AEV (adversarial exposure validation)

AEV, short for adversarial exposure validation, is the market category Gartner named on 24 March 2026 for technologies that deliver consistent, continuous and automated evidence of the feasibility of an attack. They run attack scenarios against the real environment and measure the outcome, proving that an exposure exists and is exploitable on that asset.

Updated

What Gartner named in March 2026

AEV, short for adversarial exposure validation, is the market category Gartner named on 24 March 2026, in the Market Guide for Adversarial Exposure Validation, covering technologies that deliver consistent, continuous and automated evidence of the feasibility of an attack. The document's definition already describes the method: run attack scenarios against the environment and measure the outcome, proving the existence and exploitability of exposures.

The word carrying the weight is adversarial. The system does what an adversary would do, in the environment as it stands today, and the test result is the output. No score derived from a table enters that calculation.

In Portuguese and Spanish the term still circulates in English. Validação adversarial de exposição and validación adversarial de exposición are the forms that appear when somebody translates it.

What AEV proof adds to a number

A mature program already has three numeric signals on every flaw: theoretical severity from CVSS, exploitation probability from EPSS, and confirmed exploitation in the world from CISA's catalog. All three describe the flaw. None of them describes your asset.

AEV answers the fourth question, the only specific one: is this path open here, now, in this configuration?

The difference shows up in the conversation with the system owner. "This CVE has an EPSS of 0.61" opens a negotiation about maintenance windows. "This server answered a request coming from outside the network and the response arrived on the channel we set up for the test" closes it.

Proof has a cost. It is more expensive to produce than a score, and some flaws cannot be proven without taking the service down. An honest program separates what was demonstrated from what was probable, and writes that distinction next to the finding.

What the AEV category absorbed

AEV merged two labels Gartner had treated separately up to the 2023 Hype Cycle.

Breach and attack simulation. Known as BAS, it starts from a position already inside the environment and runs known techniques against the controls, measuring what detection caught and what slipped. The question is about control effectiveness.

Automated penetration testing. It starts from an external position, or any point in the network, and chains steps until it reaches an effect. The question is about the path.

The new name puts both under one idea: evidence produced by execution, in place of a conclusion drawn from version matching. A scanner compares a component version against a database of known flaws and returns candidates. Adversarial validation takes those candidates and tries them.

Where AEV fits in a CTEM program

CTEM organizes the work into five phases: scoping, discovery, prioritization, validation and mobilization. AEV is the market name for the fourth.

The same Gartner guide projects that by 2029, 60% of organizations will have adopted a structured exposure validation practice inside a CTEM program. The projection says more about today's gap than about the 2029 market. In 2026 structured validation is still a minority practice, and most programs stop at prioritization, with a queue ordered by a score nobody checked.

Where the AEV label becomes just a label

The AEV acronym showed up in the material of nearly every vendor in the category within months of the guide's publication. As a buying criterion, the name stopped separating anything.

Three questions do separate.

What is the proof? An out-of-band callback, a response difference, a marker written at the destination and a timing measurement do not carry equal weight. Ask for the evidence format before you look at the dashboard.

What is the frequency? One validation per quarter describes the environment of the week it ran. The cadence commitment matters more than the list of techniques covered, and that is what the continuous validation entry develops.

What is the declared limit? No platform covers every published CVE. Real coverage is per flaw with a detection module built, because not every CVE has enough public data to become one. A vendor that states this is telling the truth about the product.

What AEV does not solve

It does not discover what nobody inventoried. Validating an incomplete list with discipline produces good metrics over the known part of the problem and leaves untouched the asset that never entered the count. Discovery comes first, and the order of the CTEM phases exists for that reason.

It also does not replace testing run by people. Business logic, authorization chains and workflow abuse still require someone at the keyboard, which is what a point-in-time test is for. The machine covers less in depth and far more in frequency, and a mature program keeps both.

CSURFACE runs this AEV stage over the external surface. It discovers the asset that answers on the internet, tests exploitability over what it discovered, and delivers the finding with the proof and the confidence level written beside it. When the only way to demonstrate something would be to take the service down, the item stays recorded as probable and never moves up to demonstrated. Internal network, endpoint, email and authenticated web application testing fall outside. The three conditions that make a flaw exploitable are in the exploitability validation entry.

Veja isso na sua superfície

Análise preliminar gratuita