Oolak is an enterprise On-Premise Risk-Based Vulnerability Management (RBVM) and Cyber Asset Attack Surface Management (CAASM) platform. It correlates Tenable scanner outputs with NetBox CMDB asset graphs, enriches findings with CISA KEV and EPSS exploit probability scores, and automates closed-loop verification without sending raw data to the cloud.
Oolak operates as the authoritative On-Premise exposure engine. Ingesting multi-cloud assets, vulnerability scanners, and threat feeds; synchronizing bidirectionally with NetBox, DefectDojo, and ITSM ticketing; enabling conversational AI triage via FastMCP; and dispatching live Grafana dashboards, compliance reports, and ChatOps notifications in real time.
Legacy vulnerability scanners generate tens of thousands of raw CSV rows per cycle. Oolak ingests scanner data into an actionable, stateful operational backbone.
In traditional vulnerability management, if an endpoint is powered down, offline, or firewalled during a scan cycle, the scanner reports zero findings for that IP. Primitive tools interpret this as a successful remediation and falsely close tickets.
Oolak enforces the ScanCoverage engine: every scanned host—including clean hosts—is logged in the coverage matrix. A missing finding is transitioned to REMEDIATED only if its host was confirmed scanned in that cycle. If the host was offline, the finding remains truthfully OPEN.
Oolak sits at the core of your security telemetry pipeline, connecting asset repositories, vulnerability scanners, cloud inventory, and monitoring infrastructure.
Oolak is deployed via standard Docker Compose or Kubernetes Helm charts directly into your isolated datacenter. All relational data, scanner artifacts, and asset graphs reside exclusively inside your security perimeter.
In air-gapped defense or banking environments, threat feeds (CISA KEV catalog and FIRST EPSS probability scores) can be loaded offline via signed update bundles or routed through an internal proxy, guaranteeing 100% data sovereignty.
Evaluate Oolak's NetBox CMDB graph, Tenable reconciliation, and CISA KEV prioritization with a guided technical evaluation tailored to your infrastructure.