Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Detects vulnerabilities ingested from Google Threat Intelligence that are in the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning CISA has confirmed active exploitation and mandated remediation for federal agencies. Uses the explicit CisaKnownExploited field from the GTIVulnerabilities parser, with Tags-based fallback for coverage.
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | Google Threat Intelligence |
| ID | 650429cd-afc6-41a5-90e7-6e4a85b2335d |
| Severity | High |
| Status | Available |
| Kind | Scheduled |
| Tactics | InitialAccess, Execution, Impact |
| Techniques | T1190, T1203 |
| Required Connectors | GTIVulnerabilitiesConnector |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
GTI_Vulnerabilities_CL |
? | ✓ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Analytic Rules · Back to Google Threat Intelligence