Your scanner lists the CVEs on every laptop. Someone still has to patch them — Iru Vulnerability Management reads every app on your Macs and Windows laptops every 15 minutes, ranks the CVEs it finds by severity and known exploitation, and lets Auto Apps patch them.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Iru Vulnerability Management — CVE detection and Auto Apps remediation. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
An agent on each device lists installed software and flags versions with known CVEs, with no network scan.
What consolidation actually replaces, dimension by dimension.
| Dimension | Quarterly scans, hand-pushed patches | Iru Vulnerability Management |
|---|---|---|
| Spotting a vulnerable app | A quarterly network scan, if the laptop is on site | An agent scan every 15 minutes, wherever it is |
| Deciding what goes first | Sorting a spreadsheet by CVSS | CVSS plus a known-exploited (KEV) marker |
| Getting the update out | Packaging and pushing each update by hand | Auto Apps enforcing updates by CVE severity |
| Recording exceptions | A note in someone’s inbox | Risk acceptance and device exclusion in the console |
| Tools involved | Scanner, patch tool and MDM, reconciled by hand | One agent and one console with device management |
| What it is NOT | — | A network, server, web-app, cloud or OT scanner |
The cheapest test is the 14-day trial: enrol twenty laptops, let the 15-minute scans run for a week, and count how many critical CVEs Auto Apps closes.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The agent that already manages the Mac or Windows laptop lists its installed applications and versions every 15 minutes, so no separate scanner has to be deployed or booked.
Each hour the inventory is checked against National Vulnerability Database records, and Iru’s Security Research team enriches those entries before they reach the console.
Every finding carries its CVSS severity and a marker when the CVE sits in the Known Exploited Vulnerabilities catalogue, so flaws already used in attacks outrank the rest.
Assigned like any Library Item, it tells Auto Apps to enforce updates by CVE severity; risk acceptance and device exclusion cover what you decide not to patch yet.
One agent, two jobs — the Iru Agent that manages each Mac and PC also lists its apps for hourly CVE matching.
Iru Vulnerability Management finds vulnerable apps on managed devices and patches them from the same console.
The agent rereads installed apps and versions four times an hour, so a vulnerable build installed this morning is visible today.
Inventory is compared with NVD CVE records every hour, and Iru’s Security Research team adds context to the raw entries.
Each finding carries its CVSS score, so policies and dashboards split critical and high flaws from the low-severity long tail.
CVEs on the Known Exploited Vulnerabilities list are flagged, putting flaws attackers already use ahead of theoretical ones.
Vulnerability Response makes Auto Apps enforce updates by severity on Mac and Windows, drawing on a catalogue of 200+ apps.
Risk acceptance and device exclusion park a finding you cannot fix yet, rather than leaving it open as a standing alert.
The product overview, a short look at Vulnerability Response, and how Intruder.io automated its patching with Iru.
Iru’s own tour of the module: app inventory, CVE findings and the route from a finding to a fix.
A brief walk through the Library Item that tells Auto Apps to enforce updates by CVE severity.
Intruder.io describes moving its patching from manual effort to automated updates on Iru.
Want a live, India-context walkthrough for your environment?
Book a guided demo →What it does better than a scanner — and the surfaces it never sees.
The scan runs inside the Iru Agent already managing the laptop, so there is no network scanner to place and no scan credential to store. App inventory refreshes every 15 minutes and is matched to NVD CVEs hourly, so a laptop that never visits the office is still assessed.
Most scanners hand over a CVE list and stop. Here the Vulnerability Response Library Item makes Auto Apps enforce updates by CVE severity on Mac and Windows, so the platform that spotted a flaw also patches it. Risk acceptance and device exclusion keep exceptions on record.
Findings are ordered by CVSS severity and by whether the CVE is in the Known Exploited Vulnerabilities catalogue. That is plainer than Qualys TruRisk or Tenable VPR, but transparent: a KEV marker means attackers already use the flaw, a reason any auditor accepts for patching first.
It assesses apps on Mac and Windows devices running the Iru Agent, and nothing else: Linux, network gear, servers outside the fleet, web apps, cloud and OT are out of scope. Automatic fixes cover only Auto Apps titles. There is no public price, Gartner placement or Indian region.
Export installed software from current tools and see which titles Auto Apps covers; anything missing needs manual packaging.
Enrol a pilot group of Macs and Windows 11 24H2 laptops, and let a few days of 15-minute scans build a baseline.
Choose which severities Auto Apps should enforce, and agree who signs risk acceptances for apps you cannot update yet.
Compare open critical and KEV-flagged findings before and after Vulnerability Response, and track how long each takes to close.
Keep or buy a scanner for servers, network gear and cloud, then sign the annual contract with devices counted by platform.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“A critical browser CVE landed on a Tuesday. By lunch the dashboard showed it on 140 Macs and Auto Apps had updated most of them.”
“The KEV flag is what our CISO reads. It turned a 600-line CVE export into a short list we could defend in a board review.”
“We still run a network scanner for servers and switches. Iru only looks at the laptops, and it never pretends otherwise.”
“Risk acceptance stopped the alert noise on a legacy design tool we cannot upgrade until the next licence renewal.”
“Windows support is newer than Mac. Our Windows 10 machines could not enrol, so plan the OS upgrade before the pilot.”
“Two of our clinical apps are not in Auto Apps, so they still need a manual package. Check your critical titles before signing.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the vulnerability management market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only, per device by platform; Mac and Windows apps only.
The grid nobody publishes — how many kinds of asset it assesses vs how far it goes in fixing what it finds.
Mac and Windows apps; Auto Apps enforces fixes by severity.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Action1, Qualys VMDR, Tenable Vulnerability Management, CrowdStrike Falcon Exposure Management and Microsoft Defender Vulnerability Management — on coverage, ranking, patching, price, support and India.
| Dimension | Iru Vulnerability Management | Action1 Vulnerability Remediation | Qualys VMDR | Tenable Vulnerability Management | CrowdStrike Falcon Exposure Management | Microsoft Defender Vulnerability Management |
|---|---|---|---|---|---|---|
| What it is | Endpoint app CVEs + fix | Endpoint find-and-fix | Flagship VM platform | Cloud VM (ex-Tenable.io) | Exposure on the sensor | Inside MDE Plan 2 |
| Deployment | SaaS, via Iru Agent | Cloud console, own agent | Agents + scanners, cloud | SaaS or Security Center | Falcon sensor, SaaS | MDE sensor, SaaS |
| Assets covered | Mac + Windows apps only | Win, Mac, Linux devices | IT, cloud, OT, IoT | Hosts and network gear | Endpoint, external, OT | Five OSes, onboarded |
| Detection cadence | 15-min scan, hourly CVEs | Agent-led, not published | Continuous Cloud Agent | Agents + scheduled scans | Sensor, no scan window | Continuous from sensor |
| Prioritisation | CVSS + KEV | CVSS, exploit context | TruRisk scoring | VPR | ExPRT.AI | Threat-led, in portal |
| Remediation | Auto Apps enforces fixes | One-click patching | Patching is an add-on | Reports, does not patch | Ranks, does not patch | Intune tasks, blocking |
| Pricing model | Per device, by platform | Per endpoint, annual | Per asset | Per asset, 1–3 years | Falcon module, quoted | Per user, add-on |
| Published entry price | Not published | Free to 200, then $4 | ~$199–250/asset (rep.) | $3,700 for 100 assets | Quote only | $2/user/month add-on |
| Included vs add-on | Its own licence line | Patching in same plan | Patch, CAR are add-ons | Web and cloud separate | Needs Falcon platform | Premium data costs extra |
| Integrations | Iru stack, S3, MCP | Multi-tenant, own engine | ServiceNow, Jira, CMDB | ITSM, SIEM, connectors | Beside Falcon EDR | Intune, Sentinel, XDR |
| India data | US or EU only | Promised for 2026 | IN1 India platform | in01 site, AWS Mumbai | India cloud announced | Azure India geo |
| Support | 24/5 chat, portal, email | Support fee on paid tier | 24/7, no extra charge | 24x365 costs $400 more | Not itemised publicly | Your Microsoft plan |
| Lock-in and exit | Tied to the Iru agent | One agent, both jobs | Many apps, one agent | Exports, on-prem route | Best inside Falcon | Microsoft 365 gravity |
| Best fit | Apple-first Iru fleets | Patch-gap teams | Broad estates, India pod | Published-price VM | Existing Falcon estates | Microsoft 365 E5 shops |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Iru Vulnerability Management is one of 20 vulnerability management products TechBag carries. The Vulnerability Management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (managed Mac and Windows devices; IT-hour cost). Estimates model IT time spent tracking app CVEs and pushing updates by hand at an assumed 1.5 hours per device a year, with 70% of it removed by agent scanning and Auto Apps enforcement. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Iru Vulnerability Management is quote-only, licensed per device by platform on an annual contract billed annually, with a free 14-day trial and 24/5 support in every plan. Per-Mac prices on third-party sites are an old Kandji list, not current. TechBag gets the quote itemised by platform and bills in INR with GST.
Best for proving Auto Apps coverage
Best for a broader rollout
Best for fleets already on Iru Endpoint
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
What share of devices are Macs and Windows PCs? Linux machines and servers outside Iru get no coverage.
Are Windows laptops on Windows 11 24H2 or later? Older builds cannot be managed by Iru at all.
Do your business-critical apps appear in Auto Apps? Titles outside it still need manual updates.
Which CVSS levels should Vulnerability Response enforce at once, and which wait for a change window?
Who approves risk acceptance and device exclusion, and how often are those decisions reviewed?
Which scanner will cover servers, network devices, web apps and cloud accounts alongside Iru?
Will auditors and customers accept US or EU hosting, given Iru offers no Indian region?
Does the quote count devices per platform and state the annual term? Ask for INR with GST.
Check which of your apps Auto Apps can patch, or let a TechBag advisor scope a trial that pairs Iru with a scanner for servers and cloud.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.