Skip to main content

Threat Intel Feed (Configuration)

Path: /admin/threat-intel · Sidebar: Administration → Threat Intel Feed

The admin counterpart to the Threat Intel page: configure the live intelligence sources that enrich your vulnerabilities.

Sources

  • CISA KEV - Known Exploited Vulnerabilities.
  • EPSS - exploitation-probability scores.
  • NVD / GHSA / OSV - CVE advisory data.

What you configure

  • Enable/disable each source and set its refresh cadence.
  • Review last-sync status and any sync errors.
  • Control egress - in air-gapped deployments, disable outbound feeds and rely on the bundled data (see also the SCA OSV feed).

Why it matters

Fresh feeds are what make KEV/EPSS-driven prioritisation and KEV-match notifications accurate. Stale feeds mean you might miss that a CVE you have was just added to KEV.

Match cadence to risk tolerance

A daily KEV/EPSS refresh is a sensible default. Increase frequency if you operate high-risk, internet-facing systems where hours matter.