Included with the Client edition

Vulnerabilities are not incidents. Stop working them in one queue.

Your analysts triage alerts and close cases. A vulnerability fits neither: it leaves the SOC on day one, sits with whoever owns the host, and ends up patched, accepted or forgotten.

Keep the scanners you have

Agent-based, agentless, or findings in the index you run — Elastic, OpenSearch, Splunk, Wazuh. Missing yours? We build the connector.

✓✓

Corroboration, not a duplicate

Two scanners reporting one weakness on one host agree it is real.

A name and a date, or nothing happens

Every actionable finding carries an owner and a remediation SLA.

Risk acceptance expires

Each acceptance carries a reason and an expiry, and returns for review instead of becoming permanent by silence.

What a scanner export leaves out

An export becomes a spreadsheet. Nobody works a spreadsheet.

  • Is it real? — corroborated by a second source.
  • Does it matter here? — your exposure and the business impact, not a catalogue score.
  • Who owns it, by when? — a named owner and a remediation SLA.
  • And if we are not fixing it — until when?
Ranked by exposure, not by score

What is being exploited, where it can be reached.

A critical score on a host nobody can reach is not urgent. The register lifts what is exploited in the wild, weighs it against asset criticality, and resurfaces the oldest exposures first.

The Threat Intelligence module deepens that context; the register works without it.

Coverage before any figure

Every view states how much of the estate was examined. You cannot claim a posture you have not measured: "no criticals" on ten hosts of four hundred is not good news.

YOUR SCANNERS Agent-based reports an agent id Agentless reports a hostname ONE HOST matched across both sources ONE FINDING corroborated, not two rows in two tools WHAT IT CARRIES both sources named exploited in the wild an owner and a due date One finding, ranked on exposure — not one row per scanner. HOW IT ENDS when the date passes Assigned a named owner, and a remediation SLA Risk accepted a reason, and an expiry date never open-ended Back in the queue on the expiry date not permanent by silence Remediated the clock stops here Closed with a date and who signed it
Two sources agreeing on one host is one finding. An acceptance that never expires is not a decision.
The lifecycle

From a scanner line to a decision somebody signed.

CollectEvery scanner you run, and the index you have
CorroborateTwo sources on one weakness, one finding
PrioritiseKnown exploitation and asset criticality before catalogue severity
AssignA named owner, and the clock starts
DecidePatched, or risk accepted with a reason and an expiry
ReportA committee-ready pack that states its coverage first

Everything but the last step is in the Client edition. The committee pack belongs to the SOC Reporting module.

Linked to incidents, never merged with them

Two clocks, on purpose.

A tier-1 analyst acknowledges an incident in minutes. A patch is owned for weeks by a systems team outside the SOC. Reuse the incident SLA and every finding breaches on creation.

Each side sees the other; neither can edit it. A weakness present during an incident is not proof it was the way in.

Included with the Client edition, not a seventh module.

MSSP edition only

One register per client, never mixed.

One client's findings, report and accepted risks, nothing pooled. A finding that cannot be attributed waits rather than landing in the wrong estate.

In the Free and Client editions there is one organisation: yours.

Next step

Bring your scanner output. We will show you the queue.

The same findings, corroborated, ranked on what can be reached.