Threat Intelligence

ThreatLens

A CVE triage service that pre-ranks vulnerabilities by what is actually exploitable against your assets.

ThreatLens, application interface
Interface / ThreatLens Live demo
01 / The problem

The challenge.

Thousands of CVEs are published every month. Teams without a triage system patch alphabetically, or not at all, and waste effort on vulnerabilities nobody can reach.

02 / The system

The approach.

A FastAPI service that correlates NVD CVE data with exploit availability, asset exposure and MITRE ATT&CK techniques, producing one composite risk score per vulnerability.

03 / Under the surface

Engineering decisions.

  1. Pulls and normalises live CVE data from the NVD API.

  2. Composite score blends exploit availability, asset exposure and mapped ATT&CK techniques.

  3. Typed request and response models with Pydantic for a clean, documented API.

04 / What came out of it

The outcome.

A pre-ranked patch queue. The vulnerabilities that are actually exploitable against assets you actually run rise to the top, so triage time goes to the things that matter.