← Alle Kurse

TrustSource: Vulnerability Management

A single unpatched Apache Struts vulnerability cost Equifax the data of 147 million people. This course is about never being the team that finds out about a CVE the hard way. You'll learn what TrustSource's scoring actually means, where its own tools surface a finding, and the full set of things you can do about one — from filing a ticket to publishing a formal advisory to handing a self-found zero-day into coordinated disclosure.

Was Sie lernen

  • Explain why 'zero CVEs' is the wrong goal, and what minimizing the attack surface means instead
  • Distinguish CVE, CPE, and CWE, and read a CVSS Base/Environmental/Temporal score correctly
  • Use EPSS and KEV alongside CVSS to prioritize which finding to act on first
  • Navigate TrustSource's own vulnerability tools: Filter, Report, Lake, Activity, CVE-Impact Report
  • Choose the right handling option for a finding: ticket, risk, CSAF/VEX advisory, or CVD handoff
  • Recognize when a self-found code weakness (SAST/CWE) has become a disclosure obligation

Themen

securityvulnerability-managementtrustsourcecvsscsafsast
Modul 01 - Handling Procedure Overview
  • Introduction 1:02
  • Why It Matters 4:14
  • The Goal, Correctly Stated
  • Match the Path to What It Actually Does
Modul 02 - Vocabulary & the Vulnerability Report
  • Vocabulary & the Vulnerability Report 0:12
  • Terminology 2:17
  • Scoring 4:39
  • From Visibility to Action 1:59
  • CVE, CPE, or CWE — Which One Identifies What?
  • How TrustSource Gets From Base Score to Environmental Score
  • Put the Four-Step Response in Order
Modul 03 - TrustSource's Vulnerability Toolset
  • TrustSource's Vulnerability Toolset 0:14
  • Vulnerability Filter 7:17
  • Vulnerability Report 3:41
  • Vulnerability Lake 8:40
  • Vulnerability Activity 1:47
  • CVE-Impact Report 1:37
  • Which Tool Actually Answers This Question?
  • Simple, Expert, Find CVE, or Find CWE — Pick the Right Door Into the Lake
  • Comparing Two Versions of the Same Library
Modul 04 - Handling Options
  • Handling Options 0:12
  • Creating Tickets 1:31
  • Adding Risks 2:04
  • Publishing CSAF SA or VEX 4:50
  • Own-Code Weaknesses: SAST & SARIF 3:42
  • Handing Over to CVD 6:08
  • Pick the Right TrustSource Action
  • The CVD Lifecycle, in Order
  • Same Buttons, Different Source
  • Summary 1:04