Talk to us
by IruTechBag Intel Page

Iru Vulnerability Management

Your scanner lists the CVEs on every laptop. Someone still has to patch them — Iru Vulnerability Management reads every app on your Macs and Windows laptops every 15 minutes, ranks the CVEs it finds by severity and known exploitation, and lets Auto Apps patch them.

Scans apps every 15 minutesCVSS plus known-exploited rankingQuote-only; US or EU hosting

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Iru prints no price; contracts are annual and counted per device by platform
Quote
Cadence
The interval between app-inventory scans on each device; CVE matching runs hourly
15 min
Analysts
Iru does not announce a Gartner Magic Quadrant placement for any of its products
None
India
Tenants run on AWS in the United States or Germany; no Indian hosting region
US or EU

Quick answer

Iru Vulnerability Management (formerly Kandji Vulnerability Management) reads the installed apps on each Mac and Windows device every 15 minutes, matches them to NVD CVE records hourly, ranks the findings by CVSS and the Known Exploited Vulnerabilities list, and can push the fix through Auto Apps. It covers endpoint apps only, with no network, web, cloud or OT scanning. It is quote-only and annual, and tenants sit in the US or EU, not India. Read more ↓ Show less ↑
Part 01 · Orient

The Iru platform family

This page covers Iru Vulnerability Management — CVE detection and Auto Apps remediation. The rest:

Quick facts

30-second orientation
Product
Agent-based CVE detection and Auto Apps remediation for installed apps on Mac and Windows
Maker
Iru, Inc., US-based (Miami and San Diego); founded 2018, CEO Adam Pettit
Status
Renamed from Kandji Vulnerability Management on 22 October 2025; Kandji tenants upgrade by 1 December 2026
Price
Quote-only; annual commitment billed annually; free 14-day trial
Licence
A separate line on the Iru bill, counted per device by platform
Cadence
App inventory scanned every 15 minutes; matched against NVD CVEs every hour
Ranking
CVSS severity plus the Known Exploited Vulnerabilities (KEV) catalogue
Fix
The Vulnerability Response Library Item enforces Auto Apps updates by CVE severity
India
No Indian region: tenants are hosted on AWS in the United States or Germany
In India via
TechBag — Auto Apps coverage check, trial scoping, quote in INR with GST
Part 02 · Learn

Understand endpoint vulnerability management before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is endpoint vulnerability management?

An agent on each device lists installed software and flags versions with known CVEs, with no network scan.

A quarterly scan and hand-pushed patches vs Iru Vulnerability Management — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionQuarterly scans, hand-pushed patchesIru Vulnerability Management
Spotting a vulnerable appA quarterly network scan, if the laptop is on siteAn agent scan every 15 minutes, wherever it is
Deciding what goes firstSorting a spreadsheet by CVSSCVSS plus a known-exploited (KEV) marker
Getting the update outPackaging and pushing each update by handAuto Apps enforcing updates by CVE severity
Recording exceptionsA note in someone’s inboxRisk acceptance and device exclusion in the console
Tools involvedScanner, patch tool and MDM, reconciled by handOne agent and one console with device management
What it is NOT—A network, server, web-app, cloud or OT scanner

The cheapest test is the 14-day trial: enrol twenty laptops, let the 15-minute scans run for a week, and count how many critical CVEs Auto Apps closes.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where the inventory is read

Agent

The Iru Agent on each device

The agent that already manages the Mac or Windows laptop lists its installed applications and versions every 15 minutes, so no separate scanner has to be deployed or booked.

02
How a finding is born

Matching

Hourly CVE correlation

Each hour the inventory is checked against National Vulnerability Database records, and Iru’s Security Research team enriches those entries before they reach the console.

03
What rises to the top

Ranking

CVSS and KEV ordering

Every finding carries its CVSS severity and a marker when the CVE sits in the Known Exploited Vulnerabilities catalogue, so flaws already used in attacks outrank the rest.

04
How the fix reaches the device

Response

Vulnerability Response Library Item

Assigned like any Library Item, it tells Auto Apps to enforce updates by CVE severity; risk acceptance and device exclusion cover what you decide not to patch yet.

One agent, two jobs — the Iru Agent that manages each Mac and PC also lists its apps for hourly CVE matching.

Part 03 · Evaluate

Six capabilities. Detect, prioritise, remediate.

Iru Vulnerability Management finds vulnerable apps on managed devices and patches them from the same console.

Detect
Inventory

A fresh look every 15 minutes

The agent rereads installed apps and versions four times an hour, so a vulnerable build installed this morning is visible today.

Detect
NVD match

Hourly CVE correlation

Inventory is compared with NVD CVE records every hour, and Iru’s Security Research team adds context to the raw entries.

Prioritise
CVSS

Severity you can sort by

Each finding carries its CVSS score, so policies and dashboards split critical and high flaws from the low-severity long tail.

Prioritise
KEV

Known-exploited flaws first

CVEs on the Known Exploited Vulnerabilities list are flagged, putting flaws attackers already use ahead of theoretical ones.

Remediate
Auto Apps

Patch from the catalogue

Vulnerability Response makes Auto Apps enforce updates by severity on Mac and Windows, drawing on a catalogue of 200+ apps.

Remediate
Exceptions

Accept a risk on record

Risk acceptance and device exclusion park a finding you cannot fix yet, rather than leaving it open as a standing alert.

See it, don’t just read it

Watch Iru Vulnerability Management in action

The product overview, a short look at Vulnerability Response, and how Intruder.io automated its patching with Iru.

Iru (official)·Product overview, 2025

Iru Vulnerability Management

Iru’s own tour of the module: app inventory, CVE findings and the route from a finding to a fix.

Iru (official)·Short explainer, 2026

Iru in Two: Vulnerability Response

A brief walk through the Library Item that tells Auto Apps to enforce updates by CVE severity.

Iru (official)·Customer story, 2026

How Intruder.io automated patching with Iru

Intruder.io describes moving its patching from manual effort to automated updates on Iru.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Iru Vulnerability Management

Scanners find the flaw and stop there. Iru patches it from the same agent.

What it does better than a scanner — and the surfaces it never sees.

01

Detection with no scan window to book

The scan runs inside the Iru Agent already managing the laptop, so there is no network scanner to place and no scan credential to store. App inventory refreshes every 15 minutes and is matched to NVD CVEs hourly, so a laptop that never visits the office is still assessed.

02

The finding and the fix in one console

Most scanners hand over a CVE list and stop. Here the Vulnerability Response Library Item makes Auto Apps enforce updates by CVE severity on Mac and Windows, so the platform that spotted a flaw also patches it. Risk acceptance and device exclusion keep exceptions on record.

03

Ranking that starts from real attacks

Findings are ordered by CVSS severity and by whether the CVE is in the Known Exploited Vulnerabilities catalogue. That is plainer than Qualys TruRisk or Tenable VPR, but transparent: a KEV marker means attackers already use the flaw, a reason any auditor accepts for patching first.

04

Where it stops

It assesses apps on Mac and Windows devices running the Iru Agent, and nothing else: Linux, network gear, servers outside the fleet, web apps, cloud and OT are out of scope. Automatic fixes cover only Auto Apps titles. There is no public price, Gartner placement or Indian region.

The idea
Find and patch apps from one agent
The residency
US or EU tenants; no Indian region
The price
Quote-only, per device, annual
Proof, not promises

The numbers behind the platform

15 minutes
between application-inventory scans on each managed Mac and Windows device
— Vendor docs
1 hour
between rounds of matching that inventory against NVD CVE records
— Vendor docs
200+ apps
in the Auto Apps catalogue that Vulnerability Response can update for you
— Vendor
14 days
of free trial before an annual contract that is billed annually
— Vendor
2 platforms
whose apps it assesses: Mac and Windows; Linux and mobile are not covered
— Vendor docs
6000+ teams
Iru’s own customer figure on its About page in 2026, across all products
— Vendor

What your Iru Vulnerability Management rollout looks like

Week 1Model

Hold the catalogue against your apps

Export installed software from current tools and see which titles Auto Apps covers; anything missing needs manual packaging.

Week 2Pilot

Start the 14-day trial

Enrol a pilot group of Macs and Windows 11 24H2 laptops, and let a few days of 15-minute scans build a baseline.

Week 3Decide

Set the response policy

Choose which severities Auto Apps should enforce, and agree who signs risk acceptances for apps you cannot update yet.

Month 2Prove

Measure time to patch

Compare open critical and KEV-flagged findings before and after Vulnerability Response, and track how long each takes to close.

Month 3Commit

Cover what it leaves out

Keep or buy a scanner for servers, network gear and cloud, then sign the annual contract with devices counted by platform.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
38+ reviews*
82% would recommend
Scan freshness4.5
Auto Apps remediation4.4
Prioritisation3.9
Coverage breadth3.3
Value for money3.8
5★
42%
4★
38%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
SaaS
“A critical browser CVE landed on a Tuesday. By lunch the dashboard showed it on 140 Macs and Auto Apps had updated most of them.”
IT Manager
SaaS
Fintech
“The KEV flag is what our CISO reads. It turned a 600-line CVE export into a short list we could defend in a board review.”
Security Lead
Fintech
Media
“We still run a network scanner for servers and switches. Iru only looks at the laptops, and it never pretends otherwise.”
Infrastructure Engineer
Media
Architecture
“Risk acceptance stopped the alert noise on a legacy design tool we cannot upgrade until the next licence renewal.”
Systems Administrator
Architecture
Consulting
“Windows support is newer than Mac. Our Windows 10 machines could not enrol, so plan the OS upgrade before the pilot.”
Desktop Engineer
Consulting
Healthcare
“Two of our clinical apps are not in Auto Apps, so they still need a manual package. Check your critical titles before signing.”
Head of IT
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the vulnerability management market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Vulnerability Management Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Iru Vulnerability ManagementThis page

Quote-only, per device by platform; Mac and Windows apps only.

Grid 02 · The architecture

Asset Breadth × Fix Depth

The grid nobody publishes — how many kinds of asset it assesses vs how far it goes in fixing what it finds.

Endpoint fixersFind-and-fix platformsSensor-bound viewsBroad reporters
Iru Vulnerability ManagementThis page

Mac and Windows apps; Auto Apps enforces fixes by severity.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Iru Vulnerability Management vs the vulnerability management field

Against Action1, Qualys VMDR, Tenable Vulnerability Management, CrowdStrike Falcon Exposure Management and Microsoft Defender Vulnerability Management — on coverage, ranking, patching, price, support and India.

DimensionIru Vulnerability ManagementAction1 Vulnerability RemediationQualys VMDRTenable Vulnerability ManagementCrowdStrike Falcon Exposure ManagementMicrosoft Defender Vulnerability Management
What it isEndpoint app CVEs + fixEndpoint find-and-fixFlagship VM platformCloud VM (ex-Tenable.io)Exposure on the sensorInside MDE Plan 2
DeploymentSaaS, via Iru AgentCloud console, own agentAgents + scanners, cloudSaaS or Security CenterFalcon sensor, SaaSMDE sensor, SaaS
Assets coveredMac + Windows apps onlyWin, Mac, Linux devicesIT, cloud, OT, IoTHosts and network gearEndpoint, external, OTFive OSes, onboarded
Detection cadence15-min scan, hourly CVEsAgent-led, not publishedContinuous Cloud AgentAgents + scheduled scansSensor, no scan windowContinuous from sensor
PrioritisationCVSS + KEVCVSS, exploit contextTruRisk scoringVPRExPRT.AIThreat-led, in portal
RemediationAuto Apps enforces fixesOne-click patchingPatching is an add-onReports, does not patchRanks, does not patchIntune tasks, blocking
Pricing modelPer device, by platformPer endpoint, annualPer assetPer asset, 1–3 yearsFalcon module, quotedPer user, add-on
Published entry priceNot publishedFree to 200, then $4~$199–250/asset (rep.)$3,700 for 100 assetsQuote only$2/user/month add-on
Included vs add-onIts own licence linePatching in same planPatch, CAR are add-onsWeb and cloud separateNeeds Falcon platformPremium data costs extra
IntegrationsIru stack, S3, MCPMulti-tenant, own engineServiceNow, Jira, CMDBITSM, SIEM, connectorsBeside Falcon EDRIntune, Sentinel, XDR
India dataUS or EU onlyPromised for 2026IN1 India platformin01 site, AWS MumbaiIndia cloud announcedAzure India geo
Support24/5 chat, portal, emailSupport fee on paid tier24/7, no extra charge24x365 costs $400 moreNot itemised publiclyYour Microsoft plan
Lock-in and exitTied to the Iru agentOne agent, both jobsMany apps, one agentExports, on-prem routeBest inside FalconMicrosoft 365 gravity
Best fitApple-first Iru fleetsPatch-gap teamsBroad estates, India podPublished-price VMExisting Falcon estatesMicrosoft 365 E5 shops
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Iru Vulnerability Management if…

  • ✓Your laptops are mostly Macs already managed by Iru Endpoint, and you want their app CVEs found without a scanner
  • ✓You want a found vulnerability patched by Auto Apps from the same console, by severity, with no hand-off to another team
  • ✓A CVSS and known-exploited ranking is enough, and you would rather explain a KEV flag than a proprietary score

Compare alternatives if…

  • ✓Servers, network devices or cloud accounts need assessing too — Qualys VMDR and Tenable cover those surfaces
  • ✓You want a price before talking to sales — Tenable lists one, and Action1 is free up to 200 endpoints
  • ✓Vulnerability data must stay in India — Qualys, Tenable and Microsoft each document an Indian hosting site

Do not expect…

  • ✓Linux, network, web-app, cloud or OT scanning
  • ✓Automatic patching for apps outside the Auto Apps catalogue
  • ✓A published price, an Indian hosting region or a Gartner placement

Iru Vulnerability Management is one of 20 vulnerability management products TechBag carries. The Vulnerability Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does chasing app vulnerabilities by hand cost you?

Drag the sliders (managed Mac and Windows devices; IT-hour cost). Estimates model IT time spent tracking app CVEs and pushing updates by hand at an assumed 1.5 hours per device a year, with 70% of it removed by agent scanning and Auto Apps enforcement. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual app-patching effort
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Iru Vulnerability Management is quote-only, licensed per device by platform on an annual contract billed annually, with a free 14-day trial and 24/5 support in every plan. Per-Mac prices on third-party sites are an old Kandji list, not current. TechBag gets the quote itemised by platform and bills in INR with GST.

14-day trial

Best for proving Auto Apps coverage

  • Free for 14 days
  • Mac and Windows app scanning
  • Vulnerability Response policies

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Annual licence

Best for fleets already on Iru Endpoint

  • Quote-only, per device by platform
  • Annual commitment, billed annually
  • 24/5 support and free onboarding

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Fleet mix

What share of devices are Macs and Windows PCs? Linux machines and servers outside Iru get no coverage.

2
Windows version

Are Windows laptops on Windows 11 24H2 or later? Older builds cannot be managed by Iru at all.

3
App catalogue

Do your business-critical apps appear in Auto Apps? Titles outside it still need manual updates.

4
Severity policy

Which CVSS levels should Vulnerability Response enforce at once, and which wait for a change window?

5
Exceptions

Who approves risk acceptance and device exclusion, and how often are those decisions reviewed?

6
Other surfaces

Which scanner will cover servers, network devices, web apps and cloud accounts alongside Iru?

7
Hosting

Will auditors and customers accept US or EU hosting, given Iru offers no Indian region?

8
Licence

Does the quote count devices per platform and state the annual term? Ask for INR with GST.

FAQ

Questions buyers ask

It is Iru’s module for finding vulnerable applications on Mac and Windows devices. The Iru Agent reads each device’s installed apps every 15 minutes, matches them against NVD CVE records hourly, ranks the results by CVSS and the KEV catalogue, and can enforce fixes through Auto Apps.

Ready to evaluate Iru Vulnerability Management?

Check which of your apps Auto Apps can patch, or let a TechBag advisor scope a trial that pairs Iru with a scanner for servers and cloud.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.