The signals you can rank
A rule is only worth dragging if the data behind it exists for every finding, every day. These are the signals available to a strategy today, with examples of the feeds that supply them.
Known malware
OpenSSF Malicious Packages (OSV MAL), OpenSourceMalware, Vulnetix Malscan, VDB malware advisories
The dependency itself is hostile rather than merely vulnerable. The system default ranks this above everything else.
CISA, ENISA EU, Vulnetix and VulnCheck KEV
CISA KEV, ENISA EU KEV, Vulnetix KEV, VulnCheck KEV
Four catalogues, four separate rules, so you decide whether an ENISA EU listing carries the weight of a CISA one.
Weaponized exploit
Metasploit modules, Nuclei templates, Snort rules, Nmap NSE scripts
Someone has packaged the vulnerability into a tool that runs. No research phase required, just a target list.
Active exploitation (sightings)
CrowdSec honeypots, Shadowserver Foundation, CIRCL and MISP sightings
Attack traffic observed against real sensors, with a first-seen date kept on the signal.
PoC exploit
Exploit-DB, VulnCheck XDB, GitHub PoCs, 0day.today, HackerOne and Bugcrowd disclosures, Project Zero 0day in the wild
Public proof the vulnerability is reachable in practice.
EPSS and Coalition ESS
EPSS (FIRST), Coalition ESS
Two models answering two different questions. EPSS asks whether an exploit will surface publicly in the next 30 days; Coalition ESS asks whether attackers are using it now. Separate rules, so you decide which worries you more.
CVSS, CWSS, and your own scores
NVD and CNA CVSS, CWSS, Custom CVSS, Custom CWSS
CVSS rates the vulnerability and arrives the same for everyone; CWSS rates the underlying weakness and is built to be tailored to your environment. Both measure impact, so Vulnetix ranks on the higher of the two. Custom CVSS and Custom CWSS are those scales re-scored by your analysts, on their own rules, so you decide whether your scoring outranks the vendor number.
All remaining
Ordered oldest first
Everything the rules above did not match. Exactly one of these, always pinned at the bottom.
Those feeds are samples, not the list
Naming a handful of sources per rule keeps the explanation readable. The real inputs run much wider, because prioritisation is only as good as the enrichment sitting behind each finding. The Vulnetix VDB is the largest global collection of vulnerability and patch data: 160+ upstream authorities, aggregated, normalised and cross-referenced, covering vulnerabilities, exploits, patch reality, malware and end-of-life across 47+ ecosystems.
How a strategy works
Every organisation starts on a read-only system default of 23 rules, with exploitation evidence at the top, org-owned scores next, and prediction and vendor impact underneath. Clone it to edit. Each rule is one signal plus an operator: evidence signals match on presence, score signals take a comparison or a range. Drag a rule and its position becomes its priority, 0 being highest, and a finding inherits the tier of the first rule it matches. One rule stays pinned at the bottom, All remaining, which sweeps up whatever the rules above did not catch, oldest first. Once activated, the ranking applies wherever the queue appears: the What to fix first view, the dashboard priority widget, and the findings API.
Read the launch write-up in the Risk Prioritization announcement, see how the exploitation catalogue is built in Vulnetix KEV, or read how the maturity tiers are graded in Exploit intelligence signals.