Enrichment Tables

The Enrichment table offers additional details about CVE findings that are not visible in the Vulnerable Item Table.

Qualys ETM CVE Enrichment

Table name: ( x_qual5_etm_app_cve_enrichments)

You can see the following information on the CVE Enrichment table:

Field on Qualys ETM UI

Field in Qualys ETM API Response

Field on ServiceNow Table

Title

finding.title

 title

CVE

finding.cveId

cve_id

Description

finding.description

description

CISA Known 
Exploitable

finding.cve.cisaKnownExploits

cisa_known_exploits

EPSS Score

finding.cve.epssScore

epss_score

Result

 finding.detectionResult

detection_result

Impact

finding.impact

impact

Recommendations / Remediation Guidance

finding.solution

solution_recommendation

CVSS V3 Attack Vector

finding.cve.cvss3Info.accessVector

v3_access_vector

CVSS V3 Base

finding.cve.cvss3Info.basescore

v3_base_score

CVSS V3 Temporal

finding.cve.cvss3Info.temporalScore

v3_temporal_score

-

finding.cve.cvss2Info.accessVector

v2_access_vectore

-

finding.cve.cvss2Info.basescore

v2_basescore

-

finding.cve.cvss2Info.temporalScore

v2_temporal_score

-

finding.cve.exploitavailable

exploit_available

-

finding.cve.ismalware

is_malware

-

finding.cve.publiclyexploitable

publicly_exploitable

Malware Names 

Table name: ( x_qual5_etm_app_cve_enrichments)

You can see the following information on the Malware table:

Field on Qualys ETM UI

Field in Qualys ETM API Response

Field on ServiceNow Table

CVE

finding.cveId

etm_cve_enrichment

Malware

finding.malwareNames

name

Exploit Maturity

Table name: ( x_qual5_etm_app_exploit_maturity)

You can see the following information on the Exploit Maturity table:

Field on Qualys ETM UI

Field in Qualys ETM API Response

Field on ServiceNow Table

-

finding.exploitMaturity

name

CVE

finding.cveId

etm_cve_enrichment

Mitre Attacks

Table name: (x_qual5_etm_app_mitre_attacks)

You can see the following information on the Mitre Attacks table:

Field on Qualys ETM UI

Field in Qualys ETM API Response

Field on ServiceNow Table

CVE

finding.cveId

etm_cve_enrichment

-

finding.mitreAttacks.techniques

techniques

-

finding.mitreAttacks.tactics

tactics

-

finding.mitreAttacks.subtechniques

subtechniques

RTI

Table name: (x_qual5_etm_app_rti)

You can see the following information on the Mitre Attacks table:

Field on Qualys ETM UI

Field in Qualys ETM API Response

Field on ServiceNow Table

CVE

finding.cveId

etm_cve_enrichment

-

finding.rti

indicator

Threat Actor Names

Table name: (x_qual5_etm_app_threat_actor_names)

You can see the following information on the Threat Actor Names table:

Field on Qualys ETM UI

Field in Qualys ETM API Response

Field on ServiceNow Table

CVE

finding.cveId

etm_cve_enrichment

-

finding.threatActorName

name