Vulnerability Enrichment

Axonius uses a variety of sources to collect information on reported CVEs and other Security Findings, and enriches them with that information.

enrichment_diagram

Below is the list of enrichment sources used by Axonius and their icons. When viewing a Security Finding on the relevant Assets page, the icon of the enrichment from which the vulnerabilities originate is displayed under the Adapter Connection column.

See Configuring Enrichment Settings for more information on vulnerability enrichment settings.

Out-of-the-Box Enrichment Sources

Name and IconDescription
NVD NVDLogoIndicates Security Findings enriched with data from the NIST NVD database.
EPSS EPSSLogoIndicates software Security Findings enriched with details from the Exploit Prediction Scoring System EPSS from connected adapters.
CISA CISALogoIndicates Security Findings enriched with vulnerability information from your connected adapters with additional details from the CISA Known Exploited Vulnerabilities (KEV) Catalog. When relevant, the CISA fields and information are available for viewing and querying in the Security Findings and Devices modules. Only CVEs that are part of the CISA KEV Catalog will be enhanced.
MSRC MSRCLogoIndicates software Security Findings enriched with details from MSRC from connected adapters.
EUVDEUVDLogoA platform that offers information on security vulnerabilities from the European Union Vulnerability Database.
CISA Vulnrichment CISA Vulnrichment logoA vulnerability enrichment initiative launched by the U.S. Cybersecurity and Infrastructure Security Agency (Cybersecurity and Infrastructure Security Agency) in 2024 to add missing context and prioritization data to CVE records.
OSV (Open Source Vulnerabilities) OSVLogoA database that identifies affected open-source packages, ecosystems, severity (when available), and references.
GitHub Advisory Database GitHubAdvisory logoA database that adds curated security advisories from GitHub's vulnerability database, including detailed information about affected packages, CVSS scores, EPSS data, and exploit availability.
Note: When enabling GitHub Advisory Database in the Enrichment Settings page, you can select which advisories to fetch:
  • Fetch GitHub Reviewed Advisories - Fetch curated advisories (recommended)
  • Fetch GitHub Unreviewed Advisories - Fetch community-contributed advisories
MITRE CAPEC (Common Attack Pattern Enumeration and Classification) GitHubAdvisory logoEnriches software vulnerabilities with known attack patterns, including severity, likelihood of exploit, mitigations, and related MITRE ATT&CK techniques.

Adapter Enrichments

Configure the following adapters in Axonius to enrich Security Finding assets with data fetched by them.

Name and IconDescription
VulnCheckVulnCheckLogoIndicates vulnerabilities enriched with data from the VulnCheck enrichment enforcement action.
Intel 471 EnrichmentIntel471LogoProvides cyber threat intelligence to assess, identify, and manage potential risks.
Mandiant EnrichmentMandiantLogoOffers threat intelligence, incident response, and security consulting services to detect and mitigate advanced cyber threats.
BastazoBastazoLogoA security platform that offers comprehensive attack surface management solutions.
Qualys Cloud PlatformQualysLogoMonitors customers' global security and compliance posture using sensors. This adapter connects to the Qualys Cloud Platform service to import information about devices and vulnerabilities.
VulnDB EnrichmentVulnDBLogoA vulnerability intelligence platform that offers detailed information on software, hardware, and third-party library vulnerabilities to support risk assessment and remediation efforts.
Empirical Security EnrichmentEmpiricalSecurityLogoProvides vulnerability intelligence and exploitation activity data to enhance CVE analysis and prioritization.
GreyNoise GreyNoiseLogoCollects, analyzes, and filters internet scan activity.
Group-IB Threat Intelligence CVE Enrichment GroupIBLogoProvides threat intelligence and vulnerability data from the OSI Vulnerability feed to enhance CVE analysis.
Threat Connect ThreatConnectLogoA threat intelligence operations platform that provides ingestion, enrichment, automation, orchestration, and cyber risk quantification in a unified workflow.
IAVM Enrichment
IAVM logo
A DoD process for identifying and managing security vulnerabilities in critical systems, ensuring timely protection through alerts, bulletins, and advisories.
Rapid7 Threat Command Rapid7ThreatCommand logoAn external threat intelligence tool that helps users find and mitigate threats targeting organizations.
Recorded Future RecordedFuture logoIdentifies the vulnerabilities that pose an actual risk to an organization, adding context and data to CVE scoring.
Google Threat Intelligence Vulnerability Intelligence Kenna logoA security intelligence service that provides vulnerability data, exploitation context, and threat insights to support risk assessment and remediation workflows.
Kenna Security Platform (Kenna VI Plus) Kenna logoA vulnerability assessment solution that provides risk scoring, prioritization, and benchmarking.
Tenable Vulnerability Management Kenna logoAutomatically discovers and assesses a customer's environment for vulnerabilities, misconfigurations, and other cybersecurity issues.

Did this page help you?