Only call it fixed when it is really fixed.
A finding can disappear from a scan because it was fixed, or simply because the server was switched off that day. oolak tells the two apart, so nothing is closed by accident and every fix is confirmed by a fresh scan.
No false closures
A finding only closes when its host was actually scanned and the problem was gone.
Coverage gaps in plain sight
Hosts that were missed in a scan are marked, so you can see where your scanning falls short.
Fixes confirmed in minutes
A targeted rescan checks just the affected hosts and marks the request as verified.
What's included
- Every scan cycle records every host that was scanned, clean ones included.
- If a host was scanned and the finding is gone, it closes as remediated.
- If a host wasn't scanned, its findings stay open and are marked as not scanned.
- A finding that comes back is reopened automatically.
- Findings on decommissioned assets close with their own status, so average fix times stay honest.
- Assets that were never scanned, or not scanned for a long time, are listed.
- Rescans are requested from the asset page and launched after approval.
- Scans respect freeze windows and a minimum interval between runs.
- Scan definitions, jobs, freeze windows and policies can be managed from oolak.
See it in action
The ticket says fixed. Is it really?
Confirm every fix with a fresh scan, and never close a finding just because a server was offline.
See how it works Urgent vulnerabilitiesA critical vulnerability is in the news. Are we affected?
Find every affected system in minutes, scan just those systems and track the fix until it is confirmed.
See how it works Audit and complianceThe auditor wants to see our risk decisions.
Show an approved, time-limited risk register and a complete record of who did what, in a few clicks.
See how it worksSee oolak on your own data in 14 days.
We install oolak in your environment, connect your tools and show you your real risk picture. You keep everything it finds.
Technical details
How does oolak know a host was scanned?
How does a targeted rescan work?
Explore more features
Know every asset you own, in one place.
oolak pulls servers, devices and cloud resources from the systems you already use and turns them into one clean list.
Learn more Attack surfaceSee your organisation the way an attacker does.
oolak finds the domains, host names, IP addresses, certificates and services that anyone on the internet can reach.
Learn more Relationship mapFollow the path from the internet to your data.
oolak links domains, IP addresses, certificates, servers and applications on one map.
Learn more