Skip to content
Sparkle In Technology

SourceGuard VSCM

Binary findings, cross-verified against your existing scanners

Our proprietary binary analysis is combined with Tenable's vulnerability database and endpoint telemetry. Security teams scan, evaluate and remediate from one interface — and see which findings agree, which are noise, and which nobody else caught

Scan sourcesBinary engine, Tenable VM
AssetsServers, routers, gateways, switches
AutomationCron scheduler
ExportCSV, patch evidence
Two independent streams; agreement raises confidence, disagreement is triaged rather than dumped on an engineer
VSCM · security overview
Security overview dashboard showing the security health score, asset distribution, vulnerability statistics by severity and the top ten CVEs

Security overview

An executive view that a board will read

The core monitoring dashboard is configurable — each team decides which charts and figures belong on it

Security health score

A 0–10 score derived from the overall status of all assets

Asset distribution

Breakdown by system category — payment systems, external networks, internal networks

Vulnerability statistics

Counts and trends by severity: critical, high, medium, low

Top vulnerabilities

The ten CVEs currently posing the greatest threat to the estate

VSCM · settings / categories
Category settings screen where system categories are defined with importance weights and preset risk levels

Settings · categories

Your security baseline, written down once

Category definition

Define your own system categories and set an importance weight from 0 to 10

Risk level assignment

Preset levels per category, so high-value assets always take priority

VSCM · plugin settings
Plugin settings screen for entering the Tenable Vulnerability Management URL and authorisation key

Plugin settings

Bring the scanners you already own

Tenable Vulnerability Management is integrated natively. Enter the URL and authorisation key, and SourceGuard drives Tenable's scans and manages the results alongside its own

Full setup walkthrough in the integration guide

Read the integration guide
VSCM · binary vulnerability report
Binary vulnerability analysis report listing scanned components, detected CVE identifiers, CVSS severity scores and affected versions

Analysis & report

Every component the binary actually contains

Component analysis

Total components scanned and the security status of each

CVE list

Every detected identifier with CVSS score, description and affected versions

VSCM · vulnerability & patch detail
Side-by-side comparison of the vulnerable asset code and the recommended fixed code, with affected file paths and patch details

Patch detail

Remediation guidance, and evidence the vendor fixed it

Code comparison

Vulnerable asset code beside the recommended fixed code, pinpointing the exact location

Technical detail

Affected file paths and the specific functions involved

Recommendations

Patch details that tell a developer exactly what to change

VSCM · cross-verification
Cross-verification workspace separating SourceGuard findings, external source findings and false positives

Cross-verification

The page where the argument ends

A decision-making hub for security experts and developers, showing the findings the engine has verified

Multi-source alignment

Labels separate SourceGuard, external sources and false positives, so the noise reduction is visible

False positive list

Automatically filters findings where the version matches but the code is already patched, or the vulnerable function is never called

CSV download

Track and assign the vulnerabilities that survived verification

VSCM · scheduler
Scheduler screen with Cron-style timing for automated scans and the next scheduled scan time

Scheduler

Set it once. It runs at 22:00 every night

Cron-style timing with the next scan time announced in advance. Repetitive, fixed scan jobs stop being a weekly configuration task