Known Exploited Vulnerabilities
Fetches known exploited vulnerability data from CISA's public KEV catalog.
Details
The CISA KEV input processes Known Exploited Vulnerabilities (KEV) data incrementally, ensuring that you always receive new vulnerability entries without duplicates. The input maintains state between runs, tracking which vulnerabilities have been processed to guarantee:
- No duplicate vulnerability records unless there has been an update to an existing record. You will get the new updated record.
- All new vulnerabilities are captured
- Recovery from interruptions without data loss or duplicate data
Prerequisites
The CISA KEV connector does not require any credentials, making it a straightforward plug-and-play connector.
Configuration
The following configuration defines the input parameters. Each field's specifications, such as type, requirements, and descriptions, are detailed below.
Settings
| Setting | Type | Required | Description |
|---|---|---|---|
| Backfill Start Time | string | No | The date to start fetching data from. If not specified, no past records will be fetched. |
Secrets
None.
API
To send a POST request to create this CISA KEV Connector:
Code
Sample Record
Code
Sync frequency
This input runs on an internal managed schedule. See Input Sync Frequency for details.