Fix the CVEs
that matter.
From thousands of findings to a prioritized list of actionable risks. OnDuty combines threat intelligence, exploitability, and runtime context to identify what matters most — and enables an agentic remediation and verification loop.
Noise to Signal
Noise reduced by
99.1%
Action required
87 CVEs
Agentic Vulnerability Remediation
OnDuty transforms vulnerability management from detection to resolution. It identifies and prioritizes risks, equips AI agents with structured remediation plans, and automatically validates that vulnerabilities have been successfully remediated.
Detect & prioritize
Runtime context ranks every CVE in your environment
Draft the fix plan
OnDuty generates a structured, typed remediation plan
Agents patch
AWS DevOps & coding agents execute it — approval-gated
Verify & close
OnDuty re-scans, confirms it's gone, and closes the SLA
Every signal. One priority list.
From the first heartbeat to a fixed CVE — six layers of intelligence that turn vulnerability noise into a focused action plan.
Every CVE in your packages, instantly.
The OnDuty sensor streams a real-time SBOM from every host and container via eBPF — no sidecars, no scheduled scans. We cross-reference 200,000+ CVEs against your exact package versions, so you only ever see what's actually present in your environment.
Runtime context turns CVSS into reality.
The OnDuty Score fuses CVSS severity, EPSS exploit probability, and CISA KEV status, then weights every finding by real-world context — whether the package is actually running, exposed to the internet, or adjacent to a crown-jewel asset. A theoretical 9.8 with no runtime reachability falls to 1.1, focusing your engineers on what is genuinely exploitable today.
Ranked findings · sorted by OnDuty Score
Find the toxic combinations.
OnDuty maps the chains where multiple risk signals coincide — runtime-reachable, internet-facing, weaponized exploit, and crown-jewel proximity — all at once. One graph shows exactly how an attacker reaches your sensitive data.
Attack Path — Toxic Combination
internet → nginx → postgres → crown jewel
Toxic factors
4 / 4
Reachable + Exposed + Weaponized + Crown Jewel
Toxicity score
9.0
Factor-weighted: reachability × 3.0 × exploit × 2.5
Hop count
4 hops
internet → lb → nginx → postgres → crown jewel
Weaponized exploits rise in minutes.
Live enrichment from EPSS, CISA KEV, ExploitDB, Nuclei, and AttackerKB feeds the score continuously. A freshly weaponized CVE climbs to the top within minutes — not after your next scheduled scan.
Live enrichment sources · CVE-2024-3094
92% exploitation probability in next 30 days
92%
Listed · federal agencies must patch by 2024-04-01
100%
Exploit code published · weaponized
85%
Nuclei template confirmed · active scanning
90%
AttackerKB assessment: exploitable in real conditions
70%
Exploit maturity bonuses
base = (CVSS × 0.5) + (EPSS × 10 × 0.5) + bonuses
Every score, explained in plain English.
Each OnDuty Score ships with an LLM-written explanation citing the exact runtime evidence behind it — shareable with engineers, defensible to auditors, and re-generated automatically as conditions change.
+2.0
Runtime
+2.0
KEV
+1.5
Exploit
+0.3
Exposure
SLA automation, assignment, and tracking.
OnDuty auto-assigns remediation deadlines by severity — Critical + high EPSS in 7 days, Critical/High in 30, Medium in 90 — and routes tickets to the right team. Engineers get assignments, the CISO gets a posture dashboard, auditors get a full paper trail.
CVE-2024-3094
CVE-2023-44487
CVE-2021-44228
2
critical
5
high
80
resolved
Related solutions
Explore the platform
OnDuty is one platform on a single graph. Here's where the rest of it connects.
Stop chasing CVSS
Fix the CVEs
that matter most.
See exactly which vulnerabilities are running, exposed, and exploitable in your environment — with a ranked list your team can act on today.
- 94% noise reduction — from thousands of CVEs to the handful that matter
- Runtime reachability from the first heartbeat — eBPF, no sidecars
- EPSS + KEV + ExploitDB correlated in real-time, not on a schedule
- Auto-SLA assignment and team routing from day one
- Evidence for your SOC 2 · ISO 27001 · HIPAA · PCI audits