Nucleus Insights is Nucleus Security's proprietary vulnerability intelligence feed. Nucleus produces and maintains the feed, which enriches CVEs and vulnerability findings with exploitation evidence, threat context, remediation guidance, and the Nucleus Threat Rating.
Insights data is available throughout Nucleus for vulnerability investigation, prioritization, risk scoring, automation, dashboards, and reporting.
Availability
The Nucleus Insights data available in the console may vary based on your organization's Nucleus products and subscription. Contact your Nucleus representative if you have questions about access.
Why Nucleus Insights matters
Vulnerability scanners identify potential weaknesses and assign technical severity. Nucleus Insights adds current information about exploitation, weaponization, attacker activity, and available remediation.
Teams can use this intelligence to answer questions such as:
Is exploitation active, widespread, or likely?
Is an exploit public, private, or weaponized?
Is the vulnerability associated with ransomware, malware, or known threat actors?
Can the vulnerability be exploited remotely, and what would successful exploitation allow?
Is it a current or former zero-day vulnerability?
Is a patch, fixed version, configuration change, or compensating control available?
The same fields can filter findings, influence risk scores, trigger automation workflows, and support dashboards and reports.
Intelligence provided by Nucleus Insights
Nucleus Insights includes the following Nucleus-authored intelligence:
Intelligence | What it tells you |
|---|---|
Nucleus Threat Rating | Rates each CVE from Low to Existential based on current exploitation and threat information. Teams can use the rating for prioritization, SLAs, reporting, and automation. |
Exploitation status | Shows whether exploitation has been observed, is widespread, is likely to occur, or has been weaponized for use in attacks. |
Exploit availability and maturity | Distinguishes public and private exploits, proof-of-concept material, weaponized exploits, remote exploitation, and zero-day activity. |
Malware, ransomware, and threat actors | Identifies malware, ransomware operations, and threat actors associated with a vulnerability when attribution is available. |
Exploitation impact | Describes the difficulty and likely consequence of exploitation, including potential impact to operational technology. |
Expert analysis | Summarizes why the vulnerability matters and how organizations can respond. |
Fix and mitigation intelligence | Identifies available patches, permanent fixes, configuration changes, and compensating controls. |
Threat momentum | Tracks recent and historical attention around a vulnerability. |
For the complete list of Nucleus-authored fields and structured intelligence, see Nucleus Insights proprietary intelligence reference.
Nucleus also provides attributed data from CISA KEV, EPSS, NVD, Microsoft, Shadowserver, and other vulnerability research projects. This supporting data is documented in Additional vulnerability intelligence sources.
Nucleus Threat Rating
The Nucleus Threat Rating is the primary prioritization signal in Nucleus Insights. Each CVE receives a rating from Low to Existential based on current exploitation and threat information.
NTR is refreshed daily. A rating may change when exploit code is published, exploitation is observed, malware or threat actors adopt a vulnerability, or new context becomes available.
Common uses for NTR include:
Apply a consistent threat-based priority across scanners and finding sources.
Surface vulnerabilities with active or emerging threat evidence.
Define remediation SLAs and escalation paths based on current threat conditions.
Create automation and reporting that remain current as the threat landscape changes.
Important
NTR describes the threat associated with a vulnerability. Asset criticality, exposure, compensating controls, and other environmental factors determine the risk of each affected finding. Review those factors when setting remediation priorities.
.png)
How Insights data is used in Nucleus
Nucleus automatically adds Insights data to applicable CVEs and findings.
Investigate a vulnerability
Open a CVE or vulnerability details view to review its Nucleus Threat Rating, exploitation indicators, threat context, remediation guidance, and supporting references. Analysts can review the vulnerability and its relevance to the organization from the same view.
Use this view when a vulnerability is disclosed, a security advisory is published, or a stakeholder asks whether the organization is affected.
.png)
Prioritize affected findings
Use Insights fields alongside asset and finding context to identify the instances that require action. For example, filter for:
Findings where
nucleus_exploited = true.Findings with a high Nucleus Threat Rating.
Exploited findings affecting business-critical or internet-facing assets.
Findings associated with malware that are overdue or outside the remediation SLA.
On the All Findings page, Insights fields can be added as filters and result columns in Basic mode or queried through Nucleus Query Language (NQL). See All Findings Page for details.
Automate prioritization and response
Insights fields can be used as conditions in Nucleus automation workflows. Common examples include:
Create or escalate a ticket when a vulnerability becomes exploited.
Shorten the remediation due date when the threat rating increases.
Route malware-associated vulnerabilities to an incident response or threat-hunting team.
Notify application or infrastructure owners when new remediation guidance becomes available.
Adjust a finding's risk score based on exploitation evidence.
Automation workflows evaluate updated Insights data independently of scanner cadence.
Build risk models, dashboards, and reports
Nucleus Insights fields can also be used in Custom Risk Score models, dashboard widgets, saved searches, and reports. Teams can track metrics such as:
Open findings associated with exploited vulnerabilities.
Assets affected by the highest-rated CVEs.
Exploited findings by owner, business unit, or remediation status.
Aging and SLA performance for threat-prioritized findings.
Changes in organizational exposure as new intelligence becomes available.
See Custom Risk Score Overview for information about incorporating threat intelligence and business context into your organization's scoring model.
Use Insights outside the Nucleus console
Supported APIs and integrations make Nucleus Insights available to SIEM, SOAR, analytics, ticketing, and other security tools. Connected workflows can use the same intelligence and prioritization criteria.
Recommended starting workflow
If you are new to Nucleus Insights, start with the following workflow:
Open All Findings for a project.
Filter for
nucleus_exploited = true.Add the Nucleus Threat Rating and relevant asset context as columns.
Review the highest-rated findings on critical or externally exposed assets.
Open the applicable vulnerability details to review the evidence and remediation guidance.
Save the search for ongoing monitoring.
Create an automation or dashboard once your team has validated the prioritization criteria.
Frequently asked questions
Is Nucleus Insights a third-party intelligence feed?
Nucleus Insights is a proprietary, first-party data feed produced and maintained by Nucleus Security. Nucleus produces the Insights assessments, enrichment, and Nucleus Threat Rating.
Does Nucleus Insights replace CVSS, EPSS, or CISA KEV?
CVSS, EPSS, CISA KEV, and Nucleus Insights provide different types of risk information. CVSS measures technical severity. EPSS estimates exploitation probability. CISA KEV identifies vulnerabilities that meet CISA's criteria for known exploitation. Nucleus Insights provides current exploitation, threat attribution, and remediation intelligence. These fields can be used together in Nucleus. All of these fields are bundled and included within the Insights data feed.
How often is Nucleus Insights updated?
Nucleus Insights is continuously updated as new information becomes available. The Nucleus Threat Rating is refreshed daily.
Why can the intelligence for a CVE change?
Vulnerability intelligence changes as attackers, researchers, and vendors release new information. A public exploit may be published, exploitation may be observed, malware may adopt a vulnerability, or a vendor may release a patch or mitigation. Nucleus updates the applicable Insights fields as that information becomes available.
Do I need to configure a connector to receive Nucleus Insights?
Entitled organizations receive Insights data automatically. Product access determines which fields and capabilities are available.
Related documentation
Nucleus Insights proprietary intelligence reference
Additional vulnerability intelligence sources