ThreatLedger

RMF evidence, vulnerability context, and control mapping in one workflow.

ThreatLedger helps RMF teams turn Nessus exports, STIG checklist files, and related assessment data into prioritized findings, impacted control views, and executive-ready reports.

NessusCKL / CKLBCSVZIP uploadsKEV / EPSS / CVSSCCI / NIST mapping

Core workflow

What ThreatLedger does

ThreatLedger reduces the manual effort analysts spend compiling information from multiple exports and turning it into something leadership, ISSMs, assessors, and technical teams can act on.

01

Combine assessment data

Upload Nessus, STIG checklist, CKLB, CSV, or ZIP packages and analyze related findings together.

02

Prioritize findings

Enrich vulnerability data with KEV, EPSS, CVSS, and severity context to focus remediation.

03

Show control impact

Connect findings to CCI and NIST control context for RMF reporting and control discussions.

04

Track outputs

Produce executive and RMF-focused reports from the same normalized assessment evidence.

Reports

Decision-ready exports from raw assessment data.

ThreatLedger separates leadership-level risk summaries from detailed RMF mapping so each audience gets the right level of detail.

Executive Risk ReportSummary of open findings, priority issues, KEV/EPSS indicators, and top impacted controls.
RMF Compliance & Mapping ReportControl/AP rollups, CCI mappings, host breakdowns, and open/not-reviewed checklist context.
Host and Finding ViewsTechnical breakdowns for analysts working remediation and validation.
POA&M SupportActionable remediation context for planning and tracking.

Deployment & data handling

Designed for customer-controlled deployment.

ThreatLedger is designed for customer-managed local or on-premises deployment. The intent is to keep uploaded scan data, checklist content, generated reports, and project artifacts inside the customer-controlled environment.

  • No forced SaaS model for assessment artifacts
  • Container-based deployment model
  • Built for controlled network realities
  • Customer retains control of uploaded files and generated reports