Input variant of RuleBodyVulnerability. A rule with this body must apply to APPLICATION_INSTALL, ENDPOINT, or SERVICE, the object types that carry CPEs.
Fields
| Input Field | Description |
|---|---|
granularity - RuleVulnerabilityGranularity!
|
Whether the rule raises a record for each matched CVE or one per object. Default = PER_CVE |
minimumSeverity - Severity
|
When set, only CVEs whose severity is at or above this severity are raised. A CVE's severity is its CVSS rating, raised when its EPSS score shows it's likely to be exploited soon, so a CVE with neither is not raised. |
knownExploitedOnly - Boolean!
|
When true, only CVEs on the CISA Known Exploited Vulnerabilities catalog are raised. Default = false |
excludedCveIds - [String!]
|
CVE ids never raised by this rule, as accepted risk. Each must be a CVE id such as CVE-2024-12345. |
Used by
RuleBodyInputinput: One-of input mirroring the RuleBody union.
Example
Example
{
"granularity": "PER_CVE",
"minimumSeverity": "INFORMATIONAL",
"knownExploitedOnly": true,
"excludedCveIds": ["xyz789"]
}