
DEF CON 32 - Using EPSS for Better Management Vulnerability Management - Jerry Gamblin
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 24:34
The Exploit Prediction Scoring System (EPSS) predicts the likelihood of a CVE being exploited in the next 30 days using data from 2,500 variables, updated nightly 5:58.
Key Takeaways:
• EPSS scores range from 0.00004 to 1.0, with a mean of 0.04; a threshold of 0.5 targets ~5,671 high-risk CVEs 8:49.
• EPSS is designed for network-based attacks and should only be used after all known exploited vulnerabilities are patched 12:47.
• EPSS integrates with GitHub and GitLab, enabling automated scanning of Docker containers and enforcing patching thresholds via GitHub Actions 15:51.
• Data sources include real-world threat intelligence from Microsoft, Yahoo, and other companies, with a public guide on risk-based prioritization available 14:08.
EPSS is a valuable tool for prioritizing patching, but it must be used after known exploitable vulnerabilities are addressed and with awareness of its limitations in non-network environments.
Sources:
- 2:38 Overview of EPSS and its purpose in vulnerability management.
- 5:58 Explanation of EPSS data sources and scoring mechanism.
- 8:49 EPSS score distribution and threshold recommendations.
- 12:47 Guidance on when and how to use EPSS effectively.
- 14:08 Public guide on risk-based prioritization using EPSS.
- 15:51 Integration of EPSS into GitHub and GitLab workflows.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[Applause] thank you uh thank you everyone for having me here um he didn't ask but I I'm interested how many people work directly or indirectly with vulnerability Management in in their day jobs all right that that that was the hands that I I wanted to see there right so we'll get started here this is super quick and and we'll dig in and have some time for questions at the end about me my name is Jay Gamblin uh you can just call me a vulnerability Enthusiast that's kind of my unofficial title I run two websites that you guys might like to look at one of them is cv. IU um what it'll do is it'll give you how many cves are published daily weekly help you kind of break down so if you have to write any reports and push those reports up to your management I built this site specifically for peopl…