All services
Continuous Defense

400 "critical" findings.
Your team reviews them by hand.

Manual triage at scale is broken. Attackers iterate overnight. Your team reviews scanner output during working hours. That gap is where breaches happen.

Without Horus
Weekly sprint starts with 400 "critical" findings. Team spends days triaging, most are false alarms or unexploitable.
A CVE hits CISA KEV on Tuesday. Your team finds out Friday, after someone shares the tweet in Slack.
Three subdomains you forgot existed are running unpatched services. Nobody knows they exist.
Coverage depends on who's on-call and awake. Attackers operate 24/7 without that constraint.
With Horus
Pipeline runs at 02:00 UTC. Inbox has 1-3 SSVC:Act findings by morning. Zero noise.
Watchtower syncs CISA KEV at 06:30 UTC daily. If any new entry matches your stack, PagerDuty fires before you open your laptop.
CT log sweep and CIDR ping on schedule. New subdomains auto-added to the asset inventory.
The agents run on the schedule you set. No tickets, no standups, no babysitting required.
How it works

Configure once. It keeps running without anyone prompting the agents.

Define assets and a schedule. The pipeline does the rest. Every finding that reaches you has already been correlated, enriched and SSVC-prioritized.

01 / DISCOVER

Map your attack surface

Certificate Transparency sweep finds subdomains. nmap CIDR scan finds internal hosts. New assets are auto-added to the inventory. You only configure it once.

02 / SCAN + CORRELATE

Scan, enrich, cross-reference

nmap + nuclei run per asset. Every port, service and header analyzed. Findings correlated against 338K+ CVEs, CISA KEV, EPSS scores. All deterministic, zero LLM tokens for correlation.

03 / SSVC + ALERT

Only what matters reaches you

Risk Manager runs the SSVC Deployer decision tree. Act findings trigger PagerDuty P1. Attend findings go to Slack. Track findings queue silently until you go looking for them.

Live output · sorted by SSVC priority
Findings
Assets
Incidents
1 Act 1 Attend
api.acmecorp.io · 12 findings sorted by SSVC priority
HTTP/2 Rapid Reset
api.acmecorp.io · api.acmecorp.io:443
CVE-2023-44487CVSS 7.5EPSS 94.0% KEV Active
HIGHAct
RCE · Apache Log4j
api.acmecorp.io · api.acmecorp.io:8080
CVE-2021-44228CVSS 10.0EPSS 97.0% KEV Active
CRITICALAttend
Buffer Overflow · OpenSSL 1.0.2 (internal)
db-internal-01 · 10.0.1.22:443
CVE-2022-0778CVSS 9.8EPSS 3.0%
CRITICALTrack*
Open Redirect · nginx reverse proxy config
login.acmecorp.io · login.acmecorp.io:443
CVE-2024-7347CVSS 5.3EPSS 2.0%
MEDIUMTrack
Missing HSTS header · marketing.acmecorp.io
marketing.acmecorp.io · marketing.acmecorp.io:443
no CVECVSS —EPSS —
INFOTrack
9 more findings · 1 Act, 1 Attend 7 more findings not shown Show all → Show less ↑
6 assets tracked last discovery run 6h ago
api.acmecorp.io
api.acmecorp.io:443DOMAIN
External production
10.0.1.0/24
10.0.1.0/24CIDR
Internal internal-network
vpn.acmecorp.io
vpn.acmecorp.io:443DOMAIN
External third-party
2 incidents sorted by SLA
CRITICAL
HTTP/2 Rapid Reset exploitation attempt
1 finding · security-team
2d overdue Open
HIGH
Expired TLS cert on vpn.acmecorp.io
1 finding · j.ops
Due today In progress
Full capability set

Everything in Continuous Defense.

All run on schedule, automatically.

Auto-discovery

Asset Discovery

CT log sweep + nmap CIDR ping sweep. Configure a domain or IP range once. Everything reachable from it gets mapped, including subdomains you forgot existed.

  • CT logs via crt.sh + certspotter
  • Internal CIDR sweep with nmap -sn
  • Auto-deduplication of repeated hosts
  • Optional auto-create: discovered → scan target
Inventory

Asset Management

CRUD for domains, IPs, APIs, services. Internal vs external scope, plus free-form tags. Track last-detected technologies per host. Full scan history per asset.

  • Domain, IP, API, service types
  • Internal vs external classification
  • Technology inventory per asset
  • Scan history + posture trend
Scanner

Vulnerability Scanning

nmap port + service enumeration, nuclei template execution, header/SSL/TLS analysis. Multi-agent pipeline persists an executive summary per scan.

  • Port + service detection (nmap)
  • Vulnerability templates (nuclei)
  • Header, SSL, TLS config analysis
  • Executive summary per scan
Deterministic · 0 LLM tokens

SSVC Prioritization

Deterministic SSVC Deployer decision tree. No LLMs, no hallucinations, no per-query cost. Inputs: Exploitation state (KEV-active → active, EPSS > 0.9 → likely), Exposure, Technical Impact, Automatable heuristic. A CVSS 9.8 on an internal host with no public exploit → TRACK. An actively exploited 7.5 on a public API → ACT.

  • KEV-active → Exploitation: active
  • EPSS > 0.9 → Exploitation: likely
  • Internal host → Exposure: internal
  • Public API → Exposure: public
Continuous monitoring

Watchtower

Daily sync of CISA KEV + FIRST EPSS. Re-correlates your persisted software inventory without re-scanning. Detects EPSS spikes (0.2+ overnight) before KEV.

  • CISA KEV daily sync
  • EPSS spike detection
  • Zero re-scan overhead
  • ThreatFox + URLhaus IOC feeds
Case management

Incidents

Group related findings into tracked cases. Assign owners, set SLA, add timeline notes. Auto-created from SSVC:Act findings. Bidirectional links to findings.

  • States: open → in_progress → resolved
  • SLA countdown (red if overdue)
  • Auto-created from SSVC:Act
  • Timeline notes per case
Risk tracking

Posture Timeline

Deterministic risk score per org, snapshotted daily. Stacked area chart by severity. Annotated events. Trend line: improving / degrading / stable.

  • Daily snapshots + events
  • % criticals closed in 7d
  • Trend direction indicator
Automation

Schedules + Jobs

Cron jobs for recurring scans, discovery, CVE intel sync, Watchtower. Full job execution history. Auto-retry on failure. Next-run prediction in UI.

  • Cron expressions per pipeline type
  • Auto-retry on scan failure
  • Append-only job history

Your scanner found 400 issues.
Horus tells you which 3 matter.

The live demo has 30 days of posture history and real CVE findings.