AI for Enterprise Security
Blast Radius Tells You Which Vulnerability to Fix First.
Crogl computes a vulnerability's blast radius using live threat intelligence: what's exploited, what it can reach, what's already exposed, and whether to patch now or capture forensics first.
Crogl handles the investigation. The analyst makes the call.
New to this? Read the blog.
Top priorityscore 91.4
CVE-2025-68686 — anchor rank #1
Largest blast radius of the four (5 touched hosts, 2 dependent services) despite having the most runway left on its BOD due date — radius outweighs the clock.
Notable rippleCVE-2025-68686
Patching VPNGW01 risks breaking the CFO's nightly finance-close report.
VPNGW01 → erp-finance-nightly-sync → svc-finance-nightly-report: an uncoordinated patch window on the VPN gateway can silently break the finance-close pipeline Finance and the CFO depend on every morning — not just remote access.
Click a CVE to trace its blast radius →
Rendered from the same ring_data / final_summary schema crogl/blastradius's report.py produces, hand-populated from the real entities.json fleet and the documented 4-CVE demo story — not a live run, which requires an agent container's MCP environment. Automations render inside the “Services” ring alongside business/infra services.
CISA BOD Three-Day Clock
Every day looks like Patch Tuesday now.
CISA's Binding Operational Directive puts known-exploited vulnerabilities on a three-day remediation clock, and requires documented forensic justification when an externally facing asset can't be patched in time. One Class B network pair runs that cycle at roughly 80,000 machines. Project Glasswing's first discovery run alone surfaced more than 10,000 vulnerabilities. a preview of how fast the queue fills once vulnerability research runs at machine scale.
Blast radius decides which of those machines get fast action and which get care. Critical services and core infrastructure sit at the top of the pyramid, then business applications, executive workstations, general endpoints, and kiosks at the base. The physics holds regardless of team size: the higher up the stack, the more a wrong call costs. in an outage thousands of people depend on, or in forensic evidence a reboot destroys for good.
This is vulnerability management with the patch-or-preserve decision built in, not patch management bolted on after the fact.
3 Days
CISA's Binding Operational Directive remediation clock for known-exploited vulnerabilities on externally facing assets
80,000
Machines one Class B network pair runs the patch-forensics-validate cycle against, every three days
10,000+
From vulnerability discovery to the new scale the three-day clock has to absorb
The Crogl Approach
Blast radius computed. Patch or preserve evidence, in the right order.
Confirmed Against the KEV Catalog
Crogl skills pull confirmed exploitation status and the remediation due date live from CISA's own KEV feed.
Blast Radius Walked Across the Fleet
Every asset carrying the CVE is located and tiered by criticality: critical services and core infrastructure first, then business applications, executive workstations, general endpoints, and kiosks. Crogl walks reachability from there toward anything that matters. The skills are extensible, so you can add your own criticality tiers and reachability paths.
Patch or Preserve, in the Right Order
Anything exploited, or reachable to something critical, gets flagged for evidence capture before the reboot that would destroy it. Everything else clears fast through normal patching. The pyramid tells you where your people's time actually belongs.
Validated with live data
Built and run against CVEs live on CISA's KEV catalog.
In the screen shot example, Crogl pulled confirmed KEV status straight from CISA's feed, tiered every fleet asset carrying either CVE, and walked reachability toward Sharepoint and AD FS.
What Crogl Delivers
Continuously Confirmed Against CISA's KEV Feed
Exploitation status and BOD due dates are pulled live. When a CVE's status can change; Crogl's answer changes with it.
Reachability Walked to What Actually Matters
A CVSS score doesn't know your network. Crogl walks the path from a vulnerable host to whatever it can actually reach. AD FS, a finance pipeline, a backup relay. and prioritizes by what's really at stake, not a generic severity number. Patches roll out in the order that actually matters.
Honest About What It Can't See
A segment with no telemetry is graded blind, not silently marked clear. Crogl will tell you if a path is contained or if it is dark, with a documented audit trail your compliance team can point to.
Forensics Before the Reboot
Memory capture happens before the patch on anything exploited or on a path to something critical. Evidence a reboot destroys doesn't come back. the order of operations follows how evidence decays.
Computes Blast Radius Across Your Stack
30+ out of the box. With minutes to add new ones. Connectors support federated search. No schema normalization. No recoding. If your data is there, Crogl can query it.
“Know what's exploited. Know what it can reach. Know before you patch.”
See Your Own Blast Radius
What's the blast radius of the CVE sitting in your queue right now?
We'll show you exactly how Crogl computes blast radius. point it at any CVE you're already tracking.
Deployed in air-gapped federal environments, critical infrastructure, and Fortune 500 financial institutions.