/v2/prioritize returns normalized signal cards ranked for the provided environment.
Response Envelope
/v2/prioritize returns:
Item Fields
Agent Guidance
Validate the top items with evidence and relationships before recommending disruptive remediation.CVE inventory applicability
CVE items includeproduct_match and applicability without requiring debug mode.
Non-CVE items return null for these fields. product_match compares names as
match, mismatch, or unknown. applicability.product_status additionally
accounts for your environment.inventory_complete assertion.
The same product applicability rules
apply to environment assessments. A name overlap is product-level affected;
known distinct names with a complete inventory are product-level unaffected;
missing or unresolved context is unknown. Full applicability.status remains
unknown, because names cannot confirm vulnerable versions/configuration or
complete advisory coverage.
For CVEs, recommended_action_type is validate_exposure with conditional
remediation advice. A complete inventory with known distinct products uses
monitor, caps the score at 0.2, and adds
known_product_mismatch_conditional_on_complete_inventory to suppression_reasons.
Verify inventory and source coverage before excluding the CVE. Existing automation
that triggers a patch from recommended_action_type must now perform the
applicability check first.
Equivalent inventory and source product names produce the same product applicability
on both endpoints. Their ranking scores can differ: prioritization compares signals
using activity, novelty, and corroboration; assessment considers one threat’s
severity, exploitation evidence, and exposure..png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)