Fields Used in AVS Calculation
Axonius uses multiple fields (AVS Factors) to calculate the final AVS. Some of them are computed by Axonius while others employ AI-powered calculation.
AI-Computed Fields
| UI Field Name | Value / Value Range | Field Impact | Risk Contribution |
|---|---|---|---|
| Configuration Requirement | Common | Effects Common/Default Deployments | Risk-increasing |
| Configuration Requirement | Rare | Effects Specific Deployments | Risk-reducing |
| Is Perimeter Device | True | Targeting Perimeter Management Device | Risk-increasing |
| Is Perimeter Device | False | No Perimeter Security Role | None |
| Prevalence Score | <= 3 | Rarely Used Product In The Wild | Risk-reducing |
| Prevalence Score | 4-7 | Common Product In The Wild | None |
| Prevalence Score | >= 8 | Very Common Product In The Wild | Risk-increasing |
| Is Open Source | True | Effects Open Source Products | Risk-increasing |
| Is Open Source | False | Product Is Privately Owned | Risk-reducing |
Axonius-Computed Fields
| UI Field Name | Value / Value Range | Field Impact | Risk Contribution |
|---|---|---|---|
| Is Zero Day | First Seen \<= 30 And Added To Kev \<= 30 And Exploit = Attacked | Zero Day | Risk-increasing |
| Exploit Maturity | Attacked | Attacked In The Wild | Risk-increasing |
| Exploit Maturity | Proof_Of_Concept | Exploit Code Exists | Risk-increasing |
| Exploit Maturity | Not_Reported | No Exploitation Signal Found | Risk-reducing |
| Exploitation Activity Timeline | \<= 30 | Very Recent Exploitation Activity | Risk-increasing |
| Exploitation Activity Timeline | \<= 180 | New Exploitation Activity | Risk-increasing |
| Exploitation Activity Timeline | \>= 365 | Stale Exploitation Activity | Risk-reducing |
| Exploitation Activity Timeline | < 365 And > 180 | Exploitation Activity Aging | Risk-reducing |
| Vulnerability Disclosure Timeline | \<= 30 | Recently Disclosed Vulnerability | Risk-increasing |
| Vulnerability Disclosure Timeline | \<= 180 | New Vulnerability | None |
| Vulnerability Disclosure Timeline | \<= 1095 | Established Vulnerability | Risk-reducing |
| Vulnerability Disclosure Timeline | > 1095 | Long-Standing Vulnerability | Risk-reducing |
| Attack Vector | Network | Requires Network Access | Risk-increasing |
| Attack Vector | Adjacent | Requires Adjacent Network Access | None |
| Attack Vector | Local | Requires Local Machine Access | Risk-reducing |
| Attack Vector | Physical | Requires Physical Access | Risk-reducing |
| Privileges Required | None | No Auth Required | Risk-increasing |
| Privileges Required | Low | Requires User Authentication | Risk-reducing |
| Privileges Required | High | Requires Admin Authentication | Risk-reducing |
| User Interaction | None | Doesn't Require User Interaction | Risk-increasing |
| User Interaction | Passive / Required / Active | Requires User Interaction | Risk-reducing |
| Product Type | OS | Exploit Targets Operating Systems | Risk-increasing |
| Product Type | Hardware | Exploit Targets Hardware | Risk-increasing |
| Product Type | Application | Exploit Targets Applications | Risk-increasing |
| Product Type | Package | Exploit Targets Packages/Extensions | Risk-increasing |
| Product Count | \>= 100 | Affects Large Product Ecosystem | Risk-increasing |
| Product Count | \>= 10 | Affects Multiple Products | Risk-increasing |
| Product Count | < 10 | Limited Product Scope | None |
| Exploit References | 0 | No Public Exploit References | Risk-reducing |
| Exploit References | < 5 | Very Few Exploit References | Risk-reducing |
| Exploit References | \>= 5 | Multiple Exploit References | Risk-increasing |
| Exploit References | \>= 10 | Extensively Documented Exploit | Risk-increasing |
| EPSS Score | \>= 0.90 | Very High EPSS Score | Risk-increasing |
| EPSS Score | > 0.60 | High EPSS Score | Risk-increasing |
| EPSS Score | \>= 0.1 & \<= 0.6 | Moderate EPSS Score | Risk-reducing |
| EPSS Score | < 0.10 | Low EPSS Score | Risk-reducing |
Updated 1 day ago
