Tools
Patching the software Microsoft does not patch
Windows Update covers Microsoft. The browser plugins, PDF readers and Java runtimes that get exploited are somebody else's problem, and usually nobody's.
The gap nobody owns
Most organisations have solved Microsoft patching. Update rings in Intune, a defined window, reporting that mostly works. Then they discover that the vulnerability being exploited is in a PDF reader installed by a project team in 2021 that has never been updated.
Third-party patching is unglamorous, it appears in every framework, and it is the control most likely to be assumed rather than verified.
How to close it without buying anything first
Inventory before tooling
Defender for Endpoint already reports installed software and known vulnerabilities. Read that list before deciding you need a product. It is frequently shorter than expected.
Remove rather than patch
The cheapest patch is uninstalling software nobody uses. Runtimes installed for one project a decade ago are the usual candidates.
Use the Microsoft Store and winget where you can
Applications delivered this way update themselves. Moving the common ones onto that path removes them from the problem permanently.
Then decide what is left
Whatever remains after those three steps is the actual requirement, and it is usually small enough to change what you buy.
The verdict
Inventory, remove, then re-package what remains
Three free steps that shrink the problem before you spend anything, and the last one is a permanent fix rather than an ongoing task.
Do not buy a patching product before the inventory. You will buy for a problem three times larger than the one you have.
Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.