Vulnerability Management

Fix the CVEs
that matter.

From thousands of findings to a prioritized list of actionable risks. OnDuty combines threat intelligence, exploitability, and runtime context to identify what matters most — and enables an agentic remediation and verification loop.

Ready for Autonomous Remediation

Agentic Vulnerability Remediation

OnDuty transforms vulnerability management from detection to resolution. It identifies and prioritizes risks, equips AI agents with structured remediation plans, and automatically validates that vulnerabilities have been successfully remediated.

Write actions are approval-gatedDry-run before every executeEvery agent action is audit-logged

Detect & prioritize

Runtime context ranks every CVE in your environment

Draft the fix plan

OnDuty generates a structured, typed remediation plan

Agents patch

AWS DevOps & coding agents execute it — approval-gated

Verify & close

OnDuty re-scans, confirms it's gone, and closes the SLA

loops back to detection
How it works

Every signal. One priority list.

From the first heartbeat to a fixed CVE — six layers of intelligence that turn vulnerability noise into a focused action plan.

Ingest & match

Every CVE in your packages, instantly.

The OnDuty sensor streams a real-time SBOM from every host and container via eBPF — no sidecars, no scheduled scans. We cross-reference 200,000+ CVEs against your exact package versions, so you only ever see what's actually present in your environment.

SBOM via eBPFPackage-version matching200k+ CVEs indexed
sbom-collector · prod-web-01
packages: collectedcount=1,220
cve-match: xz-utils 5.6.0CVE-2024-3094 · CRITICAL
cve-match: golang net/httpCVE-2023-44487 · HIGH
cve-match: no-matchglibc 2.31 → not in affected range
results: deliveredmatched=87 · skipped=9,655
Risk prioritization

Runtime context turns CVSS into reality.

The OnDuty Score fuses CVSS severity, EPSS exploit probability, and CISA KEV status, then weights every finding by real-world context — whether the package is actually running, exposed to the internet, or adjacent to a crown-jewel asset. A theoretical 9.8 with no runtime reachability falls to 1.1, focusing your engineers on what is genuinely exploitable today.

Universal risk scoreContextual multiplierAuto-deprioritization

Ranked findings · sorted by OnDuty Score

CVE DetailCVE-2024-3094
Fix immediately
CVSS → OnDuty↓ 0.2 pts deprioritized
Base
10.0
OnDuty
9.8
EPSS probability92%
CISA KEV listedYes
Runtime reachableConfirmed
Attack path analysis

Find the toxic combinations.

OnDuty maps the chains where multiple risk signals coincide — runtime-reachable, internet-facing, weaponized exploit, and crown-jewel proximity — all at once. One graph shows exactly how an attacker reaches your sensitive data.

Toxic combination detectionCrown-jewel proximityHop-count scoring

Attack Path — Toxic Combination

internet → nginx → postgres → crown jewel

Internet0.0.0.0/0Load Balancerport 443nginx:1.25CVE-2024-3094postgres:15CVE-2023-44487Crown Jewelcustomer-data DB

Toxic factors

4 / 4

Reachable + Exposed + Weaponized + Crown Jewel

Toxicity score

9.0

Factor-weighted: reachability × 3.0 × exploit × 2.5

Hop count

4 hops

internet → lb → nginx → postgres → crown jewel

Exploit intelligence

Weaponized exploits rise in minutes.

Live enrichment from EPSS, CISA KEV, ExploitDB, Nuclei, and AttackerKB feeds the score continuously. A freshly weaponized CVE climbs to the top within minutes — not after your next scheduled scan.

5 live intel sourcesExploit-maturity bonusesReal-time, not scheduled

Live enrichment sources · CVE-2024-3094

📊
EPSSin_the_wild

92% exploitation probability in next 30 days

92%

🏛️
CISA KEVin_the_wild

Listed · federal agencies must patch by 2024-04-01

100%

🔓
ExploitDBweaponized

Exploit code published · weaponized

85%

⚡
Nucleiweaponized

Nuclei template confirmed · active scanning

90%

🧠
AttackerKBpoc

AttackerKB assessment: exploitable in real conditions

70%

Exploit maturity bonuses

In the wild (KEV + Nuclei)+2
Weaponized (Nuclei template)+1.5
PoC available (ExploitDB)+1
KEV listing bonus+2
EOL software penalty+1.5
Max score cap10.0

base = (CVSS × 0.5) + (EPSS × 10 × 0.5) + bonuses

AI reasoning

Every score, explained in plain English.

Each OnDuty Score ships with an LLM-written explanation citing the exact runtime evidence behind it — shareable with engineers, defensible to auditors, and re-generated automatically as conditions change.

Runtime evidence citedAuditor-ready outputUpdates as conditions change
OnDuty AI Reasoning
generating

+2.0

Runtime

+2.0

KEV

+1.5

Exploit

+0.3

Exposure

Runtime evidence cited
Auditor-ready output
Updates as conditions change
Remediate

SLA automation, assignment, and tracking.

OnDuty auto-assigns remediation deadlines by severity — Critical + high EPSS in 7 days, Critical/High in 30, Medium in 90 — and routes tickets to the right team. Engineers get assignments, the CISO gets a posture dashboard, auditors get a full paper trail.

Auto-SLA assignmentTeam routingAudit trail

CVE-2024-3094

SLA: 7 days
→ platform-eng
assigned

CVE-2023-44487

SLA: 30 days
→ backend-eng
in-progress

CVE-2021-44228

SLA: 7 days
→ devops
resolved
Overall posture

2

critical

5

high

80

resolved

Stop chasing CVSS

Fix the CVEs
that matter most.

See exactly which vulnerabilities are running, exposed, and exploitable in your environment — with a ranked list your team can act on today.

  • 94% noise reduction — from thousands of CVEs to the handful that matter
  • Runtime reachability from the first heartbeat — eBPF, no sidecars
  • EPSS + KEV + ExploitDB correlated in real-time, not on a schedule
  • Auto-SLA assignment and team routing from day one
  • Evidence for your SOC 2 · ISO 27001 · HIPAA · PCI audits