Solid guide . One question how do you decide what’s actually exploitable vs just high severity on paper?
Vulnerability Check & Triage Walkthrough
Amara Graham
posted
1 min read
2 Comments
Amara Graham
•
@[Andrey Turkin] CISA does that for me with their KEV (Known Exploited Vulnerabilities) Catalog. These are known to have already been exploited in the wild. I realized after I was using this as a datasource that the AI would probably always evaluate these as a high priority and requiring immediate mitigation. Oh well.
You can also find lists that are "just" CVEs and look really severe, but can't be exploited due to a variety of things. This is where I would leverage the AI tools companies are giving access to their source code and work collaboratively to determine if it's exploitable in that particularly setup/configuration/environment/etc.
Please log in to add a comment.
Please log in to comment on this post.
More Posts
- © 2026 Coder Legion
- Feedback / Bug
- Privacy
- About Us
- Contacts
- Premium Subscription
- Terms of Service
- Refund
- Early Builders
chevron_left
More From Amara Graham
Related Jobs
- Frontend React Developer - TAMPACitigroup Inc · Full time · Tampa, FL
- Senior Full Stack Software Engineer (ControlCheck)Bluesight · Full time · Washington DC
- Frontend React Developer - TAMPACiti · Full time · Tampa, FL
Commenters (This Week)
Next Big Creative
3 comments
ashimov
1 comment
Ktzchen Web3
1 comment
Contribute meaningful comments to climb the leaderboard and earn badges!