Zafran Discover delivers continuous, agentless vulnerability scanning by reusing the EDR agents you already have deployed - no new agent, no scheduled scan windows, no blind spots.
Legacy vulnerability scanners were built for a different era. Scheduled scan windows leave gaps of days or weeks between detections. Heavy agent deployments consume memory and RAM across your entire fleet. Plugin updates lag CVE publication, widening the detection gap precisely when speed matters most. In the machine-speed era, a detection delay of even a few hours can be the difference between exposure and compromise.
Zafran Discover takes a fundamentally different approach. Instead of adding another agent to your infrastructure, Discover scans through the endpoint agents you already have deployed - CrowdStrike, SentinelOne, Defender, Tanium, Intune, and SCCM - using native APIs. The result is continuous, real-time vulnerability detection with zero additional footprint. For most customers, Discover does not just eliminate the need for a new scanner agent. It removes an existing one, freeing up memory and RAM across the fleet.
Active asset inspection builds continuous SBOM coverage, surfacing new vulnerabilities in real time rather than waiting for plugin updates and scheduled scan windows. External discovery maps your internet-facing asset inventory continuously. Unauthenticated network scanning covers environments without full endpoint agent deployment. PCI ASV scanning handles compliance use cases without separate tooling.
Discover is priced on scanned assets rather than total inventory, so you pay for what you actually scan. And because Discover feeds directly into the Zafran Exposure Graph, every finding is immediately enriched with runtime context, internet reachability, threat intelligence, and compensating control coverage - turning raw scan data into prioritized, actionable exposure intelligence from day one.
Highlights
Continuous vulnerability detection with zero new agents. Discover scans through your existing CrowdStrike, SentinelOne, Defender, Tanium, Intune, or SCCM agents via native APIs - no new footprint, no performance impact, no change management overhead. For most teams, it removes an existing scanner agent entirely.
Real-time SBOM coverage and external discovery, not scheduled scan windows. Active asset inspection surfaces new vulnerabilities the moment they appear rather than waiting for plugin updates. External discovery continuously maps internet-facing inventory. Unauthenticated network scanning covers environments without full endpoint coverage.
Priced on scanned assets, not total inventory - and feeds directly into the Zafran Exposure Graph. Every finding is immediately enriched with runtime presence, reachability, threat intelligence, and compensating control coverage, turning raw scan data into prioritized exposure intelligence from day one.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Zafran Discover continuously identifies vulnerabilities across hybrid cloud environments and consolidates all vulnerability data into a single source of truth. Eliminate silos, reduce blind spots, and gain complete visibility across your attack surface without new agents.
Zafran Discover is a single add-on priced through a contract. You buy it in units, and your cost scales with the number of units you select. This add-on layers onto your existing setup to continuously find vulnerabilities across hybrid cloud environments and pull all vulnerability data into one source of truth. Because pricing is unit-based, you can size your commitment to your environment. There is one pricing dimension here, so you choose the quantity of units rather than picking between separate tiers or plans.
Top-of-mind questions for buyers
What does one unit of Zafran Discover represent for billing?
The unit maps to the scope of your environment being scanned for vulnerabilities. You size the number of units to match your hybrid cloud footprint, including endpoints, servers, virtual machines, and running containers. Contact the vendor to confirm how units are counted against your specific asset inventory.
Do I need to deploy new agents to use Zafran Discover?
No. Zafran Discover runs continuous vulnerability discovery without deploying new agents. It uses a lightweight detector alongside your existing endpoint agents and connects to your current tools through APIs. This keeps deployment agentless and avoids disruption to your environment.
What happens to my cost if my environment grows over the contract term?
Cost scales with the number of units you commit to under the contract. If your asset footprint grows beyond your committed units, you would adjust your unit quantity. Contact the vendor to confirm how mid-term growth and additional units are handled.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Zafran Exposure Management proves 90% of critical vulnerabilities are not exploitable in your environment, then neutralizes the rest through the EDR, WAF, and firewall you already own.
Zafran AIR is the fast-start Threat Exposure Management SKU built for enterprises under 10,000 employees. Connect your CSPM, infrastructure scanner, and EDR in minutes. Prepopulated Exposure Trackers, including the Mythos Tracker, surface real exposure to the latest high-profile threats immediately. Flat-fee, online-terms purchase. No MSA, no deployment overhead, no waiting.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.