Skip to main content
oxharden identity

oxharden is a Linux security platform.

oxharden helps security and infrastructure teams verify Linux vulnerability fixes, CIS and DISA STIG evidence, exposed services, and restart debt from live host evidence. It shows whether a fix is installed, running, and ready to close.

Read-only agent RHEL-family focus Live remediation evidence
rhel-prod-042 - patch truthscan 14:02 UTC
Installed fixon disk
openssl-libs3.0.7-27fixed
kernel5.14.0-503installed
Running codein memory
nginx -> libssl.so.33.0.7-18stale
kernel running5.14.0-427old
Restart debtnginx still mapping old libssl - restart requirednot ready to close
Audit evidence - package - process - mapped lib - timestamp
what oxharden does

One platform for Linux remediation proof.

oxharden brings Linux vulnerability management, patch verification, and compliance evidence together on one live picture of every host.

Find Linux risk

Prioritize CVEs, vulnerable packages, exposed services, and host drift across RHEL-family Linux fleets.

Verify live fixes

Separate patches installed on disk from code actually running in memory or the active kernel.

Produce evidence

Give security and audit teams host-level proof for remediation, CIS, DISA STIG, and compliance reviews.

the core problem

A patched package is not always a fixed host.

Linux services can keep old libraries mapped after package updates. Kernels can remain vulnerable until the host reboots. oxharden tracks the difference between applied state and live state so teams know exactly what work remains: the gap between patched on disk and running code.

patch-truth - rhel-prod-042
okopenssl-libs fixed on disk
xnginx still mapping old libssl
->action: restart nginx
#kernel 5.14.0-427 running - reboot pending
live state reconciled status: not ready to close
01

Scanner finding

A CVE is flagged against a vulnerable package on the host.

02

Patch installed

The fixed package version lands on disk. Most scanners stop here.

03

Old code still running

Long-running services keep the old library mapped in memory.

04

Restart or reboot

The service must restart, or the host must reboot, for the fix to take effect.

05

Evidence ready to close

Applied and live agree; the finding closes with proof.

where oxharden fits

A verification layer, not another scanner.

oxharden includes Linux vulnerability management. Its difference is proving fixes are actually running.

Traditional vulnerability scannersdetect
Find vulnerable software and misconfigurations
Report package or configuration findings
Often require interpretation after patch windows
oxhardenverify + prove
Verifies whether remediations are live
Tracks applied vs running state
Produces host-level evidence for closure
Connects vulnerability, compliance, exposure, and restart debt

oxharden complements the scanners you already run. It takes their findings from installed to proven-live.

product evidence

Every finding closes with host-level proof.

oxharden captures the package version, the running process, the mapped library, and the scan timestamp so an auditor can see exactly why a finding is or is not ready to close.

Patch Truth findingrhel-prod-042
Hostrhel-prod-042
FindingCVE fixed package installed (openssl-libs 3.0.7-27)
Live stateold libssl still mapped by nginx
Actionrestart nginx
Evidencepkg 3.0.7-27pid 1183 nginxlibssl.so.3 deleted14:02 UTC
Close status: not ready to closerestart pending
common questions

Common oxharden questions.

oxharden is a Linux security platform for vulnerability management, patch verification, compliance evidence, exposed service discovery, and continuous hardening across RHEL-family Linux fleets.

oxharden includes Linux vulnerability management, but its key difference is live remediation evidence: showing whether fixes are actually running after patches are installed.

Patch verification confirms a fix is not just patched on disk but live in running code. oxharden inspects running processes and the active kernel, not only the package database, so a finding closes on live host evidence.

Restart debt is the backlog of services and hosts still running old code after a patch: processes mapping stale libraries, or a kernel awaiting a reboot. oxharden names the exact restart or reboot each host needs.

oxharden is designed around RHEL-family and RPM-based Linux environments, including RHEL, Rocky Linux, AlmaLinux, Oracle Linux, and Amazon Linux. Its evidence model focuses on packages, kernels, running processes, services, ports, and compliance state across those hosts.

get started

See what your Linux fleet is really running.

oxharden proves whether your Linux vulnerability fixes are patched on disk and live in running code, with kernel reboot evidence and CIS / DISA STIG compliance evidence built in.

No credit card required. Start with up to 30 hosts or review a sample evidence report first.