Skip to content
Whats The Hax?Source-backed field notes
← All resources

operations guide

A defensible exploited-vulnerability triage guide

A short, auditable path from a CISA KEV alert to asset scope, exploitation checks, remediation, verification, and an explicit owner.

CISA KEVvulnerability managementincident response
Published
Sources checked
By
Whats The Hax editorial process

Open one triage record per vulnerability and asset group

CISA describes the KEV catalog as an authoritative source of vulnerabilities exploited in the wild and says organizations should use it as an input to prioritization. A KEV entry establishes observed exploitation somewhere; it does not prove compromise in your environment.

  • Record the CVE, KEV date added and due date, vendor action, source URLs, detection time, and triage owner.
  • Identify products, exact versions, exposure, business service, data sensitivity, safety impact, and recovery options from an asset inventory.
  • Mark each asset group Not affected, Susceptible, Compromised, or Unknown, and retain the evidence for that decision.

Separate remediation urgency from incident evidence

Use vendor instructions and environmental facts to decide treatment. CISA's SSVC model adds exploitation status, technical impact, mission prevalence, and public-wellbeing or safety impact instead of treating CVSS as the whole decision.

  • If the vulnerable product is absent, preserve the query, inventory timestamp, and version evidence that support Not affected.
  • If present, apply the vendor update or mitigation within the risk-based deadline and track exceptions with an accountable owner and expiry.
  • Search for vendor or CISA indicators and abnormal activity. Evidence of exploitation starts incident response; patching alone does not remove an intruder.

Close with verification

Re-scan or otherwise verify the fixed build or mitigation, confirm the service is healthy, record residual exceptions, and update the asset inventory. A ticket closed because a deployment job ran is weaker evidence than a version check and exposure test.

Limits

This guide is a general workflow. Binding federal deadlines may not apply to a private organization, and the right containment, evidence-preservation, remediation, and disclosure steps depend on the system and incident.

Sources

The source-check date records editorial review. Routine builds do not advance it.

Revision history

  • — Initial guide published after checking the CISA KEV, SSVC, and response-playbook sources.