SolidLab
SolidLab VMS

SolidLab VMS

The SolidLab intelligent vulnerability management platform is designed to discover and analyze weaknesses and vulnerabilities in IT infrastructure to improve the security posture of the protected scope. The solution helps build a complete cyber risk management process: from asset inventory and vulnerability scanning to analysis, prioritization, and remediation tracking. DefectTracker helps execute remediation tasks.

Use cases

The solution enables a wide range of use cases, such as:

External attack surface discovery

Inventory of IT resources and their components

User account password resilience testing

Detection and blocking of phishing resources and leaks

One-time scanning

Web application security assessment

Control of API functions and executable JS scripts

Vulnerability management and patch management

Components

The VMS platform is built as a set of complementary components. This makes it possible to tailor the configuration to customer needs: from inventory and external perimeter monitoring to internal scanning, account testing, and digital brand protection.

Each component is licensed separately and can be purchased independently of the others.

Component Purpose
External Attack Surface Management (EASM) Automated passive and active discovery of publicly exposed IT assets and infrastructure components from open sources.
External Vulnerability Manager (EVM) Identification of known vulnerabilities on the external perimeter based on detected ports, services, and exposed technologies.
Local Vulnerability Manager (LVM) Scanning of the internal network using a dedicated server deployed within the customer’s infrastructure to identify hosts, services, and known vulnerabilities without agents.
Host Vulnerability Manager (HVM) Agent-based vulnerability detection within internal IT infrastructure with detailed inventory of hardware and software assets.
Application Vulnerability Manager (AVM) Dynamic web application security testing to detect known vulnerabilities and identify exploitable entry points.
User Account Testing (UAT) Infrastructure account security assessment, including weak password detection and password policy compliance control.
Digital Risk Protection (DRP) Monitoring and detection of brand misuse and related digital threats across the internet.

Functional capabilities

  • A unified interface for monitoring and asset operations;
  • Inventory of IT assets, web applications, and software;
  • Vulnerability scanning (black/white/gray box);
  • Information about missing updates (including CVE list);
  • Advanced tools for scan and report management;
  • Detection of configuration weaknesses and phishing sites;
  • Asset management in UI: groups, categories, labels; differential reports and templates;
  • Synchronization of vulnerability statuses with external systems (SIEM, ticketing, etc.);
  • Criticality assessment and manual verification; use of public vulnerability databases, FSTEC databases, and SolidLab’s own knowledge base.

Advantages and implementation outcomes

The main advantage of the VMS solution is the ability to purchase only the required components or each component separately. This makes the platform flexible and allows the solution to be adapted to specific customer requests.

Managed Services instead of SaaS

Our analysts fully support the solution, including manual validation of findings and fine-tuning based on customer needs. Support is included for the entire VMS solution regardless of license type or level.

Comprehensive toolset

The solution includes a complete toolkit for inventory and vulnerability management within a single environment.

Additional focus on web applications

Integration with SolidPoint DAST enables deeper analysis of web applications and more effective vulnerability detection.

Flexible modular architecture

The platform can be tailored to customer needs, scaled, and integrated via API.

Import substitution support

The platform is built on SolidLab’s own development and proven open-source solutions.

Domestic software registry

The solution is included in the Russian domestic software registry, confirming compliance with local regulatory requirements.

Reduction in the number of critical vulnerabilities

↓

Faster response to vulnerabilities

↑

Reduction in false positives

↓

Tracking and optimization of resource usage

↑