Security teams rarely struggle with a lack of vulnerability alerts. The harder problem is determining which exposures are actually exploitable and whether they still matter as environments change.
Vicarius is addressing that challenge with the launch of
vIntelligence, a new platform designed to continuously validate security exposures and help teams move more quickly from detection to remediation. The system introduces what the company calls continuous agentic validation and integrates closely with Vicarius’ remediation platform, vRx.
Together, the two platforms are meant to close a long-standing operational gap. Many security tools identify vulnerabilities but leave security teams responsible for confirming the risk, prioritizing fixes, and coordinating remediation across different systems.
Continuous Validation Instead of Scheduled Scans
Traditional vulnerability management tools typically rely on scheduled scans. Those scans provide a snapshot of the environment at a specific moment but can leave gaps between scan cycles.
Roi Cohen, CEO and co-founder of Vicarius, told MSSP Alert that this model often leaves security teams working with outdated visibility.
“Traditional VM relies on scheduled scans weekly, monthly, or quarterly,” Cohen said. “If a new asset spins up or a zero-day drops the day after a scan, the security team is blind until the next cycle. It provides a point-in-time snapshot.”
vIntelligence is designed to respond as environments change rather than waiting for the next scheduled scan. If a new asset appears or a configuration changes, the platform can immediately trigger validation through vRx to determine whether the system is exposed.
“If a new asset is identified, the agent doesn't wait for a schedule,” Cohen said. “It immediately prompts vRx to scan and validate exposure. It’s dynamic and operates in real time.”
The platform can also generate its own detection logic when new threats emerge. According to Cohen, traditional vulnerability management tools depend heavily on vendor research teams to publish new signatures or detection plugins, which can take hours or even days.
“With vIntelligence, if a signature doesn't exist, the agent leverages vuln_gpt to autonomously generate the detection logic on the fly,” he said, adding that this can reduce the
mean time to detect from days to minutes.
Turning Vulnerability Data Into Action
Another challenge for security teams is the operational gap between identifying an issue and fixing it.
Most vulnerability tools produce long lists of CVEs and alerts that require manual analysis and prioritization before any remediation work begins. Cohen described that process as similar to an alarm system that identifies problems but leaves the response entirely to security teams.
“Traditional VM acts as a sophisticated alarm system,” he said. “It dumps a massive list of CVEs onto the security team's lap, requiring them to manually cross-reference threat intel, prioritize, and then figure out how to patch or apply compensating controls.”
vIntelligence is intended to move beyond that model by validating whether exposures are real and then linking those insights directly to remediation actions.
As Cohen explained, the system aggregates telemetry from other tools such as CrowdStrike or Wiz to confirm whether an exposure actually exists in the environment. Once validated, it can recommend or execute remediation steps while maintaining a human-in-the-loop approval model.
In practice, that might mean automatically pushing a configuration change to enforce CIS compliance while allowing security teams to approve the action before it is executed.
Connecting Validation and Remediation
The tight integration between vIntelligence and vRx is central to Vicarius’ approach.
Cohen describes the relationship between the two platforms in simple terms: vIntelligence provides the analysis while vRx executes the fix.
“vIntelligence acts as the brain that ingests third-party data, while vRx acts as the brawn,” he said.
Many exposure management platforms stop after prioritizing risk and then open tickets in tools such as Jira or ServiceNow. That handoff can delay remediation and introduce friction between security and IT teams.
By contrast, the Vicarius platform is designed to keep the process within the same workflow. Once an exposure is validated, vRx can apply a patch, run a remediation script, or deploy what the company calls Patchless Protection.
The integration also aims to preserve the context of security data as it moves between systems. Cohen noted that in many security stacks, integrating tools such as Tenable or CrowdStrike with remediation platforms requires API middleware or manual exports, which can strip away important context.
“Data often loses context during the transfer,” he said. “A critical alert in Tenable might lose its asset tags or business context by the time it reaches the person responsible for patching.”
With vIntelligence, the platform maintains the original context and maps it directly to a remediation action in vRx, ensuring that the same intelligence used to detect the issue is available when fixing it.
The system can also generate remediation logic dynamically. Because vIntelligence can prompt vRx to create detection or remediation scripts using vuln_gpt, the platform does not have to wait for vendor-provided patches or fix libraries before responding to new threats.
Implications for MSSPs
Automation and scalability are constant challenges for managed security service providers. Analysts often spend significant time validating alerts, coordinating remediation with clients, and managing different security tools across multiple customer environments.
Cohen believes the agentic model behind vIntelligence could allow MSSPs to build new service offerings that were previously difficult to scale.
“The agentic nature of vIntelligence allows MSSPs to launch premium service tiers that were previously too labor-intensive to scale,” he said.
One example is continuous compliance monitoring. Instead of conducting periodic audits, MSSPs could offer services that enforce CIS or NIST configurations in real time by detecting configuration drift and automatically prompting remediation through vRx.
The platform could also help service providers respond more quickly to newly emerging threats. When high-profile vulnerabilities appear, MSSPs could generate custom detection and remediation scripts across their customer environments without waiting for vendor updates.
Operational efficiency is another factor. Normally, when an MSSP identifies a vulnerability, analysts must open tickets for a client’s IT team and wait for remediation to occur.
“With vIntelligence, the analyst presents the discovery and the fix simultaneously,” Cohen said, reducing back-and-forth coordination and shortening the mean time to remediation.
Because the system can normalize data from different tools such as Tenable or CrowdStrike, MSSPs may also be able to manage multiple clients through a single operational interface, even when those clients use different security stacks.
Validating Risk Instead of Estimating It
Many exposure management and attack surface management tools attempt to estimate exploitability using simulations or attack path analysis.
Vicarius positions its approach as direct validation rather than theoretical analysis.
“Most validation tools use simulated attacks or theoretical path analysis to guess if a vulnerability is reachable,” Cohen said.
By pairing validation with vRx, the platform can deploy non-intrusive probes or generate custom checks that confirm whether a vulnerability or threat indicator is actually exploitable in a specific environment.
According to Cohen, that approach allows security teams to move from probability-based risk scoring to confirmed exposure.
“It provides ground truth, not a probability score.”