Research

Our team (formerly of Kenna Security as well as co-creators of the EPSS) invented risk-based vulnerability management. But we believe there's areas of exposure management that haven't even been tapped, and they need to be explored urgently given the monumental challenges facing security teams. We're excited to publish our research (including ongoing benchmarks of our global and local models) and present them here.

Jay Jacobs, Chief Data Scientist

View Research

Michael Roytman, CTO

View Research

Dr. Benjamin Edwards, Head of Modeling

View Research

Jerry Gamblin, Head of Research

View Research

Jay Jacobs Jay Jacobs

Finding New Exploits with A Bespoke Model

“Why do we need another scoring system?” is not the best question to ask. Instead we need to get accustomed to asking about performance. This post walks through an example from our latest improvement to our exploit code classifier.

Read More
Jay Jacobs Jay Jacobs

It’s Not About Making a Scoring System

“Why do we need another scoring system?” is not the best question to ask. Instead we need to get accustomed to asking about performance. This post walks through an example from our latest improvement to our exploit code classifier.

Read More
Jay Jacobs Jay Jacobs

Known (Re-)Exploited Vulnerabilities

Conventional wisdom in cybersecurity tells us that if a vulnerability is known to be exploited that everyone should patch it immediately, but the reality is a lot more nuanced. Known exploited in the past does not guarantee future exploited.

Read More