Vulnerability management
Vulnerability management is the continuous process of discovering, prioritizing, remediating, and verifying weaknesses across the fleet. It’s not “run a scanner once”: it’s a cycle that, done well, closes doors before an attacker finds them.
The cycle
Section titled “The cycle”1. INVENTORY you can't protect what you don't know you have (assets, software, services)2. DISCOVER authenticated/unauthenticated scanning + sources (CMDB, SBOM, cloud)3. PRIORITIZE by real risk, not by volume (see below)4. REMEDIATE patch (def-patch), mitigate, or accept with justification5. VERIFY re-scan/validate that the remediation worked6. REPEAT continuous process; track trends (not just a point-in-time snapshot)Scoring and prioritization
Section titled “Scoring and prioritization”CVSS base technical severity (0-10) -> NOT priority on its ownEPSS probability of exploitation in practice (key data for prioritizing)CISA KEV catalog of actively EXPLOITED vulnerabilities -> top priorityContext critical asset? Internet-exposed? compensated by another control?-> priority = severity x exploitability (EPSS/KEV) x exposure x asset criticalityPrioritizing by CVSS alone wastes effort: a 9.8 on an internal, unexposed host matters less than a 7.5 on an exposed KEV.
Nessus / Tenable, Qualys, Rapid7 reference vulnerability scannersOpenVAS/Greenbone open-sourceNuclei (see tool-nuclei) template-based detection, fast for web exposureAuthenticated scanning > unauthenticated: sees real patches/config, not just bannersCloud/containers: Trivy, Grype (see dso-containers) and CSPM posture (see cloud)Common problems
Section titled “Common problems”- "vulnerability fatigue": thousands of findings with no prioritization -> nothing gets fixed- scanner false positives -> validate before opening a thousand tickets- uninventoried assets (shadow IT) -> blind spots the attacker does see- a patch that doesn't deploy or breaks production -> change management (def-patch)Blue Team / operation
Section titled “Blue Team / operation”- Start from a reliable inventory (see System hardening) and regular authenticated scanning.
- Prioritize with EPSS + CISA KEV + business context, not just CVSS.
- Agree remediation SLAs by severity/exposure and measure compliance and trend.
- Close the loop: verify remediation; integrate with patching (Patch management) and risk (Risk management).
Real-world cases
Section titled “Real-world cases”- Equifax (2017): an unpatched Apache Struts (CVE-2017-5638) for months → a 147M-person breach.
- Log4Shell (CVE-2021-44228): the inventory/SBOM decided who could respond fast.
- The CISA KEV catalog exists precisely to prioritize what’s actually being exploited.
Testing checklist
Section titled “Testing checklist”- Reliable asset/software inventory (incl. cloud and containers)
- Authenticated and regular scanning (not just the perimeter)
- Prioritization by EPSS + CISA KEV + context, not just CVSS
- Remediation SLAs by severity/exposure
- False-positive validation before opening tickets
- Post-remediation verification (re-scan)
- Trend and coverage metrics; integration with def-patch