Skip to main content

Threat Intel

Path: /threat-intel · Sidebar: Intelligence → Threat Intel

Threat Intel enriches your vulnerabilities with live, real-world exploitation signals so you fix what attackers are actually using.

Signals

  • CISA KEV - Known Exploited Vulnerabilities: proven, active exploitation.
  • EPSS - Exploit Prediction Scoring System: the probability a CVE will be exploited in the next 30 days.
  • CVE enrichment - advisories from NVD, GHSA and OSV.

The page

  • Browse incoming intelligence, grouped by source.
  • See which of your vulnerabilities match KEV/high-EPSS - these are surfaced as priorities and can trigger notifications when a CVE you have is newly added to KEV.

Configuration

The live feeds (KEV/EPSS/CVE sources) are configured by admins under Threat Intel Feed. SCA's OSV augmentation is described in SCA.

From CVE to action

Threat Intel answers "should I care right now?". A Medium CVSS with a high EPSS or a KEV listing often deserves attention before a higher-CVSS issue with no exploitation in the wild.