Conversation

boB Rudis ๐Ÿ‡บ๐Ÿ‡ฆ

Cyber folk: what are some of your fav, public tools or APIs (doesn't necessarily have to be "free") for getting info about CVEs? opencve? vulnrichment? cvemap? vulncheck? nvd? cvedetails? others?

2
0
0

@hrbrmstr ngl I forgot cvedetails. I want to like CVE.org but it lacks an obvious "This CVE is in the KEV Catalog" cc: @todb like NVD has with a "date added" column

3
0
0

@screaminggoat heh. I kind of LOL'd that the CVE 25th anniversary report had no actual CVEs in it, too. It was a tad hard on the eyes, too.

1
0
0

@hrbrmstr

tbh my go to is a combination of NVD, and searching Google, The Bad Placeโ„ข, Mastodon, and occasionally Feedly (if you use https://feedly.com/cve/CVE-2021-44228 for example)

1
0
0
@screaminggoat @hrbrmstr @todb I think while obviously incomplete, @attackerkb is great, and it includes info about active exploitation too. Also cvedetails, yes.
0
0
4

@screaminggoat oh @ntkramer made me spend a gagillion $ on Feedly's threat intel feature for the team. It's a big crutch for him ;-)

1
0
0

@hrbrmstr @ntkramer tfw when people pay a subscription on website that I search using a free account ๐Ÿ˜

1
0
0

@screaminggoat @ntkramer oh, you're just getting a tiny bit of what's behind the curtain. it's well worth the $ for us.

1
0
0

@hrbrmstr @ntkramer after a while, all of the CVE ID numbers blend together. When I started mentioning CVEs on Mastodon, I eventually decided that I wanted to see "fast facts" for myself:

  • the CVE with a link to a resource like CVE.org or NVD
  • the CVSS (and version) score
  • when the CVE ID# was first publicly known/announced
  • when it was actively exploited/added to the KEV Catalog
  • the official description for the vulnerability to include the vendor/software and possibly CWE

Plus all of that information decked out in links. That's how I've been writing out CVEs on Mastodon and I hope others enjoy that presentation.

0
0
0

@screaminggoat @hrbrmstr Security Scorecard has been a very capable custodian for CVEDetails.

I dream of an ADP (that gets its own JSON bucket in the cve.org feed) and all they do is manage media and research references - and archives them along the way to defend against C&Ds/defunding/mergers.

Software archeology will be important. Wasnโ€™t that a thing in the Culture series? Or am I thinking of Verner Vingeโ€™s series?

0
0
0