Skip to main content
Threatstealth
Login
// CVE.SCANNER

KEV-aware vulnerability management platform

Continuous CVE detection across hosts, web apps, containers, and source code — ranked by CISA KEV catalogue and EPSS exploit-probability.

Reviewed by Threatstealth Security Architects·Aligned to SOC 2 · ISO 27001 · NIST CSF · PCI DSS V 4.0.1
// DEFINITION

What is KEV-Aware Vulnerability Management Platform?

A CVE scanner discovers known vulnerabilities (CVEs) in software components and ranks them by exploitability. Threatstealth combines authenticated host scans, unauth web-app scans, container image scans, and SAST/SCA repo scans into one queue — then re-orders findings by CISA KEV inclusion, EPSS exploit-probability, and asset criticality so your patch team works on the right thing first.

// THE.PROBLEM

Why most vuln programs drown in noise

  • CVSS measures technical severity; it does not confirm active exploitation or estimate near-term exploitation probability.
  • Findings live in 4+ tools — host scanner, container scanner, SAST, SCA
  • Patch teams burn cycles on theoretical risks while KEV CVEs sit unfixed
  • No clean handoff from scanner finding to ticketed remediation work
// HOW.IT.WORKS

A four-step operational model

1

Discover

Authenticated host scans, unauth web-app scans, container registry scans, and Git repo SAST + SCA — all into one finding inventory.

  • Hosts / web / containers / code
  • Authenticated + unauth
  • Continuous + on-demand
2

Enrich

Every CVE is enriched with KEV inclusion date, EPSS score, and exploitability hints from threat-intel sources.

  • CISA KEV
  • EPSS exploit probability
  • PoC availability
3

Prioritise

Default sort = KEV first, then EPSS, then asset criticality — so your top 20 is always the top 20 by real risk.

  • KEV-first ordering
  • Asset criticality weighting
  • Exploit-probability filter
4

Remediate

One-click ticket creation in Jira, Linear, or ServiceNow with the patch path baked in.

  • Jira / Linear / ServiceNow
  • Patch evidence on close
  • Re-scan to verify
KEV
First-class prioritisation
EPSS
Exploit-probability scored
4 surfaces
Hosts · web · containers · code
Re-scan
Auto-verify on patch
// WHY.IT.MATTERS

Outcomes for security teams

Reduce noise with evidence-based prioritization

Start with vulnerabilities confirmed as exploited, then apply EPSS, internet exposure, asset criticality and compensating controls to create a remediation queue your team can explain.

Track current CISA KEV deadlines

CISA BOD 26-04 requires US Federal Civilian Executive Branch agencies to monitor KEV updates and remediate within CISA-set timelines. Threatstealth surfaces the current due date for every KEV-tagged finding and escalates overdue items automatically.

Close the loop

Every fix is verified by a re-scan; evidence is retained for SOC 2 CC4.1, ISO 27001 A.8.8, and PCI DSS Requirement 6.3 audit.

// KEV.RESEARCH.DATA

Live CISA KEV catalog data

// SOURCES.AND.METHODOLOGY

Sources and methodology

CISA KEV data is retrieved from the official CISA JSON feed and refreshed every six hours. Explore the full CISA KEV research dataset →

CISA Known Exploited Vulnerabilities Catalog
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
// FAQ

Direct answers

Is it KEV-aware?+

Yes. Every finding is tagged with CISA KEV inclusion status and the federal remediation due date.

Does it scan containers?+

Yes. Container image scans run against your registry on push and on schedule.

Can it scan our Git repos?+

Yes — see the Repo Scanner module for SAST, secret detection, SBOM, and license posture.

How is prioritisation calculated?+

Default = KEV inclusion → EPSS score → asset criticality → CVSS. The order is configurable per-org.

Closed · Expert Access

Ready to see it in your environment?

Request a private security demo from the Threatstealth team.