| External surface discoveryMapping of exposed assets on the internet |
Partial Discovery of external assets as a module within an extensive suite; the product focus remains on internal detection. |
Full The continuous discovery of the external surface is the central objective of the platform, starting from just the root domain. |
| Unrestricted discovery scopeLarger surface coverage |
Limited The external surface module operates within scope limits that may require adjustment for larger inventories. |
Full Discovery encompasses all identified external surfaces without a predefined ceiling on assets. |
| Asset attribution and classificationConfirm ownership and criticality |
Limited The organization and tagging of discovered assets depend on manual work by the team. |
Full Each asset is attributed to an organization and classified for business criticality through Machine Learning. |
| Shadow IT and subsidiaries coverageAssets outside the official inventory |
Limited The external discovery reaches part of these assets, with coverage sensitive to configured scope. |
Full Shadow IT, brands, and subsidiaries enter the scope without prior inventorying. |
| Supply chain digital footprintThird-party components embedded in assets |
Does not cover The mapping of third-party components embedded is not part of the external surface module. |
Full Third-party components embedded in assets are mapped as part of the exposure. |
| Vulnerability detection on internal assetsInternal park with agent |
Full This is a consolidated strength of Qualys, with agent-based internal detection and broad coverage of the park. |
Does not cover CSURFACE is dedicated to the external surface and does not perform agent-based internal detection. |
| Prioritization by real exploitabilityWhat is being exploited now |
Partial Threat intelligence is available in the suite, generally organized into separate modules. |
Full Dynamic prioritization by real exploitability is an integral part of the platform without separate modules. |
| Single and integrated platformCapabilities without stitching between modules |
Partial Capabilities are distributed across distinct modules of the suite, which need to be combined. |
Full Discovery, classification, prioritization, and continuous monitoring operate on a single platform. |
| Validation and testing of discovered exposuresConfirm whether an exposed asset is actually exploitable |
Partial The external surface module discovers and enumerates the assets and performs a lightweight scan at discovery; full vulnerability and web application testing requires the VMDR and WAS modules, purchased separately. |
Full Exploitability validation of external exposures is built into the platform, with no additional modules. |