---
title: EPSS Automation API - A Better Vulnerability Mousetrap
description: Learn how the EPSS API revolutionizes vulnerability management by prioritizing patching based on exploit prediction scores. Manage risk effectively with data-informed decisions.
image: https://true-positives.com/hubfs/Exploit-Prediction-Scoring-System-FIRST.org-better-mousetrap-header.webp
---

[Skip to content](https://true-positives.com/appsec-blog/epss-automation-api-a-better-vulnerability-mousetrap#main-content)

[![True Positives](https://true-positives.com/hubfs/HubSpot%20Header%20Logo%20-%20500x125-1.png)](https://true-positives.com/?hsLang=en)

- Resources 
    - [Vulnerability Atlas](https://vulnerability-atlas.true-positives.com/index.html)

![better mousetrap of Exploit Prediction Scoring System from automation API by first.org](https://true-positives.com/hubfs/Exploit-Prediction-Scoring-System-FIRST.org-better-mousetrap-header.webp)

# EPSS Automation API - A Better Vulnerability Mousetrap

![True Positives](https://true-positives.com/hubfs/T+%20%20Logo%20Webpage%20Header%20(1200%20X%20600)%2001%2009%202026-2.svg)

[True Positives June 17, 2022](https://true-positives.com/appsec-blog/author/true-positives)

- 4 mins

As I noted in April, 2020:

“If EPSS \[Exploit Prediction Scoring System\[1\]\] is going to be of use, there must be some automation for organizations to periodically check scores. The threat landscape is dynamic, so any solution must be equally dynamic.”\[2\]

Huge news: FIRST.org has done it!\[3\]

 

## Prioritization is easy to achieve

Anyone can automatically query the [EPSS API](https://www.first.org/epss/api) for each of the CVEs in their unpatched queue for a prediction score. CVEs (Common Vulnerability Enumeration) whose prediction score exceeds the tolerance of the organization or system risk tolerance would then get patched. CVEs that fall below can be ignored until their prediction score has climbed sufficiently to be of concern.

In other words, dynamic vulnerability prioritization based upon solid research is within reach for everyone. Finally!

 

## EPSS is the solution

For my analyses on why CVSS shouldn’t be used to set patch priority, please see the following two articles:

- [“Mismatch? CVSS, Vulnerability Management, and Organizational Risk”](https://ioactive.com/cvss-vulnerability-management-and-organizational-risk/)
- [“Don’t Substitute CVSS for Risk”](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/dont-substitute-cvss-for-risk-scoring-system-inflates-importance-of-cve-2017-3735/)

As I wrote in my “Mismatch” post, “research from 2014 indicates that using the CVSS base score may be no better than ‘choosing at random.’\[4\]”

There are several problems with CVSS when used beyond its intended purpose, a “potential severity score”, say as a predictor of attacker use, or worse, as a risk rating. For those who would like more detail, I tried to note a few of those in the “Don’t Substitute CVSS for Risk” post as well as explain CVSS issues in greater detail in both [Secrets Of A Cyber Security Architect](https://www.routledge.com/Secrets-of-a-Cyber-Security-Architect/Schoenfield/p/book/9781498741996) and [Building In Security At Agile Speed](https://www.routledge.com/Building-in-Security-at-Agile-Speed/Ransome-Schoenfield/p/book/9780367433260).

Exploit Prediction Scoring System (EPSS) is built on a body of research that indicates which exploits are likely to get used by attackers, and which not. The short crib: exploitation against real systems doesn’t necessarily map to a high CVSS. There are a lot of contributing factors. Please see Allodi & Massacci’s groundbreaking 2014 paper and the EPSS research (both cited in the endnotes, below).

As I noted in 2020, EPSS appears to me to be our “better mousetrap”. At that point (April 2020) only a web page existed, which couldn’t operationalize for organizations that have more than a few vulnerabilities to score. But now, an [API has been published](https://www.first.org/epss/api) and it's dead simple to use.

 

## How to get started

I have no idea whether or not FIRST.org’s API infrastructure is sufficient to support 10’s of thousands of EPSS score requests a day. Still, assuming that they’ve geared up, a little Python code ought to work through even the biggest CVE queue to find those issues that need attention now and those that can wait.

The API provides a call for all CVE above a chosen threshold. The example call returns all CVE with a score .95 or higher:

![Exploit-Prediction-Scoring-System-FIRST.org](https://true-positives.com/hs-fs/hubfs/Exploit-Prediction-Scoring-System-FIRST.org.webp?width=1480&height=58&name=Exploit-Prediction-Scoring-System-FIRST.org.webp)

My trivial Python to identify those CVE that currently hold a 50/50 chance of exploitation:

![Exploit-Prediction-Scoring-System-FIRST.org2](https://true-positives.com/hs-fs/hubfs/Exploit-Prediction-Scoring-System-FIRST.org2.webp?width=1436&height=198&name=Exploit-Prediction-Scoring-System-FIRST.org2.webp)

Each organization must determine its own risk tolerance. Perhaps yours can’t tolerate much possibility of exploitation? In that context, the best number might be low, say 20% (.20). Or, your organization may be able to survive some successful exploitation which then might lead to using a much higher prediction floor? The number to use will be entirely contextual. My Python example uses 50% (.50).

 

## Manage your vulnerability debt

In my humble opinion, the EPSS API is truly a big deal. Anyone who has a significant open vulnerability queue should adopt EPSS immediately\[5\]. Of course, EPSS provides a “prediction”, a data-informed “guess” as to which CVE attackers might use at any particular moment. There are no guarantees.

As I’ve said many times, attackers are creative, adaptable, and innovative. The threat landscape is dynamic.

Just because a CVE doesn’t score a sufficiently high prediction value doesn’t mean it won’t actually be used. Attackers are resourceful people who may do the unexpected. No security is perfect. As always, a layered defense raises attack costs, limits exploit impacts, while also surfacing indicators of compromise so that the unexpected can be caught early enough to survive.

EPSS won’t save you the trouble of building security architectures. But it will help to manage unpatched vulnerability queues so that issues that have probability to be used get priority.

Let’s fix issues that have some probability of actually being exploited rather than chasing “all” or over-reacting to every hyped, logo-ed fire-drill.

---

*\[1\] Prioritization to Prediction, Cyentia Institute, and Kenna Security: https://www.kennasecurity.com/prioritization-to-prediction-report/images/Prioritization\_to\_Prediction.pdf and “Exploit Prediction Scoring System (EPSS)” https://www.first.org/epss/*

*\[2\] Mismatch? CVSS, Vulnerability Management, and Organizational Risk*

*\[3\] Thanks to Walter Haydock for alerting me to the publish of the EPSS API*

*\[4\]Allodi, Luca & Massacci, Fabio. (2014). Comparing Vulnerability Severity and Exploits Using Case-Control Studies. ACM Transactions on Information and System Security. 17. 1-20. 10.1145/2630069. http://seconomicsproject.eu/sites/default/files/seconomics/public/content-files/downloads/Comparing Vulnerabilities and Exploits using case-control studies.pdf and NopSec, Inc’s 2016 and 2018 State of Vulnerability Risk Management Reports: http://info.nopsec.com/SOV-2016.html and http://info.nopsec.com/SOV-2018.html*

*\[5\] It would be great if organizations who use the EPSS API would contribute to subsidize FIRST.org EPSS efforts.*

![True Positives](https://true-positives.com/hubfs/T+%20%20Logo%20Webpage%20Header%20(1200%20X%20600)%2001%2009%202026-2.svg)

### True Positives

True Positives is an authorized Invicti VAR and application security MSSP delivering proof-based DAST scanning and managed vulnerability assessment services to organizations across North America. The firm operates through two delivery models: fully managed application security services for organizations seeking outsourced program operations, and direct platform licensing for teams prepared to run Invicti internally. For additional information, visit https://true-positives.com.

<https://www.linkedin.com/company/true-postives/> [mailto:appsec_solutions@true-positives.com](mailto:appsec_solutions@true-positives.com) <https://true-positives.com/?rel=author>

<https://true-positives.com/appsec-blog/author/true-positives>

## Latest posts

- [ALL POSTS](https://true-positives.com/appsec-blog/all)

[![True Positives](https://true-positives.com/hubfs/HubSpot%20Footer%20Logo%20-%20360x90.png)](https://true-positives.com/?hsLang=en)

[Managed AppSec](https://true-positives.com/managed_appsec_mssp) [In-House AppSec Support](https://true-positives.com/direct-platform-licensing)

[PRO Services](https://true-positives.com/appsec-pro-services) [Why T+](https://true-positives.com/why-true-positives)

[Resources](https://vulnerability-atlas.true-positives.com/index.html) [Contact Us](https://true-positives.com/contact-truepositives)

<https://www.facebook.com/truepositives> <https://x.com/TruePositives> <https://www.linkedin.com/company/truepositives/>

© 2026 True Positives, LLC. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "True Positives",
    "url" : "https://true-positives.com/appsec-blog/author/true-positives"
  },
  "dateModified" : "2024-03-20T23:14:07.063Z",
  "datePublished" : "2022-06-17T14:45:00.000Z",
  "headline" : "EPSS Automation API - A Better Vulnerability Mousetrap",
  "image" : [ "https://true-positives.com/hubfs/Exploit-Prediction-Scoring-System-FIRST.org-better-mousetrap-header.webp" ],
  "mainEntityOfPage" : {
    "@id" : "https://true-positives.com/appsec-blog/epss-automation-api-a-better-vulnerability-mousetrap",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://true-positives.com/hubfs/HubSpot%20Header%20Logo%20-%20500x125.png"
    }
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "US",
    "addressLocality" : "Chehalis",
    "addressRegion" : "Washington",
    "postalCode" : "98532",
    "streetAddress" : "110 Villageway Drive"
  },
  "contactPoint" : [ {
    "@type" : "ContactPoint",
    "areaServed" : "US",
    "availableLanguage" : "English",
    "contactType" : "Sales",
    "telephone" : "+1-206-854-8999"
  }, {
    "@type" : "ContactPoint",
    "areaServed" : "US",
    "availableLanguage" : "English",
    "contactType" : "Sales",
    "telephone" : "+1-404-314-3929"
  }, {
    "@type" : "ContactPoint",
    "availableLanguage" : "English",
    "contactType" : "Customer Support",
    "email" : "tplus-support@true-positives.com"
  }, {
    "@type" : "ContactPoint",
    "availableLanguage" : "English",
    "contactType" : "General Inquiries",
    "email" : "contact@true-positives.com"
  } ],
  "description" : "True Positives is a trusted AppSec MSSP delivering expert-led DAST and automated vulnerability scanning—reducing risk, eliminating false positives, and cutting overhead without compromising security.",
  "email" : "info@true-positives.com",
  "logo" : {
    "@type" : "ImageObject",
    "url" : "https://true-positives.com/hs-fs/hubfs/managed-application-security-testing-true-positives-logo.jpg?width=640&height=160&name=managed-application-security-testing-true-positives-logo.jpg"
  },
  "name" : "True Positives",
  "sameAs" : [ "https://www.linkedin.com/company/truepositives/", "https://www.facebook.com/truepositives/" ],
  "url" : "https://true-positives.com"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "Product",
  "aggregateRating" : {
    "@type" : "AggregateRating",
    "ratingValue" : "5",
    "reviewCount" : "3"
  },
  "name" : "True Positives Managed AppSec Services",
  "review" : [ {
    "@type" : "Review",
    "author" : {
      "@type" : "Person",
      "name" : "Brook Schoenfield"
    },
    "name" : "Valuable Insights for Strategic AppSec",
    "reviewBody" : "True Positives goes beyond simply identifying vulnerabilities in application security testing. Their managed service delivers actionable insights and prioritization, allowing businesses to mitigate risks effectively and allocate resources strategically, all while controlling costs.",
    "reviewRating" : {
      "@type" : "Rating",
      "bestRating" : "5",
      "ratingValue" : "5"
    }
  }, {
    "@type" : "Review",
    "author" : {
      "@type" : "Person",
      "name" : "Dan Kuykendall"
    },
    "name" : "Reliable Scanning with Human Guidance",
    "reviewBody" : "True Positives offers a great option for managed scanning, offering a cost-effective solution for quality and reliable scans. They don’t just send reports—they verify vulnerabilities, guide developers, and help prioritize and fix issues.",
    "reviewRating" : {
      "@type" : "Rating",
      "bestRating" : "5",
      "ratingValue" : "5"
    }
  }, {
    "@type" : "Review",
    "author" : {
      "@type" : "Person",
      "name" : "Julie Richard"
    },
    "name" : "Trusted DAST Partner for Enterprise Needs",
    "reviewBody" : "Partnering with True Positives for managed DAST services will save you countless hours and headaches. Their expertise and proactive approach streamline identification and prioritization of vulnerabilities while also ensuring development has the information it needs to secure valuable assets.",
    "reviewRating" : {
      "@type" : "Rating",
      "bestRating" : "5",
      "ratingValue" : "5"
    }
  } ]
}
```