Skip to main content
AxoniusCustomer feedback

A commenter recommends Axonius to solve the problem of reconciling assets between different scanners, stating they use it to join data from multiple sources into a single asset record.

What happened

Post: "Ive been ignoring that our two scanners disagree on thousands of criticals for a while. Last week I finally looked."

Source

Post

If you ask me how many critical vulnerabilities we have, you will get different numbers. Ive been ignoring it for a year because dealing with it looked worse than not knowing. We run two scanners. Last week I finally compared them properly. Tenable flagged 12,400 criticals, Qualys flagged 9,800, and they agreed on about 6,000. Ive been reporting whichever console I happened to have open. Two days into this and Im not done. Their CVE sources dont line up, so some of this is them describing the same thing two ways. But a decent chunk is the same box turning up as two assets. One tool knows it by hostname, the other by IP and a shortened name. Two identities, two different finding sets. Thats the bit I cant reconcile, because I dont know which record is the real one. Anyone cracked the asset side of this without it turning into a full time job?

Extracted from these lines

  • [comment u/Sad-Technician-5552] You cant pick which scanner is right about a box, so stop matching on hostname. Its a label somebody typed, it drifts the moment a box gets reimaged or dns goes stale. Match on something the machine owns, the serial.

  • [comment u/Sad-Technician-5552] We run that join in axonius, every sync rebuilds it so both scanners land on one asset record instead of two name strings.

reddit.com/r/blueteamsec/comments/1wjikaa/ive_been_ignoring_that_our_...Read the full source

Comments on the post

5 of 7 comments
  • “Before you chase the asset side, check both scanners are looking at the same estate. Authenticated versus unauthenticated changes the asset count on its own, and so does a discovery range that hasn't been updated since the last office move. If one tool is credentialed and the other isn't, you're comparing two different questions. Rule that out first because it's cheap. If the scope lines up, the”

    u/Metku_Krissy9 points · Sep 18, 2026View

  • “Don't match via name. Use something like serial number, asset tag, even MAC address would be better.”

    u/immewnity1 points · Sep 18, 2026View

  • “reconcile on what's actually exploited first, the rest is noise you can schedule.”

    u/ILoveAppSec1 points · Sep 19, 2026View

  • “The thing that actually got us unstuck was giving up on fixing the list and measuring it instead. Take the union of the two scanners, then track how much they overlap as a percentage. Ours was a mess at the start and it took two quarters to look resepctable, but that number going up is the thing you can take to a meeting. arguing about which console is correct isn't. The other half of it is poli”

    u/Realistic_Strike52410 points · Sep 18, 2026View

  • “You cant pick which scanner is right about a box, so stop matching on hostname. Its a label somebody typed, it drifts the moment a box gets reimaged or dns goes stale. Match on something the machine owns, the serial. We run that join in axonius, every sync rebuilds it so both scanners land on one asset record instead of two name strings. If the two scanners are the whole problem, a script and a”

    u/Sad-Technician-55520 points · Sep 18, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/blueteamsec

The full record

From the Signal API record

Numbers

Mentions
1

Details

Timing
Ongoing state
Category
Integration
Virality
Low
Post kind
Text
Prominence
Aside
Company's role
Vendor

Topics and mentions

Topics

  • asset management
  • data reconciliation
  • cybersecurity
  • vulnerability management

Flair

  • help me obiwan (ask the blueteam)

Extraction

Sentiment
Positive
Detected
Sep 18, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for Axonius and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Axonius this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/b4751af6-bec0-532e-a6a3-735fe71399ee returns this record as JSON. POST /v1/companies/enrich returns every signal for axonius.com.

{
  "signal_id": "b4751af6-bec0-532e-a6a3-735fe71399ee",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-09-18T06:35:25+00:00",
  "company": {
    "name": "Axonius",
    "domain": "axonius.com"
  },
  "data": {
    "nsfw": false,
    "stage": "none",
    "awards": 0,
    "timing": "ongoing_state",
    "topics": [
      "asset management",
      "data reconciliation",
      "cybersecurity",
      "vulnerability management"
    ],
    "post_id": "1wjikaa",
    "summary": "A commenter recommends Axonius to solve the problem of reconciling assets between different scanners, stating they use it to join data from multiple sources into a single asset record.",
    "category": "integration",
    "comments": [
      {
        "url": "https://www.reddit.com/r/blueteamsec/comments/1wjikaa/comment/pajd5ki/",
        "depth": 0,
        "score": 9,
        "author": "Metku_Krissy",
        "excerpt": "Before you chase the asset side, check both scanners are looking at the same estate. Authenticated versus unauthenticated changes the asset count on its own, and so does a discovery range that hasn't been updated since the last office move. If one tool is credentialed and the other isn't, you're comparing two different questions.\n\n Rule that out first because it's cheap. If the scope lines up, the",
        "posted_at": "2026-09-18T09:13:49.000Z",
        "author_url": "https://www.reddit.com/user/Metku_Krissy/"
      },
      {
        "url": "https://www.reddit.com/r/blueteamsec/comments/1wjikaa/comment/pakx76s/",
        "depth": 0,
        "score": 1,
        "author": "immewnity",
        "excerpt": "Don't match via name. Use something like serial number, asset tag, even MAC address would be better.",
        "posted_at": "2026-09-18T14:38:48.000Z",
        "author_url": "https://www.reddit.com/user/immewnity/"
      },
      {
        "url": "https://www.reddit.com/r/blueteamsec/comments/1wjikaa/comment/pap9vzx/",
        "depth": 0,
        "score": 1,
        "author": "ILoveAppSec",
        "excerpt": "reconcile on what's actually exploited first, the rest is noise you can schedule.",
        "posted_at": "2026-09-19T03:27:13.000Z",
        "author_url": "https://www.reddit.com/user/ILoveAppSec/"
      },
      {
        "url": "https://www.reddit.com/r/blueteamsec/comments/1wjikaa/comment/pajntzd/",
        "depth": 0,
        "score": 0,
        "author": "Realistic_Strike5241",
        "excerpt": "The thing that actually got us unstuck was giving up on fixing the list and measuring it instead. Take the union of the two scanners, then track how much they overlap as a percentage. Ours was a mess at the start and it took two quarters to look resepctable, but that number going up is the thing you can take to a meeting. arguing about which console is correct isn't.\n\n The other half of it is poli",
        "posted_at": "2026-09-18T10:38:08.000Z",
        "author_url": "https://www.reddit.com/user/Realistic_Strike5241/"
      },
      {
        "url": "https://www.reddit.com/r/blueteamsec/comments/1wjikaa/comment/pajv1mb/",
        "depth": 0,
        "score": 0,
        "author": "Sad-Technician-5552",
        "excerpt": "You cant pick which scanner is right about a box, so stop matching on hostname. Its a label somebody typed, it drifts the moment a box gets reimaged or dns goes stale. Match on something the machine owns, the serial.\n\n We run that join in axonius, every sync rebuilds it so both scanners land on one asset record instead of two name strings. If the two scanners are the whole problem, a script and a",
        "posted_at": "2026-09-18T11:25:52.000Z",
        "author_url": "https://www.reddit.com/user/Sad-Technician-5552/"
      },
      {
        "url": "https://www.reddit.com/r/blueteamsec/comments/1wjikaa/comment/paiyc4v/",
        "depth": 0,
        "score": -1,
        "author": "VividGanache2613",
        "excerpt": "Take a look at pwnkemon. Rather than just giving you a list of “maybe CVEs” it actually works out what is real for you so you end up with an actionable list and not second job doing the vendors job for them.",
        "posted_at": "2026-09-18T07:06:28.000Z",
        "author_url": "https://www.reddit.com/user/VividGanache2613/"
      }
    ],
    "evidence": [
      "[comment u/Sad-Technician-5552] You cant pick which scanner is right about a box, so stop matching on hostname. Its a label somebody typed, it drifts the moment a box gets reimaged or dns goes stale. Match on something the machine owns, the serial.",
      "[comment u/Sad-Technician-5552] We run that join in axonius, every sync rebuilds it so both scanners land on one asset record instead of two name strings."
    ],
    "virality": "low",
    "post_date": "2026-09-18T06:35:25.000Z",
    "post_kind": "text",
    "post_text": "If you ask me how many critical vulnerabilities we have, you will get different numbers. Ive been ignoring it for a year because dealing with it looked worse than not knowing.\n\nWe run two scanners. Last week I finally compared them properly. Tenable flagged 12,400 criticals, Qualys flagged 9,800, and they agreed on about 6,000. Ive been reporting whichever console I happened to have open.\n\nTwo days into this and Im not done. Their CVE sources dont line up, so some of this is them describing the same thing two ways. But a decent chunk is the same box turning up as two assets. One tool knows it by hostname, the other by IP and a shortened name. Two identities, two different finding sets.\n\nThats the bit I cant reconcile, because I dont know which record is the real one.\n\nAnyone cracked the asset side of this without it turning into a full time job?",
    "sentiment": "positive",
    "subreddit": "blueteamsec",
    "post_flair": [
      "help me obiwan (ask the blueteam)"
    ],
    "post_title": "Ive been ignoring that our two scanners disagree on thousands of criticals for a while. Last week I finally looked.",
    "prominence": "aside",
    "source_url": "https://www.reddit.com/r/blueteamsec/comments/1wjikaa/ive_been_ignoring_that_our_two_scanners_disagree/",
    "entity_role": "vendor",
    "post_author": "Aayushman_Shopbell",
    "upvote_ratio": 0.7142857142857143,
    "mention_count": 1,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/blueteamsec/",
    "total_upvotes": 6,
    "comments_total": 7,
    "total_comments": 7,
    "post_author_url": "https://www.reddit.com/user/Aayushman_Shopbell/",
    "signal_category": "feedback",
    "comments_included": 6
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.