Scenario
A new CISA KEV drops overnight.
CISA publishes a fresh exploited-vulnerability advisory. The CVE affects software you actually run. Most teams find out whenever someone next reads the bulletin. CTP247 catches it on the next feed cycle — and once ingested, the pipeline to a triaged alert takes seconds.
What lands on the analyst's desk
By the time the on-call analyst checks Slack, there's a triaged Critical alert with the CVE, the affected assets from your inventory, and a recommended remediation playbook.
CISA KEV feed ingests new entry
The scheduled KEV pull picks up the new exploited-vulnerability row on its next cycle.
→ feed=cisa_kev · cve=CVE-2026-04812
AI triage classifies against your tech stack
The triage agent matches the CVE's affected products against your declared stack. If it hits, an alert is opened with severity and reasoning.
→ match=Adobe Acrobat 24.x · severity=critical
Investigation pulls the asset blast radius
The investigation agent queries your asset inventory for assets matching the affected software and links them to the alert.
→ 23 assets in scope
Critical alert lands with action
The alert names the CVE, the matched assets, and the recommended remediation playbook — prioritized by EPSS and KEV listing.
→ alert=ALERT-9817 · sla=4h