Harpia - harpy eagle emblemHARPIAExploitation Intelligence

Choose how
to decide.

Harpia provides two complete decision frameworks. Select one for each request. The response follows only that framework, so priority and deadline never contradict one another.

Two frameworks

1.Harpia SSVC - Priority and deadline

Returns Immediate, Out of cycle, Scheduled, or Defer. Each priority has one matching timeline.

2.CISA BOD 26-04 - Compliance timeline

Returns 3 days, 14 days, 60 days, or system upgrade, plus forensic triage when required.

Your context

Your asset context

Exposure

Can an attacker reach the affected deployment?

  • exposed - reachable from the internet or another untrusted network. Examples: a public VPN gateway, email server, or customer-facing web application.
  • controlled - reachable only through meaningful access controls or segmentation. Examples: an administration service restricted to a VPN, allow-listed management network, or authenticated partner connection.
  • not_exposed - no attacker-reachable network path in its normal operating environment. Examples: an isolated lab system, offline appliance, or disconnected build environment.

Mission consequence

If the asset is compromised, how serious is the effect on your mission?

  • critical - essential operations, safety, or core control would fail. Examples: identity infrastructure, a production control plane, or a safety-critical system.
  • high - major service or sensitive-data impact with limited alternatives. Examples: a customer production service, payment platform, or primary business database.
  • moderate - disruption is contained and a practical workaround or recovery path exists. Examples: a departmental application or non-primary internal service.
  • low - little operational consequence and no sensitive data. Examples: a disposable test environment or non-production demonstration system.

Classify the affected deployment, not the vulnerability in the abstract. Both frameworks use Exposure. Mission consequence is a Harpia SSVC decision point and is not part of the BOD table. Omitted inputs use the conservative defaults: exposed and critical.

Harpia evidence

The vulnerability facts come from Harpia

Harpia resolves Exploitation, Automatable, and Technical Impact. The response preserves the source, method, confidence, and any disagreement between reported and independently derived values.

Two different consequences. Mission consequence describes the importance of your asset. Technical Impact describes the control an attacker gains over the vulnerable component. They are never substituted for one another.
Harpia SSVC

Priority selects the deadline

In Harpia SSVC mode, the priority and timeline are one decision. Changing exposure or mission consequence can change both.

1.Immediate - Act now

Break the normal schedule. The evidence and asset context indicate that waiting creates unacceptable risk.

2.Out of cycle - Bring forward

Do not wait for the normal maintenance train. Bring the fix forward, but planned coordination is still possible.

3.Scheduled - Normal cycle

Keep the fix in the regular maintenance cycle. The vulnerability matters, but current evidence does not justify disruption.

4.Defer - Monitor

Do not spend remediation capacity yet. Keep watching because new exploitation evidence can change the decision.

One-to-one timeline mapping

1.Immediate - 3 days

Act now and complete remediation within three days of discovery.

2.Out of cycle - 14 days

Bring the work forward and complete remediation within fourteen days.

3.Scheduled - 60 days

Keep the work in a managed cycle with a sixty-day deadline.

4.Defer - System upgrade

Monitor the evidence and remediate during the next system upgrade.

Inside the engine

Exploitation is a maturity ladder

Harpia does not collapse every exploit signal into a single Yes or No. Evidence advances through four states, and each stronger state can increase urgency.

1.None - Observe

No qualifying public exploit or verified exploitation evidence is currently known.

2.PoC - Exploitability shown

Public proof-of-concept code demonstrates the weakness, but does not prove operational use.

3.Weaponized - Operational capability

Exploit capability is packaged for repeatable operational use. Weaponized does not automatically mean Automatable.

4.Active - Verified exploitation

Credible evidence confirms exploitation in the wild. KEV is one source of this evidence, not the only source.

Automatable and Technical Impact answer different questions

Automatable

Can an attacker repeat initial exploitation reliably at scale? Harpia resolves this independently. A public PoC or weaponized tool can still require target-specific work and therefore remain not automatable.

Technical Impact

What control does successful exploitation provide over the vulnerable component? Total means high confidentiality and integrity impact. Other combinations are Partial.

Conservative fallback. CVSS v4 uses vulnerable-system confidentiality and integrity; CVSS v3 uses confidentiality and integrity. CVSS v2, missing vectors, or malformed modern vectors receive a provisional Total value so incomplete data cannot silently reduce urgency.

Reported evidence is checked, not blindly trusted

1.Reported - What the source said

Harpia preserves an upstream SSVC Technical Impact label when one exists.

2.Derived - What Harpia calculated

Harpia independently calculates Technical Impact from the available CVSS evidence.

3.Effective - What the policy used

The policy uses the more conservative value and exposes a conflict when reported and derived values disagree.

4.Explainable - Why it decided

The API returns value, source, method, confidence, provisional status, and conflict - not only the final label.

Policy behavior

Harpia SSVC is an urgency waterfall

The engine evaluates the highest-urgency conditions first. The first matching category wins. Stronger exploitation, greater exposure, automation, Total Technical Impact, or higher mission consequence must never produce a less urgent decision.

Vulnerability facts can only come from Harpia

Customers cannot override exploitation, automation, or Technical Impact. This prevents a request from downgrading observed threat evidence.

Asset context can only come from you

Harpia cannot know whether your deployment is reachable or mission-critical. Those two values remain explicit request inputs.

BOD 26-04 is a separate framework

BOD mode does not combine a Harpia priority with a CISA deadline. It returns the BOD remediation timeline directly from Publicly Exposed, On KEV, Automatable, and Technical Impact. Mission consequence does not participate in this table.

framework=harpia_ssvc

Uses Harpia's full exploitation ladder, asset exposure, mission consequence, automatability, and Technical Impact. The priority selects its matching timeline.

framework=bod_26_04

Uses CISA KEV membership exactly and evaluates the complete BOD 26-04 remediation table, including forensic triage.

How the due date is calculated

Both frameworks use the optional discovered=YYYY-MM-DD value to start the clock. Harpia adds the selected 3-, 14-, or 60-day window and returns due_date and overdue. System-upgrade results have no fixed due date. If discovered is omitted, the current UTC date is used.

Decision reference

How the Harpia priority decision changes with context

These examples show how the same evidence can produce a different action when the affected asset changes.

Harpia decisionTimelineExploitationExposureMission consequenceOther facts
Immediate3 daysActiveExposedCriticalAny
Out of cycle14 daysActiveNot exposedLowAny
Out of cycle14 daysWeaponizedControlledModerateAny
Scheduled60 daysPoCControlledModerateNot automatable
DeferSystem upgradeNoneNot exposedLowNot automatable · Partial

CISA BOD 26-04 remediation table

Select framework=bod_26_04 to evaluate this table exactly with CISA KEV membership. Harpia SSVC evidence does not broaden the On KEV decision point in this mode.

Remediation timelinePublicly exposedOn KEVAutomatableTechnical Impact
3 days + forensic triageYesYesYesTotal
3 daysYesYesYesPartial
3 days + forensic triageYesYesNoTotal
14 daysYesYesNoPartial
3 daysYesNoYesTotal
14 daysYesNoYesPartial
14 daysYesNoNoTotal
60 daysYesNoNoPartial
3 days + forensic triageNoYesYesTotal
14 daysNoYesYesPartial
14 daysNoYesNoTotal
14 daysNoYesNoPartial
60 daysNoNoYesTotal
60 daysNoNoYesPartial
Fix on system upgradeNoNoNoTotal
Fix on system upgradeNoNoNoPartial

Timeline source: CISA BOD 26-04, Appendix A, Table 1 ↗.

API usage

Ask the same CVE with either framework

Harpia SSVC

GET /api/v1/vulnerabilities/CVE-2024-3400/decision
  ?framework=harpia_ssvc
  &exposure=exposed
  &mission_consequence=critical
  &discovered=2026-08-24

CISA BOD 26-04

GET /api/v1/vulnerabilities/CVE-2024-3400/decision
  ?framework=bod_26_04
  &exposure=exposed
  &mission_consequence=critical
  &discovered=2026-08-24

The first response contains a Harpia priority and its matching timeline. The second contains the BOD timeline and forensic-triage requirement. The frameworks are not combined.

Try both frameworks on a real CVE.