Zafran Discover delivers continuous, agentless vulnerability scanning by reusing the EDR agents you already have deployed - no new agent, no scheduled scan windows, no blind spots.
Legacy vulnerability scanners were built for a different era. Scheduled scan windows leave gaps of days or weeks between detections. Heavy agent deployments consume memory and RAM across your entire fleet. Plugin updates lag CVE publication, widening the detection gap precisely when speed matters most. In the machine-speed era, a detection delay of even a few hours can be the difference between exposure and compromise.
Zafran Discover takes a fundamentally different approach. Instead of adding another agent to your infrastructure, Discover scans through the endpoint agents you already have deployed - CrowdStrike, SentinelOne, Defender, Tanium, Intune, and SCCM - using native APIs. The result is continuous, real-time vulnerability detection with zero additional footprint. For most customers, Discover does not just eliminate the need for a new scanner agent. It removes an existing one, freeing up memory and RAM across the fleet.
Active asset inspection builds continuous SBOM coverage, surfacing new vulnerabilities in real time rather than waiting for plugin updates and scheduled scan windows. External discovery maps your internet-facing asset inventory continuously. Unauthenticated network scanning covers environments without full endpoint agent deployment. PCI ASV scanning handles compliance use cases without separate tooling.
Discover is priced on scanned assets rather than total inventory, so you pay for what you actually scan. And because Discover feeds directly into the Zafran Exposure Graph, every finding is immediately enriched with runtime context, internet reachability, threat intelligence, and compensating control coverage - turning raw scan data into prioritized, actionable exposure intelligence from day one.
Highlights
Continuous vulnerability detection with zero new agents. Discover scans through your existing CrowdStrike, SentinelOne, Defender, Tanium, Intune, or SCCM agents via native APIs - no new footprint, no performance impact, no change management overhead. For most teams, it removes an existing scanner agent entirely.
Real-time SBOM coverage and external discovery, not scheduled scan windows. Active asset inspection surfaces new vulnerabilities the moment they appear rather than waiting for plugin updates. External discovery continuously maps internet-facing inventory. Unauthenticated network scanning covers environments without full endpoint coverage.
Priced on scanned assets, not total inventory - and feeds directly into the Zafran Exposure Graph. Every finding is immediately enriched with runtime presence, reachability, threat intelligence, and compensating control coverage, turning raw scan data into prioritized exposure intelligence from day one.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Zafran Discover continuously identifies vulnerabilities across hybrid cloud environments and consolidates all vulnerability data into a single source of truth. Eliminate silos, reduce blind spots, and gain complete visibility across your attack surface without new agents.
This add-on uses a single pricing dimension billed by Units under a contract. You purchase the quantity of Units that matches your needs, and your total scales with how many Units you commit to. There are no separate tiers or instance sizes to choose from. The Units cover continuous vulnerability discovery across hybrid cloud environments, consolidating vulnerability data into one source of truth without deploying new agents. Because it is an add-on, you layer these Units onto your existing setup rather than selecting between plans.
Top-of-mind questions for buyers
What does one Unit of Zafran Discover represent for billing purposes?
The Units dimension bills by the volume of your environment that Zafran Discover covers. The platform continuously discovers vulnerabilities across endpoints, servers, virtual machines, and running containers in your hybrid cloud footprint. Your Unit count reflects the scale of assets under continuous discovery. Confirm the exact per-Unit definition with the vendor for your specific environment.
What happens to my cost as I add more assets to discovery?
Cost scales with the number of Units you commit to under the contract. As your monitored environment grows across cloud, on-premises, and application assets, you commit to more Units. There are no separate tiers or instance sizes. Increasing coverage means adjusting your Unit commitment rather than switching plans.
Do I need to deploy new agents to use the Units I purchase?
No. Zafran Discover uses a lightweight detector that works with your existing endpoint agents, so no new agents are required. Deployment is agentless with API-based connections to your existing tools. Your Units cover continuous vulnerability discovery across endpoints, servers, virtual machines, and running containers without added software installs.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Zafran Exposure Management proves 90% of critical vulnerabilities are not exploitable in your environment, then neutralizes the rest through the EDR, WAF, and firewall you already own.
Zafran AIR is the fast-start Threat Exposure Management SKU built for enterprises under 10,000 employees. Connect your CSPM, infrastructure scanner, and EDR in minutes. Prepopulated Exposure Trackers, including the Mythos Tracker, surface real exposure to the latest high-profile threats immediately. Flat-fee, online-terms purchase. No MSA, no deployment overhead, no waiting.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.