Skip to content

Feature: Add CISA KEV and EPSS prioritization signals #300

Description

@JustNZ

Release

Release 1 — Living CVE intelligence

Goal

Help teams prioritize actively exploited and likely-to-be-exploited vulnerabilities without introducing an opaque proprietary risk score.

Scope

  • Import CISA Known Exploited Vulnerabilities data with due date, ransomware flag, and remediation guidance.
  • Import daily FIRST EPSS probability and percentile data.
  • Display CVSS, KEV, EPSS, fixability, and asset context as separate factors.
  • Add filters and organization policy conditions for KEV and EPSS thresholds.
  • Attribute each value to its source and publication date.

References:

Acceptance criteria

  • KEV additions update current posture and can trigger policy/notification events.
  • EPSS refreshes preserve historical values needed for audit.
  • UI copy explains that EPSS is a threat signal, not a complete risk score.
  • Organization policies can use either EPSS probability or percentile.
  • Missing or stale data is distinguishable from a low score.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions