Scoring Methodology
ThreatScoreAI® uses a weighted algorithm that combines multiple threat intelligence sources into a single, actionable risk score.
ThreatScore® Formula
CVSS - Base Severity (40%)
The Common Vulnerability Scoring System (CVSS) provides a standardised way to capture the principal characteristics of a vulnerability and produce a numerical score reflecting its severity.
Low
0.1 - 3.9
Medium
4.0 - 6.9
High
7.0 - 8.9
Critical
9.0 - 10.0
EPSS - Exploit Probability (30%)
The Exploit Prediction Scoring System (EPSS) estimates the probability that a vulnerability will be exploited in the wild within the next 30 days. This data-driven approach helps prioritise vulnerabilities that pose the most immediate risk.
CISA KEV - Known Exploitation (20%)
The CISA Known Exploited Vulnerabilities (KEV) catalogue contains vulnerabilities that are being actively exploited in the wild. If a CVE is in the KEV catalogue, it indicates confirmed, real-world exploitation.
Not in KEV
No confirmed exploitation
In KEV
Active exploitation confirmed
MITRE ATT&CK - Tactical Context (10%)
MITRE ATT&CK provides tactical context by mapping CWE identifiers to known adversary techniques. This helps understand how a vulnerability might be used in real-world attacks.
Example Mappings:
Risk Level Classification
The final ThreatScore® is mapped to a risk level that provides clear remediation guidance: