Products

Four products.
One platform, one console.

Security operations, network operations and exposure management built on shared foundations — so the data, the cases and the people don't fragment across four tools.

Security · Entry

VultSight SOC

Detect. Ticket. Respond.

A complete entry-level security operations centre — detection and alerting, case management with native ITSM, automation and threat intelligence.

SIEM detection & alerts Cases & native ITSM SOAR playbooks Threat intel & MITRE
Explore SOC →
Includes SOC

Security · Premium

VultSight XDR

Correlate. Investigate. Hunt.

Everything in SOC, plus cross-domain correlation into unified incidents, attack story, entity graph, behavioural analytics and threat hunting.

Everything in SOC XDR incident correlation UEBA & risk scoring Threat hunting & attack story
Explore XDR →

Network · Operations

VultSight NOC

Monitor. Measure. Maintain.

Real-time monitoring of every device and service — with live topology, auto-discovery, SLA tracking and a command-center wallboard.

Device & service health Live topology & discovery SLA, thresholds & uptime Maintenance & wallboard
Explore NOC →

Security · Exposure

VultSight Scope

Scan. Rank. Fix.

Vulnerability assessment across network, web applications and external attack surface — unified into one risk-ranked list, tracked to retest.

Network & web app scanning Unified, de-duplicated findings CVSS · EPSS · KEV scoring Remediation & retest
Explore Scope →
Capability matrix

What each product does

XDR is a superset of SOC. NOC and Scope stand alone and can run beside either — or on their own.

Capability SOCEntry security XDRPremium security NOCNetwork ops ScopeVulnerability
Detection & response
Log & event ingestion
SIEM detection & alerting
SOAR playbooks & automation
Threat intelligence & MITRE ATT&CK
Advanced security analytics
Cross-domain XDR correlation
Unified incidents & attack story
Entity graph
UEBA & behavioural risk scoring
Threat hunting
Network operations
Device & service monitoring
Network topology & auto-discovery
SLA tracking & uptime reporting
Command-center wallboard
Exposure & vulnerability
Network & web application scanning
Unified, de-duplicated findings
Risk scoring (CVSS · EPSS · KEV)
Remediation tracking & retest
Shared across every product
Cases & native ITSM workflow
Multi-tenant & white-label
RBAC, SSO & audit trail
Cloud, on-premises or hybrid
Reporting & compliance evidence
Available as a managed service

Every product is available to run yourself or to have our team operate for you — see managed services.

Choosing

Which one do you actually need?

🛡

Start with SOC

You have no central detection today. SOC gives you ingestion, detection, alerting, cases and automation — a working security operation without a hunting team.

🧠

Step up to XDR

You already triage alerts but drown in them. XDR correlates across domains into single incidents with attack story, UEBA and hunting. SOC is included — it's an upgrade, not a migration.

📶

Add NOC

Your network and security teams are on-call for the same infrastructure with different tools. NOC brings availability, performance and SLAs into the same console.

🔭

Add Scope

You can detect attacks but can't say what's exposed. Scope finds and ranks weaknesses before they're exploited, and feeds asset risk back into detection.

Shared foundations

Why one platform beats four tools

Every product sits on the same tenancy, identity, case and reporting layer — so adding one doesn't mean another integration project.

🏢

One tenancy model

Multi-tenant and white-label throughout — run your own estate, or deliver to many clients from a single console with per-tenant isolation.

🎫

One case workflow

A security alert, a network outage and a vulnerability all become work items in the same native ITSM — one queue, one on-call rota, one MTTR number.

🔐

One identity layer

RBAC, SSO and a complete audit trail apply across every product, so access review is one exercise instead of four.

🔄

Deploy your way

Cloud, on-premises or hybrid — the same product either way, so a deployment constraint never costs you capability.

📑

One reporting layer

Posture, uptime and exposure reported from shared data, so the board deck doesn't need three exports reconciled by hand.

🔌

Open integrations

Standards-based ingestion and APIs mean the platform fits the estate you already have rather than replacing it wholesale.

Not sure where to start?

Tell us what you're running today and what's hurting. We'll tell you which product actually solves it — and which one you don't need yet.