Skip to content

Add Exploit Prediction Scoring System (EPSS) scores #850

Description

@pombredanne

See https://www.first.org/epss/ ... this is an interesting CVSS alternative scoring system.
For data, The fisrt link https://www.first.org/epss/data_stats links to https://epss.cyentia.com/ and https://epss.cyentia.com/epss_scores-current.csv.gz

Data license is per https://www.first.org/epss/#Usage-Agreement

Usage Agreement

EPSS is an emerging standard developed by a volunteer group of researchers, practitioners, academics and government personnel. We grant the use of EPSS scores freely to the public, subject to the conditions below. We reserve the right to update the model and these webpages periodically, as necessary, though we will make every attempt to provide sufficient notice to users in the event of material changes. While membership in the EPSS SIG is not required to use or implement EPSS, however, we ask that if you are using EPSS, that you provide appropriate attribution where possible. EPSS can be cited either from this website (e.g. "See EPSS at https://www.first.org/epss), or as: Jay Jacobs, Sasha Romanosky, Benjamin Edwards, Michael Roytman, Idris Adjerid, (2021), Exploit Prediction Scoring System, Digital Threats Research and Practice, 2(3)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Core modelsData collectionriskevaluate severity, exploitability, and context factors to determine a vulnerability risk score

Type

No type

Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions