Skip to main content

CISA Known Exploited Vulnerabilities

Threat Intelligence

The CISA Known Exploited Vulnerabilities (KEV) Connector integrates with the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog data feed. The catalog is a public, authoritative list of CVEs that CISA has confirmed are being actively exploited in the wild, along with the remediation action and federal compliance due date for each.

The connector downloads the catalog feed (a single JSON document, optionally gzip-compressed), parses every catalog entry, and emits one Exploited Vulnerability record per CVE. These records map to the Brinqa Unified Data Model (UDM) CveRecord model, enriching CVE records in the platform with CISA's actively-exploited flag, the CISA-mandated remediation action, and the federal remediation due date. This connector is a Threat Intelligence data source.

Data retrieved from CISA Known Exploited Vulnerabilities

Connector ObjectRequiredMaps to Data Model
Exploited VulnerabilityYesCve Record
note

For detailed steps on how to view the data retrieved from CISA Known Exploited Vulnerabilities in the Brinqa Platform, see How to view your data.