August 27, 2026
Riskability
Correlate the software your fleet already reports against offline CVE databases on a search head with no internet access. Ranks findings by exploitation likelihood and by whether the network can actually reach them. Makes no outbound connections, ever.Built by Christian HauganSplunk Enterprise, Splunk Cloud
Platform Version: 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2
Log in to rate this app
Most vulnerability tooling cannot run where it is needed most. A search head with no route to the internet cannot call an API, pull a feed on a schedule, or fetch a score on demand. Riskability is built for exactly that machine. It takes the software inventory your hosts already report, correlates it against vulnerability databases you carry across the air gap yourself, and answers the question a CVE count never answers: of everything found, what should somebody actually do tonight? THE PROBLEM A fleet of any size produces tens of thousands of open findings. Severity alone does not reduce that to a working list. CVSS describes how bad a vulnerability would be if exploited, not how likely anyone is to exploit it, and neither number knows whether your copy of the software is reachable at all. WHAT THIS APP ADDS Exploitation likelihood. Findings are ranked by EPSS, the published probability that a vulnerability will be exploited in the wild, and by the CISA KEV catalogue of vulnerabilities already observed under exploitation. Both arrive in the feed you import. Neither is fetched live. Reachability. The collector reports listening ports, the process holding each one, and the containers behind them. Riskability uses that to separate findings that answer a network address from those that answer only loopback, and from those with nothing listening at all. On a test fleet of two hosts that turns 10,206 open findings into 11 that answer the network. It reorders the work. It never shortens it, and an unreachable vulnerability is still reported in full. WHAT IT REFUSES TO GUESS Every finding carries a confidence level, and confidence describes the strength of the evidence rather than the severity of the vulnerability. Ubuntu and Red Hat backport fixes without changing the upstream version, so a version comparison alone cannot settle whether such a package is patched. Riskability reports that as informational and says why, rather than asserting a vulnerability it cannot prove. Windows software carries no package identity, only a display name and a registry version, so every Windows finding is reported at low confidence. A Coverage dashboard lists what the feed cannot speak to at all, because a gap in visibility is not the same as an absence of risk. Accepted risks are recorded in an audit index that is written once and never rewritten, holding who accepted the risk, when, the justification, and the date the acceptance expires. NO OUTBOUND NETWORK ACCESS The app makes no outbound requests. You build a feed bundle on a connected machine using the builder the app itself hands you, carry it across, and import it. Nothing is scheduled at install time and nothing reaches the internet on its own.
Log in to report this app listing.