Method
KEV Exposure Triage Tool
Prioritizes review of a known-exploited vulnerability using user-entered exposure, asset criticality and compensating controls.
Field scoring contract
| Field | Type | Role | Direction | Scored |
|---|---|---|---|---|
| CVE or advisory reference | text | context | context | no |
| Known exploitation status | select | risk_driver | higher_is_worse | yes |
| Asset criticality | select | risk_driver | higher_is_worse | yes |
| Internet exposure | select | risk_driver | higher_is_worse | yes |
| Patch availability | select | risk_driver | higher_is_worse | yes |
| Compensating controls | select | risk_driver | higher_is_worse | yes |
| Patchability | select | risk_driver | higher_is_worse | yes |
Limits
- Preliminary output
- Human review required
- Not certification
- Context text is not averaged into numeric scores.
- Outputs require source/evidence review before decisions.