Disciplines

🔥 Vulnerability Intelligence (VULNINT)

Weaknesses, Exploitation, and Prioritization
Cyber & Threat

Sources

6
6 no-auth

Mission domains

4
reach

Data points

2
covered

Related INT

3
disciplines

🔌 Sources for Vulnerability Intelligence (6)

SourceCategoryAuthFormat
CISA ICS Advisories
ICS/OT vulnerability advisories.
Critical InfrastructureNONExmlhome↗ api↗
FIRST EPSS
Exploit-probability scoring for CVEs.
VULNINTNONEjsonhome↗ api↗
huntr AI/ML Vulnerabilities
Disclosed vulnerabilities in AI/ML OSS.
Emerging TechNONEhtmlhome↗
MITRE ATLAS (AI threats)
Adversarial ML threat matrix.
Emerging TechNONEyamlhome↗ api↗
MITRE ATT&CK for ICS
ICS adversary techniques matrix.
Critical InfrastructureNONEjsonhome↗ api↗
NIST NVD (ICS vendors)
Authoritative vulnerability database.
Critical InfrastructureNONEjsonhome↗ api↗

🔍 Lookup

📜 Playbook — Vulnerability Intelligence collection

  1. Direction — frame the requirement for Vulnerability Intelligence: what decision does this support, by when?
  2. Collection — collect from the 6 mapped sources (6 free) — filter the catalog by VULNINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Mission

Vulnerability Intelligence tracks disclosed vulnerabilities, exploit availability, and real-world exposure across the attack surface to prioritize remediation. It answers which CVEs matter right now, whether they are being exploited, and where the organization is exposed.

📡 Collection methods

  • CVE/NVD feed ingestion with CVSS, EPSS, and KEV enrichment
  • CISA KEV catalog monitoring for confirmed exploited vulnerabilities
  • Exploit-availability tracking across Exploit-DB, Metasploit, and public GitHub PoCs
  • Attack-surface scanning with Shodan/Censys to map exposed services to CVEs
  • Vendor advisory and GHSA monitoring for affected products and packages
  • PoC and weaponization chatter monitoring on GitHub and social platforms
  • SBOM and dependency analysis (OSV) for transitive exposure

🔧 Tools & frameworks

  • Nuclei
  • Greenbone/OpenVAS
  • Nmap
  • Shodan
  • Trivy
  • Grype
  • EPSS
  • ATT&CK

📜 Vulnerability Intelligence Tradecraft

  1. Collect: continuously ingest NVD, GHSA, and vendor advisories alongside CISA KEV and EPSS updates
  2. Process: enrich each CVE with CVSS, EPSS probability, KEV status, and exploit-availability flags
  3. Analyze: correlate CVEs against the asset inventory and Shodan/Censys exposure to compute real risk
  4. Attribute: link exploited CVEs to the threat actors and malware families weaponizing them
  5. Disseminate: publish a ranked remediation queue and a vuln-map of exposed assets to owners
  6. Act: drive patch tickets, deploy Nuclei detections or virtual patches, and verify closure via rescan

📊 Dashboard KPIs

Open KEV countMean time-to-remediateExposed-asset count% assets patchedExploited CVEs tracked
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php