TrustSource: Vulnerability Management
A single unpatched Apache Struts vulnerability cost Equifax the data of 147 million people. This course is about never being the team that finds out about a CVE the hard way. You'll learn what TrustSource's scoring actually means, where its own tools surface a finding, and the full set of things you can do about one — from filing a ticket to publishing a formal advisory to handing a self-found zero-day into coordinated disclosure.
Was Sie lernen
- Explain why 'zero CVEs' is the wrong goal, and what minimizing the attack surface means instead
- Distinguish CVE, CPE, and CWE, and read a CVSS Base/Environmental/Temporal score correctly
- Use EPSS and KEV alongside CVSS to prioritize which finding to act on first
- Navigate TrustSource's own vulnerability tools: Filter, Report, Lake, Activity, CVE-Impact Report
- Choose the right handling option for a finding: ticket, risk, CSAF/VEX advisory, or CVD handoff
- Recognize when a self-found code weakness (SAST/CWE) has become a disclosure obligation
Themen
securityvulnerability-managementtrustsourcecvsscsafsast
Modul 01 - Handling Procedure Overview ▶
- ▶ Introduction 1:02
- ▶ Why It Matters 4:14
- ? The Goal, Correctly Stated
- ? Match the Path to What It Actually Does
Modul 02 - Vocabulary & the Vulnerability Report ▶
- ▶ Vocabulary & the Vulnerability Report 0:12
- ▶ Terminology 2:17
- ▶ Scoring 4:39
- ▶ From Visibility to Action 1:59
- ? CVE, CPE, or CWE — Which One Identifies What?
- ? How TrustSource Gets From Base Score to Environmental Score
- ? Put the Four-Step Response in Order
Modul 03 - TrustSource's Vulnerability Toolset ▶
- ▶ TrustSource's Vulnerability Toolset 0:14
- ▶ Vulnerability Filter 7:17
- ▶ Vulnerability Report 3:41
- ▶ Vulnerability Lake 8:40
- ▶ Vulnerability Activity 1:47
- ▶ CVE-Impact Report 1:37
- ? Which Tool Actually Answers This Question?
- ? Simple, Expert, Find CVE, or Find CWE — Pick the Right Door Into the Lake
- ? Comparing Two Versions of the Same Library
Modul 04 - Handling Options ▶
- ▶ Handling Options 0:12
- ▶ Creating Tickets 1:31
- ▶ Adding Risks 2:04
- ▶ Publishing CSAF SA or VEX 4:50
- ▶ Own-Code Weaknesses: SAST & SARIF 3:42
- ▶ Handing Over to CVD 6:08
- ? Pick the Right TrustSource Action
- ? The CVD Lifecycle, in Order
- ? Same Buttons, Different Source
- ▶ Summary 1:04