About Harpia
Named after the harpy eagle - an apex predator that watches from above and strikes only what matters.
Security teams drown in vulnerability counts. Hundreds of thousands of CVEs are published, yet under 1% are ever confirmed exploited in the wild - and of the ones that are, 60.7% are already under attack 24 hours after disclosure. Treating every finding the same wastes the scarcest resource a team has - remediation time - on the vast majority that never gets attacked.
Harpia inverts the problem. Instead of asking "how severe could this be?" we ask "is anyone actually exploiting it - and what does that mean for this asset, here, now?"
- An exploitation feed - every CVE continuously tracked across the maturity ladder: disclosed → PoC public → weaponized → exploited in the wild.
- A decision engine - live SSVC decisions per asset context, aligned with CISA guidance, computed on every request. Never cached, never stale.
- Open interfaces - one JSON API for everything, plus a standards-compliant STIX 2.1 / TAXII 2.1 feed. What the web page shows is exactly what the API returns.
The feed is built from public, auditable sources - NVD, OSV.dev (all published ecosystems, including distribution advisories from Ubuntu, Debian, Red Hat, SUSE, AlmaLinux, Rocky Linux and more), CISA KEV, EPSS, exploit databases and repository telemetry - merged, de-duplicated, and scored continuously.
- Evidence over prediction. Exploitation facts come from the feed and cannot be overridden by configuration.
- Decisions over scores. Output is an action - Immediate, Out of cycle, Scheduled, Defer - not another number.
- No black boxes. Aliases, criteria, and policy inputs are shown on every verdict.
Questions, feedback, or partnership ideas? Get in touch.
