Exploits

Find exploited vulnerabilities with the CISA KEV and EPSS filters, and read exploitation details in the vulnerability drawer.

Guard has no separate Exploits page. The Vulnerabilities page has two tabs, Vulnerabilities and Signatures. Exploit information appears in the filters and in each vulnerability's drawer.

Find vulnerabilities that are being exploited

  1. Go to Vulnerabilities.
  2. Use the CISA KEV filter to show vulnerabilities on CISA's Known Exploited Vulnerabilities list.
  3. Use the epss range filter to show vulnerabilities by their predicted likelihood of exploitation.

See exploitation details for a vulnerability

  1. Open a vulnerability from the table.
  2. On the Details tab, select Exploitation in the left-hand menu. It shows exploitation activity recorded for this finding, including live agent progress, or Not yet exploited if there is none.
  3. For CVE findings with enrichment data, select Exploitation Activities for the exploitation timeline and the threat actors linked to the CVE, and Risk Score for the CVSS and EPSS details.

If a Hannibal hunt exploited the vulnerability, the evidence appears on the risk. See Emergent-Threat CVE Automation for how Guard hunts newly detected critical CVEs.

Support

If exploit details are missing, contact support@praetorian.com.