← All use cases
Use case · Free + Commercial

MSSPs and MDR Teams

A handful of CVEs gain new exploitation evidence overnight. Those become your first customer notifications.

Marcus runs threat intelligence for an MSSP that monitors 60 customer environments, roughly 180,000 open vulnerabilities combined. Every morning his team needs the handful of CVEs that gained new exploitation evidence overnight. Those become the first customer notifications of the day.

Before the headlines. Before the vendor advisories. Before the scanner runs.

Free tier
What you get
The daily snapshot. A 06:30 job compares today's against the copy the team kept from yesterday: the CVEs that gained new exploitation evidence in the last 24 hours, typically 10 to 20.
What you do
Each notification carries the CVE, the specific evidence that changed (KEV inclusion, new Metasploit module, new ExploitDB entry), and whether it is in that customer's inventory, from the CMDB join. ESIP provides the signal; the MSSP provides the asset context.
Outcome
By 07:30 every customer with a moved CVE in their environment has a notification. A simple build that runs every morning. From Marcus’s side, it is a daily JSON comparison.
  • Daily snapshot
  • Full observation history per CVE
  • Free API key
Commercial
What you get
The change feed: verdict-level changes, not observation diffs. evidence.what_changed pre-assembled, plus current_trend, signal_velocity, compound_risk, and a decay-aware lifecycle.
What it does for you
Notifications become intelligence: “CVE-2026-41940 escalated to Confirmed Critical overnight. Three independent sources now corroborate: CISA KEV, EUVD, and Metasploit. Signal velocity is High.” The feed can be filtered by each customer’s inventory for per-customer delta reports.
Outcome
Customers get contextualised, evidence-backed notifications, including “threat reducing” notes when a Confirmed signal starts Declining. The interpretation happens inside ESIP’s signal engine, not in Marcus’s scripts.
  • Change feed (verdict-level)
  • evidence.what_changed per CVE, pre-assembled
  • current_trend + signal_velocity for context
  • Lifecycle-decline notifications when threats reduce
  • compound_risk for corroboration strength

The free tier gives you observable facts. The commercial platform turns those facts into an explainable exposure signal: what changed, why it matters, and what to do next.

Get a free key See pricing →