🔥 Vulnerability Intelligence (VULNINT)
Weaknesses, Exploitation, and Prioritization
Cyber & Threat
Sources
6
6 no-auth
Mission domains
4
reach
Data points
2
covered
Related INT
3
disciplines
🔌 Sources for Vulnerability Intelligence (6)
| Source | Category | Auth | Format | |
|---|---|---|---|---|
| CISA ICS Advisories ICS/OT vulnerability advisories. | Critical Infrastructure | NONE | xml | home↗ api↗ |
| FIRST EPSS Exploit-probability scoring for CVEs. | VULNINT | NONE | json | home↗ api↗ |
| huntr AI/ML Vulnerabilities Disclosed vulnerabilities in AI/ML OSS. | Emerging Tech | NONE | html | home↗ |
| MITRE ATLAS (AI threats) Adversarial ML threat matrix. | Emerging Tech | NONE | yaml | home↗ api↗ |
| MITRE ATT&CK for ICS ICS adversary techniques matrix. | Critical Infrastructure | NONE | json | home↗ api↗ |
| NIST NVD (ICS vendors) Authoritative vulnerability database. | Critical Infrastructure | NONE | json | home↗ api↗ |
🎯 Mission Domains served
🎫 Data Points
🔍 Lookup
📊 Pre-built Queries · Vulnerability Intelligence
🔄 Live Datasets & APIs (4 key-free · ingestible)
📜 Playbook — Vulnerability Intelligence collection
- Direction — frame the requirement for Vulnerability Intelligence: what decision does this support, by when?
- Collection — collect from the 6 mapped sources (6 free) — filter the catalog by VULNINT; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
🔗 Pivot to related disciplines
✨ Enrichment pathways
🎯 Mission
Vulnerability Intelligence tracks disclosed vulnerabilities, exploit availability, and real-world exposure across the attack surface to prioritize remediation. It answers which CVEs matter right now, whether they are being exploited, and where the organization is exposed.
📡 Collection methods
- CVE/NVD feed ingestion with CVSS, EPSS, and KEV enrichment
- CISA KEV catalog monitoring for confirmed exploited vulnerabilities
- Exploit-availability tracking across Exploit-DB, Metasploit, and public GitHub PoCs
- Attack-surface scanning with Shodan/Censys to map exposed services to CVEs
- Vendor advisory and GHSA monitoring for affected products and packages
- PoC and weaponization chatter monitoring on GitHub and social platforms
- SBOM and dependency analysis (OSV) for transitive exposure
📚 Key sources & datasets
🎫 Data points produced
🔧 Tools & frameworks
- Nuclei
- Greenbone/OpenVAS
- Nmap
- Shodan
- Trivy
- Grype
- EPSS
- ATT&CK
📜 Vulnerability Intelligence Tradecraft
- Collect: continuously ingest NVD, GHSA, and vendor advisories alongside CISA KEV and EPSS updates
- Process: enrich each CVE with CVSS, EPSS probability, KEV status, and exploit-availability flags
- Analyze: correlate CVEs against the asset inventory and Shodan/Censys exposure to compute real risk
- Attribute: link exploited CVEs to the threat actors and malware families weaponizing them
- Disseminate: publish a ranked remediation queue and a vuln-map of exposed assets to owners
- Act: drive patch tickets, deploy Nuclei detections or virtual patches, and verify closure via rescan
📊 Dashboard KPIs
Open KEV countMean time-to-remediateExposed-asset count% assets patchedExploited CVEs tracked
🔍 Pre-built queries
🔗 Cross-discipline pivots
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron