Continuous Threat Exposure Management Maturity Model (CTEMMM)
-
Updated
Feb 6, 2026
Continuous Threat Exposure Management Maturity Model (CTEMMM)
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
Adds Tenable's CVE intelligence to third-party findings ingested into Tenable One. Enriches third-party CVE findings with Tenable plugin intel and on-demand AI explanations.
🕵️ Purely passive OSINT/EASM/CTEM platform — 15+ data sources, zero-touch asset discovery, risk detection
Open-source Continuous Threat Exposure Management (CTEM) platform: asset discovery, attack surface management, risk-based prioritization, validation and remediation in one place. Go API + Next.js web UI.
Bug bounty reconnaissance pipeline — 25+ tools, CVSS 3.1, HackerOne/Bugcrowd submission
MCP server for CVEasy AI — connect Claude Desktop & Claude Code to your live CVEasy install. Thin client over the CVEasy REST API.
OpenCTEM Sensor: lightweight scanner runtime that runs Nuclei, Trivy, Semgrep, Betterleaks and recon tools close to your assets and reports results to the OpenCTEM platform.
The CVEasy open lab — runnable security harnesses, red-team probes, and experiments. Good-faith open source from CVEasy AI.
CTEM scanner over nmap: asset identity + exploitability (OSV/NVD/EPSS/KEV) + nuclei verification + detection-gap analysis
Documentation for OpenCTEM: getting started, deployment, operations, architecture and integration guides. Published at docs.openctem.io.
An Enterprise-Grade Attack Surface Management (ASM) & Open-Source Intelligence (OSINT) engine. Features autonomous dark web telemetry, automated Nuclei vulnerability scanning, real-time SEC financial risk scoring, and AI-driven executive reporting.
CVEasy threat intel payloads. Quarterly free drops. MIT licensed.
Go SDK for OpenCTEM: API client, sensor runtime kit and ready-made scanner integrations (Nuclei, Trivy, Semgrep, CodeQL, subfinder, httpx, naabu, katana) with an SSRF-safe HTTP layer.
Synthetic vulnerability exposure management portfolio covering asset inventory, vulnerability risk scoring, patch SLA tracking, stale assets, EDR coverage, exceptions, remediation dashboards, and control mapping.
RISKX - Research-first enterprise cyber-risk CLI: attack-surface discovery, vulnerability intelligence and risk prioritization. Evidence-backed, no guessing, offline-capable.
Vulnerability Management - AI - CTEM
Cogent — independent third-party profile of a public API surface, by API Evangelist. Cogent Security is an AI-driven vulnerability management platform whose AI agents discover, assess, remediate, and report on software vulnerabilities at machine speed, before attackers can exploit them.
Simulation of elastic scattering in electron microscopy using the multislice algorithm. Simulations include various STEM and TEM techniques such as ADFSTEM, BFSTEM, ABFSTEM and CoM.
To associate your repository with the ctem topic, visit your repo's landing page and select "manage topics."