Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Legacy vulnerability scanners were built for a different era. Scheduled scan windows leave gaps of days or weeks between detections. Heavy agent deployments consume memory and RAM across your entire fleet. Plugin updates lag CVE publication, widening the detection gap precisely when speed matters most. In the machine-speed era, a detection delay of even a few hours can be the difference between exposure and compromise.
Zafran Discover takes a fundamentally different approach. Instead of adding another agent to your infrastructure, Discover scans through the endpoint agents you already have deployed - CrowdStrike, SentinelOne, Defender, Tanium, Intune, and SCCM - using native APIs. The result is continuous, real-time vulnerability detection with zero additional footprint. For most customers, Discover does not just eliminate the need for a new scanner agent. It removes an existing one, freeing up memory and RAM across the fleet.
Show the rest of the publisher’s description (2 more lines)
Active asset inspection builds continuous SBOM coverage, surfacing new vulnerabilities in real time rather than waiting for plugin updates and scheduled scan windows. External discovery maps your internet-facing asset inventory continuously. Unauthenticated network scanning covers environments without full endpoint agent deployment. PCI ASV scanning handles compliance use cases without separate tooling.
Discover is priced on scanned assets rather than total inventory, so you pay for what you actually scan. And because Discover feeds directly into the Zafran Exposure Graph, every finding is immediately enriched with runtime context, internet reachability, threat intelligence, and compensating control coverage - turning raw scan data into prioritized, actionable exposure intelligence from day one.
Highlights
Highlighted by the publisher on AWS Marketplace.
Continuous vulnerability detection with zero new agents. Discover scans through your existing CrowdStrike, SentinelOne, Defender, Tanium, Intune, or SCCM agents via native APIs - no new footprint, no performance impact, no change management overhead. For most teams, it removes an existing scanner agent entirely.
Real-time SBOM coverage and external discovery, not scheduled scan windows. Active asset inspection surfaces new vulnerabilities the moment they appear rather than waiting for plugin updates. External discovery continuously maps internet-facing inventory. Unauthenticated network scanning covers environments without full endpoint coverage.
Priced on scanned assets, not total inventory - and feeds directly into the Zafran Exposure Graph. Every finding is immediately enriched with runtime presence, reachability, threat intelligence, and compensating control coverage, turning raw scan data into prioritized exposure intelligence from day one.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Plans and pricing as listed
4 listed- Units
- Units
- Units
- Units
Refund terms
As stated by the publisher on AWS Marketplace.
https://www.zafran.io/legal/terms-of-use
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

