Threat Intel
Path: /threat-intel · Sidebar: Intelligence → Threat Intel
Threat Intel enriches your vulnerabilities with live, real-world exploitation signals so you fix what attackers are actually using.
Signals
- CISA KEV - Known Exploited Vulnerabilities: proven, active exploitation.
- EPSS - Exploit Prediction Scoring System: the probability a CVE will be exploited in the next 30 days.
- CVE enrichment - advisories from NVD, GHSA and OSV.
The page
- Browse incoming intelligence, grouped by source.
- See which of your vulnerabilities match KEV/high-EPSS - these are surfaced as priorities and can trigger notifications when a CVE you have is newly added to KEV.
Configuration
The live feeds (KEV/EPSS/CVE sources) are configured by admins under Threat Intel Feed. SCA's OSV augmentation is described in SCA.
From CVE to action
Threat Intel answers "should I care right now?". A Medium CVSS with a high EPSS or a KEV listing often deserves attention before a higher-CVSS issue with no exploitation in the wild.