Vulnerability EPSS Score Update
Overview
Automate the refresh of EPSS scores for your priority vulnerabilities, ensuring your tracked CVEs are always up to date.
Overview
This playbook automates the refresh of EPSS scores for a targeted set of vulnerabilities. It focuses exclusively on priority vulnerabilities, those actively tracked and requiring regular assessment to determine whether action is needed, defined by a status. It is designed to run on a scheduled basis (daily by default) and ensures that EPSS scores remain up to date to support timely and informed decision-making.
Dependencies
- FIRST EPSS enrichment connector must be deployed and available on the platform
- Vulnerabilities must be tagged with the appropriate priority status (e.g. Attend) which needs to be set as the filtering criteria in the playbook trigger
How to use it
- Import the playbook into your OpenCTI platform
- Review and adjust the schedule of the first component to match your desired refresh frequency (default: daily)
- Verify that the filter condition on the first component correctly targets your priority vulnerabilities based on their status (e.g. Attend) or other criteria (e.g. label)
- Ensure the FIRST EPSS connector is active and usable on the platform and set the configuration of the 'Run First EPSS Connector' component.
- Activate the playbook
Expected outcome
Once active, the playbook will automatically trigger EPSS score updates for all expected vulnerabilities on the defined schedule. You should see updated EPSS scores reflected on the relevant vulnerability entities in the platform after each execution cycle.