Features

From collection to deployed fix

Every component serves to reduce volume, bring out what matters, then fix it and prove it.

Collection

Three channels feed the same repository.

  • Host agents: system and language packages, ports, services, container images, SSH and NFS relationships
  • Network probes: one container per subnet for ports, services, web and containers
  • Connectors to your code platforms, scanners and vulnerability management tools, report import

Threat intelligence

Every CVE is continuously enriched to separate the exploited from the theoretical.

  • CISA KEV and EUVD: observed exploitation
  • EPSS: thirty-day probability of exploitation
  • Public exploits and known modules: exploit maturity
  • Temporal CVSS score recomputed at every sync

Attack paths

We reason in exploitation chains and risk per asset.

  • External exposure, network vulnerability, then SSH or NFS pivot
  • Combined score along the path
  • For each path, the action that cuts it

Prioritization

An explained decision for every finding.

  • SSVC verdict: ACT, ATTEND, TRACK, with its one-line explanation
  • Risk profile per sector that reweights the whole ranking
  • Grouping by fix: one action closes several findings

Asset view

All the vulnerabilities of an asset, across every source.

  • Risk score, exposure, criticality
  • Systems, runtimes and images past end of support
  • Recurring or on-demand scans from a single timeline

Governance

What your auditors and your board expect.

  • Compliance frameworks assessed continuously, with history
  • Built-in roles and scopes per project, SSO
  • Multi-entity, isolated down to the database
  • Indicators, time to fix, PDF and CSV exports, audit log
Fix deployment

The fix leaves from the platform and comes back with its result

You do not leave with a list to copy into a deployment tool. You pick an action, Vulneo updates the affected hosts and tells you, host by host, what happened.

One click from the prioritized list

Agents install the target version on each host, using the system or language package manager. One transaction per host, replayed package by package if one of them blocks.

Patch campaigns

Proposed scope, approval by someone else, canary wave then rollout only if the canary is fully green. Automatic pause otherwise.

Safety net

Hypervisor snapshot before each host, rollback available, maintenance window respected.

Verified result

Status per host, required reboot flagged, findings closed when the next inventory confirms the version.

See Vulneo on your own data

A demo on a case close to yours, with your sources.

45 minutes, on your own scanner exports if you wish.