Research
Our team (formerly of Kenna Security as well as co-creators of the EPSS) invented risk-based vulnerability management. But we believe there's areas of exposure management that haven't even been tapped, and they need to be explored urgently given the monumental challenges facing security teams. We're excited to publish our research (including ongoing benchmarks of our global and local models) and present them here.
Jay Jacobs, Chief Data Scientist
Michael Roytman, CTO
Dr. Benjamin Edwards, Head of Modeling
Jerry Gamblin, Head of Research
Finding New Exploits with A Bespoke Model
“Why do we need another scoring system?” is not the best question to ask. Instead we need to get accustomed to asking about performance. This post walks through an example from our latest improvement to our exploit code classifier.
It’s Not About Making a Scoring System
“Why do we need another scoring system?” is not the best question to ask. Instead we need to get accustomed to asking about performance. This post walks through an example from our latest improvement to our exploit code classifier.
Known Exploited vs Recently Exploited
Past exploitation is not a guarantee of future exploitation. However, recent exploitation is in fact a powerful predictor of future exploitation!
Known (Re-)Exploited Vulnerabilities
Conventional wisdom in cybersecurity tells us that if a vulnerability is known to be exploited that everyone should patch it immediately, but the reality is a lot more nuanced. Known exploited in the past does not guarantee future exploited.