Skip to content

docs: editable Exploit Maturity and manual Reachability on findings - #16039

Open
Maffooch wants to merge 1 commit into
bugfixfrom
cmm/editable-exploit-docs
Open

Maffooch wants to merge 1 commit into
bugfixfrom
cmm/editable-exploit-docs

Conversation

@Maffooch

@Maffooch Maffooch commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Shortcut: sc-15620

What

Documents the new ability to hand-edit Exploit Maturity and Reachability on a finding, in the Threat Intelligence panel of the Add and Edit Finding forms. This is the docs half of a Pro change on the same release line.

Changes

  • Editing Findings (triage_findings/findings_workflows/editing_findings.md) — the Threat Intelligence panel section now lists Exploit Maturity and Reachability, with the persistence rules (a hand-set value on a CVE-bearing finding is replaced by the next sync; a finding with no CVE keeps it) and how hand-set values feed the priority floors. Corrects the prior text that called Exploit Maturity feed-only.
  • Reachability (triage_findings/finding_scoring/reachability.md) — adds a "Setting reachability by hand" section: a manual verdict competes with scanner verdicts by tier (a stronger scanner verdict still wins the Resolved value) and is exempt from the staleness sweep.
  • Threat Intelligence (asset_modelling/PRO_hierarchy/threat_intelligence.md) — notes Exploit Maturity can be set by hand.

Text-only, per the OSS docs conventions. English source pages only; translations are handled separately.

@Maffooch Maffooch added this to the 3.3.300 milestone Sep 22, 2026
@github-actions github-actions Bot added the docs label Sep 22, 2026
@Maffooch
Maffooch enabled auto-merge September 22, 2026 18:09

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant