The mechanism

How ESIP builds an exposure signal

ESIP watches public evidence about how vulnerabilities are being exploited, detects when that picture changes, and turns the change into a verdict you can act on. This page explains the mechanism. For what an exposure signal is, see the definition.

EvidenceChangeVerdictDecision

ESIP produces the verdict. You make the decision.


Why a score isn't enough

A CVE's base score is set near disclosure and rarely moves. The exploitation state underneath it does not sit still: a proof of concept appears, an exploit is weaponized, a government catalog confirms it in the wild, a patch ships. The score cannot tell you any of that happened. ESIP is built to.


Step 1 · Observe public evidence

ESIP draws only on globally observable evidence: public sources anyone can check, never your environment. They group by the job they do.

Signal-firing
the changes that move a verdict
  • CISA KEV
  • FIRST EPSS
  • ExploitDB
  • GitHub PoC
  • Metasploit
  • ENISA EUVD (Exploited)
Enrichment
context on the exposure class
  • NVD
  • ENISA EUVD (Metadata)
Reference
identity, patch state, cross-reference
  • OSV
  • GitHub Security Advisories
  • CISA CSAF
  • Red Hat Security Data
  • Microsoft CSAF

13 ingested sources, enumerated above; the count is the sum of the list, not a figure asserted on its own. MITRE ATT&CK is applied as a mapping framework for attack relevance, separate from the ingested sources.


Step 2 · Detect the change

When something qualifying happens in one of those sources (a proof of concept lands, an exploit is weaponized, a CVE is added to KEV, a prediction score moves materially), ESIP records it as an observed change event: dated, attributed to its source, with a navigable reference to the artifact itself. These observed changes are the inputs, not the verdict.


Step 3 · Read the change into a verdict

ESIP rolls the active changes for an exposure class into one verdict, across four dimensions you can query on their own:

Lifecycle stage
where the exposure is in its arc.
Trend
which direction it is moving.
Velocity
how fast.
Corroboration
the strength of independent agreement.

Alongside the verdict sits the evidence narrative: what changed, and why ESIP reached this reading. A verdict moves only when the exploitation state materially moves; it stays quiet otherwise.


Step 4 · Let it decay

A signal is not a permanent label. It fires the moment strong evidence arrives, and it fades as that evidence ages, on a clock that differs by evidence type: confirmed exploitation stays relevant far longer than a single day's prediction move. The transitions are deliberately asymmetric. Strong evidence pulls a signal up at once; only decay brings it down, so the verdict does not flicker every time one observation comes and goes. Decay lowers influence. It does not erase history: a faded signal still leaves its record, and fresh evidence wakes it.


Built to be defended

Every verdict traces to the public evidence under it, and the same evidence under the same rules always produces the same verdict. That is what lets you defend a decision months later, to an auditor or a board. The full integrity argument (provenance, determinism, reproducibility) lives on its own page.

Why you can rely on it →

The concept, and where it sits

This page describes how ESIP implements exposure signals. The term itself is defined in the reference. For how ESIP sits alongside your scanner, your VM platform, and your CTEM program, see where it fits.


Get a free key and run it against a CVE you care about.

Get a free key