Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

confidence #9

Open
danielsadoc opened this issue Feb 23, 2024 · 4 comments
Open

confidence #9

danielsadoc opened this issue Feb 23, 2024 · 4 comments
Labels
documentation Improvements or additions to documentation

Comments

@danielsadoc
Copy link

Thanks a lot for inthewild.io! Please, how is "confidence" set? What is its meaning? Knowing the "confidence" on the artifacts is great, but we need to know how is it set. Is it possible to also include this information in the .db file?

@gmatuz gmatuz added the documentation Improvements or additions to documentation label Feb 28, 2024
@gmatuz
Copy link
Owner

gmatuz commented Feb 28, 2024

@danielsadoc it is more something for our triage. Some sources are a little inconsistent in our experience (either for certainty or the way we automatically parse them). e.g. we also add lower certainty to anything we have not triaged and submitted externally. In this I'd recommend you disregard non "High" certainty ones unless you want to be very cautious that is also the reason why they are not included in the db or the main API.
I'll make a doc of this on the readme!

Also if you like the project, we always appreciate help in terms of detailed feedback or ongoing submissions. Please reach out if you feel like contributing

@danielsadoc
Copy link
Author

thanks! On that same note, I've noticed that there are 10 sources at inthewild.io, right? Most of them are clear, but one is called API. What does API mean?

Please, if you could also share the heuristics for confidence that would be great. We noticed that even CISA/KEV sometimes appear with medium confidence. However, CISA/KEV is an authoritative source. Why some CISA/KEV entries are marked as medium confidence?

@gmatuz
Copy link
Owner

gmatuz commented Feb 29, 2024

Sometime KEV has incorrect dates of exploitation of vulnerabilities. Vulnerabilities are marked as currently exploited in case they were known to be exploited years ago. For us the having only recent data on RSS is very important so we manually verify this.

I'm not sure about your question but we have APIs where people can submit exploitation information directly and to get exploitation information, explicitly one for all the exploited vulns https://inthewild.io/api/exploited

@danielsadoc
Copy link
Author

dear @gmatuz please, did you have a chance to share some notes about the confidence values? What do they mean? And how are they computed?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

2 participants