Vulnerability BI — sidebar hides with the toggle

Attack-Stage Relevance

Which attack stages the published CVSS metrics can speak to — and the six stages this data cannot assess at all.

Mode: Global CVE catalogue
0 CVEs in scope
Global CVE catalogue
Supports investigation
Investigate if present — not detected exposure.

Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.

Data sources, exact rule, and what is unknown

Powered by: public.cves via fetchCves (CVSS vector metrics only)

Rule: Each stage is evaluated from published CVSS metrics and returns pass, fail or unknown: Initial access = AV; Execution = AC and UI; Privilege escalation = PR; Impact = C/I/A. Persistence, defense evasion, credential access, discovery, lateral movement and collection are not modeled.

Not known by this lens:
  • CVE metadata alone is not proof that an end-to-end attack path exists.
  • Persistence, defense evasion, credential access, discovery, lateral movement, collection: Not modeled

Previously called “Kill Chain Lens”. Renamed because the underlying evidence does not support that stronger claim.

Initial access relevant

0

Execution relevant

0

Impact relevant

0

Attack vector missing

0
Not assessed
How this works — definitions, thresholds, and what to doShow

Each stage below is evaluated from published CVSS metrics only and returns pass, fail or not assessed when the metric is absent from the record.

  • Initial access — attack vector (AV).
  • Execution — attack complexity (AC) and user interaction (UI).
  • Privilege requirement — privileges required (PR).
  • Impact — confidentiality, integrity, availability (C, I, A).

Not modeled by this lens: Persistence, Defense evasion, Credential access, Discovery, Lateral movement, Collection. CVE metadata contains nothing that could evaluate them.

Clearing all four assessed stages is not proof that an end-to-end attack path exists in your environment.