Risk Prioritization

Your queue, in your order.

Sorting a backlog by severity ranks it for somebody who has never seen your deployment. Vulnetix ranks open findings against an ordered rule strategy your organisation owns: malware, four KEV catalogues, weaponized exploits and live sightings, prediction models, vendor impact, and the scores your own analysts set. Drag the rules into the order your risk manager decides, save, and every priority view re-ranks against them. This is Risk-Based Vulnerability Management (RBVM) you actually control, not a fixed vendor score.

Request a Demo

The signals you can rank

A rule is only worth dragging if the data behind it exists for every finding, every day. These are the signals available to a strategy today, with examples of the feeds that supply them.

Evidence

Known malware

OpenSSF Malicious Packages (OSV MAL), OpenSourceMalware, Vulnetix Malscan, VDB malware advisories

The dependency itself is hostile rather than merely vulnerable. The system default ranks this above everything else.

Evidence

CISA, ENISA EU, Vulnetix and VulnCheck KEV

CISA KEV, ENISA EU KEV, Vulnetix KEV, VulnCheck KEV

Four catalogues, four separate rules, so you decide whether an ENISA EU listing carries the weight of a CISA one.

Evidence

Weaponized exploit

Metasploit modules, Nuclei templates, Snort rules, Nmap NSE scripts

Someone has packaged the vulnerability into a tool that runs. No research phase required, just a target list.

Evidence

Active exploitation (sightings)

CrowdSec honeypots, Shadowserver Foundation, CIRCL and MISP sightings

Attack traffic observed against real sensors, with a first-seen date kept on the signal.

Evidence

PoC exploit

Exploit-DB, VulnCheck XDB, GitHub PoCs, 0day.today, HackerOne and Bugcrowd disclosures, Project Zero 0day in the wild

Public proof the vulnerability is reachable in practice.

Prediction

EPSS and Coalition ESS

EPSS (FIRST), Coalition ESS

Two models answering two different questions. EPSS asks whether an exploit will surface publicly in the next 30 days; Coalition ESS asks whether attackers are using it now. Separate rules, so you decide which worries you more.

Impact

CVSS, CWSS, and your own scores

NVD and CNA CVSS, CWSS, Custom CVSS, Custom CWSS

CVSS rates the vulnerability and arrives the same for everyone; CWSS rates the underlying weakness and is built to be tailored to your environment. Both measure impact, so Vulnetix ranks on the higher of the two. Custom CVSS and Custom CWSS are those scales re-scored by your analysts, on their own rules, so you decide whether your scoring outranks the vendor number.

Catch all

All remaining

Ordered oldest first

Everything the rules above did not match. Exactly one of these, always pinned at the bottom.

Those feeds are samples, not the list

Naming a handful of sources per rule keeps the explanation readable. The real inputs run much wider, because prioritisation is only as good as the enrichment sitting behind each finding. The Vulnetix VDB is the largest global collection of vulnerability and patch data: 160+ upstream authorities, aggregated, normalised and cross-referenced, covering vulnerabilities, exploits, patch reality, malware and end-of-life across 47+ ecosystems.

How a strategy works

Every organisation starts on a read-only system default of 23 rules, with exploitation evidence at the top, org-owned scores next, and prediction and vendor impact underneath. Clone it to edit. Each rule is one signal plus an operator: evidence signals match on presence, score signals take a comparison or a range. Drag a rule and its position becomes its priority, 0 being highest, and a finding inherits the tier of the first rule it matches. One rule stays pinned at the bottom, All remaining, which sweeps up whatever the rules above did not catch, oldest first. Once activated, the ranking applies wherever the queue appears: the What to fix first view, the dashboard priority widget, and the findings API.

Read the launch write-up in the Risk Prioritization announcement, see how the exploitation catalogue is built in Vulnetix KEV, or read how the maturity tiers are graded in Exploit intelligence signals.

Request a Demo →