🔥 CVE / Vulnerability
Common Vulnerabilities and Exposures identifier for a known flaw.
Cyber
🔧 Native workbench
🔎 Live indicators (IoC view)
🔗 Analyst pivots
🔌 Sources that yield CVE / Vulnerability (8)
| Source | Category | Auth | Format | |
|---|---|---|---|---|
| CISA ICS Advisories ICS/OT vulnerability advisories. | Critical Infrastructure | NONE | xml | home↗ api↗ |
| FIRST EPSS Exploit-probability scoring for CVEs. | VULNINT | NONE | json | home↗ api↗ |
| GitHub / Exploit-DB / OSV Code, package & exploit technical intel. | TECHINT | NONE | json | home↗ api↗ |
| huntr AI/ML Vulnerabilities Disclosed vulnerabilities in AI/ML OSS. | Emerging Tech | NONE | html | home↗ |
| MITRE ATLAS (AI threats) Adversarial ML threat matrix. | Emerging Tech | NONE | yaml | home↗ api↗ |
| MITRE ATT&CK for ICS ICS adversary techniques matrix. | Critical Infrastructure | NONE | json | home↗ api↗ |
| NIST NVD (ICS vendors) Authoritative vulnerability database. | Critical Infrastructure | NONE | json | home↗ api↗ |
| SANS Internet Storm Center Internet threat telemetry & handler diary. | CYBINT | NONE | json | home↗ api↗ |
🧭 Disciplines
🎯 Mission Domains
🔍 Lookup
🔄 Live Datasets & APIs (6 key-free · ingestible)
📜 Playbook — CVE / Vulnerability exploitation
- Direction — frame the requirement for CVE / Vulnerability: what decision does this support, by when?
- Collection — pull the 8 mapped sources (8 free) and the native workbench (open); capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
✨ Enrichment pathways
🎫 CVE / Vulnerability
A CVE is a public identifier for a specific software or hardware vulnerability, carrying scoring (CVSS), affected-product data (CPE), and weakness classification (CWE). It matters because it is the shared language for prioritizing patching, mapping exploitability, and attributing intrusions to known attack surface.
Format: CVE-YYYY-NNNN+ (e.g. CVE-2024-3400); CVSS v3.1/v4.0 vector string; CPE 2.3 URI (cpe:2.3:a:vendor:product:version:...); EPSS 0-1 probability.
📡 How it is collected
- NVD / MITRE CVE feed ingestion
- Vendor security advisories and PSIRT bulletins
- Vulnerability scanner findings (Nessus/OpenVAS)
- Exploit-DB and PoC repository monitoring
- KEV catalog subscription
- Threat-intel reporting on exploited-in-the-wild bugs
📚 Enrichment & validation sources
🔗 Pivot to
🧩 Analysis & hunting techniques
- CVSS + EPSS + KEV combined risk scoring
- CPE-to-asset inventory matching
- Exploit-availability & maturity assessment
- Attack-surface mapping via Shodan/Censys
- MITRE ATT&CK technique linkage
- Patch-lag / MTTR trend analysis
- PoC-to-weaponization timeline tracking
- CWE root-cause clustering
🔧 Tools
- Nuclei (ProjectDiscovery)
- Nessus / OpenVAS
- Nmap NSE vuln scripts
- Metasploit
- Trivy / Grype
- searchsploit
- nvdlib
⚡ Workbench actions
- Pull NVD/CVSS detail
- Check KEV & EPSS
- Map affected CPEs to assets
- Find public exploits
- Scan surface for exposure
- Link to ATT&CK & malware
- Prioritize by risk score
- Track patch status
📊 Dashboard KPIs
CVSS base scoreEPSS exploit probabilityKEV listed (yes/no)Exposed asset countDays since disclosure / patch lag
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron