1. Document Purpose
This document explains how SAFE incorporates environmental context into Finding Scores using a transparent, standards-based evaluation model. It outlines how technical, business, and threat intelligence signals are systematically combined to produce risk scores that are explainable, consistent, and actionable.
2. Summary
SAFE’s scoring model integrates technical context, business relevance, and real-world threat intelligence to prioritize findings effectively. The approach ensures that risk decisions are:
Context-aware
Consistent across the organization
Defensible during audits
3. Understanding Finding Scores
A finding score is a 0-10 risk metric that combines vulnerability characteristics with real-world environmental context to answer the question: "How much risk does this vulnerability pose to my organization right now?"
Unlike generic severity scores (CVSS), which assume all vulnerabilities exist in identical environments, finding scores reflect your specific environment: your network topology, deployed security controls, business priorities, and current threat intelligence.
Finding scores provide intuitive risk categorization:
3.1. Finding Score Component Breakdown
SAFE exposes the Finding Score through three explainable component groups: Access, Threat, Impact and Mitigation. These components help users understand why a finding is prioritized and what remediation teams should act on first.
.png)
3.1.1. Access
Asset Type & SubtypeZone: Location within the major network zones, whether Perimeter (Internet-facing or direct access to the Internet), or Internal (typically behind a firewall).
Attack Vector: SAFE uses CVSS v2.0 or v3.0 vector strings for CVEs (and infers vector strings for Misconfigurations, using an SLM (small language model) trained on CVE data) to infer accessibility. E.g., Network attack vector vulnerabilities have a higher accessibility than Local attack vector vulnerabilities.
User Interaction: The CVSS metric captures the requirement for a human user, other than the attacker, to participate in the successful compromise of the vulnerable component. The score is greatest when no user interaction is required.
Privileges Required: The CVSS metric describes the level of privileges an attacker must possess before successfully exploiting the vulnerability. The score is greatest if no privileges are required.
Scope: The CVSS metric captures whether a vulnerability in one vulnerable component impacts resources in components beyond its security scope. The score is greatest when a scope change occurs.
3.1.2. Threat
Threat Level: Latest threat level related to potential adversary exploitation, represented as Critical, High, Medium, Low.
Finding Age: Number of days since any instance of this finding was first observed in the environment.
Attack Complexity: The CVSS metric describes the conditions beyond the attacker's control that must exist in order to exploit the vulnerability. The score is greatest for the least complex attacks.
EPSS: The Exploit Prediction Scoring System score estimates the likelihood, between 0 and 100%, that exploit evidence will be observed within the next 30 days, from https://www.first.org/epss/
CISA KEV: CISA's Known Exploited Vulnerabilities Catalog is an authoritative list of security flaws that have been confirmed by the Cybersecurity and Infrastructure Security Agency (CISA) to be actively exploited in the wild from https://www.cisa.gov/known-exploited-vulnerabilities-catalog
HEV (Highly Exploitable Finding): Security issue that has been previously exploited by threat actors, as identified through SAFE's Threat Intelligence monitoring.
TIIF: Threat Intel Informed Finding - a security issue that has been recently exploited by threat actors or observed across multiple security campaigns, as identified through SAFE's Threat Intelligence monitoring.
Asset Tags: Labels from source tools or assigned within SAFE (e.g., CMDB Tags like Business Criticality and Operational Status) are included as part of the Finding Score.
Threat Tags: Include threat and exploit indicators associated with this vulnerability, such as linkage to ransomware, malware, or known exploits.Pulled from NVD & other Threat Intelligence sources, and inferred based on weakness data in vulnerabilities. Supported tags are:
CISA KEV
Known Exploit
Ransomware Linked
Malware Linked
OWASP Top 10
End-of-Life Risk (EOL OS)
3.1.3. Impact
CVSS Severity: Represents the severity of exploit of this particular vulnerability, based on Confidentiality/Integrity/Availability Impact from CVSS base metrics.
Asset Criticality is now more strongly influenced by CMDB Tags, making it more aligned with real business impact. Inputs contributing to Asset Criticality:
CMDB Tags
CMDB Business Impact: Impact classifications come from your CMDB tags (Mission Critical, Critical, High, Medium, Low).
Business Criticality
Operational Status - Tags for Production, Staging, Development, Active, and Decommissioned Assets (exact string match)
Zone (network exposure)
Confidentiality: This CVSS metric measures the impact on the confidentiality of the information resources managed by a software component when a successfully exploited vulnerability is exploited. The score is greatest when the loss to the impacted component is highest.
Integrity: The CVSS metric measures the impact on the integrity of a successfully exploited vulnerability. The score is greatest when the consequence to the impacted component is highest.
Availability: The CVSS metric measures the impact on the availability of the impacted component resulting from a successfully exploited vulnerability. The score is highest when the impact on the affected component is greatest.
3.1.4. Mitigation or Compensatory Control Evaluation
Mitigation Efficacy: Mitigation efficacy measures how effectively security controls reduce vulnerabilities within an organization. By analyzing the relationships between vulnerabilities, ATT&CK TTPs (Tactics, Techniques, and Procedures), and security controls, organizations can identify gaps, prioritize investments, and enhance their security posture. Mitigation Efficacy is ranging from 0 to 10, the available mitigating controls reduce the likelihood of a finding, with the following levels:
Low is 0 - 3.99
Medium is 4.0 - 6.99
High is 7.0 - 10.0
The security control such as Endpoint Detection & Response (EDR) and Hardening that most effectively mitigates the most exposed adversarial techniques related to this finding. Represents the control that best protects against the 'weakest link', or the easiest route for adversaries to exploit.
Control-to-TTP Coverage: CIS benchmark and secure configuration compliance controls are mapped to ATT&CK techniques using CIS-provided mappings.
Secure configuration compliance controls (like CIS benchmarks) either pass or fail for individual techniques as well. The aggregate of all controls for a given technique becomes a new control source, whose efficacy is defined as the ratio of passed controls to all controls for that technique.
Findings-to-TTP Mapping: Finding are mapped to MITRE ATT&CK techniques using:
External sources
SAFE inference models based on vulnerability/Finding descriptions
If no mapping is identified above the confidence threshold, the vulnerability is assigned to an “Unmapped Technique”.
EDR-to-TTP Coverage: EDR efficacy against ATT&CK techniques is derived from MITRE Engenuity evaluations. Each EDR on an asset acts as a control source with technique-level efficacy values and by Integration with MITRE Engenuity Evaluations.
To improve accuracy, the system incorporates vendor evaluations from MITRE Engenuity ATT&CK Evaluations. This ensures:
Grounding efficacy calculations in real-world data.
Validation against independent testing.
Calibration with vendor claims.
The system leverages ATT&CK TTPs to establish relationships between vulnerabilities and controls:
Vulnerabilities/Findings are linked to ATT&CK techniques they might enable.
Security controls are mapped to ATT&CK techniques they mitigate.
Efficacy is calculated by correlating these mappings.
This process creates a matrix that includes:
Category | Details |
|---|---|
Findings | CVEs, misconfigurations, and entry points for attacks |
Techniques | ATT&CK TTPs and related attack methods |
Controls | Security products and configurations |
Refer to Examples and Scenarios in Appendix 1
3.2. Scoring Model Benefits
Transparent: Every score includes clear contributing factors
Standards-Based: Aligned with frameworks such as CVSS and CIS
Proven: Backed by real-world threat intelligence and evidence
3.3. Why Environmental Context Matters
The same vulnerability can have drastically different risk profiles depending on context:
Example: CVE-2025-24813 (Apache Tomcat Path Traversal, CVSS 8.1)
Internet-facing server → Finding Score: 9.2 (Critical)
Internal server, low business impact → Finding Score: 2.0 (Low) or Medium
Without environmental context, both instances would be treated identically (CVSS 8.1). With context, security teams remediate based on actual risk.
3.4. Prioritization
Finding scores enables organizations to:
Focus Resources: Remediate vulnerabilities that pose the highest actual risk, not just the highest theoretical severity
Reduce Alert Fatigue: Filter out noise from low-risk vulnerabilities, allowing teams to concentrate on what matters
Communicate Business Risk: Translate technical findings into business language that executives understand
Maintain Compliance: Demonstrate risk-based decision-making aligned with frameworks like CIS, NIST, ISO 27001
4. Key Outcomes
The transparent, systematic approach to environmental context integration delivers concrete benefits:
4.1. 97%+ Alert Noise Reduction
Context-aware scoring eliminates low-priority alerts. In deployed environments, SAFE typically prioritizes 1-2% of total vulnerability instances - focusing remediation on what matters most. The same CVSS 8.1 vulnerability could be scored as Critical (9.2), Medium (5.5), or Low (2.0) based on actual environmental factors.
SAFE derives these from CMDB attributes and operational/business tags ingested from other tools.
4.2. Organizational Consistency
Systematically determined technical factors and centrally-defined business priorities (CMDB tags) ensure infrastructure, and cloud teams see consistent prioritization. No configuration drift.
5. Industry-Standard Normalization
SAFE aligns scoring with widely accepted standards.
Industry-Based Baselines
Asset impact is evaluated against global criticality benchmarks
Removes bias from isolated or localized environments
More Accurate Risk Representation
Prevents inflation of impact scores for relatively less critical assets
Example:
End-user workstations may receive lower impact scores compared to legacy models
Reflects true enterprise-wide risk contribution
Standardized Scale (0.1 – 10.0)
Consistent with CVSS and EPSS frameworks
Eliminates reliance on proprietary scoring systems
Calibrated Severity Bucketing
Internal weights mapped to standard severity thresholds
Minor classification shifts may occur near boundary values
5.1. Threat Modeling: Precision and Consensus
SAFE introduces a more stable and data-driven approach to threat scoring.
Floor-Based Threat Model
Critical threat tags establish a minimum score threshold (floor)
Prevents premature score saturation seen in additive models
The remaining score is calculated using:
EPSS probability
Active threat intelligence signals
Multi-Signal Consensus Requirement
No single signal can independently drive a critical score
High severity requires corroboration across multiple data sources
Reduces false positives and improves prioritization accuracy
Proprietary Threat Intelligence (TIIF & HEV)
Threat Intel Informed Findings (TIIF) and Highly Exploitable Vulnerabilities (HEV)
Enable intelligent overrides for high-impact or emerging threats
Ensures “celebrity vulnerabilities” are appropriately prioritized
5.2. Decoupled Risk Dimensions (Threat vs Accessibility)
SAFE enforces strict separation between threat intelligence and technical exposure.
Independent Scoring Dimensions
Threat signals (e.g., CISA KEV, exploits) influence Threat only
Accessibility is derived purely from:
Network topology
Attack vector
Privilege requirements
User interaction
Improved Technical Accuracy
Eliminates artificial inflation of accessibility scores
Example: An exploited vulnerability on an air-gapped or offline asset will correctly show low accessibility
Note
SAFE evaluates CISA KEV findings on internal assets using exploitability context (Attack Vector, Complexity, User Interaction, Privileges Required), resulting in Medium or High severity where appropriate.
Appendix 1
Examples and Scenarios for Mitigations
Example 1: No MITRE Technique, No Control
MITRE Technique | None |
Control | None |
Resulting Efficacy | 0.0 |
Explanation: With no MITRE Technique or controls, the resulting efficacy is 0.0.
Example 2: MITRE Technique with Matching Control
MITRE Technique | TTP T1190 (Exploit Public-Facing Application) |
Control Framework | Vendor A |
Control TTPs | T1190 |
Control State | Passed |
Control Stats | 8 passed out of 10 total |
Resulting Efficacy | 8. |
Explanation: The control directly mitigates the MITRE Technique, resulting in a high efficacy score.
Example 3: MITRE Technique with Non-Matching Control
Field | Value |
|---|---|
MITRE Technique | TTP T1190 |
Control Framework | Vendor A |
Control TTPs | T1110 (unrelated technique) |
Control State | Passed |
Resulting Efficacy | 0.0 |
Explanation: Since the control does not address the MITRE Technique, the efficacy is 0.0.
Example 4: Unmapped MITRE Technique with Controls
Field | Value |
|---|---|
MITRE Technique | None |
Control Framework | Vendor A |
Control 1 | T1190 |
Control 2 | T1110 |
Resulting Efficacy | 3.6 |
Explanation: The weighted efficacy of unmapped controls is computed, resulting in an overall score of 3.6.