Vulnerability management

Know exactly what's exploitable. With nothing leaving the wire.

Skans syncs the public CVE List and MITRE ATT&CK onto the appliance and matches them against your live, per-host inventory — no cloud scanner, no internet. Findings come CVSS-scored, ranked by KEV and EPSS so real-world exploitation sorts to the top, tagged with the ATT&CK techniques that exploit them, and rolled up per device. And because the match uses a strict version-range gate, a patched host shows zero — green means green, not unscanned.

Skans console · NOC
The Skans NOC wall — fleet-health tiles including open vulnerabilities and ATT&CK-tagged findings across the enclave.

The match

Matched to your live fleet — not to a name.

A first-party worker, Skans.VulnFeed, syncs the public CVE List (cvelistV5) and MITRE ATT&CK Enterprise into an on-box store, then joins your live per-host inventory against each CVE's affected-version ranges. A broad product match finds candidates; a strict version-range check then gates every one, so software patched past the affected range stays quiet. The whole match runs on the appliance — there is no cloud scanner in the loop.

  • Version-range gate, not name lookup — a candidate only becomes a finding when the installed version actually falls inside the affected range.
  • Green means green — a fully-patched host produced zero findings in a live drill, so a clean result means secured, not unscanned.
  • Live inventory as the source — the same software and firmware Skans already inventories per host is what the CVE corpus is joined against.
  • Nothing leaves the wire — sync, match and write all happen on-box; your inventory never goes to a cloud scanner.
Skans console · Devices
The Skans device inventory — the live per-host software and firmware picture the CVE match is joined against.

Prioritisation

Ranked by what's actually being exploited.

CVSS tells you how bad a flaw could be; it doesn't tell you what attackers are using this week. Skans enriches every matched finding with two public threat-intel feeds so triage can rank by real-world risk rather than severity alone — and tags each finding with the adversary techniques that target it.

  • CISA KEV — a CVE in the Known Exploited Vulnerabilities catalog is stamped kev=true, so actively-exploited flaws sort to the top.
  • FIRST.org EPSS — each finding carries its exploit-prediction score, the estimated probability the CVE is exploited in the wild.
  • ATT&CK technique tags — a CVE → CWE → ATT&CK join labels each hit with the techniques (for example T1110, brute force) that exploit it.
  • A Critical CVE match rule — watches the findings index and raises an on-box alert that dispatches to your configured sinks alongside every other Skans alert.
Skans console · Alerting
The Skans alerting view — rules by type and severity, including the offline CVE plus MITRE ATT&CK feed that fires a Critical CVE match.

Built to run disconnected

Air-gap integrity, end to end.

The feed is designed for a site with no internet: the threat intel arrives by offline transfer and is verified before it's ever trusted.

A signed feed bundle

For an air-gapped site the CVE + ATT&CK feed arrives as a PackSigner-signed .skb bundle. Skans CMS-verifies it against the held pack anchor before a single record is indexed — a tampered or unsigned bundle is refused, and nothing is ingested.

The whole corpus, on-box

About 342k CVEs and 697 ATT&CK techniques live in the appliance's own search store. A severed WAN changes nothing about your assessment — the match keeps running.

No cloud scanner

The match is on-box, joining live inventory against affected-version ranges. Because that gate is version-range rather than name-match, a patched host stays honestly quiet.

Supervised, not a cron job

Sync-and-scan runs weekly as a supervised job inside the always-on control plane — no OS scheduled task and no separate scheduler service to maintain.

From finding to fix

A hand-off to a human, not a black box.

Skans tells you what is vulnerable and what version clears it — then hands the fix to a person. Each device's Vulnerabilities tab lists its findings with the fix target; one action routes the remediation into the approved patch rings, where a human approves the patch. This is deliberate: it is known-CVE posture assessment (RA-5), not an IDS or EDR — pair it with one for full Detect coverage.

  • Per-device rollup — each host's Vulnerabilities tab shows its own findings, each with the fixedIn version that clears it.
  • One-click remediation request — routes the fix into the approved patch rings; there is no CVE-to-exact-fix automation, by design.
  • Firmware flagged, not forced — stale device firmware is surfaced; where a vetted image and vendor path exist, an optional push re-hashes against the recorded SHA-256 and requires an explicit confirm.
  • An honest boundary — Skans records, correlates and assesses; it is not a full IDS/EDR and does not apply fixes for you.
Skans console · Updates
The Skans updates and patch-rings view — where a vulnerability finding's remediation lands for human approval.

Compliance evidence

The evidence for RA-5, already in place.

The same matching that keeps operators ahead of exploitation is the technical evidence an assessor asks for. Continuous CVE matching against live per-host inventory supports NIST RA-5 (vulnerability monitoring), and the vuln-to-patch hand-off supports SI-2 (flaw remediation). It is an enabler for those controls, never a certification of them — Skans supplies the technical evidence while your organizational risk-management process stays yours.

  • Supports RA-5 — offline CVE matching against live inventory is the risk-assessment evidence for an isolated enclave.
  • Supports SI-2 — the vulnerability-to-patch hand-off is the evidence for flaw remediation, always as an enabler.
  • Rolls into the evidence pack — findings feed the enclave's live NIST 800-171 / CMMC posture and the one-command supporting-evidence export.
  • An enabler, never a badge — no product makes you compliant; organizational, people and process controls remain the customer's.
Skans console · Compliance
The Skans compliance view — the NIST posture ring and the Risk Assessment control family that CVE matching supports.

Talk to us

See Skans on your network.

Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.