Vulnerability Enrichment

Axonius uses a variety of sources to collect information on reported CVEs and other Security Findings, and enriches them with that information.

enrichment_diagram

Below is the list of enrichment sources used by Axonius and their icons. When viewing a Security Finding on the relevant Assets page, the icon of the enrichment from which the vulnerabilities originate is displayed under the Adapter Connection column.

Out-of-the-Box Enrichment Sources

Name and IconIndicates
NVD NVDLogoIndicates Security Findings enriched with data from the NIST NVD database.
EPSS EPSSLogoIndicates software Security Findings enriched with details from the Exploit Prediction Scoring System EPSS from connected adapters.
CISA CISALogoIndicates Security Findings enriched with vulnerabilitiy information from your connected adapters with additional details from the CISA Known Exploited Vulnerabilities (KEV) Catalog. When relevant, the CISA fields and information are available for viewing and querying in the Security Findings and Devices modules. Only CVEs that are part of the CISA KEV Catalog will be enhanced.
MSRC MSRCLogoIndicates software Security Findings enriched with details from MSRC from connected adapters.
EUVDEUVDLogoA platform that offers information on security vulnerabilities from the European Union Vulnerability Database.
OSV (Open Source Vulnerabilities) OSVLogoA database to identify affected open-source packages, ecosystems, severity (when available), and references.

Adapter Enrichments

Configure the following adapters in Axonius to enrich Security Finding assets with data fetched by them.

Name and IconIndicates
VulnCheckVulnCheckLogoIndicates vulnerabilities enriched with data from the VulnCheck enrichment enforcement action.
Intel 471 EnrichmentIntel471LogoProvides cyber threat intelligence to assess, identify, and manage potential risks.
Mandiant EnrichmentMandiantLogoOffers threat intelligence, incident response, and security consulting services to detect and mitigate advanced cyber threats.
BastazoBastazoLogoA security platform that offers comprehensive attack surface management solutions.
Qualys Cloud PlatformQualysLogoQualys Cloud Platform monitors customers' global security and compliance posture using sensors. This adapter connects to the Qualys Cloud Platform service to import information about devices and vulnerabilities.
VulnDB EnrichmentVulnDBLogoVulnDB is a vulnerability intelligence platform that offers detailed information on software, hardware, and third-party library vulnerabilities to support risk assessment and remediation efforts.
Empirical Security EnrichmentEmpiricalSecurityLogoEmpirical Security provides vulnerability intelligence and exploitation activity data to enhance CVE analysis and prioritization.
GreyNoise GreyNoiseLogoGreyNoise collects, analyzes, and filters internet scan activity.