Intelligence-Ranked Findings

KEV + EPSS Threat Intel

CVSS tells you how bad a vulnerability could be. Threat intelligence tells you whether anyone is actually exploiting it. The Immortal Defender fuses both into a single risk score, so your report reads in the order attackers would strike.

1

CISA KEV

Known Exploited Vulnerabilities

The US Cybersecurity and Infrastructure Security Agency maintains the authoritative catalog of vulnerabilities confirmed to be exploited in the wild. A KEV match means attackers are using this flaw right now — it jumps the queue no matter its CVSS score.

Confirmed in-the-wild exploitationDaily-refreshed catalogAutomatic P1 escalationRisk multiplier applied
2

FIRST EPSS

Exploit Prediction Scoring System

The Forum of Incident Response and Security Teams publishes a daily probability that each CVE will be exploited in the next 30 days. EPSS separates the 5% of vulnerabilities attackers actually weaponize from the 95% they ignore.

30-day exploit probabilityDaily model updatesBatch enrichmentProbability-weighted risk

The P1–P5 Ladder

P1
Act now

KEV-listed or critical severity with high exploit probability — actively dangerous.

P2
This week

High severity with meaningful exploit likelihood.

P3
This sprint

Moderate severity or elevated probability — schedule it.

P4
Backlog

Low residual risk after intel weighting.

P5
Awareness

Informational; negligible exploitation signal.

Fix What Attackers Use First

KEV-first, probability-weighted reporting ships in every fortress.