CVE matching, MITRE ATT&CK technique annotations, and composite risk scoring — with a finding-suppression workflow to cut false positives from your report. Client-ready, print-ready HTML reports included.
Version-based CVE matching is just the start. Every finding is scored — CVSS weighted by verification status, with an uplift for findings carrying an initial-access technique — and the queue is then ordered exploit-first. Findings are emitted unverified — you adjudicate what stays, not the scanner.
A finding-suppression workflow lets you mark items accepted-risk or false-positive; suppressed findings drop out of the report and the risk rollup. Every decision is recorded per scan.
Severity ranks how bad a vulnerability would be if it were exploited. It cannot tell you whether anyone is exploiting it. Pro closes that gap at scan time: every finding carrying a CVE is joined by CVE ID against a local CISA KEV catalog and a local FIRST EPSS scores file, then banded and reordered exploit-first.
The justification travels with the finding — the KEV flag, the EPSS score with its percentile, the CVE ids that matched, and the store’s own as-of date. Your ranking is always something you can date and defend. Both catalogs are free, public and operator-supplied: point Pro at files you control and the join runs entirely on your machine.
Your existing riskScore does not move — exploitPriority is a new axis
beside it. And this is enrichment, not detection: it reorders what the scanner already found.
How the bands were named, and what each one deliberately refuses to claim:
The explainer covers the Pro exploit-intelligence workflow and, in its second half, the Enterprise compliance report.
# 1 · Download the feeds (public, no account needed for either) mkdir -p ~/.nsauditor/feeds curl -fsSL https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json -o ~/.nsauditor/feeds/kev.json curl -fsSL https://epss.empiricalsecurity.com/epss_scores-current.csv.gz | gunzip > ~/.nsauditor/feeds/epss.csv # 2 · Point the scanner at them (add both lines to your shell profile to persist) export NSAUDITOR_EXPLOIT_KEV_STORE=~/.nsauditor/feeds/kev.json export NSAUDITOR_EXPLOIT_EPSS_STORE=~/.nsauditor/feeds/epss.csv # 3 · Scan as usual — findings that carry CVEs arrive banded and ordered exploit-first nsauditor-ai scan --host 192.168.1.0/24 --plugins all
The stores are the feeds' own formats — no conversion step. Refresh KEV within 14 days and EPSS within 10 (a cron works);
a stale or unparseable store fails closed and the scan says so — it never silently reports
“not exploited”. Setting these outside a shell? ~ expands only in a shell —
in a --env file or Claude Desktop’s MCP env config, write the absolute path (e.g.
/Users/you/.nsauditor/feeds/kev.json); a path the scanner cannot read is reported as no-store, never as
“not exploited”. Full walk-through: getting-started → exploit intelligence.
Exploit intelligence is a Pro-tier capability and is off until you configure it. Enterprise includes Pro.
Pro sharpens the queue. Enterprise turns the result into something an assessor reads — 28 Enterprise plugins across AWS, Azure and GCP, and one read-only scan mapped to seven frameworks with an explicit out-of-scope column.
It is also where suppression stops being a filter and becomes a record. Pro’s finding-suppression workflow drops an accepted-risk item out of your report and its risk rollup. The Enterprise compliance engine takes the same decision and gives it an owner, a rationale, a date and an expiry inside the evidence pack — and as of EE 0.36.0 the report checks that approval’s signature against the key material the approver’s registry entry declares, rather than repeating what the record says about itself. A missing verdict reads not checked and never failed.
None of that is part of a Pro licence. If your buyer is an auditor rather than a remediation queue, that is the tier to look at.
CISA KEV + FIRST EPSS joined by CVE ID at scan time, banded KNOWN_EXPLOITED / ELEVATED / BASELINE, queue ordered exploit-first. Operator-supplied catalogs; the join runs locally. See how →
Auto-generated CPEs from detected services matched against the NVD feed — offline, no API calls. Know which CVEs affect each host before writing a single line of your report.
Every finding is annotated with the ATT&CK techniques it relates to, with kill-chain context. Compliance teams love it. Clients understand it. Takes zero extra effort on your part.
Five specialized agents run concurrently — Auth, Crypto, Config, Service, and Exposure. Each produces structured findings for its category, then feeds the risk engine.
CVSS weighted by verification status — VERIFIED 1.0×, UNVERIFIED 0.6×, suppressed 0.0× — with a 15% uplift for findings carrying an initial-access ATT&CK technique. Reports render severity-grouped, highest-impact first, and suppressed findings drop out of the rollup.
Export findings as HTML, JSON, or Markdown — print the HTML to PDF for a client-ready document. Risk-ranked, with a summary overview and technical findings in one file.
Same OpenAI / Claude / Ollama providers you use in CE — but Pro injects CVE matches, MITRE techniques, and risk scores into every prompt. Vastly better output.
Unlimited scan history in SQLite. CVE-level delta detection — new vulnerabilities since last scan, not just host diffs. Risk trend analysis (improving / degrading / stable).
Configurable profiles (strict / moderate / minimal), additional patterns for AWS keys, DB connection strings, and JWTs. Full redaction audit log for compliance.
The MCP server registers seven tools and lists all seven to every client; the licence gate is applied when a tool is called. Pro unlocks probe_service and get_vulnerabilities on top of the three every tier can run.
Agents run via Promise.allSettled — if one category has no relevant services, it's skipped. Results feed the risk engine.
list_plugins completes the every-tier set;
scan_cloud and
get_findings are Enterprise. Seven tools in total — all seven are listed to every client, and the licence is checked when one is called.
Start the MCP server with nsauditor-ai-mcp — works with Claude Desktop, Cursor, and any MCP-compatible AI assistant.
# @nsasoft/nsauditor-ai-ee is a private (restricted) package. # Use the npm read-token delivered with your license email. npm config set //registry.npmjs.org/:_authToken npm_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx # Or, project-scoped, in an .npmrc file echo "//registry.npmjs.org/:_authToken=npm_xxxx..." >> ~/.npmrc
# One line — installs both the CE platform and the Pro package npm install -g nsauditor-ai @nsasoft/nsauditor-ai-ee
# The CE license installer verifies the JWT signature before persisting # and stores the key in macOS Keychain (or ~/.nsauditor/.env mode 0600 elsewhere). nsauditor-ai license install pro_eyJhbGciOiJFUzI1NiIs... ✓ Pro license installed Stored at: macOS Keychain (service=nsauditor-ai) Org: you@example.com Expires: 2027-04-29 # Verify nsauditor-ai license --status ✓ Pro license active
nsauditor-ai scan --host 192.168.1.0/24 --plugins all # View your AI report in browser open out/192.168.1.0_*/scan_response_ai.html # macOS xdg-open out/192.168.1.0_*/scan_response_ai.html # Linux # Each scan writes HTML, JSON, and Markdown reports — print the HTML to PDF for clients nsauditor-ai scan --host 10.0.0.0/24 --plugins all open out/10.0.0.0_*/scan_response_ai.html # print → PDF
Subscribe directly to unlock CVE matching, MITRE ATT&CK annotations, risk scoring, and parallel analysis agents — with risk-ranked, print-ready HTML reports. Cancel anytime — reverts to Community Edition with no data lost.