The CMDB says you run PostgreSQL and Nginx.
Reality: three teams run Redis 4 that hit EOL in 2020, one team pinned Node 12 in a legacy Lambda, and a forgotten instance is running an outdated Elasticsearch open on port 9200. Every one of those has known exploits, and none of them are in your asset inventory.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
Onam probes running workloads through cloud metadata, container image inspection, and process metadata — read-only, no agents.
- 2
The engine identifies 34 technology categories and thousands of individual products, versions, and configurations across your fleet.
- 3
Each detected technology is checked against version-specific security rules covering defaults, hardening, and end-of-life status.
- 4
Findings are joined to the identity, network, and vulnerability graph so an EOL database that is internet-reachable ranks appropriately.
- 5
New technologies and versions are added continuously as they appear in customer environments — so shadow IT is discovered without a rule-writing sprint.
Specific outputs, measurable outcomes
Technology Engine in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see Technology Engine in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.