The engine beneath the platform.
Vestryn is a clean-room network reconnaissance and detection engine: it finds every host, reads the traces it leaves, and identifies exactly what’s running — ports, services, versions, OS — then hands off clean CPEs for vulnerability matching.
Your networks. Direct, across VPN tunnels, in unprivileged and containerized deployments, and on modern cloud networks.
Structured results. Every host it finds — ports, services, versions, OS family and hostname — machine-readable, with CPE identifiers for CVE matching.
Say it VES-trin.
Latin. A trace, a footprint. The root of investigate.
Every host leaves a trace.
- vest
- the trace it leaves
- ryn
- the ending it shares with Kestryn
Three toes converging to a point: a V first, a raptor’s footprint a beat later. Kestryn and Vestryn rhyme by design — the raptor and the tracker.
Vestryn ships inside Kestryn.
Kestryn is the exposure-management platform that doesn’t stop at a list of findings — it finds, explains, prioritizes, and drives the fix, every step grounded in evidence and an auditable trail.
Kestryn hunts. Vestryn tracks. Prospica foresees. AuthX governs.
See the Kestryn platformWhere it runs.
One engine, in every place Kestryn reaches — including the sites that have no route back.
The platform runs it.
The central installation runs the engine, deployable wholly on-premise with no external call in any product path.
A collector carries it to a site with no link.
A site collector runs the engine with no link at all, exposing no inbound service and keeping its previous policy if a new one cannot be verified.
And the agent runs it on the host.
The agent runs the same engine on the host itself, holding no shared secret and shipping with its ingestion off by default.
One engine, not three builds of it. The same binary runs in all three places, so a host identified at a disconnected site and a host identified from the console are identified the same way — and a finding does not change because of where it was found.
Read what’s really there.
What Vestryn reports for a host it finds — and what it declines to report.
$ vestryn --detect -p 22,80,443 10.0.4.12 | jq -c 'select(.type=="service") | {port,state,service,product,version}'{"port":80,"state":"open","service":"http","product":"","version":""}{"port":443,"state":"open","service":"ssl/http","product":"nginx","version":"1.24.0"}{"port":22,"state":"filtered","service":"","product":"","version":""}
Three ports observed. One fully identified. Port 443 gave up a product and a version. Port 80 gave up only its service — the product and version fields are left empty rather than guessed. Port 22 answered nothing, and is reported filtered rather than assumed closed.
Field by field, that record reads:
- Live host
- Reachable.
- Hostname
- When one is found.
- Ports
- Open, closed or filtered — each state as observed.
- Service
- What is listening.
- Product
- Identified.
- Version
- Reported — the observed evidence supports it.
- Service
- What is listening.
- Product
- Identified.
- Version
- Withheld. The observed evidence does not support a version, so none is reported.
- OS family
- Reported.
- CPE identifier
- Issued for the first service. None for the second.
reported from observed evidencewithheld — nothing assumed
When a scan cannot run as asked, Vestryn says so. It never narrows the scan and reports it as complete.
Built from the inside out.
- In-house
- Written by the vendor that ships it. No third-party scanner inside the product.
- Clean-room
- Built from public standards.
- License-clean
- Permissively licensed. Carries no copyleft. Yours to ship inside a commercial product.
- One binary
- Single and embeddable. Releases are signed.
- Refuses to guess
- A version is reported only when the observed evidence supports it.
- Fails loud
- Rather than quietly narrowing a scan into one that only looks complete.
Nothing you can’t ship.