You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<li>Types of CVEs that <abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> works best for</li>
1557
1557
</ul>
1558
1558
</div>
1559
+
<divclass="admonition tip">
1560
+
<pclass="admonition-title"><abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> is only available for published CVEs</p>
1561
+
<p><ahref="https://riskbasedprioritization.github.io/epss/Introduction_to_EPSS/#what-is-epss"><abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> produces probability scores for all known published CVEs</a> based on current exploitation ability, and updates these scores daily.</p>
1562
+
<p>This has the following repercussions:</p>
1563
+
<ol>
1564
+
<li><strong>Timeliness</strong>: It will not be available for vulnerabilities exploited before they have an associated <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> (a process that can sometimes take weeks). <ol>
1565
+
<li><ahref="https://riskbasedprioritization.github.io/risk/Understanding_Risk/?h=zero#zero-days">Zero days don't have a <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> ID</a></li>
1566
+
</ol>
1567
+
</li>
1568
+
<li><strong>Coverage</strong>:<ol>
1569
+
<li>Vulnerabilities without a <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> ID or which are listed on other <ahref="../../risk/Data_Sources/">Other Vulnerability Data Sources</a> will not receive an <abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> score.</li>
1570
+
</ol>
1571
+
</li>
1572
+
</ol>
1573
+
</div>
1559
1574
<h2id="epss-for-your-environment"><abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> for YOUR Environment<aclass="headerlink" href="#epss-for-your-environment" title="Permanent link">¶</a></h2>
1560
1575
<p>The <ahref="https://www.first.org/epss/model"><abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> Model</a> ground truth and validation is based on exploitation observations from
1561
1576
network- or host-layer intrusion detection/prevention systems (IDS/IPS),
Copy file name to clipboardExpand all lines: print_page/index.html
+15Lines changed: 15 additions & 0 deletions
Original file line number
Diff line number
Diff line change
@@ -3392,6 +3392,21 @@ <h2 id="epss-introduction_to_epss-count-of-cves-at-or-above-epss-score">Count of
3392
3392
<li>Types of CVEs that <abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> works best for</li>
3393
3393
</ul>
3394
3394
</div>
3395
+
<divclass="admonition tip">
3396
+
<pclass="admonition-title"><abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> is only available for published CVEs</p>
3397
+
<p><ahref="https://riskbasedprioritization.github.io/epss/Introduction_to_EPSS/#what-is-epss"><abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> produces probability scores for all known published CVEs</a> based on current exploitation ability, and updates these scores daily.</p>
3398
+
<p>This has the following repercussions:</p>
3399
+
<ol>
3400
+
<li><strong>Timeliness</strong>: It will not be available for vulnerabilities exploited before they have an associated <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> (a process that can sometimes take weeks). <ol>
3401
+
<li><ahref="https://riskbasedprioritization.github.io/risk/Understanding_Risk/?h=zero#zero-days">Zero days don't have a <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> ID</a></li>
3402
+
</ol>
3403
+
</li>
3404
+
<li><strong>Coverage</strong>:<ol>
3405
+
<li>Vulnerabilities without a <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> ID or which are listed on other <ahref="#risk-data_sources">Other Vulnerability Data Sources</a> will not receive an <abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> score.</li>
3406
+
</ol>
3407
+
</li>
3408
+
</ol>
3409
+
</div>
3395
3410
<h2id="epss-applying_epss_to_your_environment-epss-for-your-environment"><abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> for YOUR Environment<aclass="headerlink" href="#epss-applying_epss_to_your_environment-epss-for-your-environment" title="Permanent link">¶</a></h2>
3396
3411
<p>The <ahref="https://www.first.org/epss/model"><abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> Model</a> ground truth and validation is based on exploitation observations from
3397
3412
network- or host-layer intrusion detection/prevention systems (IDS/IPS),
0 commit comments