Data Points

🔥 CVE / Vulnerability

Common Vulnerabilities and Exposures identifier for a known flaw.
Cyber

Sources

8
8 no-auth

Disciplines

4
that use it

Mission domains

6
reach

Workbench

native tool

🔌 Sources that yield CVE / Vulnerability (8)

SourceCategoryAuthFormat
CISA ICS Advisories
ICS/OT vulnerability advisories.
Critical InfrastructureNONExmlhome↗ api↗
FIRST EPSS
Exploit-probability scoring for CVEs.
VULNINTNONEjsonhome↗ api↗
GitHub / Exploit-DB / OSV
Code, package & exploit technical intel.
TECHINTNONEjsonhome↗ api↗
huntr AI/ML Vulnerabilities
Disclosed vulnerabilities in AI/ML OSS.
Emerging TechNONEhtmlhome↗
MITRE ATLAS (AI threats)
Adversarial ML threat matrix.
Emerging TechNONEyamlhome↗ api↗
MITRE ATT&CK for ICS
ICS adversary techniques matrix.
Critical InfrastructureNONEjsonhome↗ api↗
NIST NVD (ICS vendors)
Authoritative vulnerability database.
Critical InfrastructureNONEjsonhome↗ api↗
SANS Internet Storm Center
Internet threat telemetry & handler diary.
CYBINTNONEjsonhome↗ api↗

🔍 Lookup

📜 Playbook — CVE / Vulnerability exploitation

  1. Direction — frame the requirement for CVE / Vulnerability: what decision does this support, by when?
  2. Collection — pull the 8 mapped sources (8 free) and the native workbench (open); capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎫 CVE / Vulnerability

A CVE is a public identifier for a specific software or hardware vulnerability, carrying scoring (CVSS), affected-product data (CPE), and weakness classification (CWE). It matters because it is the shared language for prioritizing patching, mapping exploitability, and attributing intrusions to known attack surface.

Format: CVE-YYYY-NNNN+ (e.g. CVE-2024-3400); CVSS v3.1/v4.0 vector string; CPE 2.3 URI (cpe:2.3:a:vendor:product:version:...); EPSS 0-1 probability.

📡 How it is collected

  • NVD / MITRE CVE feed ingestion
  • Vendor security advisories and PSIRT bulletins
  • Vulnerability scanner findings (Nessus/OpenVAS)
  • Exploit-DB and PoC repository monitoring
  • KEV catalog subscription
  • Threat-intel reporting on exploited-in-the-wild bugs

🧩 Analysis & hunting techniques

  • CVSS + EPSS + KEV combined risk scoring
  • CPE-to-asset inventory matching
  • Exploit-availability & maturity assessment
  • Attack-surface mapping via Shodan/Censys
  • MITRE ATT&CK technique linkage
  • Patch-lag / MTTR trend analysis
  • PoC-to-weaponization timeline tracking
  • CWE root-cause clustering

🔧 Tools

  • Nuclei (ProjectDiscovery)
  • Nessus / OpenVAS
  • Nmap NSE vuln scripts
  • Metasploit
  • Trivy / Grype
  • searchsploit
  • nvdlib

⚡ Workbench actions

  • Pull NVD/CVSS detail
  • Check KEV & EPSS
  • Map affected CPEs to assets
  • Find public exploits
  • Scan surface for exposure
  • Link to ATT&CK & malware
  • Prioritize by risk score
  • Track patch status

📊 Dashboard KPIs

CVSS base scoreEPSS exploit probabilityKEV listed (yes/no)Exposed asset countDays since disclosure / patch lag
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php