Skip to content
Release: Australia · Updated: 2026-06-23 · Official documentation · View source

Early Warning CVD Attributes field reference

The Early Warning CVD Attributes table stores threat intelligence signals for vulnerabilities. Each attribute represents a pre-disclosure threat indicator ingested from the Early Warning feed.

Early warning threat signals are stored in the Armis Early Warning CVD Attributes [sn_vul_ew_cvd_attributes] table, a specialized extension table for vulnerability attributes. Each record in this table represents a unique CVE and stores the set of threat intelligence attributes ingested from Armis.

Attribute fields

FieldDescription
CVE IDIdentifier of the CVE record, such as `CVE-2026-33824`.
CWECommon Weakness Enumeration identifier associated with the CVE, such as `CWE-415`.
Date AddedDate and time when this CVE was added to the Armis Early Warning dataset.
Intel DateDate and time when Armis first obtained intelligence about this CVE.
Admiralty ScoreNATO grading system for threat intelligence confidence and reliability. Scores range from A1 \(highest confidence\) to F6 \(lowest confidence\). Use this score to assess the credibility of associated threat signals.
Vendor/ProjectName of the vendor or project associated with the affected software.
Research DateDate when academic or security research was published that details the vulnerability, its impact, or exploitation techniques.
Honeypot DateDate and time when honeypot systems recorded exploit activity against this CVE. A honeypot is a decoy system deliberately exposed to attackers. This field is empty when no honeypot activity has been observed.
ProductName of the specific product affected by the CVE, such as `Windows 10 1607`.
Notification DateDate and time when ServiceNow received notification of this CVE from Armis.
Updated OnDate and time when this record was last updated in ServiceNow.
EnabledOption to indicate whether this CVE record is active and included in risk scoring and downstream processing.
SpecialOption to flag this CVE as a special case for further review or custom handling.
Summary NoteFree-text summary describing the intelligence gathered for this CVE, including the source of the information and the basis for the admiralty score.
External NoteStructured free-text field containing sub-categories of intelligence detail: Intel Source, Honeypot, Research, Detection, Vulnerable, Malware hash, Analyst note, Intel note, and Admiralty score. Values are reported as `NA` when no data is available for a sub-category.

Parent Topic:Early Warning for Security Exposure Management integration