Hakken 発見

Know what you're
buying before
you own it.

Technical due diligence is still a document exercise. You read a spreadsheet written by a seller with an interest in the outcome, then meet the real infrastructure at integration, when every problem has become your problem.

Hakken is dropped into the target's network and returns an evidence-backed picture of the estate: what's there, what depends on what, what's expiring, what's unlicensed, what moves first, and how confident it is in each of those claims.

Read-only, and nothing is installed on a single host. No agent, no telemetry, no hosted service. Runs entirely inside an air-gapped network.

The cost of finding out late

The same finding is worth three different amounts.

Nothing about the estate changes across these three moments. What changes is who pays for it, and that is entirely a function of when you learn it.

Before signing

A price adjustment

Costs you nothing

An end-of-life estate, an unlicensed Oracle footprint, a certificate wall expiring in ninety days. Discovered here, each one is a line in your negotiating position, or a reason to walk.

Between signing and close

A condition

Costs you leverage

Still recoverable: an escrow, a rep, a remediation covenant. But the price is set, and you are now asking rather than negotiating.

After close

Your integration budget

Costs you cash

The dependency nobody mapped takes the cutover weekend into a Tuesday outage. The licence nobody counted arrives as a vendor audit. You own all of it.

Discovery and dependency mapping are commodities. The scarce thing is an interpretation you can defend in front of a deal committee.

Why Hakken exists

What you get

Three outputs, each one a decision you were going to have to make anyway.

Price the risk while you still have leverage

Every commercial exposure in the estate, counted by the metric the vendor actually audits on, not the metric the seller reported.

  • Oracle by processor core, with the core factor
  • VMware by core subscription, post-Broadcom repricing
  • SQL Server by core minimums and CALs
  • SAP by named user and indirect access
  • End-of-life debt with the date support actually stopped

Sequence the integration before Day One

The dependency ordering is the part humans reliably get wrong, because nobody holds the whole graph in their head.

  • Migration waves ordered so nothing moves before what it depends on
  • Dependency cycles surfaced as blockers, not hidden
  • Carve-out aware: shared infrastructure last when a TSA says so
  • Blockers attached to the wave they will actually stop

Defend every number in the room

The output gets challenged by the seller's advisors. It is built to survive that.

  • Every fact carries its source, method, timestamp and privilege
  • Every claim carries a confidence score and the evidence behind it
  • Every operator action is in a hash-chained audit log
  • The report quotes the hash of the database it was rendered from

Your numbers, not ours

We are not going to invent a savings figure for you.

Put in what your diligence actually costs today. Every figure below is arithmetic on your own inputs. There is no assumption of ours hidden in it.

Discovery labour you spend per year, before a single finding is interpreted $2,592,000
Per deal $432,000
Cost per host, inventoried by interview and spreadsheet $864
Calendar weeks of deal clock consumed each year 36

Hakken does not replace your diligence team. It replaces the six weeks they spend assembling an inventory that is already stale on delivery, and gives them the interpretation as the starting point rather than the deliverable. What that is worth against the figure above is a judgement only you can make, which is why we have not made it for you.

Why the report survives cross-examination

Nothing in a Hakken report was guessed.

There is no language model anywhere in the pipeline. A narrative that cannot be traced to specific evidence is worthless in front of a committee, and nothing that depends on a hosted model can run inside an air-gapped network. Every sentence is produced by a deterministic rule, from evidence you can follow back to the host it came from.

Confidence is computed, and published

Evidence combines by noisy-OR, so more agreeing evidence always helps and no finite amount produces certainty. No claim ever reaches 1.0.

Evidence sourceWeightWhy not higher
Host read directly, over SSH or WinRM0.93A credential and a network are in the path
Active probe response0.80The host answered directly
Passive network observation0.70Traffic, not testimony
Derived inference0.60Reasoned, not observed
Customer spreadsheet0.50A claim by someone with an interest in the outcome
Hostname alone0.25db01 has been a web server since 2019. A role supported only by a hostname is rejected outright.

Commercial exposure, by the metric that gets audited

Eleven licensing families, each flagged with the entitlement question to put to the seller and the document to ask for.

FamilyCounted by
Oracle Databaseprocessor cores × core factor
VMware vSpherecore subscription
Microsoft SQL Servercores or CALs
Windows ServerDatacenter vs Standard
SAPnamed users, indirect access
Red Hat Enterprise Linuxsubscriptions per socket pair
IBM Db2 · WebSphere · MQprocessor value units
Citrixconcurrent users or devices
Veeam Backupprotected workloads

Security posture, checked the way an acquirer cares about it

Fifteen deterministic checks across the estate. Each one is a finding with the hosts it applies to and the evidence that produced it.

No endpoint protection Unhealthy endpoint protection No host firewall SSH password authentication SSH root login RDP without NLA Management ports exposed Cleartext protocols in use Certificates expiring inside 90 days Unpatched beyond 90 days Reboot pending Privileged interactive logins Stale local accounts SMBv1 enabled

The objection that actually blocks deployments

Their security team will say no. Hand them this first.

A target's CISO has every reason to refuse an acquirer's software on their network during a deal. Hakken ships a document that exists solely to be handed over before anything connects. It lists every file read, at what privilege, on each platform. Not a policy. An inventory.

Read-only, enforced by the code path

No collector opens a file for writing, signals a process, takes a package manager lock, or issues a non-GET request to a local API. There is no code path that mutates a target system.

Secrets are not collected, because there is nowhere to put them

Environment variable values, key material, password hashes, authorized_keys bodies and Kerberos tickets are never read. The data model has no field that could hold them.

One outbound request, and you can turn it off

The cloud metadata probe. That is the entire network footprint. No telemetry, no phone-home, no runtime dependency on any hosted service.

Active probing is off, behind three gates

Turning it on requires a scope file that permits it, an explicit flag, and a written authorisation flag. Every probe, and every refusal, is written to the audit log.

Nothing leaves the network unless you carry it

Analysis runs entirely offline. Vulnerability, end-of-life and hardware data come from a local feed cache with embedded fallbacks, so a fully air-gapped engagement produces a full report.

No offensive capability at all

No exploitation, no credential harvesting, no detection evasion. There is nothing in the binary that a blue team would need to make an exception for.

Don't take our word for it

Read a sample report before you ever talk to us.

Not a mockup, not a sales deck and not a screenshot. A sample report for a fictional target, Northwind Manufacturing Ltd: a 2,529-device estate across three sites, of which only 947 could be read directly. Produced by the same signature-verified import and offline analysis a live engagement uses. Nothing to install, nothing to download, nothing to sign.

2,529devices in scope, across three sites
1,582of them have no login to read
37%read directly, stated before any finding
0network calls during analysis

Read the first two sections. The second one is the point: it says what Hakken could not see, before it says anything it found. Every claim after that carries a confidence score and the evidence behind it, and the footer quotes the hash of the database it was rendered from.

Open the sample report

The estate is the same either way. Only the timing is yours to choose.

Bring us one live deal. We will walk your team through a full report on a representative estate, section by section, and you can decide whether it changes what you would have paid.

We use your details to arrange the walkthrough and nothing else. No newsletter, no list, no third party. Or read the sample report first.

Deployed into the target's environment under your engagement letter. Licensing and commercial terms are set per engagement. Ask us on the call.