Vulnerability Enrichment
Axonius uses a variety of sources to collect information on reported CVEs and other Security Findings, and enriches them with that information.

Below is the list of enrichment sources used by Axonius and their icons. When viewing a Security Finding on the relevant Assets page, the icon of the enrichment from which the vulnerabilities originate is displayed under the Adapter Connection column.
See Configuring Enrichment Settings for more information on vulnerability enrichment settings.
Out-of-the-Box Enrichment Sources
| Name and Icon | Description |
|---|---|
| NVD | Indicates Security Findings enriched with data from the NIST NVD database. |
| EPSS | Indicates software Security Findings enriched with details from the Exploit Prediction Scoring System EPSS from connected adapters. |
CISA ![]() | Indicates Security Findings enriched with vulnerability information from your connected adapters with additional details from the CISA Known Exploited Vulnerabilities (KEV) Catalog. When relevant, the CISA fields and information are available for viewing and querying in the Security Findings and Devices modules. Only CVEs that are part of the CISA KEV Catalog will be enhanced. |
MSRC ![]() | Indicates software Security Findings enriched with details from MSRC from connected adapters. |
EUVD![]() | A platform that offers information on security vulnerabilities from the European Union Vulnerability Database. |
CISA Vulnrichment ![]() | A vulnerability enrichment initiative launched by the U.S. Cybersecurity and Infrastructure Security Agency (Cybersecurity and Infrastructure Security Agency) in 2024 to add missing context and prioritization data to CVE records. |
| OSV (Open Source Vulnerabilities) | A database that identifies affected open-source packages, ecosystems, severity (when available), and references. |
| GitHub Advisory Database | A database that adds curated security advisories from GitHub's vulnerability database, including detailed information about affected packages, CVSS scores, EPSS data, and exploit availability. Note: When enabling GitHub Advisory Database in the Enrichment Settings page, you can select which advisories to fetch:
|
MITRE CAPEC (Common Attack Pattern Enumeration and Classification) ![]() | Enriches software vulnerabilities with known attack patterns, including severity, likelihood of exploit, mitigations, and related MITRE ATT&CK techniques. |
Adapter Enrichments
Configure the following adapters in Axonius to enrich Security Finding assets with data fetched by them.
| Name and Icon | Description |
|---|---|
| VulnCheck | Indicates vulnerabilities enriched with data from the VulnCheck enrichment enforcement action. |
Intel 471 Enrichment![]() | Provides cyber threat intelligence to assess, identify, and manage potential risks. |
| Mandiant Enrichment | Offers threat intelligence, incident response, and security consulting services to detect and mitigate advanced cyber threats. |
| Bastazo | A security platform that offers comprehensive attack surface management solutions. |
| Qualys Cloud Platform | Monitors customers' global security and compliance posture using sensors. This adapter connects to the Qualys Cloud Platform service to import information about devices and vulnerabilities. |
| VulnDB Enrichment | A vulnerability intelligence platform that offers detailed information on software, hardware, and third-party library vulnerabilities to support risk assessment and remediation efforts. |
| Empirical Security Enrichment | Provides vulnerability intelligence and exploitation activity data to enhance CVE analysis and prioritization. |
GreyNoise ![]() | Collects, analyzes, and filters internet scan activity. |
| Group-IB Threat Intelligence CVE Enrichment | Provides threat intelligence and vulnerability data from the OSI Vulnerability feed to enhance CVE analysis. |
| Threat Connect | A threat intelligence operations platform that provides ingestion, enrichment, automation, orchestration, and cyber risk quantification in a unified workflow. |
IAVM Enrichment![]() | A DoD process for identifying and managing security vulnerabilities in critical systems, ensuring timely protection through alerts, bulletins, and advisories. |
| Rapid7 Threat Command | An external threat intelligence tool that helps users find and mitigate threats targeting organizations. |
| Recorded Future | Identifies the vulnerabilities that pose an actual risk to an organization, adding context and data to CVE scoring. |
| Google Threat Intelligence Vulnerability Intelligence | A security intelligence service that provides vulnerability data, exploitation context, and threat insights to support risk assessment and remediation workflows. |
| Kenna Security Platform (Kenna VI Plus) | A vulnerability assessment solution that provides risk scoring, prioritization, and benchmarking. |
| Tenable Vulnerability Management | Automatically discovers and assesses a customer's environment for vulnerabilities, misconfigurations, and other cybersecurity issues. |
Updated 13 days ago
Did this page help you?








