Vulnerability Management (VM) focuses on what makes the most impact on risk to business-critical assets. We deliver actionable risk insights by identifying exposures from exploitable vulnerabilities across your endpoints and prioritizing what should be addressed first to keep the attack surface shrinking. This offering combines vulnerability management with native patch management and asset management, so identification, remediation, and visibility all happen within a single platform.
PDQ Connect is a cloud-based endpoint vulnerability and patch management platform that we have partnered with to deliver VM services. PDQ makes it easy to identify vulnerabilities across your Windows and macOS endpoints with no unnecessary complexity. The PDQ platform is MSP enabled, empowering partners to provide their clients with a proactive solution to manage and mitigate risk.
This offering through SonicSentry provides partners the combined intelligence of the PDQ platform and the SonicSentry organization. SonicSentry provides the product and reporting at a reduced, consumption-based, month-to-month price point, and works closely with partners to help them focus their attention on what to remediate or patch and how to do so effectively. SonicSentry also provides highly praised support and training, enabling partners to become as self-reliant as needed while ensuring they always have a direct contact when an issue arises. Crucially, this offering closes the loop on the vulnerability management lifecycle, allowing your team to identify and remediate vulnerabilities in the same place.
The agent scans enrolled Windows and macOS endpoints for known vulnerabilities, drawing from multiple sources including the MITRE CVE database, NIST NVD, CISA's Known Exploited Vulnerabilities (KEV) catalog, vendor release notes, and ongoing security research. Once the agent is installed on a machine, it begins reporting on discovered vulnerabilities and outdated software automatically. It is then validated whether a machine meets all conditions required for a vulnerability to actually be applicable, keeping findings accurate and actionable.
Each identified vulnerability is assigned a risk score based on its CVSS rating, potential business impact, and likelihood of exploitation. Vulnerabilities are ranked by this score, so the most critical issues in your environment are always surfaced first. If your team decides to accept the risk of a particular vulnerability rather than remediate it, it can be marked as ignored, for a single device or across the environment.
Scans run automatically on a recurring basis as devices check in, so newly discovered vulnerabilities and outdated software are typically surfaced within hours rather than days. Your team can also trigger an on-demand scan for an individual device or in bulk at any time.
Native patch management is what sets this offering apart. Once a vulnerability or outdated application is identified, your team can deploy the patch directly to the affected endpoint from within the platform, no separate patching tool required. This creates a true end-to-end workflow where identifying and fixing a problem happen in the same place.
This applies to:
Beyond vulnerability and patch management, the platform provides visibility into the hardware and software assets across your environment. Enrolled endpoints automatically report device configuration and hardware details, along with a full inventory of installed software and versions.
This gives your team a centralized, up-to-date view of what is running across the environment, without needing a separate asset tracking tool. Devices can also be organized into dynamic groups based on inventory data, making it easier to manage and act on specific subsets of your environment.
This applies to:
Typical Workflow
Asset visibility runs continuously in the background, while the core vulnerability-to-patch workflow follows this sequence:
The offering gives your team the ability to patch vulnerabilities directly from the platform, eliminating the need to pivot to an RMM or separate software deployment tool to find, download, and push an update. In most cases, the update needed to mitigate a vulnerability is already available within the platform, ready to deploy.
For the rare case where a patch is not readily available, the platform allows for quick and efficient custom package creation, so you can still push the needed update across multiple machines in the environment. Custom packages can be created directly by your team, and SonicSentry can also assist with package creation and maintenance as part of ongoing advisory support.
The platform also supports patch and update automation for many commonly used applications (for example, Chrome, Edge, and Notepad++), so your team can ensure the latest patch is installed automatically once it becomes available.
No. This offering is currently co-managed, meaning the platform identifies vulnerabilities, but the responsibility for reviewing and applying patches falls to the partner. A fully managed offering, in which SonicSentry performs patching on the partner's behalf, is on our roadmap.
Yes. We offer a 14-day Proof of Concept so you can test all supported features of the platform firsthand. A PoC is not required to take advantage of this offering, but it is available if you would like to evaluate the platform before committing.
Starting a PoC
To begin a 14-Day Proof of Concept, contact your SonicSentry account representative to request a quote. Once the quote is signed, SonicSentry will provision access and your kickoff call will be scheduled. This offering PoC allows for up to 100 endpoints on Windows and macOS devices.
PoC Timeline
Day 1 – Kickoff Call
Day 7 – Midpoint Check-in
Day 14 – PoC Converts to Live Offering
Converting to Production/Live Offering
At the end of the 14-day evaluation period, the PoC automatically converts to the live offering, and SonicSentry handles billing and licensing automatically, with no action required from the partner to formally convert. Reports and findings from the PoC period carry forward, so no data is lost in the transition.
Once live, partners can continue onboarding new customer tenants on an ad hoc basis without needing to contact SonicSentry first. Customers can also be removed on an ad hoc basis as needed. A SonicSentry representative will follow up periodically to schedule check-ins and implementation reviews.
Canceling the PoC
If a partner decides not to move forward after the PoC, they must contact SonicSentry before the PoC ends, through the respective PoC ticket. SonicSentry will send a reminder one business day before the PoC is scheduled to auto-convert.
Agent uninstall can be pushed directly from the portal, by either the partner or SonicSentry. SonicSentry will be responsible for shutting down the instance once the PoC is canceled.
Yes. In the platform, a parent organization is initially created for the partner, which they can use to install their own internal devices if desired. The partner can then create additional tenants for each of their customers, with these tenants nested as separate instances under the partner's existing parent organization.
Vulnerability review and patching are performed at the tenant level. There is currently no parent-level view or bulk action across tenants, so each customer tenant must be reviewed and remediated individually.
Yes. The portal supports a range of authentication and MFA options to keep your account secure. For primary login, you can use passwordless email authentication or link a Google or Microsoft account. For MFA, the portal currently supports an Authenticator App, with the option to add a Passkey or SMS as additional methods. When Account MFA is required, the portal ensures at least one method always remains active, so you can never be locked out by disabling your last available option.
Yes. This offering uses an agent-based deployment, currently supported on Windows and macOS endpoints. The agent is what enables both vulnerability scanning and patch management, so keeping agents deployed and healthy across your endpoints is essential to getting the full value of the platform.
An additional, optional agent is also available for remote desktop functionality, allowing partners to remotely access and manage endpoints directly through the platform if desired.
No. This offering is not intended to replace your existing RMM tool; it is purpose-built around vulnerability management, patch management, and asset management, as outlined above. That said, the platform does include RMM-style features and functionality, and some partners have chosen to fully migrate from their existing RMM to this offering as a complete solution.
No. This offering is scoped to vulnerability identification and remediation, not threat detection. Findings are not currently ingested, analyzed, or alerted on by the SonicSentry Security Operations Center (SOC). Vulnerability data remains within the platform and is reviewed directly by your team.
See the Service Plan for a full breakdown of responsibilities.
See the Service Plan for full deliverable details.
To contact SonicSentry support, visit the SonicSentry Support Portal. When asked to select a product, choose Vulnerability Management.
Support hours and targets: