Ragnarok ยท Vuln Management
Vulnerability Management
Ragnarok discovers vulnerabilities continuously. Heimdall tracks your patch posture in real time. Together they give you a live risk score across your entire environment โ not a quarterly PDF.
Continuous Discovery, Not Point-in-Time Scanning
Traditional vulnerability management runs a scan, produces a report, and hands it to a team that may or may not act on it before the next scan. Ragnarok operates differently โ it runs continuously, discovers vulnerabilities as they emerge (new CVEs disclosed, new assets deployed, new misconfigurations introduced), and feeds findings directly into a prioritized remediation queue.
Heimdall's patch posture module tracks the state of every finding in real time โ open, in-progress, remediated, accepted โ with SLA timers that alert when a CVSS 4.0+ finding approaches its remediation deadline. Your risk score reflects reality, not a snapshot from three months ago.
Ragnarok โ Continuous Vulnerability Discovery
- CVSS 4.0+ tracking: Ragnarok prioritizes using CVSS 4.0 scoring, which incorporates environmental and threat context โ not just base score โ to distinguish exploitable risk from theoretical exposure.
- Exploit availability signal: Findings with confirmed public exploits or active exploitation in the wild are escalated immediately, regardless of CVSS score.
- Asset discovery built in: Ragnarok discovers new assets as they're provisioned โ shadow IT, new cloud resources, and test environments that bypass your asset register are scanned automatically.
Heimdall โ Patch Posture Tracking
- Real-time posture score: Heimdall's patch posture score updates as vulnerabilities are discovered and as patches are applied โ giving you a live number, not a stale report.
- SLA enforcement: Configurable remediation SLAs by severity (e.g., Critical: 7 days, High: 30 days) with automated escalation when deadlines are missed.
- Patch verification: After a fix is applied, Heimdall re-tests the affected asset to confirm remediation โ closing the loop without manual validation.
Remediation Workflow Integration
- Auto-generated fix PRs: For application-layer vulnerabilities, Ragnarok opens pull requests with remediation diffs โ developers receive a fix, not just a finding.
- Jira and linear integration: Vulnerability findings sync to your project management tool with severity, affected asset, exploit status, and SLA deadline โ no manual ticket creation.
- Risk acceptance workflow: For vulnerabilities that cannot be patched immediately, a formal risk acceptance process with CISO sign-off is built into the platform.
Combined Coverage
Ragnarok handles discovery and Heimdall handles posture โ but they share the same data model. A vulnerability discovered by Ragnarok's pentest agent surfaces in Heimdall's risk dashboard alongside patch status and SLA timers. When Heimdall detects active exploitation of a known CVE in your environment, it correlates with Ragnarok's open findings to identify the affected asset immediately.