Intelligence by CVE Security

Three named datasets from CVE Security arrive with the daily database download and are matched against your findings on your machine.

  • Early warning, based on evidence KEV Watch A nightly list of vulnerabilities with credible exploitation reports that are not yet in the CISA KEV catalog. Not affiliated with or endorsed by CISA.
  • Documented KCV, Known Chained Vulnerabilities A catalog of vulnerabilities documented as working together in an attack path, with the source cited for each chain.
  • Inferred, never "known" KCV Watch Analysis that flags vulnerabilities likely to chain, by matching what one gives an attacker to what another requires. Candidates to research, never known attacks.

Exploitation evidence

Exploitation reports in KEV Watch come from trackers including:

The complete source list, with each source's required attribution wording, will be added here before launch.

Vulnerability records and scoring

The full list of feeds behind CVE Security is published on its sources page.

Local model

CASSI ships with IBM Granite, an openly licensed model that runs on your own hardware.

Trademarks and non-affiliation

CVE is a registered trademark of The MITRE Corporation. KEV is the Known Exploited Vulnerabilities catalog published by CISA. This site is not endorsed by MITRE, NIST or CISA. KEV Watch, KCV and KCV Watch are trademarks and service marks of InfoBakery LLC and are not affiliated with or endorsed by CISA. Other product names are trademarks of their respective owners, and their use here does not imply affiliation or endorsement.