Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “VEX”
3 publicationsTechnical guideSource-based analysisTechnical guideSource-based analysisTechnical guideSource-based analysis
A defensible cloud patch queue starts with exploitation evidence
Join exploitation evidence to affected assets, exposure, ownership and verified remediation without turning CVSS, EPSS or a catalog entry into a complete risk score.
Detection & response · CISA / NIST / FIRST · By Cloud Security DeskTurn SBOM and VEX records into patch decisions
A VEX statement is an assertion about a specific product and vulnerability. Match its scope and conditions before using it to suppress a finding.
Workload security · CISA / OpenVEX / CycloneDX / OASIS · By Cloud Security DeskVerify container provenance before admitting a pinned image
Use the digest to identify the artifact, then check who signed it, which builder produced it, and which evidence survived promotion into the deployment registry.
Workload security · Kubernetes / Docker / Sigstore · By Cloud Security Desk