Where everything
the agent finds lives.

The agent is how you talk to it. The platform is the system of record: findings, assets, scans, scores and compliance evidence persist here, across a dashboard and thirteen modules, and you can open any of it at any time.

13 modules · 4 built-in scanners · one conversation

[ dashboard ]

Dashboard

Thirteen widgets aggregate risk, vulnerability, endpoint and exposure metrics into one screen: counters for overdue and remediated findings, the top Kikimora Scores, findings by month, disconnected endpoints, the most critical and the most under-prioritized CVEs. Every widget has a View More that opens the module behind it, already filtered to what the widget was showing.

ask the agent

Martin Malinov

What changed in our posture this week?
  1. Home
  2. Dashboard

Dashboard

Not Scanned Web ApplicationsView More
1
Remediated VulnerabilitiesView More
273
Overdue VulnerabilitiesView More
62
Avg. Hardening ScoreView More
74%
Kikimora Score
Vulnerabilities with the highest Kikimora risk scores.
View More
Vulnerability NameCVEKikimora Score
Apache Log4j2 RCE (Log4Shell)CVE-2021-4422894.60
Netlogon Elevation of Privilege (Zerologon)CVE-2020-147292.10
Citrix NetScaler session hijack (Citrix Bleed)CVE-2023-496688.70
Remote Desktop Services RCE (BlueKeep)CVE-2019-070886.40
Exchange Server SSRF (ProxyLogon)CVE-2021-2685584.10
SQL Injection in Authentication Endpoint77.90
Vulnerabilities Overview
Vulnerabilities by month, grouped by status.
View More

Total Vulnerabilities

3,218

Last 6 months
0175350525700MarAprMayJunJulAug
In ProgressRemediatedOpen
Endpoints
Endpoints with most unapproved software apps.
View More
Endpoint NameIP AddressUnapproved Software
db-prod-02.kikimora.internal10.0.0.22
318
mail-gw.kikimora.internal172.16.0.5
258
fileserver-01192.168.10.30
208
Disconnected Endpoints
Endpoints whose agent is not currently reporting in.
View More
2/24Disconnected
Endpoints
Overdue vs New Vulnerabilities
Vulnerabilities past their resolution deadline vs. those added in the last 7 days.
View More
62118
OverdueNew
Most Critical CVEs
Highest-risk CVEs by average Kikimora score.
View More
CVEAvg. Kikimora ScoreAffected Assets
CVE-2020-147292.101
CVE-2021-4422891.309
CVE-2023-496688.702
CVE-2019-070878.4012
Most Under-prioritized CVEs
CVEs where Kikimora scores higher than CVSS.
View More
CVEVulnerabilityKikimora ScoreCVSS Score
CVE-2018-15473OpenSSH username enumeration57.005.3
CVE-2022-22965Spring Framework RCE (Spring4Shell)68.406.1
CVE-2023-38408OpenSSH ssh-agent RCE64.205.9
  • 13 widgets
  • Overdue vs new
  • Most under-prioritized CVEs

[ vulnerabilities ]

Vulnerabilities

Every finding lands in one repository, whether a Qualys WAS scan, the endpoint agent, exposure discovery or a pentester found it, and a rescan updates the entry instead of duplicating it. Each finding carries a lifecycle (Open, In Progress, Closed, False-Positive), an owner, a Time to Resolve for SLA tracking, an activity log and a proof-of-concept viewer.

ask the agent

Martin Malinov

Show open criticals above Kikimora Score 80 and who owns them.
  1. Home
  2. Vulnerabilities

Vulnerabilities

Total
3,218
+4% from last month
Open
2,904
+3% from last month
In Progress
41
+12% from last month
Impact: Critical
187
-9% from last month
Impact: High
1,036
+2% from last month

Total Vulnerabilities

3,218

Last 6 Months
MarAprMayJunJulAug
RemediatedOpen
Advanced FiltersQuick filter...
Save
NameCVECVSS ScoreKikimora ScoreAssetImpactStatusOwner
Apache Log4j2 RCE (Log4Shell)CVE-2021-4422810.094.60host-003.kikimora.internalCriticalOpenDP
Netlogon Elevation of Privilege (Zerologon)CVE-2020-147210.092.10dc-01.kikimora.internalCriticalOpenMR
Citrix NetScaler session hijack (Citrix Bleed)CVE-2023-49669.488.70vpn.kikimora.ioCriticalIn ProgressDP
Remote Desktop Services RCE (BlueKeep)CVE-2019-07089.886.40workstation-22.kikimora.internalCriticalOpenAO
Exchange Server SSRF (ProxyLogon)CVE-2021-268559.884.10mail-gw.kikimora.internalCriticalOpenMR
SQL Injection in Authentication Endpoint8.877.90shop.kikimora.ioHighOpenDP
Columns
Rows per page10
1/322
  • Open · In Progress · Closed · False-Positive
  • Time to Resolve
  • Activity log and PoC viewer

[ exposure ]

Exposure

Continuous discovery of the domains, hostnames and IP addresses tied to your organisation, through DNS and certificate data. Each asset records its open ports and service banners, and every CVE found on it carries an EPSS exploit probability. Shodan and the locally deployable Network Scanner are built in, and the whole view exports as a report.

ask the agent

Martin Malinov

What does the internet see on our IP ranges?
  1. Home
  2. Exposure

Exposure

Vulnerabilities
57Vulnerabilities
Vulnerable Services
02468OpenSSHnginxExchangeOpenVPNPostfix
CriticalHighMediumLow

Assets

Advanced FiltersQuick filter...
Save Download Report Add New
Domain / NameIP AddressHost NamesPortsVulnerabilitiesEPSS Score
shop.kikimora.io203.0.113.10
cdn-edge-3.kikimora.io+1 more
443808443
1894%
portal.kikimora.io203.0.113.11
4438080
1591%
api.kikimora.io203.0.113.12
api-lb.kikimora.io
4438443
1177%
vpn.kikimora.io203.0.113.14
4431194
888%
mail.kikimora.io203.0.113.15
mx1.kikimora.io+1 more
25587993
541%
admin.kikimora.io203.0.113.13
22443
00%
Columns 0 of 6 row(s) selected.
Rows per page10
1/1
  • Ports and banners
  • EPSS per CVE
  • Download Report

[ infrastructure and endpoints ]

Infrastructure and endpoints

Infrastructure is the central inventory: every known asset, populated by exposure discovery, endpoint agents and integrations, with the criticality rating that feeds the Kikimora Score. Endpoints run the built-in agent (Wazuh under the hood) and report whether they are connected, plus their network interfaces, open ports, running processes, installed packages and policy checks.

ask the agent

Martin Malinov

Which endpoints stopped reporting in the last 24 hours?
  1. Home
  2. Endpoints

Endpoints

Advanced FiltersQuick filter...
Save Deploy New
HostnameIP AddressStatusRisk OwnerRemediation Owner
web-prod-01.kikimora.internal10.0.0.11ConnectedDPAO
db-prod-02.kikimora.internal10.0.0.22ConnectedDPMR
mail-gw.kikimora.internal172.16.0.5DisconnectedMR
workstation-22192.168.10.8ConnectedAOAO
fileserver-01192.168.10.30ConnectedMR
k8s-node-03.kikimora.internal10.0.1.33DisconnectedDP
Columns 0 of 24 row(s) selected.
Rows per page10
1/3
  • Connected / Disconnected
  • Networks · ports · processes · packages
  • Asset criticality

[ scans and web applications ]

Scans and web applications

Qualys WAS web application scanning is built in, with no licence to buy. A web application entry defines the target URL, the crawl scope and the authentication record for logged-in scanning; a scheduled scan runs it Once, Daily, Weekly or Monthly, and every run keeps its own status, timings and findings.

ask the agent

Martin Malinov

Schedule a weekly authenticated scan of staging.
  1. Home
  2. Scans

Scans

Advanced FiltersQuick filter...
Save New Scan
Scan NameWeb ApplicationStatusStartedEnd DateVulnerabilities
shop.kikimora.io Daily ScansScheduleshop.kikimora.ioScheduled at: 8/26/20268/26/2026, 02:00 UTC12
portal.kikimora.io Weekly ScansScheduleportal.kikimora.ioScheduled at: 8/29/20268/29/2026, 02:00 UTC15
api.kikimora.io On-demand Scanapi.kikimora.ioFinished8/25/2026, 09:148/25/2026, 10:0211
shop.kikimora.io Release 4.2 Scanshop.kikimora.ioRunning8/25/2026, 10:20
admin.kikimora.io Authenticated Scanadmin.kikimora.ioFinished8/22/2026, 02:008/22/2026, 03:153
Columns 0 of 5 row(s) selected.
Rows per page10
1/1
  • Qualys WAS built in
  • Once · Daily · Weekly · Monthly
  • Authenticated scans

[ manual tests ]

Manual tests

One manual test per engagement, with OWASP-style checklists for Web, Android and iOS and a Pass, Failed or N/A verdict per check. Manual vulnerabilities carry their technical scope, owners and proof of concept, and flow into the same Vulnerabilities repository as scanner findings, so they are tracked, remediated and reported together.

ask the agent

Martin Malinov

Create a manual finding for the IDOR we found on /invoices.
  1. Home
  2. Manual Tests
  3. Details
  4. Checklist
Back

Manual Test

InputsManual VulnerabilitiesChecklist

Checklists

WebAndroidiOS
Advanced FiltersQuick filter...
NamePlatformCategory NameStatus
Conduct Search Engine Discovery and Reconnaissance for Information LeakagewebOTG-INFO-001Pass
Fingerprint Web ServerwebOTG-INFO-002Pass
Review Webserver Metafiles for Information LeakagewebOTG-INFO-003Failed
Enumerate Applications on WebserverwebOTG-INFO-004Pass
Review Webpage Comments and Metadata for Information LeakagewebOTG-INFO-005N/A
Identify application entry pointswebOTG-INFO-006none
Columns
Rows per page10
1/11
  • OWASP checklists
  • Web · Android · iOS
  • Pass · Failed · N/A

[ kikimora score ]

CVSS is a number. The Kikimora Score is a number about your environment.

A contextual risk rating from 0 to 100. Two findings with the same CVSS can rank very differently in your estate, and every score opens into a breakdown that shows exactly why.

CVSS

The base severity of the vulnerability itself. The starting point, never the whole story.

Threat intelligence

EPSS-based likelihood that this vulnerability is being exploited in the wild right now.

Hardeningadds or subtracts

The hardening posture of the asset and the organisation around it. Can pull the score down.

Asset criticality

The business impact weight you set on the asset. Your context, not a generic table.

Exposureadds or subtracts

Network reachability of the affected asset. Can pull the score down.

CVSS, threat intelligence and asset criticality only ever add. Hardening and exposure can pull a score down: the same CVE on a well-hardened asset nobody can reach lands far lower than it does on an exposed one.

Critical 80 to 100 · High 60 to 79 · Medium below 60

Martin Malinov

Explain this finding's score.

Kikimora Score · CVE-2021-44228

CVSSExposureAsset CriticalityHardeningThreat Intel
94.60Kikimora Score
CVSS10.0Score +59 pts
Threat Intelligence0.97Score +6 pts
Hardening-0.18Score -1 pts
Asset Criticality1.00Score +6 pts
Exposure1.00Score +6 pts
  1. Home
  2. Risk Management

Risk Management

CVE Frequency
All CVE ScoreAll Assets
Widespread + critical → patch firstRare + critical → targeted fix
0204060801000102030405060708090100Avg Kikimora score
Widespread + lower risk → scheduleCVE occurrence count (number of affected asset instances)Rare + lower risk → backlog
Critical (80–100)
High (60–79)
Medium (<60)

Bubble size = affected assets. Hover to view details.

Kikimora Score vs CVSS
All Vulnerabilities
Kikimora > CVSS (context elevates)
0204060801000.02.04.06.08.010.0Kikimora score (0–100)
CVSS > Kikimora (context reduces)CVSS score (×10 → 0–100 scale)
Under-prioritized · CVSS missed, Kikimora caught
Over-prioritized · CVSS overstated, Kikimora corrected
Algorithms on par · within ±10 pts
Portfolio Composition – 4 fixes selected
CVE-2021-44228CVE-2017-0144CVE-2014-0160CVE-2023-44487
21,904 pts selected184,320 pts
162,416 pts – 88% Portfolio Impacted21,904 pts – 12% Risk Reduction
Advanced FiltersQuick filter...
CVEFindingAvg. Kikimora ScoreCVSS ScoreAffected AssetsPortfolio Score
CVE-2021-44228Apache Log4j2 RCE (Log4Shell)91.3010.09
7,412 pts
CVE-2017-0144SMBv1 RCE (EternalBlue)69.808.160
6,186 pts
CVE-2014-0160OpenSSL Heartbleed65.707.548
4,652 pts
CVE-2023-44487HTTP/2 Rapid Reset DoS65.907.538
3,654 pts
CVE-2021-34527Windows Print Spooler RCE (PrintNightmare)72.308.820
2,110 pts
CVE-2019-0708Remote Desktop Services RCE (BlueKeep)78.409.812
1,376 pts
CVE-2018-11776Apache Struts 2 RCE72.208.113
1,290 pts
Columns 4 of 7 row(s) selected.
Rows per page10
1/1

Score vs CVSS. Under-prioritized: CVSS missed it, Kikimora caught it. Over-prioritized: CVSS overstated it, Kikimora corrected it. On par: the two agree within 10 points.

Portfolio risk points. Select the fixes, see the portfolio risk reduction before you schedule them. A moderate finding on many hosts can outrank a severe one on a single host.

See the vulnerability repository
[ compliance ]

Evidence your auditor
can click on.

ISO 27001, SOC 2, PCI-DSS and NIS2 audits ask the same technical questions: are the hosts hardened, did anything change that should not have, is there software nobody approved. The platform runs those checks on every agent-monitored endpoint and keeps the results, so evidence is a query, not a screenshot hunt. The endpoint agent is built on Wazuh and ships as one of the four built-ins: nothing to license.

Martin Malinov

Which hosts fail the CIS SSH checks, and what is the fix?

Kikimora Agent

mail-gw fails Ensure SSH root login is disabled. The remediation is attached to the check, opened below.

  1. Home
  2. Compliance
  3. Hardening Assessments
  4. CIS Ubuntu Linux 22.04 LTS Benchmark v1.0.0
  5. mail-gw.kikimora.internal
Back
Policy ChecksLast 6 Months
0153045603252Jun3052Jul
FailedPassed

mail-gw.kikimora.internal

Advanced FiltersQuick filter...
Save
Check IDTitleTargetCheck Status
31001Ensure permissions on /etc/ssh/sshd_config are configuredFile: /etc/ssh/sshd_configPassed
31002Ensure SSH root login is disabledCommand: sshd -TFailed
31003Ensure password expiration is 365 days or lessCommand: chage -lFailed
31004Ensure SSH MaxAuthTries is set to 4 or lessCommand: sshd -TPassed
Columns
Rows per page10
1/1

A failed CIS check on mail-gw, opened to its rationale and remediation.

01

hardening

Hardening

Automated Security Configuration Assessment against benchmarks such as CIS. Documented today: CIS Microsoft Windows 11 Enterprise Benchmark v3.0.0 and CIS Ubuntu Linux 22.04 LTS Benchmark v1.0.0. Build a custom policy from any subset of checks and apply it to the endpoints you choose.

  • ·Pass score per endpoint and per policy
  • ·Every check: Passed, Failed or Not Applicable
  • ·Rationale and remediation on each check

Maps to ISO 27001 A.8.9 · SOC 2 CC7.1 · PCI-DSS Req. 2.2 · NIS2 Art. 21(2)

02

integrity monitoring

Integrity monitoring

Real-time changes to system files, directories and Windows Registry keys on managed endpoints: the path, the modifying user, the timestamps. Unauthorised modifications, additions, deletions and registry tampering surface as events, per host.

  • ·File and directory changes with the user behind them
  • ·Registry keys and values tracked per host
  • ·Read-only inspector, structured tables

Maps to PCI-DSS Req. 11.5 · ISO 27001 A.8.9 · SOC 2 CC7.1 · NIS2 Art. 21(2)

03

approved software

Approved software

An allow-list of authorised applications. Anything installed on an endpoint that is not on it gets flagged, per host. Match by name, or by name and version together. Import the baseline from CSV.

  • ·Unapproved software per endpoint
  • ·Name or name-and-version matching
  • ·CSV import of the baseline

Maps to ISO 27001 A.8.19 · SOC 2 CC8.1 · PCI-DSS Req. 2.2 · NIS2 Art. 21(2)

ISO 27001 · SOC 2 · PCI-DSS · NIS2

Kikimora

In Slavic folklore, the kikimora is the household spirit that watches the house while everyone sleeps.

Yours now watches your stack.

Start Free