Harpia - harpy eagle emblemHARPIAExploitation Intelligence

See what attackers are using now.

Harpia continuously correlates exploit maturity, active exploitation, threat activity, and vulnerability context so security teams can prioritize remediation with evidence, not severity alone.

Sign in to search · No credit card · Machine-readable intelligence
HARPIA / LIVE LOOKUP

Is it exploited in the wild?

try
Advanced search syntax
Search syntax
CVE & advisory IDs
Full text
Scores & evidence
Threat flags
has: shorthands
Software
Weakness & combinations
Who & why Pro
Origin and target accept ISO-2, a country name, or a partial word.
ATT&CK, CAPEC & tactics Pro
Worked examples Pro
AND is implicit · OR / NOT / - / parentheses supported · quote a phrase to match it literally · click any example to run it
37.7%of exploited CVEs attacked before disclosure
60.7%under attack within 24 hours
93%of what CVSS calls Critical has no weaponized exploit
15 daysahead of CISA KEV

From vulnerability signal to remediation decision.

A focused intelligence layer for vulnerability management, SOC workflows, threat intelligence, and security products.

01 / Exploit intelligence

Know when vulnerability becomes attack.

Track PoCs, weaponization, exploitation in the wild, ransomware associations, repository activity, and evidence provenance.

Explore exploit intelligence
02 / Prioritization

Turn evidence into a defensible action.

Combine feed facts with asset exposure and mission impact to produce operational remediation decisions rather than another score.

See decision workflow
03 / Threat context

Connect vulnerabilities to adversary activity.

Map relevant actors, ransomware, ATT&CK techniques, targeting, sectors, and observed probing around vulnerable technologies.

Explore threat context
04 / Machine delivery

Put the same intelligence into your stack.

Consume Harpia through REST, bulk APIs, STIX 2.1, TAXII 2.1, and delta synchronization.

Developer platform

Severity is context. Exploitation is intent.

Harpia separates theoretical impact from operational urgency, helping teams concentrate remediation capacity where attacker behavior changes the decision.

How Harpia decides
  1. 01

    Disclosed

    A vulnerability exists. Severity describes potential impact.

  2. 02

    PoC / weaponized

    Exploit code changes feasibility and attacker cost.

  3. 03

    Exploited in the wild

    Real-world evidence changes remediation urgency.

  4. 04

    Decision

    Immediate · Out of cycle · Scheduled · Defer.

One feed. Every security workflow.

Search interactively or operationalize the same intelligence in pipelines, SIEM enrichment, TIPs, patch queues, and security products.

Same evidence, every interface

From one lookup to continuous enrichment.

The web experience and machine interfaces resolve against the same exploitation evidence and decision context.

Open developer documentation
GET /api/v1/vulnerabilities/CVE-2024-3400

{
  "x_intel_priority": {
    "exploited_in_wild": true,
    "exploit_maturity": "active",
    "cisa_kev": true
  }
}
REST APISTIX 2.1TAXII 2.1Bulk APIDelta syncSIEM / SOAR
Start with evidence

Prioritize what attackers are exploiting now.

See whether attackers are already using the vulnerability.