Skip to main content
Riskability app icon

Riskability

Correlate the software your fleet already reports against offline CVE databases on a search head with no internet access. Ranks findings by exploitation likelihood and by whether the network can actually reach them. Track software that is already or soon becoming End Of Life!Built by Christian Haugan
splunk product badge

Default Version 1.4.1

September 5, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

Most vulnerability tooling cannot run where it is needed most. A search head with no route to the internet cannot call an API, pull a feed on a schedule or fetch a score on demand. Riskability is built for that machine. It takes the software inventory your hosts already report, correlates it against databases you carry across the air gap yourself, and answers what a CVE count never does: of everything found, what should somebody do tonight? CVSS says how bad a flaw would be if exploited, not how likely that is, and never whether your copy is reachable. WHAT THIS APP ADDS Exploitation likelihood. Findings are ranked by EPSS, the published probability of exploitation in the wild, and by the CISA KEV catalogue of vulnerabilities already exploited. Both arrive in the feed you import, never fetched live. Reachability, measured on the host. The collector reports listening ports and the process behind each, so findings answering a network address are separated from those answering only loopback or nothing. On a test fleet that turned 10,206 open findings into 11 that answer the network. It reorders the work. It never shortens it. Reachability, observed at the boundary. With your firewall logs in Splunk, the app can also say whether a permitted flow from the internet or an admin network has actually reached a port, and draw the jumps from entry point to the findings at the end. A site without firewall logs loses nothing. End of support. A CVE says a thing is broken; end of support says nobody will fix it again, which no advisory states. The app names software with no supported release. Rules your fleet needs. A risk the scoring signals cannot see can be written as a rule raising a finding one tier. Rules ship off, and a replay shows what each would move first. Optional AI explanation. A model on your own hardware writes the reasoning beside each finding: why it ranks where it does, what to do, which ATT&CK techniques apply. The score is arithmetic from measured facts and the model cannot change it. Where an answer contradicts the evidence, the row says so. WHAT IT REFUSES TO GUESS Every finding carries a confidence level describing the evidence, not the severity. A distribution that backports fixes without changing the version is reported as informational rather than asserted. A Coverage dashboard lists what the data cannot speak to, because a gap in visibility is not an absence of risk. Accepted risks go to an audit index written once, never rewritten. NO UNINTENTIONAL DATA OUT Nothing goes out unless you set up AI, and the recommended shape is a model in the same location as this Splunk instance, so nothing leaves the organisation. You build a feed bundle on a connected machine, carry it across and import it.