Download icon
Get icon
Script icon
If icon
Request icon
ChatCompletion icon
GoogleGemini icon
SlackIncomingWebhook icon
Set icon
Schedule icon

Match Newly Exploited CVEs from CISA KEV to Your Stack and Triage Them with AI

Match new CISA KEV entries to your stack, enrich them with FIRST EPSS scores and post a Slack alert where Gemini sets a priority and next step.

Categories
AIInfrastructure

The CISA Known Exploited Vulnerabilities (KEV) catalog lists CVEs that attackers are already using. When a product you run lands in it, it should jump ahead of every CVSS-sorted backlog. The catalog is public, but nobody reads it every day. This blueprint does: it polls KEV, keeps only new entries that match the vendors and products you list, adds the FIRST EPSS exploit probability for each, and asks Gemini to rate how urgent each one is for your environment.

How it works

  1. fetch_kev downloads the KEV catalog (public JSON, no key).
  2. load_seen reads the CVE ids this watch has already evaluated, from the Kestra KV store.
  3. match_stack keeps entries that are unseen, added within lookback_days, and match a vendor/product in stack (case-insensitive substring match, so Apache with no product matches every Apache project).
  4. if_matches skips the next steps when nothing matched.
  5. fetch_epss gets the EPSS score of every matched CVE from the FIRST API (no key).
  6. triage sends the matches, EPSS scores and where you run each product to Gemini and gets structured JSON back: priority (P1/P2/P3), exposure and next_step per CVE.
  7. build_alert joins the triage to the KEV facts by CVE id. Unknown ids from the model are dropped, a CVE the model skipped still appears as P2, and overly long notes are shortened.
  8. alert_slack posts each CVE with its name, dates, EPSS and ransomware flag, all from CISA and FIRST, plus the triage.
  9. remember_seen stores every catalog id after the alert, so a failed Slack call is retried.

The errors branch posts to Slack if a feed cannot be read or the model call fails.

Prerequisites

  • A Google AI Studio API key for Gemini (the free tier covers typical KEV volumes: a few new entries per week).
  • A Slack Incoming Webhook.

Secrets

  • GEMINI_API_KEY: Gemini API key used by triage.
  • SLACK_WEBHOOK_URL: Slack Incoming Webhook URL for alerts and failures.

In the open-source edition, secrets are environment variables on the Kestra container, prefixed with SECRET_ and base64-encoded. See how to manage secrets.

Inputs

  • stack (JSON): list of {"vendor", "product", "where"} objects. Leave product empty to match every product of a vendor. where tells the triage step how exposed the product is.
  • environment_context (STRING): a sentence or two about your environment and patch process.
  • lookback_days (INT, default 30): ignore entries added to KEV before this window.
  • model_name (STRING, default gemini-2.5-flash).

Quick start

  1. Add the two secrets and replace stack with the vendors and products you run. Use the spelling CISA uses in vendorProject and product (for example Microsoft / Exchange Server).
  2. Execute the flow. Matching entries from the last lookback_days are reported once.
  3. Execute it again: nothing is posted until CISA adds a matching CVE.
  4. Enable every_two_hours.

To re-run the first-run report, delete the KV key cisa_kev_watch_seen in the namespace.

Outputs

  • {{ outputs.match_stack.vars.matches }}: new KEV entries matching the stack.
  • {{ outputs.build_alert.vars.rows }}: the same entries with EPSS and the AI triage.
  • KV entry cisa_kev_watch_seen: every CVE id in the catalog at the last run.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.