<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Had you heard of/worked with EPSS (Exploit Prediction Scoring System) before? in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Had-you-heard-of-worked-with-EPSS-Exploit-Prediction-Scoring/m-p/58879#M3904</link>
    <description>&lt;P&gt;EPSS&amp;nbsp;(Exploit Prediction Scoring System)&lt;BR /&gt;&lt;BR /&gt;• Open-source project led by RAND and Cyentia&lt;BR /&gt;• Machine learning system designed to predict the likelihood&amp;nbsp;of a given vulnerability being exploited&lt;BR /&gt;• Explicitly trying to provide better intelligence than the Common Vulnerability Scoring System (CVSS)&lt;BR /&gt;• Training inputs: past observations of CVE exploitation&lt;BR /&gt;• Fortinet, Cisco, Greynoise, F5!&lt;BR /&gt;• Runtime inputs: &amp;gt;1500 vulnerability features&lt;BR /&gt;• E.g. exploit code available, RCE, CPE, CVSS vectors&lt;BR /&gt;• Model: XGBoost (ensemble of decision trees with gradient&amp;nbsp;boosting)&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.first.org/epss/" target="_blank"&gt;https://www.first.org/epss/&lt;/A&gt; for general information&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.first.org/epss/api" target="_blank"&gt;https://www.first.org/epss/api&lt;/A&gt; for API documentation&lt;BR /&gt;&lt;BR /&gt;More details on webinar :&amp;nbsp;&lt;A title="&amp;quot;Vulnerability Intelligence, Three Ways&amp;quot;" href="https://www.isc2.org/News-and-Events/Webinars/Security-Briefing?commid=578541&amp;amp;?utm_campaign=communication_reminder_starting_now_registrants&amp;amp;utm_medium=email&amp;amp;utm_source=brighttalk-transact" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;"Vulnerability Intelligence, Three Ways"&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.csoonline.com/article/3680570/epss-explained-how-does-it-compare-to-cvss.html" target="_blank"&gt;https://www.csoonline.com/article/3680570/epss-explained-how-does-it-compare-to-cvss.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 May 2023 13:43:06 GMT</pubDate>
    <dc:creator>Kyaw_Myo_Oo</dc:creator>
    <dc:date>2023-05-03T13:43:06Z</dc:date>
    <item>
      <title>Had you heard of/worked with EPSS (Exploit Prediction Scoring System) before?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Had-you-heard-of-worked-with-EPSS-Exploit-Prediction-Scoring/m-p/58879#M3904</link>
      <description>&lt;P&gt;EPSS&amp;nbsp;(Exploit Prediction Scoring System)&lt;BR /&gt;&lt;BR /&gt;• Open-source project led by RAND and Cyentia&lt;BR /&gt;• Machine learning system designed to predict the likelihood&amp;nbsp;of a given vulnerability being exploited&lt;BR /&gt;• Explicitly trying to provide better intelligence than the Common Vulnerability Scoring System (CVSS)&lt;BR /&gt;• Training inputs: past observations of CVE exploitation&lt;BR /&gt;• Fortinet, Cisco, Greynoise, F5!&lt;BR /&gt;• Runtime inputs: &amp;gt;1500 vulnerability features&lt;BR /&gt;• E.g. exploit code available, RCE, CPE, CVSS vectors&lt;BR /&gt;• Model: XGBoost (ensemble of decision trees with gradient&amp;nbsp;boosting)&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.first.org/epss/" target="_blank"&gt;https://www.first.org/epss/&lt;/A&gt; for general information&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.first.org/epss/api" target="_blank"&gt;https://www.first.org/epss/api&lt;/A&gt; for API documentation&lt;BR /&gt;&lt;BR /&gt;More details on webinar :&amp;nbsp;&lt;A title="&amp;quot;Vulnerability Intelligence, Three Ways&amp;quot;" href="https://www.isc2.org/News-and-Events/Webinars/Security-Briefing?commid=578541&amp;amp;?utm_campaign=communication_reminder_starting_now_registrants&amp;amp;utm_medium=email&amp;amp;utm_source=brighttalk-transact" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;"Vulnerability Intelligence, Three Ways"&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.csoonline.com/article/3680570/epss-explained-how-does-it-compare-to-cvss.html" target="_blank"&gt;https://www.csoonline.com/article/3680570/epss-explained-how-does-it-compare-to-cvss.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 13:43:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Had-you-heard-of-worked-with-EPSS-Exploit-Prediction-Scoring/m-p/58879#M3904</guid>
      <dc:creator>Kyaw_Myo_Oo</dc:creator>
      <dc:date>2023-05-03T13:43:06Z</dc:date>
    </item>
  </channel>
</rss>

