Avennorth
Avennorth/Pathfinder
02 — Live Discovery

Pathfinder

The closed-loop CMDB engine.

Pathfinder combines agentless behavioral discovery and agent-based CI enrichment into a single closed loop — scoring every CI across three independent confidence dimensions and routing it through a human-in-the-loop merge queue before anything touches your CMDB.

The result: a ServiceNow CMDB that is trusted, current, and continuously maintained — without credentials, without manual entry, and without the kind of remediation projects that cost $1M and fail anyway.

PATHFINDER — CLOSED-LOOP DISCOVERYLIVE
AGENTLESSeBPF · ETW
app-middlewaredb-primary
api-gatewaycache-layer
web-frontendapi-gateway
orders-apiapp-middleware
AGENT-BASEDcollector
CIapp-middleware-v2
OSUbuntu 22.04 LTS
Hostnameprod-mw-02
RAM8 GB
CPU4 vCPU
CI HYPOTHESIS CONVERGENCE
app-middleware-v2.prod.svc
Application Service · 2 signals converged
QUEUED
SIGNAL87%
SAMPLE92%
STABILITY68%
MERGE QUEUE3 pending
db-replica-1.prod
APPROVED
cache-layer-v3
PENDING REVIEW
svc-gateway-new
DEFERRED
Discovery modes
Agentless behavioral observation + agent-based CI enrichment working as a single closed loop
3D
Confidence scoring
Signal, Sample, and Stability scored independently — never collapsed to a single opaque number
Zero
Credential vault needed
The agentless layer observes behavioral traffic without privileged access to any target host
90 days
To first trusted CMDB
From kickoff to a practitioner-approved, continuously refreshing CI inventory
The Problem

Your CMDB has never been accurate. Here's why.

Legacy discovery tools scan the network and record whatever responds to a probe. They miss ephemeral services, container-to-container traffic, application-layer relationships, and anything behind a firewall that doesn't answer to a MID server.

The result is a CMDB that was partially accurate on day one and has been decaying ever since — filled with merge conflicts, phantom CIs, and missing relationships that your ops team quietly stopped trusting years ago.

73% of major incidents are made worse by inaccurate CMDB data. Every time an engineer spends 20 minutes figuring out what's actually connected to what, that's time the SLA clock is running.

The Mechanism

Two modes. One loop. No gaps.

Neither agentless nor agent-based discovery alone gives you a complete picture. Pathfinder runs both — and closes the loop between them.

MODE 1Agentless

Observe the traffic layer

  • eBPF hooks on Linux kernel — zero overhead
  • ETW on Windows — no new software required
  • Captures: who talks to whom, how often, on what protocol
  • Discovers ephemeral services, containers, sidecars
  • Covers ~80% of estate with zero agent deployment
The Closed Loop
01
CI Hypothesis formed
Both signals converge
02
3D Confidence scored
Signal × Sample × Stability
03
AI narrates proposal
Assumed facts stated
04
Practitioner commits
Human decision, immutable log
05
CMDB updated natively
No ETL, no sync job
Drift monitoring restarts
The loop never stops
MODE 2Agent-Based

Enrich with CI detail

  • Lightweight collector deployed via single change window
  • Captures: OS, installed software, config, resource usage
  • Confirms agentless hypotheses with deep attribution
  • Covers the 20% where behavioral data alone isn't enough
  • Works in air-gapped and locked-down environments
Competitive Comparison

How Pathfinder stacks up.

16 capabilities across discovery method, CI confidence, and CMDB integration.

CAPABILITY
PATHFINDER
by Avennorth
ServiceNow ITOM Discovery
Tanium
Dynatrace
Discovery Method & Coverage
eBPF / ETW kernel-level agents
Kernel hooks observe traffic at the OS level — no network scan ports, no polling, no credential exposure
Linux eBPF + Windows ETW — zero scan overhead, zero credentials
PROBE-BASED
SENSOR-BASED
NATIVE
Application-layer relationship capture
Which services call which — observed at Layer 7, not just which IPs are reachable at Layer 3
Every service connection observed at app layer — not just network reachability
L2/L3 FOCUS
ENDPOINT FOCUS
NATIVE
Ephemeral, container & microservice coverage
Container-to-container, sidecar, and short-lived service traffic captured — not just persistent infrastructure
Container-to-container + ephemeral traffic captured via eBPF
PERSISTENT ONLY
CONTAINER AWARE
NATIVE
Zero-credential, zero-scanner operation
No admin credentials, no scan ports opened, no SSH/WMI polling — operates purely from observed traffic
No credentials required — Pathfinder observes, it doesn't interrogate
CREDS REQUIRED
AGENT REQUIRED
AGENT INSTALL
Passive OT & shadow-infrastructure discovery
Operational technology devices and unregistered shadow infrastructure detected without emitting probe packets — zero risk of disrupting industrial or legacy systems with active scanning
Zero probe packets to OT/shadow infra — detected from observed traffic only
ACTIVE PROBING
OT AGENT REQ.
APM ONLY
Coverage & blind-spot intelligence
Quantifies what discovery cannot see and ranks blind spots by criticality — the inverse of confidence scoring, a question scan-and-reconcile tools aren't architected to answer: they score what they found, not what they're blind to
Knows what it can't see — blind-spot map ranked by criticality
NOT AVAILABLE
NOT AVAILABLE
NOT AVAILABLE
CI Confidence & Merge Quality
Three-dimensional confidence scoring
Signal (observation strength), Sample (statistical reliability), and Stability (consistency over time) — scored independently, never collapsed to one number
Signal × Sample × Stability — each kept separate, never averaged
OPAQUE SCORE
BINARY
INTERNAL
Falsifier-mandatory AI narration per CI
Every merge proposal explicitly states which assumed facts would invalidate it — practitioners see the reasoning, not just the recommendation
Each proposal states the assumptions that would make it wrong
NOT AVAILABLE
NOT AVAILABLE
NOT AVAILABLE
Structured practitioner merge queue
Every discovered CI enters a review queue before CMDB entry — no silent auto-population, no IRE rules overriding practitioner judgment
Every CI reviewed before CMDB entry — no silent auto-populate
IRE ENGINE
AUTO-POPULATE
AUTO-POPULATE
Immutable practitioner decision audit log
Every approve, reject, defer, and override is hash-committed — the full decision trail is forever recoverable, not just the current CI state
Hash-committed log — every decision, forever, with full reasoning
AUDIT LOG ONLY
AUDIT LOG ONLY
NOT AVAILABLE
Confidence-gated CMDB population
CIs below a configurable confidence floor are held in the review queue rather than auto-written — quality gate prevents CMDB pollution
Configurable confidence threshold gates every CMDB write
NOT AVAILABLE
NOT AVAILABLE
THRESHOLD RULES
CMDB Population & Platform
Native ServiceNow CMDB table writes
CI records written directly into ServiceNow CMDB tables — no ETL middleware, no IRE lag, no sync jobs
Patent-protected direct CMDB writes — no ETL, no middleware
NATIVE
VIA CONNECT
VIA API
Bitemporal CI state history
Every CI state stored immutably — any past CI record replayable at any timestamp for compliance, audit, or post-incident investigation
Any CI state replay-able at any past timestamp — immutable
AUDIT LOG ONLY
SNAPSHOT ONLY
ROLLING WINDOW
Continuous behavioral re-discovery
CI relationships update as traffic patterns change — not on a scheduled scan, but whenever behavior is observed
Behavioral stream updates CI relationships continuously
SCHEDULED
NEAR REAL-TIME
NATIVE
5-class principal CI taxonomy
Every CI registers under five principal classes — Application, Infrastructure, Service, Data, Contract — instead of being triaged by hand into hundreds of CMDB tables
5 principal classes — no hundreds-of-tables triage toil
DEEP HIERARCHY
NOT AVAILABLE
NOT AVAILABLE
Cross-product GPS intelligence chain
Live CI inventory and discovered relationships feed every downstream product — Bearing, Contour, Assets, Vantage, Architect, Trust, and the Compass executive layer — natively, no manual handoff
Feeds all seven downstream GPS modules natively
ITSM PARTIAL
STANDALONE
STANDALONE
COVERAGE (FULL OR PARTIAL)
16 / 16
7 / 16
6 / 16
8 / 16
Full native support
Partial / manual / integration required
Not available

All third-party product names and logos are trademarks of their respective owners and are used for identification and comparison purposes only. Comparisons are based on publicly available product documentation as of 2025–26 and reflect Avennorth's good-faith assessment; they do not imply affiliation, sponsorship, or endorsement.

The Commercial Case

What a broken CMDB costs you every year.

The CMDB isn't a nice-to-have. It's the foundation every ITSM process sits on. When it's wrong, everything downstream is wrong too.

$300K
Average P1 cost per hour
Gartner

73% of major incidents are worsened by inaccurate CMDB data

$500K–$2M
Typical CMDB remediation project
Industry avg.

Most projects are stale within 6 months of completion

2–5
FTEs spent on manual CMDB maintenance
Per enterprise

Per year, just keeping up with drift — never catching up

90 days
Pathfinder: first trusted CMDB
Guaranteed

No remediation projects. No manual entry. No drift.

The Pathfinder Proposition

One fixed engagement. One trusted CMDB. No ongoing debt.

Pathfinder is delivered through your existing ServiceNow partner at a fixed project price — not a per-node discovery license that compounds as your estate grows. The implementation is measured in weeks, not quarters.

  • No per-node licensing — fixed engagement price
  • Delivered by your existing ServiceNow partner
  • No credential vault required — reduces implementation scope
  • First practitioner-approved CIs in 30 days
  • Full trusted CMDB in 90 days
  • Continuous refresh included — no remediation projects, ever
~30 days
First CIs
observed and practitioner-approved
90 days
Trusted CMDB
full practitioner-approved inventory
Zero
Ongoing cost
remediation projects needed
Fixed
Licensing model
not per-node
Common Objections

We've heard every reason not to.

Every enterprise that's been through a failed CMDB project has scar tissue. Here's why Pathfinder is different.

The Objection

We've tried CMDB before and it failed.

The Answer

Pathfinder isn't a CMDB project — it's a CMDB engine. Past projects failed because they were one-time snapshots that decayed immediately. Pathfinder never stops discovering. Behavioral drift is detected in hours and generates a new merge proposal automatically. The loop closes itself.

The Objection

We can't deploy agents everywhere.

The Answer

You don't have to. The agentless layer — running on your existing kernel via eBPF and ETW — covers 80% of your environment with zero new software. Agents only go where you need deep CI attribution, and they're lightweight enough for a single change window.

The Objection

We can't trust AI to populate our CMDB.

The Answer

You don't have to trust the AI — you trust your practitioners. Every merge proposal comes with confidence scores and mandatory assumed facts. The AI narrates; your team commits. The immutable audit trail shows exactly who approved what and why, forever.

The Objection

Integration projects always run over.

The Answer

Pathfinder doesn't integrate with ServiceNow — it was purpose-built for it. There are no ETL pipelines, no field-mapping spreadsheets, no sync jobs. The merge queue writes directly to the CMDB. Implementation is measured in days, not months.

$
The Objection

What does this actually cost?

The Answer

Pathfinder is delivered through your existing ServiceNow partner relationship at a fixed project price — not a per-node discovery license that scales against you as your estate grows. One engagement, one price, one trusted CMDB.

The Outcome

Your first trusted CMDB. Living and breathing.

Trusted

Every CI in the CMDB was approved by a practitioner who saw the confidence scores, the assumed facts, and the evidence. Nothing enters silently.

Current

Behavioral drift is detected in hours. The closed loop restarts automatically — generating a new merge proposal before your next change window opens.

Auditable

An immutable, hash-chained log records every approve, reject, defer, and override — with the practitioner, the timestamp, and the evidence used to decide.

Fundational

Pathfinder feeds Contour's service maps, Bearing's health scores, and Vantage's incident intelligence. The quality of your entire platform depends on it.

Intelligence Chain

Pathfinder is the foundation layer.

Every other product in the platform improves when Pathfinder is live — because they're all scoring, mapping, or responding to CIs that Pathfinder discovered.

Explore the platform

Ready to see it

See Pathfinder discover your environment.

Thirty minutes. A live demonstration against a real ServiceNow environment. We'll show you what's already in your estate that your current tools aren't seeing.

No commitment required. No credential vault needed for the demo.

Book a Demo