Skip to main content
TA-Vulnerability catalog app icon

TA-Vulnerability catalog

Collects vulnerability intelligence from CISA KEV catalog and FIRST.org EPSS scores for vulnerability prioritization and threat correlation.Built by hiroaki ogawa
splunk product badge

Default Version 1.0.0

September 5, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4

Rating
0
(0)

Log in to rate this app

Support
Not Supported

The TA-Vulnerability catalog is a Splunk add-on that ingests vulnerability intelligence from authoritative external sources to support security operations and vulnerability management workflows. It collects data from the CISA Known Exploited Vulnerabilities (KEV) catalog, which lists CVEs actively exploited in the wild, and the FIRST.org Exploit Prediction Scoring System (EPSS), which provides probabilistic scores for the likelihood of CVE exploitation. The add-on uses modular inputs to perform incremental data collection at configurable intervals, writing events to source types vulninfo:kevcatalog and vulninfo:epss. By centralizing vulnerability intelligence in Splunk, the add-on enables correlation of enterprise asset inventories and patch status against known threats, supports prioritization based on exploit probability, and provides up-to-date threat context for incident response and risk assessment. The add-on includes a configuration interface for managing data collection parameters and proxy settings.