What Docusnap365 does for vulnerability management

Docusnap365 automatically matches known vulnerabilities against your inventoried IT estate. The data comes from agentless discovery and covers hardware, software, and version levels. Each identified CVE includes a severity rating, affected versions, and remediation guidance. The matching also covers legacy systems that traditional patch management does not reach.

How the matching works

From inventory to CVE detection

Step 1

Inventory your estate

Docusnap365 inventories hardware, software, and version levels automatically and without agents. The data comes from discovery, not from manual upkeep. Systems outside your patch management are covered as well.

Step 2

Match against CVEs

The inventoried estate is automatically checked against known vulnerabilities. The matching considers actual installed versions and shows which systems are concretely affected.

Step 3

Assess and act

Every identified vulnerability receives a severity rating, remediation guidance, and a deadline. Owners are assigned, measures documented.

AI-powered analysis

Ask your inventory about vulnerabilities

Instead of filtering reports, ask questions in natural language: Which systems are affected by CVE-2026-XXXX? Where are remediation deadlines expiring? Which critical vulnerabilities affect servers with external connectivity? The AI-powered query searches your inventoried estate and returns answers based on actual data. When a vulnerability makes headlines, you know within minutes whether and where you are affected.

Which systems are affected by CVE-2026-XXXX?

Eleven systems are running an affected version, three rated critical. Two systems have no owner assigned yet.

Where are remediation deadlines expiring?

Four remediation deadlines expire within the next seven days. One deadline has already passed.

Which critical vulnerabilities affect servers with external connectivity?

Six critical vulnerabilities across four externally connected servers. Remediation guidance is available for five of them.

CVE details

Full information on every vulnerability

For every identified CVE, Docusnap365 shows a structured detail view: description of the vulnerability, CVSS severity rating, affected software versions, and concrete remediation guidance. Additionally, the permissions assigned on affected systems are visible. This means the risk assessment considers the vulnerability itself and its attack surface in the specific context of your environment.

From finding to fix

Remediate vulnerabilities with full documentation

The path from an identified vulnerability to a documented remediation runs in Docusnap365 without a media break. Assessment, decision, and deadline sit in the same system as the inventory itself.

Deadlines and owners

Every vulnerability receives a remediation deadline and an assigned owner. Open deadlines are visible at any time, escalations are traceable.

Auditable triage

Every assessment is documented and audit-ready. Deliberately accepting a vulnerability is recorded as a decision, including the rationale and the date.

Track remediation

Remediation measures are assigned directly and their status is documented. The entire process maps the NIS2 requirement for handling vulnerabilities as a continuous workflow.

Vulnerability, owner, and remediation in one system. No tool switching, no exports.

Frequently asked questions about vulnerability management with Docusnap365

Where do the CVE data in Docusnap365 come from?

Docusnap365 sources CVE data from publicly available vulnerability databases. The matching runs automatically against the inventoried estate, so only hits that affect actually installed software and versions are shown.

Does the scan cover systems outside patch management?

Yes. Docusnap365 discovery inventories hardware and software regardless of whether a patch management system is in place. Legacy systems, specialist applications, and manually installed software appear in the matching as long as they are reachable on the network.

How can the process support NIS2 compliance evidence?

Docusnap365 maps the handling of vulnerabilities as a continuous process: detection, assessment, deadline setting, and documented remediation. NIS 2 requires exactly this traceable handling of known vulnerabilities. Every decision is documented and auditable.

What happens when a vulnerability is deliberately not remediated?

A deliberate acceptance is recorded in Docusnap365 as a documented decision. The triage record includes who decided, when, and with what rationale. This is relevant for audits and regulatory evidence requirements.

Does the IT inventory need manual maintenance for the matching to work?

No. The inventory is built automatically from discovery, the same data source that feeds the IT documentation in Docusnap365. There is no separate inventory and no double maintenance.

Identify vulnerabilities in your estate

Try Docusnap365 and see which known CVEs affect your IT environment.