Risk-based vulnerability
management, scored and evidenced.
The exploitation risk score fuses EPSS likelihood, CISA KEV status, CVSS severity, CWE-based impact weighting and threat-actor telemetry into one 0 to 100 prioritisation score that uses live exploitation data from Shadowserver, so you can defend the decision to your board, your auditor, and yourself.
Precursor Intelligence is a risk-based vulnerability management platform that fuses EPSS, CISA KEV, CVSS, CWE-based impact weighting and threat-actor telemetry into one prioritisation score, so teams patch the 2 to 5 percent of CVEs attackers actually exploit. Every ranking comes with the evidence behind it, the baseline of a five-dimension exploitation risk score which uses live exploitation data from Shadowserver honeypot sensors, with transparent published pricing and a production MCP server.
Already have an account? Log in
The exploitation risk score
A five-dimension score from 0 to 100. The baseline blends EPSS exploitation likelihood, CISA KEV listing status and CVSS severity above 7.0. The full production score adds two further dimensions: a CWE-based impact weighting for vulnerability classes like remote code execution and command injection, and threat-actor attribution telemetry.
Most tools hand you a score with no working. Every ranking shows the signals that drove it. If you can see the evidence, you can challenge it. If you can challenge it, you can trust it.
EPSS exploitation likelihood
+ CISA KEV listing status
+ CVSS severity uplift
Of all published CVEs, only 2 to 5 percent are ever confirmed exploited in the wild (EPSS v3, Jacobs et al.). The rest is noise your team is paying to triage.
A rising share of confirmed breaches begin with vulnerability exploitation as the initial access vector (Verizon DBIR 2025), ahead of credential-based attacks in several sectors.
CVEs added to the CISA Known Exploited Vulnerabilities catalogue are typically weaponised within days of disclosure, not weeks.
Built on real exploitation signal
The score uses live exploitation data from Shadowserver honeypot sensors, so the ranking reflects what is being attacked, not just theoretical severity. Every single signal on its own leaves a gap, and fusing them is what makes the ranking hold up, alongside our threat intelligence platform.
| Scoring method | The gap on its own |
|---|---|
| exploitation risk scoreBest | Combines likelihood, confirmed exploitation, severity, threat-actor attribution and honeypot signal |
| EPSS alone | Predicts likelihood, but ignores confirmed and observed exploitation |
| CVSS alone | Measures severity, but around 60% of CVEs score 7 or above, so it cannot sequence them |
| CISA KEV alone | Confirms exploitation, but misses mass-exploited CVEs it has not listed yet |
We are not a Nessus-style host scanner
The exploitation risk score is a triage signal, not an exploit detector or a patch orchestrator. It does not scan your network. It takes the CVE list your existing scanner already produces, or a plain tech-stack inventory, and hands back a defensible, evidenced queue: what to patch first, what can wait, and the data to justify both calls in a change advisory board or an audit.
The prioritisation layer for your vulnerability management tools
Precursor Intelligence is the risk-based vulnerability management layer that sits on top of the vulnerability management tools and software you already run, from Nessus, Qualys and Rapid7 to your own tech-stack inventory. It turns raw findings into an evidenced, exploitability-ranked queue, so threat and vulnerability management becomes a decision you can defend rather than a list you work down by severity.
Get the fix, not just the finding
A ranked list still leaves the work to you. Every scored CVE in Precursor Intelligence comes with a remediation plan and an ATT&CK mapping, and the ranking that produced it can reach your team the moment it changes, so the score turns into a patch in minutes rather than another afternoon in the vendor advisory.
Remediation plans with the exact commands
Every ranked CVE ships with a step-by-step remediation plan: the exact CLI commands to apply the fix, a workaround configuration if you cannot patch immediately, and a direct link to the vendor patch. No re-deriving the right syntax under a change freeze.
$ apt-get install --only-upgrade openssl
$ systemctl restart nginx
Alerts that reach the right channel
The moment a CVE lands in the NVD, or a tracked vulnerability's score changes, an alert routes to Email, Slack, MS Teams or a webhook, wherever the team already works.
A weekly PDF executive report gives leadership the summary without a dashboard login, so the board sees the trend, not just the backlog.
Mapped to MITRE ATT&CK
Each vulnerability is mapped to the ATT&CK techniques it enables, so the finding connects directly to the detection coverage your SOC already tracks, not a severity number sitting on its own. The score, the fix and the detection rule stay tied to the same technique from triage through to close-out.
Score your backlog. Defend the decision.
Free to start, no card required. Query the same scoring engine from Claude via the production MCP server, or through the dashboard and API. Transparent published pricing when you outgrow the free tier. Precursor Intelligence is the continuous bookend to point-in-time penetration testing and 24/7 managed SOC.
Common questions
The exploitation risk score is a 0 to 100 vulnerability prioritisation score built from EPSS exploitation likelihood, CISA KEV status and a CVSS severity uplift, plus two further dimensions in the production model.
- The baseline blends: EPSS exploitation likelihood, CISA KEV listing status, and a CVSS severity uplift above 7.0.
- The full production score adds CWE-based impact weighting for vulnerability classes such as remote code execution and command injection, plus threat-actor attribution telemetry.
Most tools hand you a score with no working. Every ranking shows the signals that drove it, so it is a number you can check, not a black box you have to trust on faith.
CVSS measures theoretical severity: what could happen if a vulnerability were exploited. It does not tell you whether it will be. The exploitation risk score layers EPSS exploitation-likelihood data and confirmed CISA KEV exploitation on top of CVSS, so a high-CVSS bug with no exploitation evidence scores lower than a moderate-CVSS bug already on the KEV list and being used by threat actors.
It uses live exploitation data from Shadowserver honeypot sensors as one of its inputs, so the ranking reflects what is being attacked, not just theoretical severity. Fusing that with EPSS, CISA KEV and CVSS puts the vulnerabilities most likely to be used ahead of those that are not.
No. Precursor Intelligence is not a host scanner and does not detect vulnerabilities on your estate. It takes the CVE output from your existing scanner, or a simple tech-stack inventory, and returns a defensible, evidenced priority order. It is a triage layer that sits on top of a scanner, not a replacement for one.
Yes. Precursor Intelligence runs a production MCP server, so you can query the same scoring engine directly from Claude or another MCP-compatible agent, alongside the REST API and dashboard.
Precursor Intelligence is free to start, with transparent, published pricing for higher usage tiers rather than a quote-only sales process. Score your first backlog without talking to sales.
Risk-based vulnerability management (RBVM) prioritises vulnerabilities by how likely they are to actually be exploited, rather than by raw CVSS severity. Precursor Intelligence is the RBVM layer: it takes the output of your existing vulnerability management tools and returns a queue ranked by the exploitation risk score, so you fix what attackers use, not what a scanner flags.
Vulnerability management is the whole lifecycle of finding, assessing and remediating vulnerabilities. Vulnerability prioritisation is the step in the middle that decides what to fix first. Most teams have tools for discovery and remediation but sequence by severity alone. Precursor Intelligence adds exploitability-based prioritisation on top of the vulnerability management tools you already run.