What is KEV-Aware Vulnerability Management Platform?
A CVE scanner discovers known vulnerabilities (CVEs) in software components and ranks them by exploitability. Threatstealth combines authenticated host scans, unauth web-app scans, container image scans, and SAST/SCA repo scans into one queue — then re-orders findings by CISA KEV inclusion, EPSS exploit-probability, and asset criticality so your patch team works on the right thing first.
Why most vuln programs drown in noise
- CVSS measures technical severity; it does not confirm active exploitation or estimate near-term exploitation probability.
- Findings live in 4+ tools — host scanner, container scanner, SAST, SCA
- Patch teams burn cycles on theoretical risks while KEV CVEs sit unfixed
- No clean handoff from scanner finding to ticketed remediation work
A four-step operational model
Discover
Authenticated host scans, unauth web-app scans, container registry scans, and Git repo SAST + SCA — all into one finding inventory.
- Hosts / web / containers / code
- Authenticated + unauth
- Continuous + on-demand
Enrich
Every CVE is enriched with KEV inclusion date, EPSS score, and exploitability hints from threat-intel sources.
- CISA KEV
- EPSS exploit probability
- PoC availability
Prioritise
Default sort = KEV first, then EPSS, then asset criticality — so your top 20 is always the top 20 by real risk.
- KEV-first ordering
- Asset criticality weighting
- Exploit-probability filter
Remediate
One-click ticket creation in Jira, Linear, or ServiceNow with the patch path baked in.
- Jira / Linear / ServiceNow
- Patch evidence on close
- Re-scan to verify
Outcomes for security teams
Reduce noise with evidence-based prioritization
Start with vulnerabilities confirmed as exploited, then apply EPSS, internet exposure, asset criticality and compensating controls to create a remediation queue your team can explain.
Track current CISA KEV deadlines
CISA BOD 26-04 requires US Federal Civilian Executive Branch agencies to monitor KEV updates and remediate within CISA-set timelines. Threatstealth surfaces the current due date for every KEV-tagged finding and escalates overdue items automatically.
Close the loop
Every fix is verified by a re-scan; evidence is retained for SOC 2 CC4.1, ISO 27001 A.8.8, and PCI DSS Requirement 6.3 audit.
Live CISA KEV catalog data
Sources and methodology
CISA KEV data is retrieved from the official CISA JSON feed and refreshed every six hours. Explore the full CISA KEV research dataset →
Direct answers
Is it KEV-aware?+
Yes. Every finding is tagged with CISA KEV inclusion status and the federal remediation due date.
Does it scan containers?+
Yes. Container image scans run against your registry on push and on schedule.
Can it scan our Git repos?+
Yes — see the Repo Scanner module for SAST, secret detection, SBOM, and license posture.
How is prioritisation calculated?+
Default = KEV inclusion → EPSS score → asset criticality → CVSS. The order is configurable per-org.
