Skip to main content

Raw Findings & Occurrences

The Triage queue tells you what to do first. These two views answer the other questions: what has this scanner found?, which assets have this CVE?, what is the state of this one occurrence?

Raw findings

Where: Vulnerability Management → Raw findings.

Raw findings, Container CVEs source: Log4j, liblzma, Spring RCE and other CVEs on container images with severity, affected assets, open/total, SLA breached and first seen

The list is grouped by vulnerability: one row per unique check or CVE with the number of affected assets, open / total occurrences, SLA state, assignee and first seen. The source chips at the top switch between All Sources, Cloud Misconfig, Kubernetes, Container CVEs, App Scans, Code, IaC, API, Domain and Wazuh, each with its count; filter further by severity and status, or search by title, check ID or CVE. Sort by any column.

Expand a row for the description, the remediation (with the fixed version or the fix recipe), and the affected assets — account, cluster, image or repository plus region or namespace — with a link to each asset's detail.

Raw findings, Code source: GHSA advisories in pyyaml, urllib3 and cryptography with package versions

A raw finding expanded: Apache Log4j2 JNDI RCE with description, remediation (upgrade to 2.17.1) and the affected container image

Sync All Sources pulls the latest results from every module and re-reconciles; use it after a burst of scans rather than waiting for the scheduled sync.

Source views are for owners

The cloud team lives in Cloud Misconfig, the platform team in Kubernetes and Container CVEs, developers in Code. Bookmark the filtered URL for each team — the counts on the chips are the fastest weekly status.

All Occurrences

Where: Vulnerability Management → All Occurrences.

Vulnerability Occurrence Management: filters (status, severity, priority), 521 occurrences with occurrence ID, asset, severity, VPR, priority, status, scanner, SLA due and View Details

An occurrence is one vulnerability on one asset — the unit that SLAs, assignments and Jira tickets attach to. The occurrence list is the flat, auditable view:

ColumnMeaning
Occurrence IDStable identifier used in the API and in tickets
AssetCloud account, cluster, image, repository or application target
Severity / VPRScanner severity and the Vulnerability Priority Rating (KEV × EPSS × CVSS × reachability × criticality)
PriorityP1–P4 from the Triage Engine
Statusopentriagedin_progressresolvedverifiedclosed, or false_positive / accepted_risk
Scanner / SLA dueWhich tool found it, and when the SLA policy says it must be fixed

View Details opens the occurrence: vulnerability details, remediation, lifecycle and SLA (due, breached, notified), assignee, and the status history. From there Assign (by email) and Update Status move it through the lifecycle — verified is the state that confirms a fix was checked, and closed is terminal.

Grouped vs. occurrence status

Raw findings and the Triage queue act on the vulnerability (all its occurrences at once); All Occurrences acts on one asset. Use the occurrence view when a fix landed on some assets but not others, or when one asset legitimately needs an exception.