Predicting exploitation: A practitioner's guide

In this session, Tod Beardsley (runZero) sits down with Jay Jacobs (Empirical Security), a co-creator of the Exploit Prediction Scoring System (EPSS), to explore the science and practice of predicting vulnerability exploitation. Jacobs details the evolution of EPSS from a research initiative into a vital, daily-published API that provides probability scores and percentile rankings for hundreds of thousands of CVEs. This data-driven approach allows security teams to move beyond traditional severity scores and focus on the vulnerabilities that attackers are actually targeting in the wild.

The conversation clarifies how EPSS differs from other scoring systems, specifically explaining the relationship between a probability score and a percentile rank. Jacobs addresses common misconceptions about low-probability scores, noting that even a small percentage can be highly significant when measured across a massive population of vulnerabilities. He also breaks down the technical backend, distinguishing between the use of Large Language Models for data cleaning and the core machine learning models used to generate accurate, transparent scores.

Meet Our Speakers

todb

VP of Security Research, runZero

Jay Jacobs

Founder at Empirical Security; Chief Data Scientist Emeritus, Founder at Cyentia Institute

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Podcasts
Bug bounties in the age of AI
In this session, Tod Beardsley and Casey Ellis explore the evolving role of bug bounties in a world increasingly shaped by artificial intelligence.
Podcasts
The network edge: EOL and exploitation
Tod Beardsley is joined by Kimber Duke & Patrick Garrity of VulnCheck to discuss the critical intersection of EOL hardware and cybersecurity...
Podcasts
Mute the sirens: Prioritizing vulnerability noise
In this session, Tod Beardsley and Mark Lambert discuss the escalating challenge of managing vulnerability noise in the era of AI.
Podcasts
Force multiplied: Community-powered vuln detection
Tod Beardsley & Rishi Sharma discuss the origins of Nuclei, an open-source framework that has revolutionized how security teams validate...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.