Know when vulnerability becomes attack.
Track PoCs, weaponization, exploitation in the wild, ransomware associations, repository activity, and evidence provenance.
Explore exploit intelligenceHarpia continuously correlates exploit maturity, active exploitation, threat activity, and vulnerability context so security teams can prioritize remediation with evidence, not severity alone.
Is it exploited in the wild?
Movement matters. Harpia tracks rising exploit activity, public repositories, exploitation evidence and observed probing to surface what deserves attention next.
A focused intelligence layer for vulnerability management, SOC workflows, threat intelligence, and security products.
Track PoCs, weaponization, exploitation in the wild, ransomware associations, repository activity, and evidence provenance.
Explore exploit intelligenceCombine feed facts with asset exposure and mission impact to produce operational remediation decisions rather than another score.
See decision workflowMap relevant actors, ransomware, ATT&CK techniques, targeting, sectors, and observed probing around vulnerable technologies.
Explore threat contextConsume Harpia through REST, bulk APIs, STIX 2.1, TAXII 2.1, and delta synchronization.
Developer platformHarpia separates theoretical impact from operational urgency, helping teams concentrate remediation capacity where attacker behavior changes the decision.
How Harpia decidesA vulnerability exists. Severity describes potential impact.
Exploit code changes feasibility and attacker cost.
Real-world evidence changes remediation urgency.
Immediate · Out of cycle · Scheduled · Defer.
Search interactively or operationalize the same intelligence in pipelines, SIEM enrichment, TIPs, patch queues, and security products.
The web experience and machine interfaces resolve against the same exploitation evidence and decision context.
Open developer documentationGET /api/v1/vulnerabilities/CVE-2024-3400
{
"x_intel_priority": {
"exploited_in_wild": true,
"exploit_maturity": "active",
"cisa_kev": true
}
}See whether attackers are already using the vulnerability.