Find Linux risk
Prioritize CVEs, vulnerable packages, exposed services, and host drift across RHEL-family Linux fleets.
oxharden helps security and infrastructure teams verify Linux vulnerability fixes, CIS and DISA STIG evidence, exposed services, and restart debt from live host evidence. It shows whether a fix is installed, running, and ready to close.
oxharden brings Linux vulnerability management, patch verification, and compliance evidence together on one live picture of every host.
Prioritize CVEs, vulnerable packages, exposed services, and host drift across RHEL-family Linux fleets.
Separate patches installed on disk from code actually running in memory or the active kernel.
Give security and audit teams host-level proof for remediation, CIS, DISA STIG, and compliance reviews.
Linux services can keep old libraries mapped after package updates. Kernels can remain vulnerable until the host reboots. oxharden tracks the difference between applied state and live state so teams know exactly what work remains: the gap between patched on disk and running code.
A CVE is flagged against a vulnerable package on the host.
The fixed package version lands on disk. Most scanners stop here.
Long-running services keep the old library mapped in memory.
The service must restart, or the host must reboot, for the fix to take effect.
Applied and live agree; the finding closes with proof.
Vulnerability, exposure, compliance, and restart debt connected on one live picture of each host.
CVE and package risk rolled up by affected hosts, exploit signals, available fixes, and remediation impact.
Learn moreProof that fixed packages, libraries, and kernels are actually live, not only installed.
Learn moreIdentify services, processes, and hosts waiting on restarts or reboots after patching.
Learn moreContinuous CIS and DISA STIG evidence with expected vs actual host state.
Learn moreMap listening services, ports, packages, and host context into a single security view.
Learn moreDesigned around RHEL, Rocky, AlmaLinux, Oracle Linux, and Amazon Linux environments.
Learn moreoxharden includes Linux vulnerability management. Its difference is proving fixes are actually running.
oxharden complements the scanners you already run. It takes their findings from installed to proven-live.
oxharden captures the package version, the running process, the mapped library, and the scan timestamp so an auditor can see exactly why a finding is or is not ready to close.
oxharden is a Linux security platform for vulnerability management, patch verification, compliance evidence, exposed service discovery, and continuous hardening across RHEL-family Linux fleets.
oxharden includes Linux vulnerability management, but its key difference is live remediation evidence: showing whether fixes are actually running after patches are installed.
Patch verification confirms a fix is not just patched on disk but live in running code. oxharden inspects running processes and the active kernel, not only the package database, so a finding closes on live host evidence.
Restart debt is the backlog of services and hosts still running old code after a patch: processes mapping stale libraries, or a kernel awaiting a reboot. oxharden names the exact restart or reboot each host needs.
oxharden is designed around RHEL-family and RPM-based Linux environments, including RHEL, Rocky Linux, AlmaLinux, Oracle Linux, and Amazon Linux. Its evidence model focuses on packages, kernels, running processes, services, ports, and compliance state across those hosts.
oxharden proves whether your Linux vulnerability fixes are patched on disk and live in running code, with kernel reboot evidence and CIS / DISA STIG compliance evidence built in.