Skip to main content
Using exploit intelligence to identify vulnerable detected products - Tanium Tech Talks #153 video thumbnail
Module Deep Dive

Using exploit intelligence to identify vulnerable detected products - Tanium Tech Talks #153

Vulnerability backlogs are growing faster than most teams can manage them. Tanium Product Portfolio Lead Julia Grunewald walks through the newest Tanium Comply features that combine exploit intelligence, endpoint criticality, and detected products to cut through the noise and focus remediation where it matters most.

Managing vulnerabilities at enterprise scale is one of the most operationally demanding challenges in IT security. Many organizations are dealing with thousands of vulnerabilities — in some cases, millions — and the traditional approach of relying on CVSS scores alone leaves teams without the context they need to make confident prioritization decisions. Knowing a vulnerability scores a 5.5 out of 10 tells you very little about whether attackers are actively exploiting it today, whether ransomware campaigns are using it, or whether the endpoint it affects is a domain controller. Tanium Product Portfolio Lead Julia Grunewald joins this episode to walk through significant new improvements to Tanium Comply that address exactly this gap.

Julia covers three interconnected capabilities now available within Comply: exploit intelligence data (including EPSS scores, exploit maturity levels, and ransomware campaign associations), endpoint criticality, and a new detected products field that narrows remediation from a list of 80 potentially affected products down to the single application actually found on the endpoint. Together, these additions give teams the three-legged prioritization framework Julia describes: how important is the vulnerability, how likely is it to be exploited, and how business-critical is the affected asset.

Julia also introduces the new Exploitability Dashboard, which brings together CVSS and EPSS overlays, the CISA Known Exploited Vulnerabilities feed, and MITRE ATT&CK technique mappings through CWEs, all in a single view designed for both day-to-day triage and executive-level reporting.

If your team is still working from spreadsheets or struggling to connect vulnerability findings to clear remediation actions, this episode is worth your full attention. Watch the video below to see every feature demonstrated live inside the Comply console.

Key takeaways

  • CVSS alone is not enough: Customers managing thousands or even millions of vulnerabilities need more than a CVSS score to make prioritization decisions. They need to know if a vulnerability is actively being exploited, if specific threat actors are using it, and if ransomware campaigns are tied to it.
A lot of customers have thousands of vulnerabilities. In some cases, millions of vulnerabilities. And managing that type of estate is challenging, right? You need to understand what to prioritize, what to fix now, what can go through a normal patching cycle that might take a couple of weeks, maybe a month to fix.
Tanium Product Portfolio Lead Julia Grunewald
  • EPSS score and exploit intel: Comply now surfaces the EPSS score, a likelihood-of-exploitation metric that maxes out at 1, alongside a new exploit intel panel that shows the number of individual exploits tied to a vulnerability and how many ransomware campaigns are using it.
  • Max maturity field: One of the most actionable new fields is max maturity, which differentiates between a proof-of-concept exploit identified by a researcher and an exploit that is actually weaponized in the real world, a distinction that CVSS score alone would never surface.
This vulnerability is actually really important for me to fix now—and that's something I would never know if I was just using CVSS for prioritization.
Tanium Product Portfolio Lead Julia Grunewald
  • Endpoint criticality as the third leg: Comply now incorporates endpoint criticality, a measure of business impact, alongside CVSS and EPSS. Tanium ships with three default rules (all domain controllers are critical, all servers are high, all workstations are medium), and teams can define their own dynamic rules based on any data Tanium has access to, including application presence, user identity, or custom tags.
  • Detected products narrow remediation: Rather than listing every product a vulnerability could affect, which can number 80, the new detected products field shows only the specific application actually found on the endpoint that triggered the vulnerability detection, giving teams a precise, actionable remediation target.
We're trying to help you find things faster, give you all of the data that you need to prioritize, and then give you really clear steps and, wherever possible, direct links to remediation actions to just tighten up that meantime to remediate and make your vulnerability a state more manageable.
Tanium Product Portfolio Lead Julia Grunewald
  • Exploitability Dashboard: A new managed dashboard released alongside the exploitability data in Comply displays the overlay of CVSS and EPSS scores, the top 10 most exploitable CVEs with findings in your environment, CISA Known Exploited Vulnerability feed data, and MITRE ATT&CK technique mappings through CWEs, all clickable and cloneable for team-specific reporting needs.

Additional resources