The match
Matched to your live fleet — not to a name.
A first-party worker, Skans.VulnFeed, syncs the public CVE List (cvelistV5) and MITRE ATT&CK Enterprise into an on-box store, then joins your live per-host inventory against each CVE's affected-version ranges. A broad product match finds candidates; a strict version-range check then gates every one, so software patched past the affected range stays quiet. The whole match runs on the appliance — there is no cloud scanner in the loop.
- Version-range gate, not name lookup — a candidate only becomes a finding when the installed version actually falls inside the affected range.
- Green means green — a fully-patched host produced zero findings in a live drill, so a clean result means secured, not unscanned.
- Live inventory as the source — the same software and firmware Skans already inventories per host is what the CVE corpus is joined against.
- Nothing leaves the wire — sync, match and write all happen on-box; your inventory never goes to a cloud scanner.