Ulduz Logo DEFENSE
Ulduz Security / Sovereign Intelligence
OFFENSIVE CYBER OPERATIONS & SOVEREIGN SECURITY SYSTEMS

Illuminate the unseen perimeter.
Defend with deterministic control.

Ulduz designs sovereign offensive security operations, attack surface discovery engines, and enterprise vulnerability orchestration platforms. We help critical infrastructure, financial institutions, and regulated enterprises isolate actionable risk across air-gapped, on-premise, and hybrid networks.

100%
On-Premises Data Sovereignty (Zero SaaS Egress)
85%
Noise Reduction via CISA KEV & EPSS Correlation
3.2x
Accelerated MTTR through Automated Triage
0
Phantom Remediation via ScanCoverage Verification
FLAGSHIP PLATFORM

Oolak — On-Premise RBVM & Cyber Asset Intelligence

Engineered for organizations that refuse to ship vulnerability telemetry to public multi-tenant clouds. Oolak unifies Tenable scan findings, NetBox CMDB graphs, CISA KEV exploitation feeds, and automated remediation workflows entirely within your perimeter.

Oolak
MODULE 01
CAASM & NetBox Sync
Bidirectional REST synchronization with NetBox DCIM/IPAM. Identifies orphan IPs on the network not documented in CMDB.
MODULE 02
Deterministic FindingState
Persistent state machine tracking Open, Remediated, and Reopened states. Never closes a finding if the host was offline during scan.
MODULE 03
SoD Exception Governance
Four-eyes separation of duties. Risk acceptance register with mandatory expiration, justification, and automated rescan verification.
View Complete Oolak Specifications → Schedule Architecture Review
ENGINEERING PRACTICES

Specialized Cyber Defense & Offensive Engineering

OFFENSIVE SVC_01
Adversary Emulation & Red Teaming
Full-scope adversary simulations targeting Active Directory forest architectures, internal lateral movement paths, operational technology (OT) bridging, and cloud credential escalation vectors.
• MITRE ATT&CK Mapping
• Domain Trust Traversal
• EDR Bypass Assessment
DEFENSIVE SVC_02
Attack Surface & Exposure Assessment
Passive and active network perimeter telemetry analysis. We identify stale VPN endpoints, misconfigured DNS namespaces, exposed internal interfaces, and untracked cloud assets.
• External Perimeter Audits
• Subdomain Takeover Analysis
• Shadow IT Inventory Reconcile
GOVERNANCE SVC_03
High-Assurance Architecture & Hardening
Architectural advisory for isolated enterprise environments. Technical implementation of zero-trust network boundaries, RFC 5424 audit telemetry pipelines, and air-gapped system baselines.
• BDDK / PCI-DSS 4.0 Compliance
• DORA & NIS2 Mandates
• Air-Gapped Key Infrastructure
ENTERPRISE CONNECTIVITY

Native Infrastructure & Toolchain Integrations

Both our operational consulting and software platforms interface natively with enterprise scanners, CMDB backbones, SIEM sinks, and container orchestrators.

SCANNERS
Tenable & Nessus
REST API integration for automated scan ingestion, host-level raw evidence extraction, and on-demand rescan dispatch.
CMDB & IPAM
NetBox DCIM & IPAM
Bidirectional synchronization with virtual machines, physical devices, network interfaces, and tenant allocation scopes.
VULN TRACKING
DefectDojo (Community & Enterprise)
Engagement synchronization, finding correlation, and automated risk acceptance tracking.
SIEM & AUDIT
Splunk & RFC 5424 Syslog
Real-time structured syslog streaming with strict parameter redaction and actor-type tagging.
ANALYTICS
Grafana
Real-time burndown, MTTR, SLA compliance, and multi-tenant security dashboards.
AI WORKERS
Anthropic FastMCP
Enterprise LLM integration via secure MCP tools with indirect prompt injection boundaries and two-phase dry-run commit.
THE COMPANY

Engineered for Sovereignty. Guided by Precision.

Named after the Turkic term for Star (the celestial reference point for navigators), Ulduz was founded on a singular engineering philosophy: critical organizations must possess absolute visibility and deterministic sovereignty over their cyber attack surface.

We reject the dogma that sensitive vulnerability data must be exported to overseas multi-tenant clouds. Our advisory engagements and software deliverables run entirely inside your walls, ensuring total compliance with strict data protection mandates.

OPERATIONAL PRINCIPLES
Zero SaaS Egress
Your vulnerability reports, host topologies, and risk acceptance registers stay strictly on-premises.
Actionable Exploitation Telemetry
Prioritization powered by CISA KEV and FIRST EPSS probability scoring, not arbitrary vendor rankings.
Auditable Governance
Four-eyes principle enforced at the code layer. Immutable audit logs ready for regulatory inspection.

Initiate Technical Engagement

Whether evaluating Oolak for enterprise vulnerability orchestration or scheduling an offensive penetration assessment, reach out directly to our engineering team.

✉️ info@ulduz.net →