kevrichment CVE enrichment
← Dashboard

Schema Reference

Full field reference for the kevrichment CVE enrichment schema. Version 1.0.

Top-Level
Field Type Description Source
schema_versionstringSchema version identifierkevrichment
cve_idstringCVE identifier (CVE-YYYY-NNNNN)KEV
cve_publishedISO 8601When the CVE was published by NVDNVD
last_researchedISO 8601When this record was last enrichedkevrichment
KEV Catalog Fields
Field Type Description Source
kev_date_addeddateWhen CISA added this to KEVCISA KEV
kev_vendor_projectstringVendor/project nameCISA KEV
kev_productstringProduct nameCISA KEV
kev_short_descriptionstringCISA's short vulnerability descriptionCISA KEV
kev_required_actionstringRequired remediation action per CISACISA KEV
kev_due_datedateCISA-assigned remediation due dateCISA KEV
kev_vulnerability_namestringFormal vulnerability nameCISA KEV
NVD Fields
Field Type Description Source
nvd_descriptionstringEN-language description from NVDNVD
cwestring[]CWE weakness identifiersNVD
cvss_v3_base_scorefloat (0-10)CVSS v3 base scoreNVD
cvss_v3_vectorstringFull CVSS v3 vector stringNVD
cpe_affectedstring[]Affected CPE URIsNVD
Vulnrichment (SSVC)
Field Type Description Source
vulnrichment.automatable'yes' | 'no' | 'unknown'Whether exploitation can be automated per SSVCCISA Vulnrichment
vulnrichment.technical_impact'total' | 'partial' | 'unknown'SSVC technical impact assessmentCISA Vulnrichment
vulnrichment.exploitation_status'active' | 'unknown'Whether exploitation has been detectedCISA Vulnrichment
BOD 26-04 Timeline
Field Type Description Source
bod_26_04.timeline_if_publicly_exposedstringRemediation timeline for internet-facing assetskevrichment
bod_26_04.timeline_if_not_publicly_exposedstringRemediation timeline for internal assetskevrichment
bod_26_04.three_day_qualifyingboolAll BOD 26-04 risk factors presentkevrichment
bod_26_04.requires_forensic_analysis_if_publicboolForensic triage required (public assets)kevrichment
kevrichment Research
Field Type Description Source
kevrichment_research.vulnerable_componentstringSpecific component/feature affectedResearch
vulnerable_component_enabled_by_default'yes' | 'no' | 'unknown'Whether component is default-enabledResearch
delivery_mechanismstringHow attacker delivers the exploitResearch
preconditions_for_exploitstringDeployment conditions needed for exploitationHermes AI / Deterministic
public_poc_exists'yes' | 'no' | 'unknown'Whether public exploit/PoC was foundResearch
public_poc_urlsstring[]URLs to discovered PoC repositoriesResearch
vendor_advisory_urlstringLink to vendor security advisoryResearch
hunting_hypothesisstringSpecific attacker behavior/TTP to monitor forHermes AI / Deterministic
kevrichment_summarystringOne-line summary of findingsResearch
Research Metadata
Field Type Description Source
research_meta.timestampISO 8601When research was performedkevrichment
research_meta.wall_time_secondsfloatElapsed research timekevrichment
research_meta.searches_performedintNumber of web searcheskevrichment
research_meta.sources_consultedstring[]URLs visited during researchkevrichment
QC Notes
Field Type Description Source
qc_notes[].severity'error' | 'warn' | 'info'QC check severitykevrichment
qc_notes[].checkstringQC check identifierkevrichment
qc_notes[].fieldstringJSON path to affected fieldkevrichment
qc_notes[].detailstringHuman-readable QC findingkevrichment
qc_notes[].auto_fixedboolWhether issue was auto-correctedkevrichment
Sample CVE Record (click to expand)