Vulnerability management
Finding weaknesses, ranking them honestly, and actually fixing some.
58 sketches
CVEA catalogue number, not a verdict
CVSSFour dials, one gets turned
CVSS Base scoreThe same number, wherever it sits
CVSS Environmental metricsThe adjusters nobody turns
CVSS Threat metricsThe dial that looks outside
Asset criticalitySame crack, different consequence
Emergency patchingBreak the glass, but name the hand first
End-of-life softwareStanding still is not staying safe
ExploitabilityHow likely, then what now
Exposure managementPull on the thread that reaches
False negativesNothing found is not nothing there
False positivesWrong often enough to be ignored
Known exploited vulnerabilitiesA footprint proves it
N-daysThe gap the fix never closed
PatchingSpeed comes from the way back
Remediation SLAsMove the label, not the machine
Scanner coverageCoverage measures the pointing
Virtual patchingA plaster over the crack
Vulnerability backlogThe tap is faster than the drain
Zero-daysOne word, three meanings
'a high CVSS means patch first'Something jumps the queue
KEV, EPSS and SSVC turn exploitation evidence and likelihood into different prioritisation signalsThree instruments, three answers
Patch available does not mean patch deployedThe tin is not the wall
Asset inventory bounds vulnerability truthThe scan stops where the list stops
Compensating controls can change exploitabilitySame flaw, no way across
Patch windows are risk decisionsSomebody sets the angle
End-of-life software turns patching into replacementThe spares drawer is empty
Vulnerability closure needs verificationThe ticket closed. The port did not
The Internet sees what you expose, not what your CMDB remembersCounted three. Answering six
A new subdomain can create a new perimeterThe fence just got longer
Shadow IT becomes shadow attack surfaceDoors around the back
Acquisitions merge attack surfaces before inventoriesThe wire arrives first
Internet exposure is a property that changesThe tide does not read your map
A forgotten test system can be a production entry pointThe shed is still joined to the house
Third-party hosted assets still carry your nameTheir building, your name over the door
Attack surface reduction removes paths instead of adding alertsA bell on the door, or no door
IPv6 can create exposure beside an IPv4 mental modelTwo ways through, one on the plan
Exposure without ownership stays exposed longerThe one with a name on it gets fixed
EDR visibility depends on the sensor being aliveSilence is not the same as safety
Application allowlisting controls execution, not intentThe list checks the name
Local admin changes the consequence of compromiseOne click, two blast radii
Device compliance is a snapshot, not permanent healthA tick is a photograph
Full-disk encryption protects a powered-off device bestAt rest means switched off
USB controls are a system design problemDesign the socket, not the poster
Patch compliance percentages can hide critical exceptionsWhat the number covers
Endpoint isolation buys investigation timeCut the wire, keep the power
Reimaging removes software, not stolen credentialsA new machine, the same pass
Security agents can become privileged attack surfacesThe tool that reaches everything
Domain Admin is a forest-scale keyOne root under the whole forest
Kerberos tickets are credentialsWhoever holds it, gets in
Golden Ticket attacks target the ticket authorityThey took the press, not a ticket
Group Policy is a fleet control planeOne dial, every desk
LAPS reduces shared local-admin secretsOne secret, or one each
NTLM fallback preserves older trust assumptionsThe hatch nobody bricked up
Service accounts can become invisible administratorsThe pass with no face
Tiered administration separates privilege contextsSeparate benches, separate ladders
Directory replication is a privileged capabilitySend me everything you hold
Active Directory recovery is not ordinary server restoreThey put each other back
