Skip to content
Net Bright — Tech Company
Free tools from the Net Bright team
Free

Risk Radar

Continuous vulnerability and risk management you host yourself

Risk Radar lets security teams and system owners scan for vulnerabilities, score the risk and track remediation in real time — instead of waiting for the annual pentest. It turns risk management from a once-a-year project into a continuous service anyone in the organization can use.

Built in-house by the Net Bright team with Claude Code

Free, self-hosted and open. Deploy it on your own infrastructure — vulnerability data stays 100% inside your organization.

Risk Radar

What it does

  • Continuous Attack Surface Management — automatically discovers new assets and assesses them immediately
  • Multi-scanner engine — Nmap, Nuclei and OWASP ZAP across network, config and web application
  • Malware and compromise detection — web shells, injected JS, blocklist reputation and defacement (HTTP-only, safe on production)
  • Dynamic risk scoring — CVSS × asset criticality × threat intel (EPSS/KEV), combined into a 0–100 score
  • Real-time dashboard over WebSocket — risk radar, spider chart and trend, updated live
  • Self-service scanning — system owners run their own scans after deploy and schedule daily runs
  • Remediation guidance with code examples for every finding, plus a full finding lifecycle (close, accept risk, false positive)
  • Alerting to Slack, Teams, Jira and ServiceNow, plus PDF reports with a Thai-language executive summary
  • RBAC and OIDC/SSO — three roles, sign-in via Keycloak or Microsoft Entra ID
  • Safe-scan guardrails — rate limiting, maintenance windows and a circuit breaker so production stays up

Who it helps

  • Security and SOC teams
  • System and application owners
  • DevSecOps teams
  • CISOs and executives who need a readable risk picture
  • Compliance and audit functions
  • IT infrastructure teams

At a glance

Deployment
On-premise, private cloud (AWS/Azure/GCP) or hybrid, via Docker Compose
Requirements
2+ CPU cores, 4 GB RAM minimum (8 GB recommended), Docker Engine + Compose
Data security
AES-256 at rest, TLS in transit, scanner zone isolated from the console, full audit log
Built with
Go · Python/Celery · React · PostgreSQL + TimescaleDB · NATS + Redis · Keycloak

Request free access

Tell us a little about your environment and our team will send you access details and help you get started.

Download the user manual (PDF)

Request access

Delivering Superior IT Solutions

Helping organizations achieve operational excellence through Infrastructure, Cybersecurity, Cloud, AI, and Managed Services.