Enrichment Tables
The Enrichment table offers additional details about CVE findings that are not visible in the Vulnerable Item Table.
Qualys ETM CVE Enrichment
Table name: ( x_qual5_etm_app_cve_enrichments)
You can see the following information on the CVE Enrichment table:
|
Field on Qualys ETM UI |
Field in Qualys ETM API Response |
Field on ServiceNow Table |
|---|---|---|
|
Title |
finding.title |
title |
|
CVE |
finding.cveId |
cve_id |
|
Description |
finding.description |
description |
|
CISA Known |
finding.cve.cisaKnownExploits |
cisa_known_exploits |
|
EPSS Score |
finding.cve.epssScore |
epss_score |
|
Result |
finding.detectionResult |
detection_result |
|
Impact |
finding.impact |
impact |
|
Recommendations / Remediation Guidance |
finding.solution |
solution_recommendation |
|
CVSS V3 Attack Vector |
finding.cve.cvss3Info.accessVector |
v3_access_vector |
|
CVSS V3 Base |
finding.cve.cvss3Info.basescore |
v3_base_score |
|
CVSS V3 Temporal |
finding.cve.cvss3Info.temporalScore |
v3_temporal_score |
|
- |
finding.cve.cvss2Info.accessVector |
v2_access_vectore |
|
- |
finding.cve.cvss2Info.basescore |
v2_basescore |
|
- |
finding.cve.cvss2Info.temporalScore |
v2_temporal_score |
| - |
finding.cve.exploitavailable |
exploit_available |
| - |
finding.cve.ismalware |
is_malware |
| - |
finding.cve.publiclyexploitable |
publicly_exploitable |
Malware Names
Table name: ( x_qual5_etm_app_cve_enrichments)
You can see the following information on the Malware table:
|
Field on Qualys ETM UI |
Field in Qualys ETM API Response |
Field on ServiceNow Table |
|---|---|---|
|
CVE |
finding.cveId |
etm_cve_enrichment |
|
Malware |
finding.malwareNames |
name |
Exploit Maturity
Table name: ( x_qual5_etm_app_exploit_maturity)
You can see the following information on the Exploit Maturity table:
|
Field on Qualys ETM UI |
Field in Qualys ETM API Response |
Field on ServiceNow Table |
|---|---|---|
|
- |
finding.exploitMaturity |
name |
|
CVE |
finding.cveId |
etm_cve_enrichment |
Mitre Attacks
Table name: (x_qual5_etm_app_mitre_attacks)
You can see the following information on the Mitre Attacks table:
|
Field on Qualys ETM UI |
Field in Qualys ETM API Response |
Field on ServiceNow Table |
|---|---|---|
|
CVE |
finding.cveId |
etm_cve_enrichment |
|
- |
finding.mitreAttacks.techniques |
techniques |
|
- |
finding.mitreAttacks.tactics |
tactics |
|
- |
finding.mitreAttacks.subtechniques |
subtechniques |
RTI
Table name: (x_qual5_etm_app_rti)
You can see the following information on the Mitre Attacks table:
|
Field on Qualys ETM UI |
Field in Qualys ETM API Response |
Field on ServiceNow Table |
|---|---|---|
|
CVE |
finding.cveId |
etm_cve_enrichment |
|
- |
finding.rti |
indicator |
Threat Actor Names
Table name: (x_qual5_etm_app_threat_actor_names)
You can see the following information on the Threat Actor Names table:
|
Field on Qualys ETM UI |
Field in Qualys ETM API Response |
Field on ServiceNow Table |
|---|---|---|
|
CVE |
finding.cveId |
etm_cve_enrichment |
|
- |
finding.threatActorName |
name |