See your entire attack surface. As one unified picture.

Before you can prioritize, you need to see. Hackuity connects to every tool in your stack, collects assets and findings continuously, and eliminates duplicates automatically so your inventory finally reflects reality.

Three types of data. One unified workspace.

Every connector feeds one or more of these three data categories into your Hackuity workspacea automatically normalized and correlated.

Asset Catalog Integration

Hosts, IPs, domains, applications, cloud workloads, code repositories.
Hosts
External assets
Container images
Applications
Cloud instances
Identities

Findings

CVEs, misconfigurations, outdated software, pentest reports, bug bounty submissions all findings in a single inventory.
CVE vulnerabilities
Misconfigurations
Container images
Pentest findings
Bug bounty reports
Identities
Outdated software
AD & cloud findings
Container images

Threat Intelligence

OSINT feeds, CISA KEV, EPSS scores, Mandiant, private feeds automatically attached to each finding.
CISA KEV list
MITRE ATT&CK mapping
Container images
Exploit maturity data
CVSS base & temporal
Identities
EPSS scores
Private intel feeds (e.g. Mandiant, Recorded Future, or your own CERT CTI)

How connectors work

Hackuity is not a scanner. It connects to your existing tools and centralizes their output. No agent to deploy. Collection runs on a schedule you control.
130+
active connectors

API connection

Direct, secure connection to SaaS and on-prem console endpoints.

File upload

Support for automated or manual XML, JSON, and CSV exports.

Connector filters

Restrict collection to specific perimeters, tags, or severity thresholds.
Infrastructure scanners
Qualys VMDR, Tenable, Rapid7 InsightVM
Application & Software Security
Checkmarx, Snyk, SonarQube, Invicti
Endpoint & EDR
CrowdStrike, Microsoft Defender, Tanium
Cloud security (CSPM)
Wiz, Prisma Cloud, MS Defender for Cloud
Asset inventory & CMDB
ServiceNow, Qualys CSAM, Ivanti
Pentest & Bug bounty
YesWeHack, Ambionics, manual imports
Attack Surface Mgmt
Hadrian, PaloAlto Xpanse, Hardenize
Active Directory & ICS
ANSSI ORADAD, PingCastle, ClarotyANSSI ORADAD, PingCastle, Claroty
Browse all connectors

Every asset type, in one inventory

HOST
Servers, workstations, network, local infrastructure
EXTERNAL ASSETS
IPs, domains, certificates
CONTAINERS IMAGES
Container images, tags and digests
APPLICATIONS
Auto-scaling, ephemeral and serverless
CLOUD INSTANCES
Auto-scaling, ephemeral and serverless
INSTANCES
Users, service accounts
Perimeters & groups
Assets can be organized into logical perimeters (by entity, geography, business unit, or environment) and queried independently, so each team sees exactly their scope.

Every tool speaks a different language. Hackuity translates.

Normalization converts scanner-specific syntax and local severity ratings into standardized formats, allowing real correlation.

Common data model

Converts diverse payloads into standardized fields: Host, App, Cloud, or Finding models.

CVSS normalization

Calculates standardized CVSS v2 and v3 vectors, regardless of scanner interpretation.

Full source history

Retains original payloads untouched alongside normalized data for audits.

CPE consolidation

Normalizes vendor and product names using the NVD Common Platform Enumeration index.

One server, detected by five tools. One asset in Hackuity.

The Asset Correlation Engine reconciles duplicate asset reports from different scanners using multi-criteria matching rules.

FACTORIZATION PROCESS EXAMPLE

01
Tenable reports a new asset
FQDN: server.internal.corp - IP: 10.0.1.42
02
A.C.E evaluates identifiers by weight
Checks Agent UID → not found. Checks FQDN → match found.
03
Match found with existing asset
Asset [abc123] already reported by Tanium with the same FQDN.
04
Factorization complete
Asset [abc123] enriched with Tenable as new source + new IP address.

A.C.E IDENTIFIER WEIGHTS

Agent UID
Highest
MAC address
High
FQDN / Hostname
High
AD Domain + Hostname
Medium
IP address alone
Low
Admins can manually merge duplicate assets (Manual Fusion) or exclude an unreliable identifier from future automatic matching.

One vulnerability. One entry. Every source accounted for.

When multiple scanners detect the same vulnerability on a single asset, Hackuity deduplicates them into a single logical finding to prevent work queue inflation.

By correlating vulnerability records by CVE and affected asset, Hackuity typically eliminates 10% to 45% of duplicate CVE findings, while preserving the discovery context from every reporting source.

One logical entry created per CVE detected on a specific host, regardless of the reporting scanners.
Retains full history: first-seen, last-seen, and specific payload data from each scanner.
Automatic enrichment: automatically links vulnerabilities to public exploit databases.

Misconfigurations, outdated software, AD risks, and cloud policy violations don't have CVE IDs. Hackuity uses VulnDB Family, its proprietary finding repository, to normalize and deduplicate these non-standard findings across sources.

Misconfigurations from cloud posture tools, AD scanners, and infra scanners unified
Outdated software identified and grouped across multiple reporting tools
No loss of context: raw source data preserved alongside the unified record
Non-CVE findings tracked with the same history and lifecycle as CVEs

Fits your infrastructure. No compromise.

Whether you require fully-managed cloud services or self-hosted air-gapped environments, Hackuity supports your security topology.

SaaS

Fully managed, secure cloud platform. Instant setup, zero maintenance.

On-Premises

Self-hosted, air-gapped deployment for high-security sectors.

Organize your attack surface. Spot the blind spots.

Perimeters & groups

Build segments based on geography, technology, business criticality, or technical scope.

Coverage visibility

Instantly see which hosts are monitored by Endpoint, VM, or both, and spot unmonitored blind spots.

Tags & custom fields

Enrich inventory with business context via automated queries, API sync, or CMDB attributes.

Role-based access

Configure access per perimeter so teams only see the assets they are responsible for.

You've unified the picture. Now, what actually matters?

A unified attack surface is only the foundation. Once you see everything, the real challenge begins: determining what to fix first among thousands of detected findings.

THE PROBLEM RAW DATA ALONE CAN'T SOLVE

CVSS says everything is critical. Your team can't tell where to start.
Millions of findings in your inventory. No business context to separate noise from risk.
Same CVE. Five different assets. Which one is actually exploitable in your environment?
Perimeters & groups
Assets can be organized into logical perimeters (by entity, geography, business unit, or environment) and queried independently, so each team sees exactly their scope.

How does this work in practice?

How does Hackuity collect data does it require deploying agents?

No, Hackuity is agentless. It leverages the APIs of your existing security scanners and asset managers (like Qualys, Snyk, Wiz, etc.) to collect asset properties and vulnerability findings on a schedule you configure.

Aggregate & Deduplicate

Can I filter what each connector brings in?

Yes. Each connector offers granular filters by asset tag, perimeter, severity threshold, scan profile, or date. You control exactly what enters your Hackuity workspace.

Aggregate & Deduplicate

What if the same server is reported by five different tools?

A.C.E evaluates each source entry against a weighted Decision Tree. Once a match is found (e.g. FQDN), the engine stops and creates a single unified asset enriched with data from all five sources. No double-counting.

Aggregate & Deduplicate

Does Hackuity deduplicate non-CVE findings like misconfigurations?

Yes. Through VulnDB Family Hackuity's proprietary finding repository non-CVE findings (misconfigurations, outdated software, AD risks) are normalized and deduplicated across sources, even when they don't share a CVE ID.

Aggregate & Deduplicate

What if automatic asset correlation fails?

If two assets have no overlapping identifier, A.C.E won't merge them automatically. In that case, an operator can manually merge them from the UI, preserving source history and deduplicated findings from both assets.

Note: manual merges are one-way once assets are merged, they cannot be split back apart, and the operation becomes irreversible after an 8-hour grace period.

Aggregate & Deduplicate