SentriKat Early Access is open: Cloud is free on the plan you choose, no credit card. Get started
Compare

SentriKat and open-source security tools

Each of them does one job well, and the table below says which. SentriKat goes from the software installed on your machines to the vulnerabilities that affect it, with the exploited ones first.

How we read them

Product What it is Read from Read on
DefectDojo Triage of findings from other tools source code, dojo/finding/ui/filters.py 27 September 2026
Fleet Management of a fleet of agents source code, server/fleet/hosts.go 27 September 2026
Dependency-Track Inventory of software components source code, REST resources 27 September 2026
OpenCVE Watch on new vulnerabilities, by vendor source code, search and saved views 27 September 2026

None of them was run. This page compares what each product declares it can do, not how it feels to use, so it says nothing about which one is simpler or faster.

What SentriKat does differently

From your inventory to the machine
Every vulnerability says which machines have it and in which installed product. SentriKat starts from the software that actually runs, not from a scan of the network.

OpenCVE tells you that a vulnerability was published for a vendor you follow. SentriKat tells you where you have it. Source: OpenCVE, source code, search and saved views, read 27 September 2026.

The engine says how sure it is
Every match carries a confidence, and you can filter on it. Software that cannot be identified for certain is not given a wrong identity. Detection is deterministic: no AI inside it, and the same input always gives the same answer.

None of the products we read has an equivalent filter. Source: DefectDojo, source code dojo/finding/ui/filters.py, read 27 September 2026. Source: Fleet, source code server/fleet/hosts.go, read 27 September 2026. Source: Dependency-Track, source code, REST resources, read 27 September 2026. Source: OpenCVE, source code, search and saved views, read 27 September 2026.

What the distribution already fixed stays quiet
Fixes published by Red Hat, Debian and Windows close the vulnerabilities they already patched, so they do not reach your list.
Several organizations, on your own servers too
One installation holds several organizations, each with its own machines and its own tags.
Filters for the daily work
Machines by status (online, not responding, offline, stale) and by tag. Vulnerabilities past their SLA or past their remediation due date. The import queue of each machine. Columns you can adjust on every list.

Where they are ahead of us

One row for each thing they have and SentriKat does not, kept here until it is closed.

Capability Who has it SentriKat today
Filter by “a fix exists” Show only the vulnerabilities that already have a fix you can install. DefectDojo Source: source code dojo/finding/ui/filters.py, read 27 September 2026. Not yet. SentriKat knows the version that fixes it, but you cannot filter on it.
Installed software as a filter on the machine list Ask for every machine that has a given product installed. Fleet Source: source code server/fleet/hosts.go, read 27 September 2026. Not as a filter. You get there the other way round: open the product and see its machines.
Date ranges for first and last detection Pick any from and to date for when a finding was first or last seen. DefectDojo, Dependency-Track Source: source code dojo/finding/ui/filters.py, read 27 September 2026. Source: source code, REST resources, read 27 September 2026. Fixed windows only: 7, 30 or 90 days.
Saved views with a name Keep a search under a name and come back to it. OpenCVE Source: source code, search and saved views, read 27 September 2026. Not yet. A shared link keeps the filters, but there are no named searches.
A query language Write searches as text, for people who prefer that to filters. OpenCVE Source: source code, search and saved views, read 27 September 2026. No. SentriKat has filters only.
Outdated components List components that are behind their latest release, vulnerable or not. Dependency-Track Source: source code, REST resources, read 27 September 2026. Not yet.
Number of filter fields on findings How many fields you can filter a list of findings on. DefectDojo (45 fields) Source: source code dojo/finding/ui/filters.py, read 27 September 2026. About twenty.

What this page does not compare

  • Prices. We have no dated source for theirs. Ours are on the pricing page.
  • Ease of use and speed. Nobody has measured them side by side.