Skip to content
Threat intelligence

Context tells you how dangerous a vulnerability is to your organization

Threat intelligence is only useful when it lands on your assets, your exposure and your business context. AegisVMP correlates the outside world with the inside one.

Corroborated signals

Evidence, not isolated alerts

A single source can suggest. Independent sources agreeing on the same asset is a stronger basis for action.

Vulnerability dataThe finding exists on a known asset.
Threat intelligenceThe issue carries external threat context.
Security telemetryRelated activity was observed in the environment.

Corroborated signal

One observation is a data point. Several agreeing observations are evidence.

When vulnerability data, threat intelligence and security telemetry point at the same asset, confidence rises and the finding moves up the queue for a reason a team can explain.

  • Independent sources agree
  • Confidence is stated, not implied
  • The reasoning stays attached to the finding
AegisVMP security signals view correlated with vulnerability data
Security signal analysis — illustrative product view
Contextual risk

Severity describes the flaw. Context describes the danger.

The same vulnerability can be an emergency on one asset and a routine item on another. Contextual risk scoring makes that difference explicit.

Severity alone

One number, no context

A severity rating describes the vulnerability. It does not describe your organization.

  • Finding AHigh
  • Finding BHigh
  • Finding CHigh

Three findings look identical, so the queue offers no guidance.

Contextual risk

Severity plus organization context

Exposure, asset criticality, threat context and business meaning separate the same three findings.

  • Finding ACritical
  • Finding BModerate
  • Finding CLow

Context tells you how dangerous a vulnerability is to your organization.

Contributing factors

What goes into a score

  • Vulnerability severity

    The technical severity of the underlying issue.

  • Threat intelligence

    Threat context associated with the vulnerability.

  • Exploitability signals

    Indicators relating to likelihood of exploitation.

  • Asset criticality

    How important the affected asset is to the organization.

  • Exposure

    How reachable or accessible the affected system may be.

  • Business context

    The organizational meaning of the affected system.

Scores are explainable: every factor that moved a finding up or down stays visible.

Exposure

Reachability changes everything

represents how reachable or accessible an affected system may be. The same vulnerability carries a different meaning on an internet-reachable system than on an isolated one.

  • Internet reachablerelative weight
  • Partner network reachablerelative weight
  • Internal onlyrelative weight
  • Isolated / segmentedrelative weight
AegisVMP exposure analysis view showing reachability of affected systems
Exposure analysis — illustrative product view
Attack path intelligence

See the route, not just the rungs

Relationships between systems and vulnerabilities are represented as paths, showing how progression toward important assets could occur.

Internet-facing serviceWeb tier hostShared service accountApplication serverInternal admin hostBusiness-critical asset
Entry point Intermediate system Business-critical assetIllustrative representation
AegisVMP attack graph view showing relationships between systems and vulnerabilities
Attack graph — illustrative product view
Plain language

The vocabulary, defined

Shared definitions so security, engineering and leadership discuss the same concepts the same way.

CVSS
Measures the technical severity of a vulnerability.
EPSS
Estimates the probability that a vulnerability will be exploited.
CISA KEV
A catalog of vulnerabilities known to have been actively exploited.
Exposure
Represents how reachable or accessible an affected system may be.
Attack Path
A sequence of reachable systems or vulnerabilities that may enable progression toward a target.
Contextual Risk
Risk calculated using vulnerability, threat, asset, exposure and business context.

Bring context to your own findings

Request a walkthrough of AegisVMP and see how unified intelligence changes what your team works on first.