Ulduz / Oolak RBVM / Solutions
ENGINEERED FOR COMPLEX ENTERPRISE CHALLENGES

Purpose-Built Solutions for
High-Velocity Security Operations

Legacy vulnerability management fails because of scanner alert fatigue, unverified phantom fixes, missing CMDB asset contexts, and compliance-violating cloud egress. Oolak provides a unified on-premise operational foundation that bridges the chasm between vulnerability scanners, asset inventories, and engineering remediation workflows.

85%
Alert Volume Reduction via KEV + EPSS Prioritization
100%
Reconciliation between Scanned IPs & CMDB Interfaces
0
Phantom Ticket Closures via ScanCoverage Integrity Guard
Zero Egress
100% Air-Gapped Sovereign On-Premise Operation
THE CORE PROBLEMS OOLAK SOLVES

End-to-End Problem & Solution Matrix

CAASM SOLUTION NETBOX DCIM & IPAM SHADOW IT DETECTION
31% of Enterprise Hosts are Missing from CMDB

1. Cyber Asset Attack Surface Management (CAASM) & CMDB Asset Graph Reconciliation

Security scanners discover IP addresses; IT teams manage configuration items. When an active IP is not registered in NetBox or Active Directory, it becomes unmanaged Shadow IT without an assigned owner, SLA, or patch policy.

THE ENTERPRISE CHALLENGE:

Scanners dump thousands of raw IP addresses into spreadsheets. Security teams cannot determine which tenant owns the host, what business application runs on it, or whether it is in Staging or Production. Unmanaged VMs and rogue subnets bypass security controls completely.

THE OOLAK SOLUTION:

Oolak continuously correlates live scanner discovery sweeps (Tenable, Nmap, Qualys) against NetBox DCIM/IPAM interfaces, VMware ESXi guests, and Active Directory computer objects. Any unmapped IP is automatically flagged as Shadow IT, provisioned into a staging quarantine group, and routed to the infrastructure team for ownership tagging.

  • Orphan Host Detection: Immediately surfaces live network endpoints that exist in network sweeps but are missing from NetBox CMDB.
  • IP-to-Interface Topology Graph: Maps primary IPs, secondary aliases, and virtual interfaces into a unified asset hierarchy.
  • Automated CMDB Sync: Automatically creates device stubs and updates custom fields (e.g. Oolak_Scanned=True, Risk_Score=84) back into NetBox.
RBVM SOLUTION CISA KEV FIRST EPSS
97% of CVSS 9.0+ CVEs are Never Exploited

2. Exploit-Led Vulnerability Prioritization (Moving Beyond Theoretical CVSS)

CVSS measures theoretical severity in a vacuum; it does not measure real-world weaponization or attack likelihood. Remediating every CVSS 7.0+ vulnerability is mathematically impossible for enterprise engineering teams.

THE ENTERPRISE CHALLENGE:

Vulnerability scans report 25,000+ findings every cycle. Overwhelmed engineering teams waste weeks patching theoretical, unweaponized vulnerabilities on internal test boxes, while actively exploited zero-days on perimeter gateways remain unpatched.

THE OOLAK SOLUTION:

Oolak synchronizes daily with the CISA Known Exploited Vulnerabilities (KEV) catalog and FIRST Exploit Prediction Scoring System (EPSS). Findings are ranked by real-world weaponization probability, asset exposure (internet-facing vs isolated), and business criticality, cutting actionable alert volume by 85%.

  • CISA KEV In-the-Wild Exploitation Flags: Instantly pinpoints vulnerabilities weaponized by ransomware cartels and nation-state threat actors.
  • 30-Day Probability Scoring (EPSS): Forecasts which newly disclosed CVEs will be weaponized within the next 30 days.
  • Composite Risk Scoring Formula: Weights EPSS, CISA KEV, asset criticality, network zone, and data classification into an objective 0–100 risk score.
REMEDIATION INTEGRITY SCANCOVERAGE GUARD ZERO PHANTOM FIXES
42% of Manually Closed Tickets Reappear Later

3. Closed-Loop Remediation & Elimination of Phantom Vulnerability Fixes

When an engineer clicks "Closed / Resolved" in Jira or ServiceNow, it only indicates that code was deployed or a package was updated. Without scanner verification proving the vulnerability cannot be triggered, the risk remains active.

THE ENTERPRISE CHALLENGE:

Engineers close tickets based on assumptions. When a broad monthly scan runs, if the target host was firewalled, down, or rebooting, the scanner outputs 0 findings. Systems mistakenly interpret this absence as "remediated," creating hazardous phantom fixes.

THE OOLAK SOLUTION:

Oolak enforces the ScanCoverage Guard state machine. A finding can only transition to REMEDIATED if a targeted re-scan explicitly verifies that the host was reachable AND the specific plugin confirms the flaw is eradicated. If the host was unreachable, the finding remains truthfully OPEN.

  • Automated Targeted Rescan Dispatch: Directly triggers Tenable or OpenVAS scans for specific host-plugin tuples via REST API upon ticket closure request.
  • Deterministic Finding State Transitions: Strictly models states: OPEN → IN_PROGRESS → PENDING_VERIFICATION → REMEDIATED.
  • Four-Eyes Exception Governance: Formal risk acceptance register with mandatory peer approvals, expiration dates, and audit justification.
DATA CONSOLIDATION 58+ CONNECTORS CANONICAL SCHEMA
58+ Native Security Toolchains Unified

4. Multi-Scanner Toolchain Consolidation & Cross-Discipline Deduplication

Enterprises run Tenable for infrastructure, Burp Suite and ZAP for web DAST, Trivy for containers, Semgrep for source code, and TruffleHog for secrets. Disparate consoles create duplicate tickets, conflicting severities, and siloed triage.

THE ENTERPRISE CHALLENGE:

Network security, application security, cloud ops, and compliance teams use disconnected portals. The same Apache OpenSSL vulnerability is flagged four times by four different tools, spawning duplicate Jira tickets and confusion over who owns remediation.

THE OOLAK SOLUTION:

Oolak serves as the authoritative exposure data fabric. Ingesting outputs from 58+ tools, normalizes raw telemetry into canonical data models (Asset, Finding, Secret, Identity), deduplicates identical CVEs across scanners, and maps them to responsible teams.

  • Universal Finding Canonicalization: Reconciles disparate vendor formats into a standardized data model with normalized severity ratings.
  • Cross-Scanner Deduplication Engine: Consolidates findings sharing identical target IP/URL and CVE/CWE identifiers into a single lifecycle record.
  • Unified Ticketing Dispatch: Dispatches clean, consolidated work items to Atlassian Jira, ServiceNow SecOps, HPSM, or DefectDojo.
SOVEREIGNTY & AIR-GAP ZERO EGRESS BDDK / ISO 27001 / PCI-DSS
0 KB Cloud Egress Guaranteed

5. Sovereign Air-Gapped Deployment for Defense, Banking & Critical Infrastructure

Central banks, defense organizations, and sovereign agencies operate under strict regulatory mandates (BDDK, NIS2, DORA, PCI-DSS) that strictly forbid sending internal IP topologies, vulnerability findings, or asset configurations to third-party US/EU SaaS clouds.

THE ENTERPRISE CHALLENGE:

Most modern RBVM platforms are pure SaaS offerings. Uploading scan files or connecting scanners to SaaS clouds violates data residency laws and risks exposing internal network vulnerabilities to external cloud breaches.

THE OOLAK SOLUTION:

Oolak runs 100% on-premise as an isolated, containerized stack inside your datacenter. Threat intelligence feeds (CISA KEV, EPSS) can be loaded offline via signed cryptographic bundles. All passwords and tokens are encrypted with AES-256 Fernet keys in local memory.

  • Zero Outbound Telemetry: No licensing callbacks, analytics beacons, or third-party cloud dependencies whatsoever.
  • Offline Threat Intelligence Ingestion: Ingests daily CISA KEV and EPSS catalogs via offline air-gapped file bundles.
  • WORM Tamper-Evident Audit Logging: Every operational action, scan launch, and exception approval is cryptographically logged with SHA-256 signatures.
SOAR & SPM AUTOMATION CELERY CANVAS DAG LOW-CODE WORKFLOWS
3.2x Faster MTTR

6. Intelligent Security Process Orchestration & Low-Code Automation (Oolak Orchestra)

Managing vulnerabilities requires multi-step collaboration: query assets → trigger scanners → filter CVEs → create tickets → escalate expiring SLAs → verify fixes. Hardcoded pipelines cannot adapt to varying departmental requirements.

THE ENTERPRISE CHALLENGE:

SecOps analysts spend 60% of their workday manually copy-pasting scan details into Jira, chasing developers via email, and running manual rescans. Workflows are fragile, inconsistent, and lack unified error recovery.

THE OOLAK SOLUTION:

Oolak Orchestra provides a visual, drag-and-drop workflow canvas powered by an enterprise Celery Canvas DAG engine. Security teams can build complex event-driven playbooks combining parallel scans, conditional branching, AI remediation generation, and multi-channel alerting.

  • Visual Workflow Canvas: Drag-and-drop design using 58+ prebuilt connector nodes (Triggers, Queries, Actions, Logic, AI).
  • Parallel Fork & Chord Join: Run Nmap, Nessus, and OpenVAS concurrently and aggregate results seamlessly upon completion.
  • Automated AI Remediation Copilot: Generates verified Ansible playbooks and Bash patches for expiring SLA findings and posts them directly to Jira.

Ready to Transform Your Exposure Management?

Deploy Oolak in your on-premise lab or datacenter to experience seamless CMDB reconciliation, exploit-driven prioritization, and closed-loop verification.

Request 14-Day PoC →