DrochaidHorizon3.ai
NodeZero/Vulnerability Management Hub
Operations

Vulnerability Management Hub

Where exposure meets action.

Most vulnerability management tools produce noise. NodeZero filters for signal — surfacing only what is exploitable, impactful, and proven through real attack paths. The Vulnerability Management Hub brings validation, tracking, and fix verification into one view, so your team moves from overwhelmed to in control.

NodeZero Vulnerability Management Hub overview showing proven weaknesses ranked by impact
01

Your command centre for proven weaknesses

The Vulnerability Management Hub centralises the weaknesses NodeZero discovers across internal, external, cloud and identity environments. Findings are deduplicated, scored by real-world impact, and tied directly to the attack paths that proved them. Your team prioritises what matters, assigns fixes, and confirms remediation — without waiting for the next pentest.

02

Exploited, not theoretical

The Hub shows the CVEs and other security weaknesses that were actually exploited during testing — not a scanner's backlog of maybes. Each weakness arrives with the affected asset, the exploit path that reached it, and the impact context, so the argument about whether a finding is real is over before triage starts.

NodeZero Vulnerability Management Hub listing exploited weaknesses with asset and impact context
Every entry was proven by a real attack path — with the affected asset, exploit path and impact attached.
03

Remediation tracked from open to verified

Every weakness carries two kinds of status: what the system observed (Open, Mitigated, Regressed) and what your team decided (To Do, Fixed, Risk Accepted, False Positive). Historical context is preserved, so you can see when a weakness was found, fixed, and — importantly — whether it came back. That status trail is exactly the remediation evidence an Essential Eight or CPS 234 assessor asks to see: not a claim that patching happened, but a record of each weakness moving from open to verified closed.

04

Quick Verify closes the loop

Once a fix lands, Quick Verify re-runs the targeted test to confirm the weakness is actually gone — remediation is verified, not assumed. Verification is currently supported for internal environments, with external support on the Horizon3 roadmap.

NodeZero Quick Verify re-running a targeted test from the Vulnerability Management Hub
A targeted retest replays the attack that found the weakness — the fix is proven closed, not marked done.
05

Built to sit inside your workflow

ServiceNow and Jira ticketing inside the Hub is coming soon — create, sync and track tickets directly from the NodeZero platform with verification status attached. In the meantime, findings flow into the workflows your team already runs through NodeZero's existing integrations and API, and the Hub remains the single view of what is open, what is fixed, and what is proven closed.

What you can now prove

Three statements your security team can defend

A

We're fixing what attackers can actually reach

Everything in the queue was proven by real attack behaviour, not ranked by a theoretical severity score.

B

We've streamlined remediation

Tracking, triage and retesting run in one system — findings arrive ready to work, and closure is recorded.

C

We can demonstrate real risk reduction

Trend reports and preserved history show exposure falling over time — with the evidence attached.

Key benefits

Why teams move their vulnerability management here

01

Focus on what's provable

Surface only the vulnerabilities that were actually exploited — and skip the scanner noise.

02

Validate fixes without waiting

One-click retesting confirms whether an issue is truly resolved, without re-scoping a pentest.

03

Collaborate without friction

Assign, annotate and track remediation progress across teams and tools.

04

Report what leadership cares about

Every weakness is tied to business risk, so reporting to your board and auditors is clear and credible.

Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

See your proven weaknesses in one place

Run a validated vulnerability management assessment with the Drochaid team and watch scanner noise collapse to a workable, evidence-backed queue.