Skip to main content

The first search

Everything on this page works with nothing connected. The corpus is the same for every workspace, so a fresh sign-in already has over 366,000 records to search. Connecting a manager adds the other half, which is which of those records touch software the fleet runs, and that is covered in Fleet exposure.

Search a package​

Open Vulnerabilities. The search box reaches CVE identifiers, titles, vendor names, product names and distro package names, so type a package name the fleet runs, libssl3 for instance, and the list narrows to the records that name it. The count above the results is the real number of matches, and under it the page says when the mirror last synced and how a record reaches the list: a CVE appears here once Wazuh CTI carries it, which can be a day or more after it is published elsewhere.

Each row carries the columns that answer the first question, which is whether this record matters:

ColumnWhat it shows
SeverityThe worst CVSS base score across the sources that scored it, or Not scored when none has
CVEThe identifier
AffectsThe vendor, product or package the record is about
ExploitationCISA KEV when the record is in the Known Exploited Vulnerabilities catalog, Public exploit when an upstream reference is tagged as one, otherwise "none known". A record with both shows the first and a +1 that names the other on hover
EPSSFIRST's probability of observed exploitation in the next 30 days
SourcesOne dot per advisory source that has ruled on the record
YoursHow many of the connected managers report an affected package installed, once a manager is sharing inventory
PublishedThe date the record was published
UpdatedThe date the record last changed upstream. Hidden by default, and Columns shows it

The Filters button narrows the list by severity, state, KEV membership, exploit availability, source, date, and a CVSS or EPSS range. Each filter in use shows as a chip under the search box. Clicking a column header sorts the whole result on that column, and a second click reverses it. The full list of filters and sorts is in The corpus.

Read a record​

Click a row and the record opens under it. The sections are in the order of the questions a person asks: do I care, who says what, does it touch my machines, what has moved, where do I read more.

  • The badge row repeats the severity, KEV, exploit and EPSS badges, adds the CWE identifiers, and, when a manager is sharing inventory, a chip saying how many of the connected managers it affects.
  • CISA required action appears only for KEV records, with the action CISA published and the date federal agencies had to act by.
  • What each source says lists every source side by side: its score, the CVSS version it used, and the vector. When the sources disagree by a point or more the subtitle says by how much, because which one to believe depends on what the fleet runs. A source that publishes a verdict word instead of a score is shown verbatim.
  • Your exposure lists the packages the connected managers report installed that this record matches, with the installed version, the fixed version where one is published, and the managers concerned. See Fleet exposure.
  • Affected is the upstream affected list: vendor and product, both clickable, the version range, and which source published the entry.
  • Packages is the list of distro package names the trackers have tied to the record, with the fixed version where there is one.
  • Advisory activity is the record's history as its sources tell it: when it was published, when each source scored or updated it, and when it entered the KEV catalog. Every timestamp is the one its source published.
  • References, with their tags, and links to the same record on Wazuh CTI and NVD.
note

An older record with a short advisory activity list is not missing data. It is the state the record arrived in, and a new line appears each time a source revisits it. See Advisory activity on a record.

Browse the Packages page​

Packages turns the corpus around: instead of records, it lists the package names, products and vendors behind them, on three tabs. Every row opens the Vulnerabilities list filtered down to it, so openssl as a vendor row is a different view from libssl3 as a package row. Package rows carry CVE and KEV counts and, once a manager is sharing inventory, where in the fleet the package is installed. On that tab the Filters button can keep only what the connected managers install. Each tab opens on the most affected rows, 20 per page with the real total under the table, and a click on a column header sorts the whole tab on that column.

Save a first watchlist​

The package and vendor rows on the Packages page each end in a Watch link. It opens the watchlist builder with that package or vendor already filled in. Pick which changes should count, give it a name, and create it. From then on Pharos raises an advisory when a matching record is published or changes in the chosen way, and the advisory lands on the Advisories page. Nothing about this is billed: advisories come from the catalog, not from the fleet.

The kinds of watchlist, the triggers and what each one honestly means are in Watchlists and advisories. When a fleet is connected, the next thing to read is Fleet exposure. Until then, Investigate is the other page that works on day one.