Demo environment

The real interface, in your browser

This is the shipping desktop app, rebuilt to click through on the web. Same layout, same modules, same twelve-layer TRIS ranking. Every module in the sidebar opens, twenty-two of them, down to the CVE detail page where each scoring layer shows its own arithmetic. Nothing is installed and no data leaves your machine, because there is no data: every finding on screen is demo data.

22 modules 12 TRIS layers No install No card

Unlock the demo

Enter your email and we send you an unlock link. One click opens every module in the sidebar, including the CVE detail page, the campaign replay and the defense map. We send you the release notes when the product ships something worth reading, and nothing else.

That did not go through. Try again, or email hello@cveasyai.com and we will send you a link.

Check your inbox. We sent an unlock link to . It works for 24 hours and opens the demo right here.

Nothing arrived, or wrong address?

We do not sell or share the list. Unsubscribe from any email. See the privacy policy.

CVEasy AI · Risk Posture Overview LIVE DEMO
CVEasyAILOCAL FIRST CTEM
Search…⌘K
Discover
Offensive Testing
Findings
Remediate
Operate
Integrate
Manage
CVEasy AI
Search CVEs, assets, findings, actions…⌘K DEMO DATA Demo Workspace
Command Center· live · 12s ago
Risk Posture Overview

You have 1,186 critical across 1,284 assets. TRIS ranks them below. Act on the top first.

Open TRIS Board TriageBrowse CVEs
Your posture18,942 findings across 1,284 canonical assets
Assets trackedInventory1,284Canonical · deduped Open findings6% fixed18,9421,204 remediated Critical↑ Act now1,1866% of findings HighCVSS 7 to 99,43050% of findings Avg TRISAvg across open34.8of 95 · 12 layers Actors targeting48 tracked18manufacturing sector
Platform intelLocal database · last refresh just now 361,000+CVEs indexed 1,602KEV tracked 48Actors 12TRIS layers Reference →
CRITICALAct within 72h1,1866% of 18942 HIGHWithin 2 weeks9,43050% of 18942 MEDIUMThis quarter6,82036% of 18942 LOWWithin 180 days1,2046% of 18942 MONITORAccept risk3022% of 18942

Priority Queue

Ranked by TRIS · 12 layers
View board →
92 CVE-2024-38077✓ BAS VALIDATEDopen detail →48 assets · dc01.corp.local · 10.20.4.11 CVSS 9.8 TRIS 92.4
88 CVE-2025-02823 assets · vpn-edge-01 · 10.20.0.4 CVSS 9.0 TRIS 88.1
76 CVE-2021-26855HAFNIUM12 assets · exch-01.corp.local CVSS 9.8 TRIS 76.2
71 CVE-2024-41110✓ BAS BLOCKED31 assets · build-runner-03 CVSS 9.9 TRIS 70.8
68 CVE-2023-343622 assets · xfer-01.corp.local CVSS 9.8 TRIS 68.4
57 CVE-2022-229654 assets · app-tomcat-04 · 10.20.8.14 CVSS 9.8 TRIS 57.3
49 CVE-2023-4863✓ BAS BLOCKED64 assets · workstation fleet CVSS 8.8 TRIS 48.9
38 CVE-2024-638722 assets · internal-jump-02 CVSS 8.1 TRIS 38.4

Top Remediations

Fix these first
CVE-2024-38077TRIS 92 · 48 assets CVE-2021-26855TRIS 76 · 12 assetsHAFNIUM CVE-2024-41110TRIS 71 · 31 assets

Active Campaigns

2 targeting you
HAFNIUMstate-sponsored · uses CVE-2021-26855 Lazarus Groupstate-sponsored · uses CVE-2021-44228

Live Activity

Integrations →
CONFIRMED_EXPLOITABLECVE-2024-38077
KEV-addedCVE-2025-0282
Proof-of-Fix signedCVE-2024-6387
Report generatedboard-quarterly
TRIS Sprint Board Triage Queue Run BAS Scan Import Scan Generate Report
CVE Triage Queue
Operations

Add CVEs to track. Move them through states as you assess, assign, and resolve them.

16 active · 3 resolvedExport CSVRefresh
New3
Triaged4
Assigned6
Mitigating3
Resolved3
Add CVE to triage queue. Enter a CVE ID (e.g. CVE-2024-1234)Add to Queue
AI Auto-TriageLearned 12 patterns, generated 8 suggestions ▾
New3
CVE-2024-21762CRITICAL 9.8

FortiOS SSL VPN out-of-bounds write

KEVOverdue 8/8/2026
CVE-2023-48795MEDIUM 5.9

SSH transport prefix truncation, Terrapin

CVE-2023-4863HIGH 8.8

libwebp heap buffer overflow in WebP decode

KEV
Triaged4
CVE-2024-41110CRITICAL 9.9

Docker Engine authorization plugin bypass

Due 8/20/2026
CVE-2024-6387HIGH 8.1

OpenSSH signal handler race, regreSSHion

CVE-2022-22965CRITICAL 9.8

Spring Framework data binding remote code execution

KEV
CVE-2024-23897CRITICAL 9.8

Jenkins CLI arbitrary file read

KEV
Assigned6
CVE-2024-38077CRITICAL 9.8

Windows Remote Desktop Licensing Service RCE

→ j.harrisOverdue 8/12/2026
CVE-2025-0282CRITICAL 9.0

Ivanti Connect Secure stack buffer overflow

KEV→ a.lopez
CVE-2023-34362CRITICAL 9.8

MOVEit Transfer SQL injection

KEV→ a.lopez
CVE-2024-3400CRITICAL 10.0

PAN-OS GlobalProtect command injection

KEV→ j.harris
CVE-2023-3519CRITICAL 9.8

Citrix ADC and Gateway unauthenticated code injection

KEV→ a.lopez
CVE-2024-47575CRITICAL 9.8

FortiManager fgfmd missing authentication

KEV→ j.harris
Mitigating3
CVE-2021-26855CRITICAL 9.8

Exchange Server SSRF, ProxyLogon

KEV→ m.chen
CVE-2023-44487HIGH 7.5

HTTP/2 Rapid Reset denial of service

→ j.harris
CVE-2022-30190HIGH 7.8

MSDT remote code execution, Follina

KEV→ m.chen
Resolved3
CVE-2021-44228CRITICAL 10.0

Apache Log4j2 JNDI remote code execution

KEV→ r.patel
CVE-2023-4966CRITICAL 9.4

Citrix NetScaler session token leak, CitrixBleed

KEV→ r.patel
CVE-2022-42475CRITICAL 9.8

FortiOS SSL-VPN heap buffer overflow

KEV→ m.chen
Dismissed2
CVE-2024-3094CRITICAL 10.0

xz-utils backdoor in liblzma, no affected build in fleet

CVE-2023-38545CRITICAL 9.8

curl SOCKS5 heap overflow, no affected version shipped

Findings · CVE catalog
Browse CVEs

Search 361,000+ CVEs by ID, keyword, product, or technology. The cache updates daily via NVD and CISA KEV.

361,000+ totalSelect
Search CVE-2021-44228, log4j, apache, openssl… RowsCards CSV
All SeveritiesCriticalHighMediumLowNone Sort:Newest FirstTRIS ScoreCVSS Score
Showing 1-11 of 361,000+ CVEsPage 1 of 7,220
CVESeverityCVSSTRISEPSSKEVPublishedSummary
CVE-2021-44228Critical10.0T9497%KEVDec 10, 2021Apache Log4j2 JNDI remote code execution
CVE-2024-38077Critical9.8T9262%·Jul 9, 2024Windows Remote Desktop Licensing Service remote code execution
CVE-2025-0282Critical9.0T8889%KEVJan 8, 2025Ivanti Connect Secure stack-based buffer overflow
CVE-2024-21762Critical9.8T8491%KEVFeb 9, 2024FortiOS SSL VPN out-of-bounds write
CVE-2021-26855Critical9.8T7697%KEVMar 2, 2021Microsoft Exchange Server server-side request forgery
CVE-2024-41110Critical9.9T7112%·Jul 24, 2024Docker Engine authorization plugin bypass
CVE-2023-34362Critical9.8T6894%KEVJun 2, 2023Progress MOVEit Transfer SQL injection
CVE-2022-22965Critical9.8T5797%KEVApr 1, 2022Spring Framework data binding remote code execution
CVE-2023-4863High8.8T4931%KEVSep 12, 2023libwebp heap buffer overflow in WebP decoding
CVE-2024-6387High8.1T388%·Jul 1, 2024OpenSSH signal handler race condition
CVE-2023-48795Medium5.9T222%·Dec 18, 2023SSH transport protocol prefix truncation
← Previous12347220Next →
Attack Path Visualization

Interactive graph showing how attackers chain vulnerabilities across your network assets.

1,284Assets 18,204Attack paths 2,946Critical paths 40Shown (top risk) 40Critical shown 400CVEs shown
Live graph with inferred pathsBuilt from your imported assets and findings. Path relationships are inferred from shared CVEs and same-subnet proximity, and sharpen as more telemetry lands.
INFERRED LIVE DATA
Min CVSS:4.0 Attack flowCluster Path (0/5): Click nodes to build path CriticalHighMediumLow
INTERNET-FACING CROWN JEWELS 98118810912 internetuntrusted vpn-edge-01CVE-2025-0282 exploitable mail-gwpatched fs01.corp.localSMB signing not required dc01.corp.localcrown jewel
Fix First · Pro
What to fix first

847 open actions across 1,284 assets, ranked by real-world risk. Group them the way your team divides the work.

Derive fix instructions
Critical fixes96
Exploited in the wild41
Internet-exposed63
Overdue28

612 patchable now (a patch or upgrade is available) · 74 hosts remediated in the last 30 days

RankedBy patchBy severityBy exploitabilityBy exposure

Start here

1Fix
Patch Windows Remote Desktop Licensing Service
CRITICALTRIS 92Public exploit1 CVE48 assets12 internet-exposedOverdue

Patch: install the July 2024 cumulative update on every licensing host, then restart the service · Domain controllers in the corp.local forest run this role.

Not verified
Review fixCreate ticketPush patch

Then work down

2Fix
Upgrade Ivanti Connect Secure to a fixed release
CRITICALTRIS 88CISA KEV1 CVE3 assets3 internet-exposed

Update: move both VPN appliances onto the vendor fixed build · Only route into the flat management VLAN.

Verifying
Review fixCreate ticketPush patch
3Fix
Bring Exchange to the current CU plus security update
HIGHTRIS 76CISA KEV1 CVE12 assetsOverdue

Patch: stage the cumulative update on exch-01 during the Saturday window · Mailbox access for the whole company.

Not verified
Review fixCreate ticketVerify fix
4Fix
Rebuild the CI runner image on a patched Docker Engine
HIGHTRIS 711 CVE31 assets

Update: pin the base image to a build past the authorization plugin fix, then redeploy the runner pool · Signing keys live on these hosts.

Verified fixed
Review fixCreate ticketVerify fix

Showing the top 4 of 847 actions.

BASzy Attack Simulation

Agentless breach and attack simulation. Discover assets, validate defenses, prove exploitability.

158,271 payloads · 120 categories · 20 campaigns
1SCOPEDefine targets
2DISCOVERFind assets and services
3PRIORITIZETRIS risk scoring
4VALIDATEAttack simulation
5MOBILIZEAI remediation
BASzy AI Connected6 scans   84 findings   12 linked CVEs
Total scans6
Active1
Findings84
Critical9
High23
Run Scan Results Campaigns Payloads Schedule
Breaking Threats25Refresh

Severe CVEs on your assets that BASzy has not proven yet. Click to test exploitability on the exact box. Proof, not a guess.

CVE-2024-21762CISA KEVCVSS 9.8EPSS 91%
vpn-edge-01.corp.local · in CISA KEV (added 2024-02-09), known exploited in the wild
Test Exploitability
CVE-2021-26855CISA KEVCVSS 9.8EPSS 97%
exch-01.corp.local · in CISA KEV (added 2021-11-03), known exploited in the wild
Test Exploitability
CVE-2025-0282CISA KEVCVSS 9.0EPSS 89%
vpn-edge-02.corp.local · in CISA KEV (added 2025-01-08), known exploited in the wild
Test Exploitability
CVE-2023-34362CISA KEVCVSS 9.8EPSS 94%
xfer-01.corp.local · in CISA KEV (added 2023-06-02), known exploited in the wild
Test Exploitability
CVE-2022-22965CISA KEVCVSS 9.8EPSS 97%
app-tomcat-04.corp.local · last: UNPROVEN
Test Exploitability
CVE-2021-44228CISA KEVCVSS 10.0EPSS 97%
log-collector-02.corp.local · last: BLOCKED
Test Exploitability
running192.168.20.0/2431 findingsStop
42% complete7m elapsed · ~9m left
completed10.20.0.0/2453 findingsAuth: moderate · Duration: 22m 14s
SeverityTitleModuleTargetMITRECVE Link
CRITICAL
EXPLOITABLE
Pre-auth stack overflow on the VPN appliancehttp.ivanti_rcevpn-edge-01T1190CVE-2025-0282
CRITICAL
EXPLOITABLE
SSRF to authenticated mailbox readhttp.proxylogonexch-01T1190CVE-2021-26855
HIGH
BLOCKED
SMB relay to the file serversmb.relayfs01.corp.localT1557.001Link CVE
MEDIUM
UNREACHABLE
SSH transport downgradessh.terrapindev-sandbox-11T1557CVE-2023-48795
Command Center · Priority Queue
CVE-2024-38077 Critical ✓ BAS VALIDATED Not in CISA KEV

Windows Remote Desktop Licensing Service remote code execution. Published Jul 9, 2024 · 48 assets affected · ranked first of 18,942 open findings.

Add to triageAccept riskCreate issueExport PDF
92TRIS CRITICAL PRIORITY SLA: patch within 72h · assigned to j.harris · overdue since 8/12/2026 CVSS 9.8EPSS 62%KEV no
TRIS elevates this above four CVEs in your estate that carry a higher CVSS. CISA has not listed it, EPSS puts it at 62%, and on severity alone it ties for fourth. It sits first because BASzy proved the exploit on two of your domain controllers, and nothing in your detection stack wrote a log line when it did.
Foundational · the three signals every scanner already has
L1CVSS Base Severity98/100 × 10% = 9.8
NVD base score 9.8. Weighted at a tenth so the other eleven layers can outvote it, and here four of them do.
L2EPSS Exploitation Probability62/100 × 12% = 7.4
62% chance of exploitation in the next 30 days, up from 31% four weeks ago.
L3CISA KEV Active Exploitation0/100 × 10% = 0.0
Not in the catalog, so this layer contributes nothing. A KEV-driven program never gets to this CVE.
Contextual · the four that are about your estate rather than the bug
L4Threat Actor Targeting88/100 × 8% = 7.0
Three tracked groups run Windows service abuse against manufacturing. Your org profile is set to manufacturing.
L5Asset Criticality100/100 × 9% = 9.0
Two of the 48 affected hosts are domain controllers in corp.local. Crown-jewel weighting applies at full strength.
L6Public Exposure Topology76/100 × 8% = 6.1
12 of 48 hosts answer on 3389 from outside, and the licensing role is running on all twelve.
L7BASzy Exploit Validation100/100 × 12% = 12.0
Proven on dc01, dc02 and rds-lic-01 during the 10.20.0.0/24 run. No control blocked it and no rule fired.
Novel · the five no other scoring model computes · patent pending
L8Attack Path Blast Radius94/100 × 9% = 8.5
Reaches 214 assets within two hops. Four distinct paths terminate at a Tier 1 system.
L9Supply Chain Dependency Propagation30/100 × 5% = 1.5
A first-party Windows role rather than a transitive package, so nothing downstream inherits it.
L10Defense Efficacy Coefficient82/100 × 7% = 5.7
The exploit chain maps to T1210 and T1068. Your stack covers 18% of it, last validated 6 days ago.
L11Predictive Threat Trajectory90/100 × 5% = 4.5
Public proof-of-concept forks tripled in nine days, and two of them now carry working shellcode.
L12Financial Impact Quantification71/100 × 5% = 3.6
Expected loss of $2.1M against your configured $500K appetite. Downtime, not fines, drives the number.

Biggest movers: BASzy validation 12.0 · CVSS base 9.8 · Asset criticality 9.0 · Blast radius 8.5, and eight more.

Weighted composite across 12 layers75.1
Validation override: proven exploitable with zero detection coverage+17.3
TRIS v292.4
Your environment48 affected · deduped to canonical assets before counting
HostnameIPProduct / versionRoleStatus
dc01.corp.local ✓ BAS VALIDATED10.20.4.11Windows Server 2022 · RDL 10.0.20348Domain controllerOpen
dc02.corp.local ✓ BAS VALIDATED10.20.4.12Windows Server 2022 · RDL 10.0.20348Domain controllerOpen
rds-lic-01.corp.local ✓ BAS VALIDATED10.20.9.30Windows Server 2022 · RDL 10.0.20348Licensing · internet-exposedOpen
rds-lic-02.corp.local10.20.9.31Windows Server 2022 · RDL 10.0.20348Licensing · internet-exposedOpen
app-term-07.corp.local ✓ BAS BLOCKED10.20.12.7Windows Server 2019 · RDL 10.0.17763Terminal servicesOpen

Showing 5 of 48 affected hosts. Three proved exploitable, one was stopped by a host firewall rule, the rest are untested.

Blast RadiusGraph-derived · L8 input
94Blast score

Compromise of a single licensing host reaches 214 assets in two hops, because the service runs as SYSTEM and its machine account is trusted by the file tier. Four separate routes end at a domain controller.

Step 1Initial access

Unauthenticated remote code execution against the licensing service. No credentials, no user interaction, reachable from the internet.

rds-lic-01EXPOSEDrds-lic-02EXPOSED
Step 2Lateral movement

The service runs as SYSTEM, so the machine account authenticates outward. SMB signing is not required on the file tier.

fs01.corp.localfs02.corp.local+38 more
Step 3Objective

Relay from the file tier reaches the domain controllers, where the same CVE is present and already proven.

dc01.corp.localCRITdc02.corp.localCRIT
Data at riskDomain credentialsPayroll exportsCustomer PIICode signing keys
Threat ActorsTradecraft, tooling and sector overlap · L4 input
CNVolt Typhoonstate-sponsored78%

Documented living-off-the-land intrusions into critical manufacturing, reaching domain admin through Windows service abuse. Sector match drawn from your org profile.

RUBlack Bastacybercrime71%

CISA advisory records this group exploiting internet-facing Windows services in manufacturing ahead of ransomware deployment.

RUFIN7cybercrime52%

Long history of terminal services abuse for initial access. No public reporting ties the group to this specific CVE, which is why confidence sits at 52%.

Matched on tradecraft, tooling and sector. A match raises the layer score, it is not an attribution.

Exploit ForecastForward-looking · L11 input
84%Weaponization
9 daysEst. timeline
MEDIUM CONFIDENCE

Vulnerabilities that follow this fork curve reached weaponized, packaged exploit code in a median of 11 days.

Contributing factors
Fork velocity14 public forks, three times the count nine days ago
Exploit maturityTwo forks carry working shellcode rather than a crash
Patch adoptionFix shipped 13 months ago, adoption stalled near 58%
Broker chatterNamed in two access-broker listings this month
Assets · Inventory
Asset Inventory

Persistent asset registry, auto-populated from BAS scans, scanner imports and connectors. Assets are canonically deduped by tiered fingerprint, so one real host is one row no matter how many tools found it.

Sync from Scans
Synced: 0 created, 1,284 updated, 18,942 findings linkedEvery finding is attached to a canonical asset before it is scored, so a host that four tools each named differently is weighted once instead of four times.
6 MIN AGO
Where these assets came from4,912 raw host records across six sources
Tenable Nessus1,109host rows Rapid7 InsightVM1,043host rows Qualys VMDR876host rows CrowdStrike Falcon812host rows Microsoft Intune731host rows BASzy discovery341host rows
4,912 rows resolved to 1,284 canonical assets. 3,628 duplicates collapsed on fingerprint, which is why the critical count on the Command Center is a number of machines rather than a number of scanner rows.
Search hostname, IP, business unit… All criticalities All environments
Hostname / IPOSCriticalityEnvironmentCVEsCriticalKEVPublicLast seen
dc01.corp.local
10.20.4.11
Windows Server 2022CRITICALproduction4163·2026-08-15
dc02.corp.local
10.20.4.12
Windows Server 2022CRITICALproduction3963·2026-08-15
exch-01.corp.local
10.20.4.30
Windows Server 2019CRITICALproduction5795Yes2026-08-15
vpn-edge-01
10.20.0.4
Ivanti Connect Secure 22.6CRITICALproduction1244Yes2026-08-15
fs01.corp.local
10.20.6.10
Windows Server 2019HIGHproduction3431·2026-08-14
xfer-01.corp.local
10.20.7.20
MOVEit Transfer 15.0HIGHproduction922Yes2026-08-15
app-tomcat-04
10.20.8.14
Ubuntu 22.04 LTSHIGHproduction6352Yes2026-08-15
rds-lic-01.corp.local
10.20.9.30
Windows Server 2022HIGHproduction2830Yes2026-08-15
build-runner-03
10.20.11.23
Ubuntu 24.04 LTSHIGHproduction4740·2026-08-15
dev-sandbox-11
10.30.2.11
Ubuntu 22.04 LTSLOWdevelopment8871·2026-08-13

Showing 10 of 1,284 assets. Note the last row: dev-sandbox-11 carries more CVEs than any host in the estate and the lowest TRIS weight of the ten. Counting findings puts it first. Counting risk does not.

Intelligence · Threat Feed
Threat Intel

Briefings, indicators of compromise and tracked adversaries, auto-synced from the signed cveasyai.com feed or carried in offline, then correlated against your own inventory.

Import bundleFetch latest
Briefings148
Indicators (IoCs)12,480
Asset matches7
Tracked actors48
Overview Briefings Indicators Asset matches Actors
Seven of your assets touch a tracked indicatorAn indicator feed on its own is a list of strangers. These rows exist because the feed was joined against the canonical asset table, so the answer is a hostname you own rather than an address you have to go look up.
Re-correlate
AssetIndicatorTypeSeverityMatchSourceSeen
exch-01.corp.local185.174.100.17IPv4criticaloutbound-sessionbriefing:proxylogon-resurgence2026-08-15
vpn-edge-01update.ivanti-cdn[.]netDomaincriticaldns-querybriefing:ivanti-jan-20252026-08-15
build-runner-039f3c1e…a742SHA-256highfile-hashbundle:2026-W332026-08-14
app-tomcat-0445.61.136.9IPv4highinbound-scanbundle:2026-W332026-08-14
ws-4471.corp.localinvoices-secure[.]topDomainmediumdns-querybundle:2026-W322026-08-12
ws-2210.corp.local103.75.190.22IPv4mediumoutbound-sessionbundle:2026-W322026-08-11
log-collector-02b71a44…09deSHA-256lowfile-hashbundle:2026-W312026-08-09

Bundles are signed. Signatures are verified before anything is ingested, which is what makes the air-gapped import path safe to use.

Total actors48
CVE attributions1,109
Origins11
Actor types3
CNHAFNIUMstate-sponsored6 of your CVEs94%

Attributed to the Exchange server-side request forgery chain you still have open on exch-01. Targets your sector.

KPLazarus Groupstate-sponsored4 of your CVEs91%

Documented use of the Log4j2 lookup chain against build infrastructure. You resolved that one in June, so it no longer moves a score.

CNVolt Typhoonstate-sponsored3 of your CVEs78%

Living-off-the-land tradecraft against critical manufacturing. Feeds L4 on three of your open findings including CVE-2024-38077.

RUBlack Bastacybercrime5 of your CVEs71%

Exploits internet-facing Windows services ahead of ransomware deployment, per the CISA advisory carried in the bundle.

RUFIN7cybercrime2 of your CVEs52%

Terminal services abuse for initial access. Sector overlap only, so the layer contribution is capped.

48 actors tracked, 18 of them active against manufacturing. Attribution confidence is carried into TRIS layer 4 rather than being rounded up to a yes.

CTEM · Defense Map
MITRE ATT&CK coverage

Technique coverage from BAS scan results, crossed with the detection rules your SIEM actually has. Two questions most programs answer in two different tools, on two different quarters.

← Back to scanner
Total techniques16
Covered11
Tested9
Findings5
Coverage69%
BAS test coverage Gap matrix · test × detect
16Total techniques 56%Test coverage 44%Detect coverage 31%Full coverage
covered test only detect only gap
Initial Access1/4 covered T1190Exploit Public-Facing App T1078Valid Accounts T1566Phishing T1133External Remote Services
Execution1/2 covered T1059Command and Scripting T1203Client Execution
Persistence0/1 covered T1505Server Software Component
PrivEsc0/1 covered T1068Exploitation for PrivEsc
Credentials1/2 covered T1110Brute Force T1552Unsecured Credentials
Discovery1/2 covered T1046Network Service Discovery T1018Remote System Discovery
Lateral Mvmt1/1 covered T1021Remote Services
C20/1 covered T1071App Layer Protocol
Exfil0/1 covered T1048Exfil Over Alt Protocol
Impact0/1 covered T1486Data Encrypted for Impact
T1068Exploitation for Privilege EscalationTactic: PrivEsc · gap class: test only
BAS test coverage✓ via win.rdl_rce, win.token_theft
Detection coverageNo detection rule covers this technique
Remediation: BAS tests this and the exploit succeeds, but nothing writes a log line when it does. Author a Sigma rule from the Posture Delta page, then re-run to confirm the cell turns green.

This is the cell that put CVE-2024-38077 first in your queue. The exploit works on two domain controllers and your stack never sees it happen. Severity did not tell you that. Neither did the exploit test on its own, and neither did the SIEM audit on its own.
CTEM · Discover
Scan Engine

Finds what exists and where it is misconfigured: cloud posture (CSPM and CIEM) plus agentless on-prem exposure mapping. This is the Discover stage of CTEM, upstream of and separate from BASzy validation.

ScheduleRun scan
Cloud providers3
CIS-tagged rules204
Mapped frameworks6
DeploymentAgentless
Read-only API access, nothing installedThe engine authenticates with a scoped read-only role per provider. It never writes to your accounts, and the results land in the same canonical asset table the scanners feed, so cloud and on-prem findings rank against each other instead of side by side.
AGENTLESS
All providersAWSAzureGCP Frameworks:CISPCI DSSNIST 800-53SOC 2HIPAAISO 27001
ProviderRulesAccountsResourcesFailingTop failing controlLast run
AWS8843,912211Public S3 bucket policy allows cross-account read18m ago
Azure6121,60496Storage account permits unencrypted transfer18m ago
GCP55174238Service account holds project-wide editor role18m ago
On-prem··1,28463Management service reachable from an untrusted VLAN2h ago

408 failing controls across 6,258 resources. Each one resolves to an owner and an asset before it reaches the queue, which is why the Command Center counts 1,284 machines rather than 6,258 rows.

BASzy · Adversary emulation
Threat-actor campaign command center

Replay documented APT campaigns end to end against your real security stack. When a control blocks a step, the AI re-routes, exactly like the adversary would.

Campaign libraryReplay campaign
Campaign risk87
Steps breached5
AI adaptations1
Steps blocked1
HAFNIUM · Exchange to domain9 steps · run 41m ago against the production stack · T1595 through T1486
01T1595 Active scanningOWA endpoint reachable from the internet, build number disclosed in the response headerBREACHED
02T1190 Exploit public-facing applicationServer-side request forgery to authenticated mailbox read on exch-01, CVE-2021-26855BREACHED
03T1505.003 Web shellEDR quarantined the aspx write within 900ms and raised an alert. This control works.BLOCKED
04T1059.001 PowerShell executionStep 3 was blocked, so the engine dropped the shell route and re-planned through WMI instead. A scripted BAS run stops here. This one did not.ADAPTED
05T1047 Windows management instrumentationExecution in SYSTEM context on exch-01. No rule fired on the WMI path.BREACHED
06~T1003.001 LSASS memoryCredential Guard limited the dump to cached machine credentials. Partial, and enough for step 7.PARTIAL
07T1550.002 Pass the hashMachine account authenticated to fs01.corp.localBREACHED
08T1557.001 LLMNR and NBT-NS poisoning, SMB relaySMB signing not required on fs01, relayed to dc01.corp.local. Same finding the attack path graph inferred.BREACHED
09T1486 Data encrypted for impactDestructive technique, excluded by the authorization scope on this engagementSKIPPED

Step 4 is the whole point. A scripted simulation reports "blocked" and stops. The engine treated the block as information, re-planned, and reached the domain controller anyway. Your EDR did its job and the campaign still succeeded.

APT29 · identity first

14 steps, cloud and on-prem, token theft into consent phishing

Volt Typhoon · living off the land

11 steps, no binaries dropped, edge device into OT segment

Black Basta · access to encryption

16 steps, broker access through to staged deployment

Campaign library 20 threat-actor campaigns, 158,271 payloads

The campaign catalog, the technique-to-payload mapping and the adaptation logic are the product. We walk through them live against your stack rather than publishing them.

Book a walkthroughSee pricing
Web Fuzzer
Offensive · authorized-only

Crafted web-request fuzzing for injection, request smuggling and differential response bugs. Every anomaly carries a reproducer, so a finding is something an engineer can run rather than a screenshot to argue about.

Load profileStart campaign
Total requests41,806
Anomalies318
Likely vulns7
Divergences24
completedhttps://app-tomcat-04.corp.local41,806 requestsDuration: 14m 02s · 49 req/s · authorized 2026-08-14
SeverityFindingClassEndpointSignal
CRITICALExpression language injection in a template parameterinjection/render?tpl=timing + echo
HIGHRequest smuggling on a chunked transfer boundarysmuggling/api/v2/uploaddesync 8/8
HIGHAuthorization differential between two role tokensdifferential/api/v2/reports200 vs 403
MEDIUMVerbose stack trace on a malformed multipart bodydisclosure/api/v2/importlen delta
curl reproducer · finding 1

curl -sk 'https://app-tomcat-04.corp.local/render?tpl=%24%7B...' -H 'Cookie: JSESSIONID=...' --data-binary @payload.bin

python reproducer · finding 1

import requests, sys; s = requests.Session(); s.headers.update({...}); r = s.post(TARGET, data=CRAFTED)

Reproducers Every finding ships a curl and a python reproducer

The generated proof-of-concept for your own targets is part of the licensed product. We will run it against a host you own on a call.

Book a walkthroughSee pricing
0-Day Engine
Offensive · authorized-only Novel-exposure discovery

Finds the unknowns on any host. Detection Scan runs the TRIS-prioritized KEV and template library for known-but-active exposures. 0-Day Audit uses app-behavior analysis and AI hypotheses to surface novel bugs that have no CVE yet, with a ready-to-file advisory.

Authorized targets onlyThese probes send active packets. Running them against a system you do not own is unlawful in most jurisdictions. Every run is attached to your name in the audit log, and the authorization record is part of the export.
SCOPE ENFORCED
Detection Scan

Known-but-active exposures, ordered by TRIS rather than by template count. Answers "what is already public and reachable here".

Configure
0-Day Audit

Behaviour-led hypotheses against an app that has no published CVE. Answers "what is wrong here that nobody has written up yet".

Configure
Advisory draft

A finding that survives triage produces a disclosure-ready writeup with affected versions, impact and a suggested fix.

View format
Hosts audited26
Hypotheses tested1,914
Survived triage3
Advisories drafted2
Candidate 1 · app-tomcat-04

Behaviour class: deserialization reachable through an unauthenticated path. Hypothesis generated from response-timing clustering across 412 probes, then confirmed by a controlled second-order write.

Candidate 2 · xfer-01

Behaviour class: path traversal past a normalisation routine that the vendor added in the fixed release for a different bug.

Discovery internals How the engine forms and tests a hypothesis is the product

The behaviour classes, the hypothesis generator and the triage gate are not published. What is public: findings that survive go through coordinated disclosure, and the advisories carry our ORCID.

Talk to usOur research
Remediate · patent pending
TRIS Sprint Board

The analyst workflow. Three columns keyed to the SLA the band implies rather than to a severity label. Act inside 72 hours, attend within two weeks, track this quarter.

96 in ACT · 214 in ATTENDSimulate patch
Patch simulation: if I patch the licensing role, what happens?Removing CVE-2024-38077 from the estate drops 48 findings, closes 4 of the 6 paths that end at a domain controller, and moves 31 assets out of ACT. The board recalculates before you file the change request rather than after.
Run simulation
ACT · 72 hours96
CVE-2024-3807792

dc01.corp.local · production · crown jewel

Volt TyphoonOverdue
CVE-2025-028288

vpn-edge-01 · production · internet-facing

KEV
CVE-2021-2685576

exch-01.corp.local · production

KEVHAFNIUM
CVE-2024-4111071

build-runner-03 · production

ATTEND · 2 weeks214
CVE-2023-3436268

xfer-01.corp.local · production

KEV
CVE-2022-2296557

app-tomcat-04 · production

KEV
CVE-2023-486349

workstation fleet · 64 hosts

TRACK · this quarter1,178
CVE-2024-638738

internal-jump-02 · production

CVE-2023-4879522

dev-sandbox-11 · development

CVE-2023-4448719

edge proxy tier · 6 hosts

CVE-2023-48795 carries a CVSS of 5.9 and sits in TRACK. CVE-2024-41110 carries a 9.9 and sits in ACT underneath a 9.8. The column is decided by the twelve layers, which is what makes the board a work plan rather than a sorted severity list.

Remediate · guidance
Solutions

Fix guidance per finding, written against the product and version actually installed on your host rather than against the vendor advisory in the abstract.

Export runbookDerive for selection
Actions derived847
Patch available612
Config change only168
No fix yet67
1Fix
Patch Windows Remote Desktop Licensing Service
CRITICALTRIS 9248 assetsReboot requiredEst. 35m per host

Steps: stage the July 2024 cumulative update on the licensing hosts, restart the Remote Desktop Licensing service, then re-run the BASzy module to confirm the exploit no longer lands · Rollback: uninstall the update and restore the service state snapshot taken at step 1.

Not verified
Open CVECreate ticketConvert to runbook
Runbook: Windows cumulative

14 steps, pre-flight snapshot, staged rings, verify gate

Runbook: appliance firmware

9 steps, failover aware, config diff before and after

Runbook: container base image

11 steps, registry pin, redeploy, drift check

Runbook library Executable runbooks and the patch orchestration layer

Dispatch runs through Intune, Automox, Tanium, Jamf or your own webhook, never straight at the machine. The runbook set and the orchestration tiers ship with the licensed build.

How it worksSee pricing
CTEM · Mobilization
Proof-of-Fix ledger

Every closed CVE is sealed with an HMAC-signed attestation. Auditors verify offline. No certificate authority, no network call, and content-addressed identifiers so a record cannot be rewritten after the fact.

Verify a bundleExport ledger
Signed1,204
Avg fix window18.4h
Does not apply302
Revoked3
SIGNED CVE-2021-44228 · log-collector-02 · remediated by r.patel · 6.2h fix window · before TRIS 94, after 0
poff:3f9c1a7e42b8…d17a
Verify
SIGNED CVE-2023-4966 · netscaler-01 · remediated by r.patel · 11.8h fix window · before TRIS 81, after 0
poff:88b0e5cc19f2…4c63
Verify
SIGNED CVE-2022-42475 · fw-edge-02 · remediated by m.chen · 27.5h fix window · before TRIS 79, after 0
poff:c14d77a90be6…9e28
Verify
DOES_NOT_APPLY CVE-2024-3094 · fleet-wide · assessed by m.chen · no affected build ever shipped in this estate
poff:5a02be4417cd…b8f1
Verify
REVOKED CVE-2023-3519 · netscaler-02 · revoked 2026-07-30 · the finding returned after a config restore, so the attestation was withdrawn rather than edited
poff:9d3f0c2b7a45…1f70
Verify

A revoked attestation stays in the ledger. Nothing is deleted and nothing is rewritten, which is what makes the export usable as evidence rather than as a report.

Operate · Reporting
Report generator

Reports for stakeholders, auditors and engineering teams. Each one downloads as a printable HTML document and stays available under Recent. Generated locally, so the data never leaves the install to produce them.

SchedulesGenerate
Executive summary

Posture, trend, and the decisions you need from the leadership team. Two pages.

Generate
Technical findings

Every open finding with TRIS, affected hosts, validation state and the fix. For the engineers doing the work.

Generate
Attack simulation writeup

What BASzy ran, what landed, what was blocked, and the detection gaps that came out of it.

Generate
Patch compliance

SLA attainment by band and by owner, with the Proof-of-Fix attestations attached.

Generate
Compliance mapping

Findings mapped to CIS, PCI DSS, NIST 800-53, SOC 2, HIPAA and ISO 27001 controls.

Generate
Remediation roadmap

Sequenced plan with effort, dependency, and the risk removed at each step.

Generate
RecentKept locally · nothing uploaded
ReportTypeScopeGeneratedSize
board-quarterly-2026Q3Executive summaryDemo Workspace3h ago412 KB
findings-manufacturingTechnical findingsDemo WorkspaceYesterday2.1 MB
baszy-campaign-hafniumAttack simulation10.20.0.0/242 days ago876 KB
patch-sla-julyPatch complianceDemo WorkspaceAug 1340 KB
Operate · Metrics
Portfolio analytics

Burndown, mean time to remediate and SLA attainment, measured against the TRIS band rather than against CVSS, so the trend tracks risk removed instead of tickets closed.

30 days90 days12 months
Risk removed31%
MTTR critical18.4h
SLA attainment82%
Findings closed1,204
New this period687
Critical-band burndownOpen findings in the CRITICAL band, week by week
W23 W24 W25 W26 W27 W28 W29 W30 W31 W32 W33 W34

The two upticks are scanner onboarding, not regressions. W25 added the Qualys import and W31 added Falcon, and each one brought hosts the other tools had never seen. Deduplication is why the line resumes instead of resetting.

Fastest bandCRITICAL18.4hTarget 72h Slowest bandMEDIUM46dTarget 90d Breached SLAOpen now283% of open
Executive · CTEM
Board narrative

Monthly executive digest. Written by the local model, HMAC-signed, audit-ready. Generated on this machine, so nothing about the estate leaves the install to produce it.

Previous monthsGenerate August
Open findings change-1,204vs July Closed1,204All signed Validated exploitable9Down from 14 Detection gaps4Test without detect
Signed and reproducibleThe digest carries the same signature scheme as the Proof-of-Fix ledger, and it cites the finding identifiers behind every number. A board member who wants to check a claim can, and so can an auditor a year later.
HMAC SIGNED
August 2026 · draft

Exposure fell 31% this month, driven mainly by the licensing-service remediation that closed 48 findings across the domain tier. Two items need a decision from this group: the appliance refresh, currently the only route into the flat management VLAN, and the detection coverage gap on privilege escalation, where our own simulation reaches domain admin without generating an alert…

Generated narrative The digest is written against your data, so we do not publish a sample

What it reads like against a real estate is the only version worth judging. We generate one on a call, or from your own scanner export.

Book a walkthroughSee pricing
Integrate · Sources and destinations
Integrations

Findings arrive from the tools you already run, land on one asset graph, and leave again as tickets, webhooks and alerts. Nothing here replaces a scanner. It reconciles them.

Test deliveryAdd destination
Integrations152
Categories16
API connectors73
File imports43
Push endpoints14
Three ways in, one way back out130 of the 152 bring findings in: 73 native API clients pull on a schedule you set, 43 file imports auto-detect the format on drop, and 14 push endpoints accept whatever your pipeline sends. 15 outbound destinations carry the work back to ticketing, patch and chat, and 7 engines and feeds ship built in. Every inbound route lands in the same canonical asset table, which is the only reason cross-tool deduplication works at all.
READ-ONLY BY DEFAULT
Coverage by category16 categories · counts from the shipping catalog, vendor names withheld
AppSec & Code40 Cloud19 Controls14 Threat Intel11 CMDB9 Network9 Automation9 Vuln Scanners8 EDR & Endpoint6 ITSM5 Patch5 Notifications5 SIEM4 EASM4 Identity3 Engines1
Network scanners

Vendor, auth mode, field mapping, schedule, dedup key, rate limits

Identity providers

Vendor, auth mode, field mapping, schedule, dedup key, rate limits

SIEM and logging

Vendor, auth mode, field mapping, schedule, dedup key, rate limits

Vendor catalog We do not publish the vendor list or the field mappings

Which products we support, how each one authenticates and how its fields map onto the asset graph is the work that took the longest, so it is shared under a call rather than on a marketing page. Tell us your stack and we will confirm coverage in the first ten minutes.

Check your stackNamed partnersSee pricing
Integrate · Automated ingestion
Connectors

Scheduled pulls from the scanners and consoles you run. Credentials are encrypted at rest on this machine, scoped per workspace, and never transmitted anywhere except to the vendor endpoint they belong to.

Sync nowAdd connector
Configured6
Healthy6
Rows last 24h4,912
Sync interval6h
Credentials never leave the deviceSecrets are sealed with a key derived on first run and held in the OS keychain. There is no CVEasy cloud to relay through, which is also why an air-gapped install can run every connector that has an on-premise endpoint.
LOCAL FIRST
ConnectorAuthEndpointScopeScheduleLast sync
connector-aAPI keyhttps://…read:assets read:vulnsevery 6h6m ago
connector-bOAuth 2https://…read:findingsevery 6h6m ago
connector-cTokenhttps://…read:devicesevery 12h2h ago
Connector detail Endpoints, scopes and auth modes stay out of the public demo

The per-vendor configuration is exactly the sort of thing that should not be sitting on a website, ours or anyone's. We set yours up with you.

Set one up with usHow it is built
Manage · Local inference
CVEasy AI Engine

cveasy-ai-v1 runs on this machine. Remediation guidance, report narrative and triage suggestions are generated locally, which is what lets the whole product work with the network cable pulled out.

BenchmarksModel card
Active modelcveasy-ai-v1
RunsOn device
EgressNone
Held-out suite17 tasks
Benchmark, v1 to v2Published methodology · 17-task held-out suite
Overall score0.717 → 0.893
Measured against the held-out suite described on the benchmark page, not on the training distribution.
Degrades, never blocksIf the model is unavailable the app keeps working. Scoring, validation, ledger and reporting are deterministic code paths; the model writes prose and suggests triage, and every surface it touches says so.
Read the benchmark
Training corpus

Composition, sourcing and the distillation gate that promotes a candidate

Eval harness

Rubric, scoring weights, and the promotion thresholds a candidate must clear

Serving profile

Quantisation, context budget and the memory envelope on Apple silicon

Model internals Architecture, corpus and eval gates are not published

The benchmark results and the methodology are public. What went into the model and how a candidate gets promoted are not.

Benchmark resultsAsk us directly
Manage · Configuration
Settings

Workspace, business context and data handling. The org profile matters more than it looks: asset criticality and sector feed layers 4 and 5, so a blank profile deflates every score in the estate.

Export configSave
Org profile

Sector, size, revenue per hour and risk appetite. Drives layers 4, 5 and 12. Currently set to manufacturing.

Edit profile
Business context

Crown-jewel assets, environments and owners. Without it, a domain controller scores like a laptop.

Edit context
Workspaces

One tenant per client or per business unit. Findings, assets and scores are scoped and never merged across them.

Manage
Data location

Everything lives in a local SQLite database on this machine. There is no CVEasy cloud to opt out of.

Show path
Telemetry

Off, and there is no switch to turn it on. The app makes no outbound call except to the feeds and connectors you configure.

Verify
License

Per-install, offline-verifiable. Editions gate feature surface rather than asset count, so the price does not grow with your own discovery.

Manage
Why the profile is the first thing we set upTRIS scores against a tenant. A default profile with no crown jewels and no sector produces a queue that looks calm and is wrong, which is the failure mode we spend the most time preventing during onboarding.
Quick start
Search CVEs, assets, findings, actions…
Quick actions
MITRE CoverageATT&CK technique coverage map
InventoryCanonical asset registry
Threat IntelBriefings, indicators and actors
BASzyBreach and attack simulation
Browse CVEsSearch all vulnerabilities
Triage QueueProcess incoming CVEs
Fix FirstRanked remediation worklist
Attack PathsMulti-step attack chain analysis
CampaignsReplay documented APT campaigns
TRIS Sprint BoardACT, ATTEND and TRACK
Proof-of-FixSigned remediation attestations
Scan EngineCloud posture and agentless discovery
0-Day EngineNovel-exposure discovery and audit
Web FuzzerInjection, smuggling, differential
SolutionsAdvisory templates and fixes
ReportsExecutive and findings reports
AnalyticsPortfolio metrics and burndown
Board NarrativeMonthly executive digest
IntegrationsSources, destinations and events
ConnectorsScheduled scanner ingestion
AI EngineManage CVEasy AI Engine
SettingsOrg profile and data handling
CVE-2024-38077Windows RDL remote code execution · TRIS 92
↑↓ navigate openesc close

Command Center. Every open finding ranked by TRIS across twelve layers, not by CVSS alone.

Click a highlighted sidebar item, press ⌘K for the palette, or open CVE-2024-38077 from the queue

Why the demo is worth clicking

Four joins that other tools leave to you

Every number in the demo is the result of two data sets being put next to each other. Most programs own both halves already and never join them, because the halves live in different products. Here they live in one.

01

Severity × proof

CVSS tells you how bad a bug could be in a lab. BASzy tells you whether it works on your box, in your configuration, with your controls running. Only one of those is a statement about you. On the CVE detail page you can see the moment they diverge: a 9.8 with no KEV listing outranks a 9.9, because the engine landed the exploit on two domain controllers and nothing stopped it.

Open the CVE detail page

The usual splitScanner gives you severity. Pen test gives you proof, once a year, for a sample. Nobody reconciles the two, so the queue stays sorted by the number that was never about your environment.

02

Exploit test × detection rule

Breach simulation vendors tell you which attacks succeeded. Detection vendors tell you which rules you own. The interesting answer is the overlap, and specifically the cells where the attack works and no rule fires. That is the defense map. Four gap classes, one screen, and the orange cells are the ones that should ruin your afternoon.

Open the defense map

The usual splitBAS platform in one tab, SIEM content inventory in another, and an ATT&CK spreadsheet somebody maintains by hand between audits.

03

Six scanners × one machine

Nessus, InsightVM, VMDR, Falcon, Intune and BASzy discovery each name the same server differently, and each counts it again. 4,912 raw host records collapse to 1,284 canonical assets on a tiered fingerprint before anything is counted, scored or reported. Every metric downstream is therefore a number of machines rather than a number of rows.

Open the inventory

The usual splitEach tool reports its own asset count, all of them are wrong, and the board sees whichever one was exported last.

04

Indicator feed × your inventory

A threat feed on its own is a list of strangers: addresses, domains and hashes with no bearing on anything you own. Correlated against the canonical asset table it turns into seven of your hostnames, each carrying the briefing that named the indicator and the date it was seen. That is the difference between reading intel and using it.

Open threat intel

The usual splitFeed subscription in one place, asset database in another, and an analyst pasting IPs into a search bar when something makes the news.

What you are looking at. Every label, column and status word here is lifted from the shipping build, so the demo goes stale the day the app changes and we re-cut it. The findings are fabricated. The product screenshots in the docs are from a real install.