Riskform Intelligence
For teams that want immediate search, prioritization and campaign intelligence without a deployment project.
Riskform turns fragmented vulnerability and threat intelligence into explainable remediation campaigns, ordered by the risk they can remove and the effort required to remove it.
NVD · CWE · CPE · CVSS · EPSS · KEV
Taxonomy · threat modifier · grouping · planning
Now · Next · Later · API · alerts
Most vulnerability programs produce more findings than teams can remediate. Riskform changes the unit of prioritization from individual CVEs to coordinated actions that remove meaningful risk.
CVSS, EPSS, KEV, ransomware use, vendor advisories and threat reporting all describe different parts of the same decision.
Engineering teams patch products, upgrade releases, change configuration and deploy controls. They do not remediate abstract vulnerability IDs one by one.
Useful prioritization should begin with public intelligence and improve when inventory, VM, CMDB, network and identity context become available.
The engine is transparent by design. Taxonomy, scoring, grouping and planning logic are externalized in versioned YAML policies so every recommendation can be reproduced and explained.
Build one CVE intelligence object from NVD, weakness, product, severity, exploitation and threat signals.
Map public evidence into a stakeholder-friendly adversarial taxonomy anchored in MITRE ATT&CK.
Combine exploitation activity, technical severity and Riskform proprietary intelligence without hiding source evidence.
Group vulnerabilities by the remediation or mitigation action that can retire the most risk with the least effort.
01 / T1190Internet Entry02 / T1203Client Exploit03 / T1068Privilege Gain04 / T1212Credential Compromise05 / T1210Lateral Exploitation06 / T1211Stealth via Exploit07 / T1687Defense Impairment08 / T1499.004Availability Impact09 / CATCH-ALLOther ATT&CK Exploitation10 / GENERALGeneral ExposureRiskform continuously converts vendor updates, security research, news, blogs, underground reporting and other intelligence into a controlled scoring modifier, using source reliability, recency, independence and duplicate suppression.
TIM (Threat Intelligence Modifier) can increase priority when new independent evidence appears. It cannot reduce priority simply because the internet is quiet.
A campaign is a set of vulnerabilities for which one coordinated remediation or mitigation action removes a meaningful amount of risk. That is what engineering teams can schedule, own and complete.
Shared vendor release · Internet Entry · 17 CVEs · strong exploit activity
One rollout pattern · Client Exploit · 24 CVEs · high action reuse
Configuration mitigation · Lateral Exploitation · reusable control
Low current exploitation signal · bounded exposure · monitor for change
Riskform uses the same decision semantics in both models. The difference is how much customer-specific context the engine can use and where the customer data resides.
For teams that want immediate search, prioritization and campaign intelligence without a deployment project.
For enterprises that want actual asset, exposure, ownership, controls and attack-path context without exporting sensitive findings.
Prove that campaign-based prioritization can produce a smaller, clearer and more defensible remediation plan before committing to broader integration.
Riskform keeps a traceable chain from source evidence to taxonomy, score, campaign and planning decision.
Yes. Public-only mode is a complete product: enriched CVE intelligence, adversarial categorization, proprietary threat signals, campaign generation, technology watchlists and notifications. Enterprise integrations increase precision later.
No. Scores are inputs to a decision model. The primary output is an explainable remediation or mitigation campaign and its relative priority.
Yes. The How It Works layer exposes source evidence, taxonomy rule, score components, Riskform intelligence events, grouping logic, confidence and policy version.
Yes. Taxonomy, classification, scoring, campaign logic, notifications and planning are externalized as versioned YAML policy so changes are governed and reproducible.
What should we change next to remove the most meaningful risk with the capacity we actually have?
Start with the 30-day pilot →