CERTCC / SSVC

Stakeholder-Specific Vulnerability Categorization
https://certcc.github.io/SSVC/
Other
128 stars 32 forks source link

Chainability of a vul #102

Closed j--- closed 1 year ago

j--- commented 3 years ago

@cgyarbrough :

Consider 'chain ability' of a given vulnerability. This is probably beyond the scope of {what's current in automatable}, but certain vulnerabilities might be considered more 'beachhead' category (i.e., tending to allow for ingress to a system or software) and others are more effective at lateral movement or secondary instantiation in a blended or staged exploitation attempt. DoDCAR has done some initial work on the additive nature of exploits, but each of those is composed of underlying exploitable vulnerabilities.

This would be a good topic to address when we address #78 (after v2 is set)

ahouseholder commented 3 years ago

Some incomplete ideas capturing notes from conversation on 2021-02-24:

ahouseholder commented 1 year ago

Converting to discussion. Note also that #78 referenced above has also been converted to discussion #227