Integrate CrowdStrike Spotlight with Vulnetix. Export vulnerability findings via the CrowdStrike Falcon API for centralised management.
How Vulnetix compares: better together
Vulnetix does not replace CrowdStrike Spotlight. Keep running it. Vulnetix sits on top of CrowdStrike Spotlight (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
CrowdStrike Spotlight is strongest at its core category and also carries features in Container & Image Scanning, Cloud Security & CSPM, IaC & Cloud Configuration, just as Vulnetix spans categories.
| Capability | Vulnetix | CrowdStrike Spotlight |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✗ |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ~ Falcon Image Assessment identifies vulns, malware and misconfigs in images as part of the build (CIS) |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ~ Security Configuration Assessment checks assets against customizable CIS benchmarks; not IaC template scanning |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ~ Falcon Cloud Security provides CSPM/misconfig; Spotlight itself is endpoint-focused |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ~ Image Assessment flags malware in container builds; broader malware detection is the EDR core, not a supply-chain package firewall |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✓ Scanless sensor-based CVE assessment on Windows/Linux/macOS endpoints in real time (falcon.crowdstrike.com Spotlight) |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✓ ExPRT.AI dynamic scoring plus EPSS; taps real-time exploitation telemetry to rank CVEs Low/Med/High/Critical |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ~ Falcon Fusion automates remediation workflows/playbooks for vulnerabilities |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What CrowdStrike Spotlight does well
- Scanless, always-on vulnerability assessment using the already-deployed Falcon sensor, giving real-time endpoint CVE data with no scan windows, agents or credentials
- ExPRT.AI dynamic per-CVE risk scoring that fuses live adversary activity, exploit maturity and asset criticality, letting teams prioritise roughly twice as many high-rated CVEs vs static CVSS
- Tight EDR integration and Falcon Fusion SOAR for automated vulnerability remediation workflows
- Falcon Image Assessment scans container images at build time for vulnerabilities, malware and CIS misconfigurations
Where Vulnetix adds to it: Vulnetix ingests Spotlight endpoint CVE and Image Assessment output and consolidates it with SAST/SCA/IaC/secrets/cloud findings from every other scanner into one deduplicated queue, adding cross-source EPSS/KEV/ESS/LEV prioritisation, reachability, immutable versioned VEX, EOL policy and SSVC. Vulnetix does not run the Falcon sensor or scan endpoints itself; Spotlight stays the real-time endpoint engine and Vulnetix is the code-to-cloud ASPM layer above it.
No migration, no rip-and-replace. CrowdStrike Spotlight keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise CrowdStrike Spotlight results in Vulnetix
Upload CrowdStrike Spotlight JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.