Skip to main content
Version: 1.0.0

Analytics Overview

Cert-IX Analytics turns the raw output of your scans and asset discovery into prioritized, actionable insight. Instead of reading through individual scan results one at a time, Analytics aggregates findings across your environment, ranks them by severity, and shows how your exposure changes as issues are remediated.

Today the core analytics surface is Vulnerability Management, which consolidates the findings produced by the Cert-IX scanning engines and scanner agents into a single, prioritized view.

info

Analytics reflects the results of completed scans. Because scans run asynchronously (queued β†’ running β†’ completed), the figures you see update as each scan finishes rather than streaming in continuously.

What feeds Analytics​

Analytics does not collect data on its own β€” it summarizes findings that other parts of the platform generate:

SourceWhat it contributes
Scan API enginesWeb, network, and infrastructure findings from the built-in engines (Nmap, OWASP ZAP, Trivy, Nuclei, Nikto, and others).
Scanner agentsVulnerability and CVE findings from Bitscanner, plus asset telemetry from Bitcollector, running inside your own network.
Asset inventoryThe devices, cloud resources, software, and network assets that findings are attributed to.

Because every finding is tied to a discovered asset, Analytics can answer not just what is wrong but where β€” which host, service, or package a given issue affects.

Vulnerability Management​

Vulnerability Management is the primary analytics view. It takes the findings from every source above and organizes them so you can focus on the highest-impact issues first.

  • Severity ranking β€” findings are classified as Critical, High, Medium, or Low so the most serious issues rise to the top.
  • Remediation guidance β€” each finding carries context and recommended steps to resolve it.
  • Trends over time β€” see how open findings break down by severity and how those counts move as issues are fixed and new scans complete.

Explore Vulnerability Management β†’

Working with the data​

The analytics views are built for narrowing a large body of findings down to a specific question:

  • Filter by severity, by asset or asset group, and by time range to isolate the findings you care about.
  • Drill in from an aggregated view to an individual finding, including the affected asset and its remediation guidance.
  • Export the current view for reporting or ticketing in your own tools.
tip

Work from the highest severity band down. Resolving a small number of Critical and High findings usually reduces real-world risk faster than clearing a large backlog of Low-severity items.

Where analytics appears elsewhere​

The same findings that drive Vulnerability Management also feed other parts of the platform:

  • The Dashboard rolls current findings into an at-a-glance security posture and summary widgets.
  • Compliance (Beta) helps map findings and controls against frameworks such as NIST CSF, ISO 27001, SOC 2, CIS Controls, and NIS2.

Next steps​

Was this page helpful?