Combine assessment data
Upload Nessus, STIG checklist, CKLB, CSV, or ZIP packages and analyze related findings together.
ThreatLedger
ThreatLedger helps RMF teams turn Nessus exports, STIG checklist files, and related assessment data into prioritized findings, impacted control views, and executive-ready reports.
Core workflow
ThreatLedger reduces the manual effort analysts spend compiling information from multiple exports and turning it into something leadership, ISSMs, assessors, and technical teams can act on.
Upload Nessus, STIG checklist, CKLB, CSV, or ZIP packages and analyze related findings together.
Enrich vulnerability data with KEV, EPSS, CVSS, and severity context to focus remediation.
Connect findings to CCI and NIST control context for RMF reporting and control discussions.
Produce executive and RMF-focused reports from the same normalized assessment evidence.
Reports
ThreatLedger separates leadership-level risk summaries from detailed RMF mapping so each audience gets the right level of detail.
Deployment & data handling
ThreatLedger is designed for customer-managed local or on-premises deployment. The intent is to keep uploaded scan data, checklist content, generated reports, and project artifacts inside the customer-controlled environment.