Transparent Scoring

Scoring Methodology

ThreatScoreAI® uses a weighted algorithm that combines multiple threat intelligence sources into a single, actionable risk score.

ThreatScore® Formula

ThreatScore = (CVSS × 0.40) + (EPSS × 0.30) + (KEV × 0.20) + (MITRE × 0.10)

CVSS - Base Severity (40%)

The Common Vulnerability Scoring System (CVSS) provides a standardised way to capture the principal characteristics of a vulnerability and produce a numerical score reflecting its severity.

Low

0.1 - 3.9

Medium

4.0 - 6.9

High

7.0 - 8.9

Critical

9.0 - 10.0

EPSS - Exploit Probability (30%)

The Exploit Prediction Scoring System (EPSS) estimates the probability that a vulnerability will be exploited in the wild within the next 30 days. This data-driven approach helps prioritise vulnerabilities that pose the most immediate risk.

Exploitation Probability0.0 - 1.0
Low RiskHigh Risk

CISA KEV - Known Exploitation (20%)

The CISA Known Exploited Vulnerabilities (KEV) catalogue contains vulnerabilities that are being actively exploited in the wild. If a CVE is in the KEV catalogue, it indicates confirmed, real-world exploitation.

Not in KEV

No confirmed exploitation

In KEV

Active exploitation confirmed

MITRE ATT&CK - Tactical Context (10%)

MITRE ATT&CK provides tactical context by mapping CWE identifiers to known adversary techniques. This helps understand how a vulnerability might be used in real-world attacks.

Example Mappings:

CWE-78→ T1059 (Command Execution)
CWE-89→ T1190 (Exploit Public-Facing App)
CWE-287→ T1078 (Valid Accounts)

Risk Level Classification

The final ThreatScore® is mapped to a risk level that provides clear remediation guidance:

CriticalScore 80-100
Patch immediately
HighScore 60-79
Patch within 7 days
MediumScore 40-59
Patch within 30 days
LowScore 0-39
Schedule for next cycle