Start with the flaw
Look up a CVE to import its impact and exploit facts. You can review or correct the source data if needed.
Edit imported CVSS details Impact, exploit preconditions, weakness type, and raw vector
Where does it live?
Resolve the affected asset’s security-impact profile. This demo uses an illustrative role catalog; CSPs may instead assign CR/IR/AR directly or use another governed mapping. The reusable profile is capped by the System Context ceiling.
How likely is exploitation?
Use the imported EPSS and KEV facts, or adjust them to explore how likelihood changes the clock.
Can a payload reach it?
Check both delivery paths: directly from the internet, or second-hand through another system.
Second-hand delivery
There is no usable direct path, so check whether a payload can ride in through another system.
Explore what would change it
Apply evidence-backed mitigations to see whether the finding moves to a lower-impact or slower clock.
Method settings Governed thresholds for administrators and model exploration
Defaults follow the High-centered PAIN calibration; sliders are for governed model exploration.