Find and track the vulnerabilities attackers look for
UTMStack includes a vulnerability scanner that checks exposed services from the network and installed software from inside your servers. Findings carry severity and exploit-likelihood scores, and you track each one until it is fixed.
Network scans
Check open ports, exposed services, web applications, SSL/TLS settings and cloud misconfigurations without installing anything.
Agent-based scans
On Windows and Linux hosts, the agent finds vulnerable installed applications and outdated libraries inside them, such as an old version of log4j.
Fix what is exploitable first
Findings carry Common Vulnerability Scoring System (CVSS) severity and Exploit Prediction Scoring System (EPSS) scores, which estimate how likely a flaw is to be exploited. You fix what attackers are most likely to use first.
Track every fix
Mark each finding open, resolved, mitigated or false positive, and schedule recurring scans to confirm fixes.
Reports for auditors
Export filtered PDF reports as evidence for SOC 2, ISO 27001, HIPAA, NIST or CIS audits.
Questions buyers ask
Does the scanner log in to hosts with stored credentials?
No. UTMStack does not do classic credentialed remote scanning. The agent on Windows and Linux hosts provides the inside view of installed software instead, so you do not store target passwords in the scanner.
Will it discover unknown devices on my network?
No. The scanner checks the IP addresses, host names and ranges you give it, and it is not a device discovery tool. For unmanaged devices, UTMStack relies on the log and network data it already collects.
Does it patch vulnerabilities?
No. It finds and tracks vulnerabilities but does not push patches. You can open tickets or run fixes through automated response flows.
Is the scanner part of the main console?
It runs as a separate application with its own sign-in, connected to the platform. Its findings and reports support the compliance work you do in the main console.
Related capabilities
- ComplianceScore 9 frameworks, including HIPAA, PCI DSS 4.0, SOC 2, ISO 27001 and CMMC 2.0, from live events, and download PDF reports for auditors.
- Asset managementKeep a live inventory of the servers, endpoints and devices sending data to UTMStack, with OS, IP, status and last-seen details plus installed software.
- Automated responseBuild response flows on a visual canvas to isolate hosts, kill processes, log off and block users or IPs. Track every run and use a live console.
Protect your organization this week, not next quarter
Talk to an engineer today, or start using UTMStack in minutes.
Need to extend your SOC team?
Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.
Want to try UTMStack?
Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.