Policies and findings · GraphQL input

RuleBodyVulnerabilityInput input

Input variant of RuleBodyVulnerability. A rule with this body must apply to APPLICATION_INSTALL, ENDPOINT, or SERVICE, the object types that carry CPEs.

Fields

Input Field Description
granularity - RuleVulnerabilityGranularity! Whether the rule raises a record for each matched CVE or one per object. Default = PER_CVE
minimumSeverity - Severity When set, only CVEs whose severity is at or above this severity are raised. A CVE's severity is its CVSS rating, raised when its EPSS score shows it's likely to be exploited soon, so a CVE with neither is not raised.
knownExploitedOnly - Boolean! When true, only CVEs on the CISA Known Exploited Vulnerabilities catalog are raised. Default = false
excludedCveIds - [String!] CVE ids never raised by this rule, as accepted risk. Each must be a CVE id such as CVE-2024-12345.

Used by

Example

Example

{
  "granularity": "PER_CVE",
  "minimumSeverity": "INFORMATIONAL",
  "knownExploitedOnly": true,
  "excludedCveIds": ["xyz789"]
}