oolak / Use cases / Verification
Verification

The ticket says fixed. Is it really?

A finding can vanish from a report because it was fixed, or because the server was switched off on scan day. oolak tells the two apart and confirms each fix with a targeted rescan.

A targeted rescan confirms the fix.
Today

What usually happens

  • Tickets are closed when the team says the work is done.
  • A server that was offline during the scan looks perfectly clean.
  • Weeks later, the same vulnerability shows up again.
With oolak

What changes

  • Closed means closed, and you can prove it.
  • Gaps in scanning are visible instead of hidden.
  • Average fix times are honest because they are based on real closures.
With oolak

How it works, step by step

  1. Record what was scanned

    Every scan cycle notes every host it reached, including the clean ones.

  2. Close only what was checked

    A finding closes only if its host was scanned and the problem was gone.

  3. Rescan on request

    When a team reports a fix, a targeted rescan checks just that host.

  4. Reopen what comes back

    If the problem returns, the finding and its ticket reopen automatically.

See oolak on your own data in 14 days.

We install oolak in your environment, connect your tools and show you your real risk picture. You keep everything it finds.

Start a free 14-day trial → Try the live demo
For engineers

Technical details

What happens to findings on an offline host?
They stay open and are marked as not scanned, which shows up as a coverage gap. They only close once the host is scanned again and the finding is gone.
Who can launch a rescan?
Anyone with the right module can request a rescan. Launching a real scan needs rescan approval rights, and scans respect freeze windows and a minimum interval.