Skip to main content

Blast Radius Tells You Which Vulnerability to Fix First.

Crogl computes a vulnerability's blast radius using live threat intelligence: what's exploited, what it can reach, what's already exposed, and whether to patch now or capture forensics first.

Crogl handles the investigation. The analyst makes the call.

New to this? Read the blog.

Blast Radius
Sample data · prototype
4
CVEs in scope
2
Overdue (BOD)
10
Hosts touched
6
Identities touched
3
Automations touched
4
Services touched

Top priorityscore 91.4

CVE-2025-68686 — anchor rank #1

Largest blast radius of the four (5 touched hosts, 2 dependent services) despite having the most runway left on its BOD due date — radius outweighs the clock.

Notable rippleCVE-2025-68686

Patching VPNGW01 risks breaking the CFO's nightly finance-close report.

VPNGW01 → erp-finance-nightly-sync → svc-finance-nightly-report: an uncoordinated patch window on the VPN gateway can silently break the finance-close pipeline Finance and the CFO depend on every morning — not just remote access.

Click a CVE to trace its blast radius →

CVESystemServiceAutomationUser / Identity
KEV4 exploitedCVE-2026-58644 SharePointCVE-2026-56164 SharePointCVE-2026-56155 AD FSCVE-2025-68686 FortiOSSPWEB01SPWEB02ADFS01VPNGW01LAPTOP-BFRANKLINERPAPP01FILESVR01EXECLAP-CFOWKS-0003GITLAB01svc-extranet-portalsvc-identity-federationad-identity-provisioning-syncsvc-remote-accesserp-finance-nightly-syncvpn-remote-backup-relaysvc-finance-nightly-reportsvc-sharepointjsanchezsvc-adfsmkowalskisvc-erp-syncsvc-backup

Rendered from the same ring_data / final_summary schema crogl/blastradius's report.py produces, hand-populated from the real entities.json fleet and the documented 4-CVE demo story — not a live run, which requires an agent container's MCP environment. Automations render inside the “Services” ring alongside business/infra services.

Every day looks like Patch Tuesday now.

CISA's Binding Operational Directive puts known-exploited vulnerabilities on a three-day remediation clock, and requires documented forensic justification when an externally facing asset can't be patched in time. One Class B network pair runs that cycle at roughly 80,000 machines. Project Glasswing's first discovery run alone surfaced more than 10,000 vulnerabilities. a preview of how fast the queue fills once vulnerability research runs at machine scale.

Blast radius decides which of those machines get fast action and which get care. Critical services and core infrastructure sit at the top of the pyramid, then business applications, executive workstations, general endpoints, and kiosks at the base. The physics holds regardless of team size: the higher up the stack, the more a wrong call costs. in an outage thousands of people depend on, or in forensic evidence a reboot destroys for good.

This is vulnerability management with the patch-or-preserve decision built in, not patch management bolted on after the fact.

3 Days

CISA's Binding Operational Directive remediation clock for known-exploited vulnerabilities on externally facing assets

80,000

Machines one Class B network pair runs the patch-forensics-validate cycle against, every three days

10,000+

From vulnerability discovery to the new scale the three-day clock has to absorb

Blast radius computed. Patch or preserve evidence, in the right order.

1

Confirmed Against the KEV Catalog

Crogl skills pull confirmed exploitation status and the remediation due date live from CISA's own KEV feed.

2

Blast Radius Walked Across the Fleet

Every asset carrying the CVE is located and tiered by criticality: critical services and core infrastructure first, then business applications, executive workstations, general endpoints, and kiosks. Crogl walks reachability from there toward anything that matters. The skills are extensible, so you can add your own criticality tiers and reachability paths.

3

Patch or Preserve, in the Right Order

Anything exploited, or reachable to something critical, gets flagged for evidence capture before the reboot that would destroy it. Everything else clears fast through normal patching. The pyramid tells you where your people's time actually belongs.

Built and run against CVEs live on CISA's KEV catalog.

In the screen shot example, Crogl pulled confirmed KEV status straight from CISA's feed, tiered every fleet asset carrying either CVE, and walked reachability toward Sharepoint and AD FS.

Continuously Confirmed Against CISA's KEV Feed

Exploitation status and BOD due dates are pulled live. When a CVE's status can change; Crogl's answer changes with it.

Reachability Walked to What Actually Matters

A CVSS score doesn't know your network. Crogl walks the path from a vulnerable host to whatever it can actually reach. AD FS, a finance pipeline, a backup relay. and prioritizes by what's really at stake, not a generic severity number. Patches roll out in the order that actually matters.

Honest About What It Can't See

A segment with no telemetry is graded blind, not silently marked clear. Crogl will tell you if a path is contained or if it is dark, with a documented audit trail your compliance team can point to.

Forensics Before the Reboot

Memory capture happens before the patch on anything exploited or on a path to something critical. Evidence a reboot destroys doesn't come back. the order of operations follows how evidence decays.

30+ out of the box. With minutes to add new ones. Connectors support federated search. No schema normalization. No recoding. If your data is there, Crogl can query it.

SplunkMicrosoft SentinelCrowdStrikeServiceNowJiraDatabricksSnowflakeAmazon S3

Know what's exploited. Know what it can reach. Know before you patch.

What's the blast radius of the CVE sitting in your queue right now?

We'll show you exactly how Crogl computes blast radius. point it at any CVE you're already tracking.

Deployed in air-gapped federal environments, critical infrastructure, and Fortune 500 financial institutions.