SecNoteMethodology

How SecNote Ranks Signals

SecNote is a triage layer over public sources. It ranks, groups, and routes signals so an analyst can decide what needs verification, ownership, or monitoring.

Dashboard
HelpMethodologySourcesPrivacy

Ranking

Score Inputs

  • Severity contributes the largest base weight: critical, high, medium, low, or informational.
  • Category changes priority: vulnerabilities, vendor advisories, cyber news, AI news, global risk, US news, world news, geopolitics, and Hacker News are treated differently.
  • Signal language adds weight for KEV, known exploited, zero-day, zero-click, ransomware, initial access, high EPSS, critical CVSS, AI safety, AI policy, AI infrastructure, and AI security.
  • Freshness adds short-lived weight so recent items rise without permanently outranking older source-backed issues.
  • Community traction can add weight for Hacker News items, but it does not turn discussion into confirmed risk.

Actions

Patch, Hunt, Monitor

  • Patch now: critical/high issues, KEV or active exploitation, public exploit pressure, or strong owner-facing remediation signal.
  • Hunt today: ransomware, initial access, credential, malware, exploit, or detection-worthy reporting where telemetry review is more useful than passive monitoring.
  • Monitor: relevant source-backed context that should stay visible but does not yet justify emergency patching or active hunting.

Trust

Confidence and False Positives

  • Source-backed means the item comes directly from a named public source and links to the original report, advisory, feed item, or API record.
  • Inferred means SecNote connected source language to a route, category, action lane, or watchlist match. Treat it as triage context.
  • Name-only means a watched vendor or keyword appeared without explicit breach, advisory, exploit, ransomware, exfiltration, or intrusion wording.
  • Global Risk and map routes are context tools. US News and World News are broad non-cyber daily-brief lanes. None should be used as attribution or incident confirmation without reading the linked source.
The linked source remains the authority. SecNote can help decide where to look first, but it does not confirm exploitation, attribution, exposure, or business impact by itself.

Section logic

Exposure and Vendor Matching

  • Exposure matches use user-selected providers, products, vendors, CVEs, and keywords stored in the browser.
  • Vendor radar separates breach evidence, advisory language, hunt/action signals, and general mentions.
  • General vendor mentions stay out of the radar unless the language indicates current security relevance.
  • Custom vendors should include aliases and products that sources are likely to use publicly.

Section logic

Blue, Red, AI, and Context

  • Blue Team consolidates vulnerability, advisory, cyber, malware, exposure, vendor, patch, hunt, and monitor work into a defensive operations view.
  • Intel maps and routes are inferred from source text, tactic language, geography, and fallback locations when geography is incomplete.
  • Global Risk covers security-adjacent political, economic, trade, military, legal, energy, infrastructure, health, and world context.
  • US News and World News intentionally carry broad non-cyber coverage so general headlines do not dilute cyber, AI, or Global Risk triage.
  • AI Watch separates model, safety, policy, enterprise, infrastructure, and research tracks using source and keyword evidence.
  • Red Team Radar highlights tool, exploit, initial-access, identity, post-exploitation, and evasion signals for authorized defensive validation.
Practical rule: use SecNote to choose the next source to open and the owner to ask, not as the final record of truth.