Cyber folk: what are some of your fav, public tools or APIs (doesn't necessarily have to be "free") for getting info about CVEs? opencve? vulnrichment? cvemap? vulncheck? nvd? cvedetails? others?
@hrbrmstr https://vulnerability.circl.lu/ ;-)
https://vulnerability.circl.lu/doc
full open source, open data and open api.
@screaminggoat heh. I kind of LOL'd that the CVE 25th anniversary report had no actual CVEs in it, too. It was a tad hard on the eyes, too.
tbh my go to is a combination of NVD, and searching Google, The Bad Placeβ’, Mastodon, and occasionally Feedly (if you use https://feedly.com/cve/CVE-2021-44228 for example)
@screaminggoat oh @ntkramer made me spend a gagillion $ on Feedly's threat intel feature for the team. It's a big crutch for him ;-)
@screaminggoat @ntkramer oh, you're just getting a tiny bit of what's behind the curtain. it's well worth the $ for us.
@hrbrmstr @ntkramer after a while, all of the CVE ID numbers blend together. When I started mentioning CVEs on Mastodon, I eventually decided that I wanted to see "fast facts" for myself:
Plus all of that information decked out in links. That's how I've been writing out CVEs on Mastodon and I hope others enjoy that presentation.