Use cases

For the response that doesn't arrive with a workflow.

KnownScope is not modeled around CVEs alone. It is built for the investigations that fall outside a scanner schema or a ticket template, where the first job is establishing what you are even looking at.

Emerging vulnerability & exploit response

A new exploit is circulating and you need to know your exposure before the day is out.

The situation

The advisory is vague, the affected-version list is moving, and proof-of-concept code is already public. Your scanner has not caught up, and every hour spent arguing over a spreadsheet is an hour attackers are not waiting for.

How a Campaign helps

Open a Campaign, pull in the candidate assets, and shape fields for version, exposure, and remediation state. As facts firm up, filter and bulk-update, while the history keeps a record of what you knew and when.

  • affected version
  • exposure
  • remediation
  • confidence

Vendor advisory & asset impact assessment

A vendor publishes an advisory. The real question is: does it touch us, and where?

The situation

The advisory names products and configurations, not your hostnames. Answering it means reconciling the vendor’s framing with your own inventory, across teams that each hold part of the picture.

How a Campaign helps

Import your asset list, map it against the advisory’s conditions, and track each item to a decision (affected, not affected, or needs review) with the owner and rationale attached to the row.

  • product
  • config match
  • decision
  • owner

Cloud & internet exposure investigation

Something is reachable from the internet that should not be. Now scope it.

The situation

A finding lands from an external scan or a bug report. It could be one bucket or a systemic misconfiguration. There is no CVE, no ticket template, and no obvious owner for the whole thing.

How a Campaign helps

Track exposed surfaces as items, capture provenance from the source that flagged them, and coordinate owners across cloud accounts and teams until every exposure is accounted for and closed or accepted.

  • surface
  • account
  • exposure
  • status

Third-party & configuration-driven response

A supplier incident or a config drift means the work does not fit any scanner’s model.

The situation

A third party discloses a breach, or a configuration change ripples across systems. The impact is indirect, spread across relationships and settings that no vulnerability feed will enumerate for you.

How a Campaign helps

Define a Campaign around the real question (which integrations, tenants, or systems are implicated) and bring non-technical stakeholders in as Workers or Viewers so the whole response stays in one place, with roles that hold.

  • relationship
  • system
  • impact
  • action

Private preview

Bring your hardest response to preview.

If your team is coordinating one of these responses in a spreadsheet right now, we would like to hear about it. KnownScope is in private preview.