Tripwire IP360 is a vulnerability and security risk management system. The product provides visibility into networks, both on-premises and in the cloud, including all devices and their associated operating systems, applications, and vulnerabilities. It discovers all networked hosts, applications and services on-premises, cloud, and container-based assets. The system supports agentless and agent-based scanning to find vulnerabilities in dynamic IP endpoints, containers, and other environments. It uses an application-centric approach to vulnerability assessment that searches for specific vulnerabilities based on operating system, applications and services, ensuring that only the required signatures are run. The product ranks vulnerabilities on a granular scale of 1–50,000. Risk scores are computed based on the age of the vulnerability, the skill level required to exploit the vulnerability, and the consequences of a successful exploit. The system is built on open standards that enable integration with existing business processes and IT systems like help desk, asset management, SIEM, intrusion detection and prevention, and other security solutions. Tripwire IP360 is available as an on-premises solution utilizing hardened Linux-based virtual or physical appliances and as a managed service.