Core Engine

Exploit Likelihood Prioritisation

Introduction

Exploit Likelihood Prioritisation re-orders your findings by how likely each vulnerability is to be attacked in the real world, rather than by severity label alone.

Why it's needed

A scan can return hundreds of findings, and ranking by severity alone treats a CVSS 9.8 that nobody has exploited the same as one used in active campaigns today. Engineering teams have a limited remediation budget, so the question to answer is which handful of findings an attacker is actually using.

How TrustDyne works

Every CVE is scored against EPSS, the Exploit Prediction Scoring System published by FIRST.org, which gives the probability of exploitation within the next 30 days. It is also checked against the CISA Known Exploited Vulnerabilities catalogue, a confirmed list of CVEs already being exploited. Findings and outbound alert emails are ordered known-exploited first, then by descending exploit probability. A separate deterministic, severity-weighted risk score summarises the overall exposure of an assessed asset. We checked the scoring against CVE-2021-44228 (Log4Shell), which returned a 99.999% exploit probability and a confirmed-exploited flag.