Use cases

CISA KEV EXPOSURE MONITORING

Turn a new known exploited vulnerability into a scoped worklist.

CISA KEV tells you which vulnerabilities are known to be exploited. PatchWindow adds the missing portfolio question: where has related technology been observed, and which properties should an authorized team confirm first?

THE ACCESS GAP

The feed is free. Correlating it to your estate is the work.

The CISA catalog is an excellent source of record, but it does not know your domains, brands, or technology history. A new entry still leaves teams collecting inventory, resolving product names, and deciding who needs to investigate.

PatchWindow automates that first-pass join. It preserves CISA facts separately from BuiltWith observations, then ranks potential matches without presenting passive evidence as proof of vulnerability.

WHAT YOU GET

A practical first pass, built for action.

01

Ingest the source of record

Track official CISA KEV additions and their required actions as the catalog changes.

02

Match against observations

Connect vendor and product aliases to technologies observed across public internet properties.

03

Produce a confirmation queue

Rank potential matches with timestamps, rationale, and the exact uncertainty an authorized owner must resolve.

HONEST BY DESIGN

Potential exposure is not confirmed vulnerability.

Public technology evidence can identify where investigation is likely to pay off. It cannot reliably prove the affected version, configuration, reachability, or remediation state.

Every PatchWindow result keeps that boundary visible and tells the asset owner what must be confirmed through authorized testing.

COMMON QUESTIONS

What buyers need to know.

Is PatchWindow affiliated with CISA?

No. PatchWindow uses the public CISA KEV catalog as an official source of record and clearly separates those source facts from its own matching output.

Does a technology match mean a domain is vulnerable?

No. It means related technology was observed and should be checked. Version, configuration, reachability, and remediation status still require authorized confirmation.

Why pay when the CISA KEV feed is free?

The paid product maintains the public-estate inventory, performs recurring product matching, preserves evidence, prioritizes results, and delivers alerts and portfolio workflow.

Can I try it on one domain first?

Yes. The public assessment provides a free passive preview for one domain before you choose portfolio monitoring.

FREE DOMAIN PREVIEW

See what the worklist looks like.

No agent, credentials, or active scan. Upgrade when you need continuous portfolio coverage.