Continuous vulnerability scanning

Continuous vulnerability scanning — because attackers don't wait for your quarterly.

A point-in-time scan is stale the moment a new CVE drops or a new subdomain appears. Perimeter scans on a schedule, diffs your attack surface week over week, re-prioritizes daily against EPSS and the CISA KEV catalog, and tracks every finding to closed with SLAs and rescan-to-verify.

Start continuous scanning free How it works

Point-in-time vs continuous

CapabilityQuarterly / point-in-timePerimeter continuous
New-CVE exposure windowUp to 90 daysDays — daily EPSS/KEV re-check
Attack-surface driftMissed until next scanWeek-over-week diff + alert
Subdomain-takeover detectionStaleCaught the week it appears
Prioritization freshnessFrozen at scan timeRe-scored daily as EPSS/KEV change
Remediation verificationManual re-scanRescan-to-verify auto-closes fixes
Compliance recency"Last scanned 3 months ago"Always-current, timestamped evidence

What "continuous" means in Perimeter

Scheduled re-scans

Weekly on Starter, daily on Pro — external (Nuclei) and internal (OpenVAS/Trivy via the Lookout agent) on a cadence you set.

Daily re-enrichment

Even between scans, every open finding is re-checked against fresh EPSS scores and the CISA KEV catalog. A CVE that gets weaponized overnight is reprioritized by morning.

Drift alerts

New asset, new open port, new exposure, expiring cert, SLA breach — pushed to Slack / Teams / email / webhook. Only what changed, only what matters.

Continuous scanning is a compliance requirement now

PCI DSS 11.3 wants scans quarterly and after every significant change. The HIPAA 2026 Security Rule makes 6-month vulnerability scans required, not addressable. CMMC RA.L2-3.11.x expects ongoing scan-and-remediate. Cyber-insurers increasingly ask for proof of continuous scanning at renewal. Perimeter timestamps every scan and maps findings to the exact control — so "are you scanning continuously?" is answered with evidence, not a promise.

Frequently asked questions

Does continuous scanning cause alert fatigue?

Not when it's prioritized. Perimeter alerts only on what changed and what matters, and multi-engine corroboration cuts false positives — so you fix 4, not 400.

How fresh is the prioritization?

EPSS and KEV are re-checked daily, so a newly-exploited CVE on your stack is re-ranked within a day — far faster than a one-off external scan.