Skip to content

Vulnerability Management

Package and artifact findings can be enriched with asset criticality, CVSS, exploitability, active-exploitation/KEV state, exposure, ownership, and SLA dates. The enterprise repository stores the normalized record and preserves its source evidence.

secopsai enterprise prioritize-vulnerability --input vulnerability.json --json

The prioritizer is a routing aid, not a replacement for analyst review. Fix verification, ticket creation, exceptions, and risk acceptance remain audited workflow actions.