Vulnerability haruspicy: picking out risk signals from scoring system entrails

Vulnerability scoring frameworks promise clarity but often deliver confusion. CVSS (Common Vulnerability Scoring System) bends messy math into neat curves, EPSS (Exploit Prediction Scoring System) leans on opaque models, and SSVC (Stakeholder-Specific Vulnerability Categorization) relies on structured intuition. 

Tod Beardsley explores the strengths and flaws of these systems, asking whether they improve risk decisions or simply rationalize them. Expect smart analysis, best practices (and astrology jokes!) along the way.

Explore related resources:

Meet Our Speakers

todb

VP of Security Research, runZero

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Talks
The once and future rules of cybersecurity (SecTor keynote)
In this session, HD revisits the rules we lived by in the 2000s, reveal which ones still matter, which ones failed us, and what new rules we'll...
Talks
Vulnerability haruspicy: using woo to confirm your biases (NorthSec 25)
This talk digs into the strengths, weaknesses, and absurdities of CVSS, EPSS, and SSVC, comparing them to the reality of how security teams...
Talks
DEF CON 33 - There and back again: detecting OT devices across protocol gateways (Rob King)
Presented by Rob King at DEF CON 33, this talk discusses techniques for detecting devices on the "other side" of protocol gateways.
Talks
DEF CON 33 - Shaking out shells with SSHamble (HD Moore)
This session is an extension of our 2024 work and includes new research as well as big updates to our open source research and assessment tool,...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.