[Vulnerability] Quick Knowledge
概要
A one-page dashboard covering CVSS/EPSS/CISA KEV scoring, exploiting threat actors and malware, ATT&CK techniques, affected software/systems, and related reports. Built for quick vulnerability triage and briefing.
[Vulnerability] Quick Knowledge is a custom OpenCTI dashboard view tailored to the Vulnerability entity type, built to give analysts and stakeholders an at-a-glance understanding of a vulnerability's risk profile and exploitation context, without needing to navigate through multiple tabs.
The layout is organized into four thematic sections:
- Overview: core reference data including basic information (description, first seen active, CWEs, markings), and detailed scoring information (CVSS3/CVSS4 base scores, severities, and vectors, CISA KEV status, EPSS score and percentile), alongside instant counters for threat actors and malware exploiting the vulnerability, related reports, and related software.
- Threat Actors & Malware: ranked visualizations of the top threat actors and top malware exploiting the vulnerability, plus the MITRE ATT&CK techniques (TTPs) associated with its exploitation.
- Softwares: lists of affected software products and affected infrastructures/systems, showing what's exposed to the vulnerability.
- Reports & Intelligence: the latest reports referencing the vulnerability and a breakdown of report sources (authors), giving a sense of reporting coverage and provenance.
This view is designed to be used as a quick-reference briefing tool for vulnerability triage and prioritization. It's ideal for Analysts and Customer-facing teams who need to rapidly assess a vulnerability's severity, exploitability, and threat landscape during demos, investigations, or executive briefings.