Oolak Logo
Ulduz / Products / Oolak RBVM
SOVEREIGN EXPOSURE MANAGEMENT & VULNERABILITY ORCHESTRATION

Discover unmanaged attack surface.
Prioritize real exploits. Verify remediation.

Oolak is an enterprise On-Premise Risk-Based Vulnerability Management (RBVM) and Cyber Asset Attack Surface Management (CAASM) platform. It correlates Tenable scanner outputs with NetBox CMDB asset graphs, enriches findings with CISA KEV and EPSS exploit probability scores, and automates closed-loop verification without sending raw data to the cloud.

85%
Alert Volume Reduction via KEV + EPSS Filtering
100%
NetBox Bidirectional CMDB Synchronization
3.2x
Faster Mean-Time-to-Remediate (MTTR)
0%
Telemetry Egress (Air-Gapped Sovereign Deployment)
ENTERPRISE TELEMETRY TOPOLOGY

Centralized Exposure Orchestration & Intelligence Flow

Oolak operates as the authoritative On-Premise exposure engine. Ingesting multi-cloud assets, vulnerability scanners, and threat feeds; synchronizing bidirectionally with NetBox, DefectDojo, and ITSM ticketing; enabling conversational AI triage via FastMCP; and dispatching live Grafana dashboards, compliance reports, and ChatOps notifications in real time.

OOLAK DATA FABRIC & INTEGRATION ECOSYSTEM
ACTIVE INGESTION: 10 SOURCES BIDIRECTIONAL SYNC: 3 CORES FASTMCP AI: READY
Host & IP Topology Raw CVEs & Findings KEV & Exploit Telemetry Natural Language Queries / tool_call Synthesized Exposure Context CONVERSATIONAL AI COPILOT (FastMCP) Natural Language Queries • Triage Prompts • Policy Drafts Clients: Claude Desktop • Cursor • Internal LLM Workers OOLAK SOVEREIGN PLATFORM ON-PREM CORE CAASM Attack Surface Engine Multi-Cloud, Virtualization & IPAM Reconciliation Dual-layer VM & DCIM model • Orphan Host Detector KEV + EPSS Risk Prioritization In-the-Wild Exploit Filtering • 85% Noise Elimination Zero reliance on theoretical CVSS base scores alone ScanCoverage Deterministic Engine Closed-Loop Verification • Eliminates Phantom Fixes Host offline: OPEN • Confirmed clean scan: REMEDIATED BIDIRECTIONAL CMDB & ITSM ORCHESTRATION (TWO-WAY SYNCHRONIZATION) NetBox DCIM IPAM & Interfaces ↔ Bidirectional Graph DefectDojo Community & Ent ↔ Finding Exemption Sync Jira / ServiceNow ITSM Ticketing ↔ Closed-Loop Verification ASSET & INFRASTRUCTURE FEEDS AWS EC2 & VPC Microsoft Azure VMs Google Cloud (GCP) VMware & Hyper-V VULNERABILITY & SBOM SCANS Tenable & Nessus OpenVAS / Greenbone Trivy Container & SBOM THREAT FEEDS & SOFTWARE INTEL CISA KEV Catalog Active In-the-Wild Exploits FIRST EPSS Scoring 30-Day Exploit Probabilities Docker & Software Intel Image Digests & Base OS Real-time Telemetry & Alerts OPERATIONAL DESTINATIONS & SINKS Grafana Live Dashboards Live MTTR, Burndown & SLAs Unified Asset Inventory Deduplicated CAASM Graph API Slack & Microsoft Teams Instant KEV & 4-Eyes Alert Cards S3-Compatible Storage Compliance Reports & Audit Trails Webhooks & RFC 5424 Splunk / SIEM Structured Stream CONVERSATIONAL AI COPILOT FastMCP Tools • Natural Language Triage Claude Desktop • Cursor • LLM Agents INBOUND TELEMETRY FEEDS (10 SOURCES) Assets: AWS • Azure • GCP • VMware Scanners: Tenable • OpenVAS • Trivy Container Threat Intel: CISA KEV • FIRST EPSS • Docker OOLAK PLATFORM (ON-PREM SOVEREIGN CORE) 1. CAASM Attack Surface Engine Multi-Cloud IP & Network Interface Reconciliation 2. KEV + EPSS Risk Matrix In-the-Wild Exploit Filtering • 85% Noise Drop 3. ScanCoverage Deterministic Verification Eliminates Phantom Fixes • Confirmed Scans Only BIDIRECTIONAL CMDB & ITSM SYNC (↔) • NetBox DCIM & IPAM (Topology & Interfaces ↔) • DefectDojo (Findings & Exemption Register ↔) • Jira / ServiceNow (Bi-directional Tickets & Rescan ↔) OPERATIONAL DESTINATIONS & AUDIT SINKS • Grafana Live Dashboards (Real-time Burndown & MTTR) • Unified Asset Inventory (Deduplicated CAASM Graph) • Slack & Microsoft Teams (Instant KEV Alerts & 4-Eyes) • S3 Reports & RFC 5424 Syslog / SIEM Streaming
CORE CAPABILITIES

Architected for High-Density Vulnerability Triage

Legacy vulnerability scanners generate tens of thousands of raw CSV rows per cycle. Oolak ingests scanner data into an actionable, stateful operational backbone.

← Swipe cards horizontally to explore capabilities (CAP_01 – CAP_06) → 6 CAPABILITIES
DETERMINISTIC VULNERABILITY LIFECYCLE

Eliminating Phantom Remediations via ScanCoverage

In traditional vulnerability management, if an endpoint is powered down, offline, or firewalled during a scan cycle, the scanner reports zero findings for that IP. Primitive tools interpret this as a successful remediation and falsely close tickets.

Oolak enforces the ScanCoverage engine: every scanned host—including clean hosts—is logged in the coverage matrix. A missing finding is transitioned to REMEDIATED only if its host was confirmed scanned in that cycle. If the host was offline, the finding remains truthfully OPEN.

STATE: OPEN STATE: REMEDIATED STATE: REOPENED STATE: DECOMMISSIONED
View FindingState Reconciliation Logic & Python Code
# FindingState Lifecycle Reconciliation
def reconcile_finding_lifecycle(cycle_id, host_ip):
  scanned = coverage.is_scanned_in_cycle(cycle_id, host_ip)
  if not scanned:
    # Host offline: Coverage gap. Do NOT close.
    return FindingStatus.OPEN

  if finding.present_in_scan(cycle_id):
    if finding.was_remediated:
      return FindingStatus.REOPENED
    return FindingStatus.OPEN
  else:
    # Confirmed clean scan. Accurate remediation.
    return FindingStatus.REMEDIATED
ENTERPRISE CONNECTIVITY

Comprehensive Integrations Ecosystem

Oolak sits at the core of your security telemetry pipeline, connecting asset repositories, vulnerability scanners, cloud inventory, and monitoring infrastructure.

← Swipe cards horizontally to explore all 19 integrations → 19 INTEGRATIONS
DEPLOYMENT & RESILIENCY

On-Premise & Air-Gapped Resiliency

Containerized Orchestration with Zero External Egress

Oolak is deployed via standard Docker Compose or Kubernetes Helm charts directly into your isolated datacenter. All relational data, scanner artifacts, and asset graphs reside exclusively inside your security perimeter.

In air-gapped defense or banking environments, threat feeds (CISA KEV catalog and FIRST EPSS probability scores) can be loaded offline via signed update bundles or routed through an internal proxy, guaranteeing 100% data sovereignty.

Enterprise Deployment Specifications (6 Controls)
ENTERPRISE DEPLOYMENT SPECIFICATIONS
Deployment Topologies: Docker Compose, Kubernetes Helm (Air-Gapped Ready)
Data Locality: 100% On-Premise; Zero external telemetry or licensing egress
Threat Feed Ingestion: Offline bundle loading or internal forward proxy (CISA KEV, EPSS)
Cryptographic Security: AES-256 data at rest, TLS 1.3 in transit, salted SHA-256 tokens
Access Governance: Role-Based Access Control (RBAC) & Four-Eyes Separation of Duties (SoD)
Audit Export: Real-time RFC 5424 structured syslog streaming with parameter redaction

Deploy Oolak in Your Lab or Datacenter

Evaluate Oolak's NetBox CMDB graph, Tenable reconciliation, and CISA KEV prioritization with a guided technical evaluation tailored to your infrastructure.

Request Technical POC →