Deriving CVSS from Multi-Scenario Attack Graphs: A Reproducible, Auditable Scoring Method @FIRSTdotorg
Deriving CVSS from Multi-Scenario Attack Graphs: A Reproducible, Auditable Scoring Method  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 3 hours ago
Karel Knibbe (Volerion, NL), Ruben Bos (Volerion, NL)

CVSS is standardized, yet difficult to apply in practice. Traditional CVSS enrichment starts by mentally constructing an attack scenario, but that context is abstracted away by the final vector. In addition to this, many vulnerabilities have multiple plausible exploitation paths, but workflows lack the ability to choose the most severe candidate. Without first considering all plausible scenarios, it is unclear which scenario the final vector should be based on, and "worst case" becomes an assumption rather than fact. In an attempt to represent multiple possibilities with a single score, analysts often end up mixing metric choices drawn from different scenarios, producing a hybrid vector that does not faithfully represent any single attack. These shortcomings drive inconsistency, inaccuracy, and lack auditability. This talk presents a transparent, multi-scenario scoring method based on attack graphs, thereby eliminating all three.

---

Ruben Bos is co-founder of Volerion, where he and co-founder Karel Knibbe use AI to improve the quality, consistency, and timeliness of CVE data. Ruben studied software engineering and holds a cum laude Bachelor’s degree in Cyber Security. He has over a decade of experience in bug bounty and penetration testing, including winning multiple live hacking events hosted by companies such as Meta and Intel. Over the past two years, he has focused on high-accuracy CVSS automation and vulnerability enrichment, progressing from direct vector prediction to guided walkthrough approaches and ultimately to a graph-based method that models exploitation as explicit scenarios and derives CVSS vectors programmatically.
Deriving CVSS from Multi-Scenario Attack Graphs: A Reproducible, Auditable Scoring MethodUnmasking Cyber Security: Rethinking Small to Medium Business Security AwarenessFrom Planning to Impact: Lessons from Poland’s National Cybersecurity Exercises with a Dedicated ...From CVD to Secure Releases: Automating Security from Source to ReleasesOnly Seeing Stars: Enabling the Open Source Scripting Community with OCSFInside the Information Stealer Ecosystem: From Compromise to CountermeasureImproving Security Across Nations with FIRST: Tom Millar, FIRST TLP SIG Co-chairDraugnet: Anonymous Threat Reporting That Actually WorksAutomated ATT&CK Technique ChainingPanel: The CVE Supplier ADP (SADP) Pilot: Am I Affected byUpstream?Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD)Lazarus Group Evolved Their Infection Chain with Old and New Malware
FIRST |

Deriving CVSS from Multi-Scenario Attack Graphs: A Reproducible, Auditable Scoring Method

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER