Understanding Metrics for Agent Val
Agent Val displays four key metrics showing the current state of exploitability validation across your environment. The following table explains what each metric reveals about your exploitable exposure:
| Metric | What It Measures | Why It Matters |
|---|---|---|
| Exposures Validated | Example: 60,000 exposures (<0.1% of 62.5M total findings) | Confirms that Agent Val is focused on the highest-priority, threat-context-informed set, not the entire unfiltered finding population. Shows validation throughput for the current cycle. |
| Confirmed Exploitable | Example: 4,200 exposures (7% of validated set) | Identifies the exact subset that poses real, confirmed attacker leverage in your production environment. Replaces inflated scanner counts with verified evidence of exploitability. |
| QVSS Amplified | Example: 4,200 exposures received amplified TruRisk scores | Quantifies how many exposures have moved from theoretical to confirmed priority, directly driving the remediation queue. Prevents under-resourcing of genuine threats and over-spending on theoretical ones. |
| Exploit Paths Closed | Example: 3,850 (92%) of confirmed-exploitable exposures | Provides cryptographic, audit-ready proof of genuine risk elimination. Closure is tied to exploit-path confirmation, not ticket resolution, eliminating paper-only remediation from your risk program. |
Reading Your Metrics
These metrics reflect only exposures that have been validated by TruConfirm in the current analysis cycle, not your total vulnerability count. This focus on confirmed, evidence-based exploitability helps you prioritize with precision.
High Confirmed Exploitable count?
Your environment has significant confirmed attacker leverage. Prioritize the amplified QVSS queue immediately; these findings represent real threats, not theoretical severity. Fast-track remediation.
TruRisk Amplified matches Confirmed Exploitable?
Expected. Every confirmed-exploitable finding automatically receives an amplified QVSS score. This 1-to-1 ratio confirms the amplification pipeline is running correctly and the remediation queue reflects real risk.
Low Exploit Paths Closed relative to Confirmed Exploitable?
Remediation is in progress but not yet closing the loop. Review the open confirmed-exploitable list, reallocate remidiation resources, and check that post-remediation revalidation triggers are configured and running.
Compare Exposures Validated to total findings
Agent Val targets the prioritized set, not the finding population. The validation scope reflects QVSS and threat-context selection working correctly. A much higher scope may indicate filters need tightening.
High Exploit Paths Closed rate?
Strong remediation closure velocity. This is your primary evidence of genuine risk elimination, suitable for CISO briefings and audit submissions as cryptographic proof of program effectiveness.
How Agent Val Works
The four-step autonomous process from selection to cryptographic proof of closure.
Step 1: Select - Decide What to Validate Next
Agent Val does not validate every finding. It identifies which prioritized exposures are most worthy of validation effort by evaluating:
- QVSS score of the exposure
- Trending CVEs relevant to the user’s industry
- Active threat-actor relevance - whether the CVE is currently weaponized, trending on the dark web, or linked to known malware or ransomware campaigns
- Business criticality of the affected asset - crown jewels, PCI scope, internet-facing systems, revenue-generating applications
- Exposure risk context asset type, compensating controls present, EOL/EOS software status
This step ensures validation resources are never wasted on low-priority or already-mitigated exposures.
Step 2: Validate - Execute Production-Safe Exploit Checks
Using ETM TruConfirm's library of production-safe exploit checks, Agent Val executes against selected findings and delivers a binary verdict - TruConfirm exploitable or not in the context of your real configurations.
- No data exfiltration, no writes to disk, no persistence
- Non-blocking async execution production stays intact
- Context-aware: EternalBlue is only flagged TruConfirm exploitable if SMBv1 is actually enabled; Log4Shell only if the JNDI lookup path is live
Step 3: Amplify - Elevate Confirmed Threats and Generate Recommendations
For every confirmed- TruConfirm exploitable exposure:
- Amplifies the associated QVSS score to reflect confirmed - not theoretical - exploitability
- Applies the AI Reliability Score to pre-clear which remediation (patch/mitigation) is safe for that asset's specific configuration
- Generates findings-tied QVSS recommendations - patch or mitigate
- Surfaces confirmed threats to the top of the remediation queue, ahead of unvalidated theoretical risk
Step 4: Prove - Revalidate and Close the Loop
After remediation actions are taken, Agent Val automatically reruns TruConfirm against the same findings and exploit paths:
- If the exploit path is confirmed closed, cryptographic proof is generated, and the exposure is SLA-closed
- If the exploit path remains open, Agent Val resurfaces the exposure with updated context and recommendations
- Post-remediation revalidation runs without human intervention, no manual steps required
Actionable Output Generation
Based on the validation analysis, Agent Val generates the following outputs:
Exploitability Verdicts
- Confirmed/not-confirmed answer per validated exposure
- Covers servers, workstations, cloud, containers, OT/IoT assets
- Context-specific, not generic CVSS-based severity
Amplified QVSS Scores
- Eliminating paper-only remediation from your risk program
- Impacted findings within your selected scope
- Criticality thresholds such as Qualys Vulnerability Score (QVS)
- Business entities or critical assets, if configured.
Draft Patch Jobs
- Confirmed-exploitable findings receive elevated QVSS scores
- Distinguishes confirmed threats from theoretical scanner output in the remediation queue
- Includes AI Reliability Score pre-clearing remediation safety
Risk-Reduction Recommendations
- Findings-tied recommendations for each confirmed-exploitable finding
- Covers patch and mitigation
- Scoped to specific assets and confirmed exploit paths - not generic guidance
Cryptographic Proof of Closure
- Post-remediation revalidation report per exploit path
- Tamper-evident cryptographic proof suitable for audit
- SLA closes at "exploit path confirmed closed" - not ticket status
- Eliminates paper-only remediation from your risk program
Validation Summary and Email Notifications
- Validation cycle summary with confirmed-exploitable count and closure rate
Decision Handling: Always Human-Controlled
Exploit validation is autonomous, but remediation actions are never executed automatically. All patch jobs and mitigation actions require human review and approval. Post-remediation revalidation runs autonomously once a human-initiated patch/mitigation is completed. This ensures Agent Val aligns with your enterprise change-control, audit, and compliance requirements, while eliminating the manual burden of loop-closing and proof generation.