Policies and findings · GraphQL type

RuleBodyVulnerability type

The body of a VULNERABILITY rule: how its records are grouped, and which known CVEs it raises.

Each time the rule runs, the CPEs recorded on every object it applies to are matched against the CVE catalog. Matched CVEs that pass the filters below raise findings and issues; a CVE that stops matching, because the software was patched or the CVE was excluded, is resolved. A rule with this body must apply to APPLICATION_INSTALL, ENDPOINT, or SERVICE, the object types that carry CPEs.

Fields

Field Name Description
granularity - RuleVulnerabilityGranularity! Whether the rule raises a record for each matched CVE or one per object. See RuleVulnerabilityGranularity.
minimumSeverity - Severity When set, only CVEs whose severity is at or above this Severity are raised. A CVE's severity is its CVSS rating, raised when its EPSS score shows it's likely to be exploited soon, so a CVE with neither is not raised.
knownExploitedOnly - Boolean! When true, only CVEs on the CISA Known Exploited Vulnerabilities catalog are raised.
excludedCveIds - [String!]! CVE ids never raised by this rule, as accepted risk.

Used by

  • RuleBody union: A polymorphic body for a rule type.
  • RuleType enum: Describes how a rule gathers the input its function evaluates.

Example

Example

{
  "granularity": "PER_CVE",
  "minimumSeverity": "INFORMATIONAL",
  "knownExploitedOnly": true,
  "excludedCveIds": ["abc123"]
}