Skip to main content

Introduction

Welcome to the scani5 AI-Driven Exposure & Vulnerability Management Platform Getting Started Guide.
This guide is designed to help you understand how to discover, assess, prioritize, and reduce exposure across your IT infrastructure using scani5 ’s agent-based detection, attack-path mapping, and real-time threat intelligence.


What is scani5?

scani5 is a next-generation AI-Driven Exposure & Vulnerability Management Platform that provides organizations with deep visibility into their attack surface and IT environment.

Founded with a mission to simplify exposure and vulnerability management, scani5 enables security and IT teams to proactively reduce risk, shrink the attack surface, and improve operational efficiency through:

  • Continuous exposure discovery
  • AI-driven prioritization
  • Intelligent dashboards
  • Actionable reporting

The platform uses an agent-based approach to:

  • Continuously collect system and configuration information
  • Detect installed software, versions, and misconfigurations
  • Map assets against the National Vulnerability Database (NVD) to identify CVEs and CWEs
  • Correlate findings with live threat intelligence to surface exploitable exposure

Advanced features include:

  • Risk to Infrastructure (RTI) scoring
  • Exploitability metrics
  • Attack path and exposure mapping
  • SLA monitoring

These features ensure organizations maintain an accurate asset inventory across hybrid environments, understand where attackers can reach critical assets, and help security teams prioritize exposure with context-driven intelligence, streamline remediation workflows, and track historical patch and hardening processes.

What is Exposure Management?

Exposure management is the practice of identifying, measuring, and reducing the ways an organization can be attacked—not just listing vulnerabilities in isolation. While traditional vulnerability management asks “What flaws exist?”, exposure management asks “What can an attacker actually reach, exploit, and use to move deeper into the environment?”

scani5 bridges this gap by combining:

  • Asset visibility — knowing what systems, applications, identities, and network paths exist
  • Vulnerability intelligence — knowing which flaws are present and how severe they are
  • Threat context — knowing which issues are actively exploited in the wild
  • Attack-path analysis — knowing how a low-severity finding on one host could lead to a critical asset

Together, these capabilities give security teams a unified view of organizational risk rather than an overwhelming list of CVEs.

How scani5 Manages Exposure

scani5 follows a continuous lifecycle to help teams move from discovery to measurable risk reduction:

  1. Discover — Agents and scanners inventory endpoints, servers, cloud workloads, applications, and network devices across hybrid environments.
  2. Assess — Findings are correlated with NVD data, CWE classifications, and configuration issues to build a complete picture of weakness and misconfiguration.
  3. Prioritize — AI-driven scoring combines CVSS severity, exploitability, business criticality, visibility in the wild, and attack-path impact so teams focus on exposures that matter most.
  4. Remediate — Actionable workflows, SLA tracking, and role-based dashboards help IT and security teams patch, harden, or isolate assets efficiently.
  5. Measure — Historical trends, compliance views, and executive reporting show whether exposure is shrinking over time.

This approach helps organizations reduce mean time to remediation (MTTR), eliminate blind spots, and align security effort with real business risk.


Getting Started

  • License page (content pending update)

scani5 Support

scani5 provides 24/7 customer support to assist with deployment, troubleshooting, and operational queries.

Customers have access to:

  • Online documentation
  • Knowledge base articles
  • Email-based support channels
  • Dedicated account assistance

This ensures organizations can quickly resolve issues and maximize the value of the platform without disruptions to their exposure and vulnerability management workflows.

Emails: (add 2 email addresses here)


Prerequisites

Before deploying scani5 , several requirements must be in place.
A valid subscription is necessary, and organizations must ensure that their license or subscription plan is active.

For new customers, onboarding assistance is available through scani5 ’s sales, Channel partners, or support teams.
Supported operating systems include Windows (available now), with Linux and macOS support planned for the upcoming version (ETA Q3 2026); all supported platforms should always be updated with the latest security patches to ensure optimal scanning and exposure assessment results.

For dashboard access, the solution supports modern browsers such as:

  • Google Chrome
  • Microsoft Edge
  • Mozilla Firefox
  • Safari

It is recommended to use the latest versions for the best performance.

Deployment of agents requires a valid scani5 Org Key, which is needed to install and register the scani5 Agent on assets.
Detailed guidance on this process is available in the Agent Installation Guide.

Finally, network connectivity is critical to ensure real-time exposure mapping, threat intelligence updates, and continuous monitoring capabilities.

Glossary of terms

TermsFull formDefinition
CVECommon Vulnerabilities and ExposuresPublic identifier for a known vulnerability.
CWECommon Weakness EnumerationClassification of software weaknesses related to CVEs.
NVDNational Vulnerability DatabaseCentral database of published CVEs and CVSS scores.
CVSSCommon Vulnerability Scoring SystemIndustry standard scoring system for vulnerability severity.
SLAService Level AgreementCommitment to respond/remediate within agreed timelines.
ExposureExposureThe set of attackable weaknesses, misconfigurations, and reachable paths across an environment.
Attack SurfaceAttack SurfaceAll entry points and assets that could be targeted or exploited by an attacker.
Attack PathAttack PathA simulated route showing how an attacker could move from an initial foothold to a critical asset.
MTTRMean Time to RemediateAverage time taken to fix or mitigate a identified exposure or vulnerability.
MDMMobile Device ManagementPlatforms (e.g., InTune, Jamf) used to manage endpoints.
ADActive DirectoryMicrosoft’s directory service for identity and device management.