Skip to content

docs: threat-intelligence (EPSS/KEV) fields are editable on the Add/Edit Finding form - #15984

Open
Maffooch wants to merge 1 commit into
bugfixfrom
docs/finding-form-threat-intel
Open

Maffooch wants to merge 1 commit into
bugfixfrom
docs/finding-form-threat-intel

Conversation

@Maffooch

@Maffooch Maffooch commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

[sc-15506]

Description

Documentation only. The Pro UI Add/Edit Finding form now exposes the threat-intelligence fields (EPSS Score, EPSS Percentile, Known Exploited, Used in Ransomware, KEV Date Added) in a collapsed Threat Intelligence panel under Optional Fields, so a finding created by hand without a CVE can still carry exploit evidence. These pages are updated to match:

  • triage_findings/findings_workflows/editing_findings.md: new Threat Intelligence bullet in the Edit Finding form field list. Explains that the EPSS/KEV sync normally owns these values, how the sync treats hand-entered values (replaced on a finding that references a CVE, KEV facets cleared when none of its CVEs are KEV-listed, kept on a finding without a CVE), that hand-set values feed priority and risk, and that a Rules Engine rule reacting to a hand-set flag should use the KEV: Known Exploited condition because the FedRAMP review template keys on Exploit Maturity from the threat-intelligence feed.
  • triage_findings/finding_scoring/epss_kev.md: the "On the Finding" bullet notes the values can also be set by hand and links to the section above.
  • asset_modelling/engagements_tests/PRO__findings.md: fixes the "ESS" typo and adds a sub-bullet about editability and sync overwrite.
  • triage_findings/findings_workflows/create_findings_manually.md: one paragraph pointing at the panel.

English pages only; translated siblings are regenerated from the English source per docs/TRANSLATIONS.md.

Test results

Docs-only change, no code or tests touched. Proofread; all internal links point at existing pages and anchors.

Documentation

This PR is the documentation change for a Pro UI form update shipping on the same release line (bugfix).

…it Finding form

The Pro UI Add/Edit Finding form now exposes EPSS Score, EPSS Percentile,
Known Exploited, Used in Ransomware and KEV Date Added in a Threat Intelligence
panel under Optional Fields. Document the panel, how the EPSS/KEV sync treats
hand-entered values (replaced on CVE-backed findings, kept on findings without a
CVE), that hand-set values feed priority and risk, and that a rule reacting to a
hand-set flag should use the KEV: Known Exploited condition because the FedRAMP
review template keys on Exploit Maturity from the threat-intelligence feed. Also
fix the "ESS" typo on the Pro Findings reference page.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@Maffooch Maffooch added this to the 3.3.200 milestone Sep 16, 2026
@github-actions github-actions Bot added the docs label Sep 16, 2026
@Maffooch
Maffooch enabled auto-merge September 16, 2026 20:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant