium-data-protection"
        },
        {
          "title": "IBM Guardium Data Security: official supporting evidence",
          "url": "https://www.ibm.com/products/guardium-dspm"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Thales Imperva Data Security Fabric",
      "company": "Imperva",
      "segment": "data-security",
      "category": "Data-store monitoring and protection",
      "url": "https://atlasofsecurity.com/landscape/vendors/thales-imperva/",
      "description": "Thales Imperva Data Security Fabric examines activity and risk around data stores. The wider Thales portfolio also provides encryption, tokenization and key management through CipherTrust. These capabilities can complement one another, but observing a database query and controlling the encryption key are different security responsibilities.",
      "scope": "This profile covers Data Security Fabric with clearly adjacent CipherTrust capabilities. Verify agent or agentless coverage per data store and the actual integration between products. It is not a general substitute for browser or security-service-edge DLP.",
      "lifecycle": {
        "status": "current",
        "note": "Thales completed the Imperva acquisition on 4 December 2023. Shared ownership does not mean every Data Security Fabric and CipherTrust deployment is automatically integrated."
      },
      "sources": [
        {
          "title": "Thales Imperva Data Security Fabric: official product evidence",
          "url": "https://cpl.thalesgroup.com/about-us/newsroom/thales-acquires-imperva-global-leader-in-cybersecurity-press-release"
        },
        {
          "title": "Thales Imperva Data Security Fabric: official supporting evidence",
          "url": "https://cpl.thalesgroup.com/data-security/data-security-fabric"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Cortex XSOAR and XSIAM",
      "company": "Palo Alto Networks",
      "segment": "security-operations",
      "category": "SOAR / automation software",
      "url": "https://atlasofsecurity.com/landscape/vendors/palo-alto-cortex-orchestration/",
      "description": "Cortex XSOAR is standalone security orchestration software with playbooks, a war room, marketplace content, and case management. Cortex XSIAM is a separate converged operations platform that embeds SIEM, XDR, and SOAR, including playbooks, Quick Actions, and automation rules.",
      "scope": "These are two licensed software products, not one SKU. The buyer staffs playbooks and owns credentials. XSIAM automation is not a staffed MDR service, and Unit 42 MDR is sold separately.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Cortex XSOAR",
          "url": "https://www.paloaltonetworks.com/cortex/cortex-xsoar"
        },
        {
          "title": "Cortex XSIAM",
          "url": "https://www.paloaltonetworks.com/cortex/cortex-xsiam"
        },
        {
          "title": "Automation in Cortex XSIAM",
          "url": "https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/automation-in-cortex-xsiam"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Splunk SOAR",
      "company": "Cisco",
      "segment": "security-operations",
      "category": "SOAR / automation software",
      "url": "https://atlasofsecurity.com/landscape/vendors/splunk-soar/",
      "description": "Splunk SOAR is licensed orchestration software, offered in cloud and on-premises forms, that automates playbooks and case management. Cisco owns Splunk. This profile is the software playbook plane, not a Cisco managed detection and response service.",
      "scope": "Buyers staff the platform and own connector credentials. Splunk apps can export events into SOAR. The product is software the customer operates, not a staffed SOC.",
      "lifecycle": {
        "status": "current",
        "note": "Cisco closed the Splunk acquisition on 18 March 2024. Splunk SOAR remains current software under Cisco, not a Cisco MDR service."
      },
      "sources": [
        {
          "title": "Splunk SOAR documentation hub",
          "url": "https://help.splunk.com/en/splunk-soar"
        },
        {
          "title": "Cisco acquisition of Splunk",
          "url": "https://www.cisco.com/site/us/en/about/corporate-development/acquisitions/splunk/index.html"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Google Security Operations SOAR",
      "company": "Google",
      "segment": "security-operations",
      "category": "SOAR / automation software",
      "url": "https://atlasofsecurity.com/landscape/vendors/google-security-operations-soar/",
      "description": "Google Security Operations SOAR connects alerts, cases and response playbooks within Google’s security operations platform. Integrations and custom actions let analysts gather context and coordinate supported response steps, while the operating team remains responsible for permissions, workflow design and approvals.",
      "scope": "The SOAR component is part of the broader Security Operations portfolio. Confirm integration and deployment requirements independently of the SIEM; the customer or its service provider operates the playbooks.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Google Security Operations SOAR",
          "url": "https://docs.cloud.google.com/chronicle/docs/secops/google-secops-soar-toc"
        },
        {
          "title": "Google SecOps playbooks screen",
          "url": "https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/whats-on-the-playbooks-screen"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Tines",
      "company": "Tines",
      "segment": "security-operations",
      "category": "SOAR / automation software",
      "url": "https://atlasofsecurity.com/landscape/vendors/tines/",
      "description": "Tines is a practitioner-oriented workflow platform used as security automation without a classic SOAR label. Analysts can build drag-and-drop or natural-language workflows with an audit trail, case templates, and vendor-agnostic APIs.",
      "scope": "This is software the buyer operates. Governance controls and human approval exist so analysts can publish workflows under policy. MSSP features do not make Tines a staffed MDR service.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Tines security workflows",
          "url": "https://www.tines.com/solutions/security/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Torq",
      "company": "Torq",
      "segment": "security-operations",
      "category": "SOAR / automation software",
      "url": "https://atlasofsecurity.com/landscape/vendors/torq/",
      "description": "Torq sells workflow automation often marketed as AI SOC or hyperautomation. Documented building blocks include HyperAgents, a Socrates orchestrator, natural-language workflow building, and case handling. Outcome statistics on vendor pages are advertised, not independently tested here.",
      "scope": "This is licensed software the buyer configures and staffs. AI-assisted authoring still requires human control of go-live. Torq is not a managed detection and response service.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Torq",
          "url": "https://torq.io/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Turbine",
      "company": "Swimlane",
      "segment": "security-operations",
      "category": "SOAR / automation software",
      "url": "https://atlasofsecurity.com/landscape/vendors/swimlane-turbine/",
      "description": "Swimlane Turbine is a pure-play automation platform that claims SOC plus governance, risk, and vulnerability workflow uses. It offers a low-code canvas, case management, API connectors, and agentic routing of simple versus complex alerts.",
      "scope": "Software the buyer operates. Ask whether you need a system of record beyond incident playbooks. Test action permissions, workflow change control, and recovery from failed steps.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Swimlane Turbine",
          "url": "https://swimlane.com/swimlane-turbine/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "FortiSOAR",
      "company": "Fortinet",
      "segment": "security-operations",
      "category": "SOAR / automation software",
      "url": "https://atlasofsecurity.com/landscape/vendors/fortinet-fortisoar/",
      "description": "FortiSOAR is Fortinet's fabric-adjacent security orchestration product with SaaS and self-managed options. It documents playbooks, case management, expert agents, API and MCP connections, and multi-tenancy aimed at managed service providers. OT-oriented packs are advertised.",
      "scope": "Software the buyer or an MSSP staffs. Connector counts change over time. OT playbooks are a capability claim to test, not a plant-safety certification or sign-off.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "FortiSOAR",
          "url": "https://www.fortinet.com/products/fortisoar"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Rapid7 Automation",
      "company": "Rapid7",
      "segment": "security-operations",
      "category": "SOAR / automation software",
      "url": "https://atlasofsecurity.com/landscape/vendors/rapid7-insightconnect/",
      "description": "Rapid7 Automation, documented under the InsightConnect name, provides security workflows that connect tools, enrich alerts and coordinate response. Analysts can combine plugins and human decision steps to make a repeatable process while retaining responsibility for its permissions and operation.",
      "scope": "No-code workflows connect supported services, while an Insight Orchestrator can execute actions within the customer’s network. This software has a different scope from Rapid7’s managed detection and response service.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Rapid7 Automation (InsightConnect) documentation",
          "url": "https://docs.rapid7.com/insightconnect/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Falcon Complete",
      "company": "CrowdStrike",
      "segment": "security-operations",
      "category": "Managed detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/crowdstrike-falcon-complete/",
      "description": "Falcon Complete is CrowdStrike's native-platform managed detection and response service. Provider analysts detect, investigate, and, when contracted, remediate using Falcon telemetry across endpoint, identity, cloud, SaaS, and optional third-party sources through Next-Gen SIEM.",
      "scope": "This is a staffed service on Falcon, not Falcon Insight endpoint detection and response and not Next-Gen SIEM as a product buy. Warranty language is a separate legal instrument, not unlimited incident response.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Falcon Complete next-gen MDR",
          "url": "https://www.crowdstrike.com/en-us/services/falcon-complete-next-gen-mdr/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Defender Experts MDR",
      "company": "Microsoft",
      "segment": "security-operations",
      "category": "Managed detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/microsoft-defender-experts/",
      "description": "Defender Experts MDR is Microsoft-staffed managed detection and response that augments a customer security operations center. It was renamed from Defender Experts for XDR. Neither plan is an incident-response engagement, and Plan 2 is not managed SIEM.",
      "scope": "Plan 1 covers Microsoft Defender workloads, hunting, and Ask Experts. Plan 2 extends selected third-party sources in Microsoft Sentinel and provides response guidance for those third parties. Defender products are sold separately.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Defender Experts MDR overview",
          "url": "https://learn.microsoft.com/en-us/defender-xdr/defender-experts/defender-experts-mdr-overview"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Sophos MDR",
      "company": "Sophos",
      "segment": "security-operations",
      "category": "Managed detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/sophos-mdr/",
      "description": "Sophos MDR is a staffed managed detection and response service with around-the-clock monitoring, hunting, containment, flexible response modes, and third-party telemetry options. Secureworks is not a second vendor; Sophos closed that acquisition.",
      "scope": "Confirm the specific Sophos or Taegis offering and the incident-response work included in its tier. Sophos documents additional response services and warranty terms whose scope and conditions require separate review.",
      "lifecycle": {
        "status": "current",
        "note": "Sophos closed the Secureworks acquisition on 3 February 2025. Secureworks is not an independent MDR vendor in this catalog."
      },
      "sources": [
        {
          "title": "Sophos managed detection and response",
          "url": "https://www.sophos.com/en-gb/products/managed-detection-and-response"
        },
        {
          "title": "Sophos completes Secureworks acquisition",
          "url": "https://www.sophos.com/en-us/press/press-releases/2025/02/sophos-completes-secureworks-acquisition"
        },
        {
          "title": "Sophos MDR service tiers",
          "url": "https://docs.sophos.com/central/customer/help/en-us/ManageYourProducts/MDR/MDRServiceTiers/MDRComplete/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Aurora MDR",
      "company": "Arctic Wolf",
      "segment": "security-operations",
      "category": "Managed detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/arctic-wolf-mdr/",
      "description": "Aurora MDR is Arctic Wolf's concierge managed detection and response service. It advertises around-the-clock detect, respond, and remediate guidance, a Concierge Experience, and open XDR integrations. Cylance is an acquired endpoint product, not a peer MDR company.",
      "scope": "Incident response and Incident360 are other solutions, not automatic inside MDR. Managed containment depends on the customer's EDR and firewall access. IR hours may sit in a retainer rather than the MDR SKU.",
      "lifecycle": {
        "status": "current",
        "note": "Arctic Wolf closed the Cylance endpoint-asset acquisition on 3 February 2025. Cylance is an endpoint product, not a second MDR vendor."
      },
      "sources": [
        {
          "title": "Arctic Wolf managed detection and response",
          "url": "https://arcticwolf.com/solutions/managed-detection-and-response/"
        },
        {
          "title": "Arctic Wolf Cylance",
          "url": "https://arcticwolf.com/cylance/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Expel MDR",
      "company": "Expel",
      "segment": "security-operations",
      "category": "Managed detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/expel/",
      "description": "Expel MDR is a vendor-agnostic staffed service that investigates threats on the customer's existing endpoint, identity, and cloud tools. A workbench, around-the-clock SOC, and AI-assisted investigation (Ruxie) are advertised. Auto-remediation needs pre-authorization after analyst validation.",
      "scope": "Optional managed SIEM is a distinct offer. Advertised mean time to respond is vendor-reported, not an independent result. The customer keeps existing tools and still must authorize auto-remediation.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Expel managed detection and response",
          "url": "https://expel.com/services/managed-detection-and-response/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Zscaler MDR",
      "company": "Zscaler",
      "segment": "security-operations",
      "category": "Managed detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/zscaler-mdr/",
      "description": "Zscaler MDR provides staffed investigation of supported endpoint, cloud and identity threats. Its portal, automation and validation capabilities help customer teams understand provider findings and test the service. The Red Canary lineage is relevant when identifying current documentation and service entitlements.",
      "scope": "The service investigates integrated EDR, cloud, and identity threats. Do not assume Zero Trust Exchange coverage without the order form. Ask which EDR classes are supported in the purchased SKU.",
      "lifecycle": {
        "status": "current",
        "note": "Zscaler closed the Red Canary acquisition on 1 August 2025. Documentation now treats Red Canary as Zscaler MDR; the service remains current."
      },
      "sources": [
        {
          "title": "Zscaler managed detection and response",
          "url": "https://www.zscaler.com/products-and-solutions/managed-detection-and-response"
        },
        {
          "title": "Zscaler completes acquisition of Red Canary",
          "url": "https://www.zscaler.com/press/zscaler-completes-acquisition-red-canary-accelerate-innovations-agentic-ai-driven-security"
        },
        {
          "title": "Red Canary release notes (now Zscaler MDR)",
          "url": "https://docs.redcanary.com/docs/red-canary-release-notes"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "eSentire MDR",
      "company": "eSentire",
      "segment": "security-operations",
      "category": "Managed detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/esentire/",
      "description": "eSentire MDR is a multi-signal staffed service packaged as Atlas Essentials, Advanced, and Complete. It advertises around-the-clock hunt, investigate, and respond across endpoint, network, log, cloud, and identity packages, with Microsoft-ecosystem MXDR listed in Azure Marketplace.",
      "scope": "Package names are not proof of automatic containment. Digital forensics and incident response may be separate from the MDR SKU. Ask which signals sit in the chosen package.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "eSentire",
          "url": "https://www.esentire.com"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Huntress",
      "company": "Huntress",
      "segment": "security-operations",
      "category": "Managed detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/huntress/",
      "description": "Huntress offers managed endpoint, identity and log-monitoring services supported by a staffed security operations center. Its portfolio is relevant to IT teams and managed service providers evaluating which operational responsibilities to delegate and which product layers they actually need.",
      "scope": "Buying Managed EDR does not automatically include identity or log coverage. Define the purchased services and confirm any specialist forensics or incident-response support instead of inferring it from the managed stack.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Huntress platform",
          "url": "https://www.huntress.com/platform"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Rapid7 MDR",
      "company": "Rapid7",
      "segment": "security-operations",
      "category": "Managed detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/rapid7-mdr/",
      "description": "Rapid7 MDR combines a staffed security operations center, an advisor, hunting and exposure-informed investigations. The service works with customer teams under an agreed scope, so learners should distinguish provider investigation and response duties from the separate Rapid7 Automation software.",
      "scope": "The Elite scope of service frames a collaboration and excludes anything not listed. Telemetry onboarding, supported detections, response prerequisites, and customer responsibilities limit what the service can do.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "Rapid7 managed detection and response",
          "url": "https://www.rapid7.com/services/managed-detection-and-response-mdr/"
        },
        {
          "title": "Rapid7 MDR Elite scope of service",
          "url": "https://www.rapid7.com/globalassets/docs/managedservices/mdr-scope-of-service-elite.pdf"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    },
    {
      "name": "Wayfinder MDR",
      "company": "SentinelOne",
      "segment": "security-operations",
      "category": "Managed detection and response",
      "url": "https://atlasofsecurity.com/landscape/vendors/sentinelone-wayfinder/",
      "description": "Wayfinder MDR is SentinelOne's current platform-linked managed detection and response service. It advertises continuous detection, investigation, response, and hunting using SentinelOne and Google threat intelligence, with Essentials and Elite service levels. Older Vigilance and Singularity MDR materials are lineage, not the current order form.",
      "scope": "Verify which endpoint, cloud, and identity signals and response actions are in the selected service tier. Confirm IR access, warranty conditions, and customer duties separately from the current datasheet.",
      "lifecycle": {
        "status": "current",
        "note": ""
      },
      "sources": [
        {
          "title": "SentinelOne managed detection and response",
          "url": "https://www.sentinelone.com/global-services/managed-detection-and-response/"
        },
        {
          "title": "Wayfinder MDR datasheet",
          "url": "https://www.sentinelone.com/resources/datasheets/wayfinder-managed-detection-response-mdr/"
        }
      ],
      "reviewedAt": "2026-09-19",
      "assessment": {
        "status": "unassessed",
        "capability": null,
        "operating": null
      }
    }
  ]
}