Which attack stages the published CVSS metrics can speak to — and the six stages this data cannot assess at all.
Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.
Powered by: public.cves via fetchCves (CVSS vector metrics only)
Rule: Each stage is evaluated from published CVSS metrics and returns pass, fail or unknown: Initial access = AV; Execution = AC and UI; Privilege escalation = PR; Impact = C/I/A. Persistence, defense evasion, credential access, discovery, lateral movement and collection are not modeled.
Previously called “Kill Chain Lens”. Renamed because the underlying evidence does not support that stronger claim.
Each stage below is evaluated from published CVSS metrics only and returns pass, fail or not assessed when the metric is absent from the record.
Not modeled by this lens: Persistence, Defense evasion, Credential access, Discovery, Lateral movement, Collection. CVE metadata contains nothing that could evaluate them.
Clearing all four assessed stages is not proof that an end-to-end attack path exists in your environment.