Each project is its own scope: staged inventory, run state, findings, per-asset reports and runner log. No project data crosses between projects — only your account API keys, which apply everywhere. Projects are saved in this browser, so they survive a refresh.
| Project | Site | Assets | Findings | KEV | Run State | Inventory Source | |
|---|---|---|---|---|---|---|---|
|
{{ p.name }}
{{ p.slug }} · created {{ p.created }}
|
{{ p.site }} | {{ p.assets }} | {{ p.findings }} | {{ p.kev }} | {{ p.stateLabel }} |
{{ p.source }}
{{ p.stagedAt }}
|
Create a project to stage an inventory and look it up against NVD, CISA KEV and EPSS through the Armexa server.
Asset inventory to exploit intelligence in one pass: each asset's vendor and model is resolved to NVD CPE names, CVEs are matched from NVD, then CISA KEV and EPSS are layered on.
Results are cached in this browser. Pausing keeps everything fetched so far.
{{ stagedStatus }}
{{ inventorySub }}
| Host | Vendor / Product | Version | Lifecycle | Zone | Resolved CPE | CVEs | Status | |
|---|---|---|---|---|---|---|---|---|
|
{{ r.host }}
{{ r.ip }}
|
{{ r.product }}
{{ r.vendor }}
|
{{ r.version }} |
{{ r.lcLabel }}
{{ r.lcSub }}
|
{{ r.zone }} | {{ r.cpe }} | {{ r.cveText }} | {{ r.statusLabel }} |
Inventory lives inside the project. Stage a CSV, paste rows or pull a discovery export from the Run Console.
Ordered CISA KEV first, then EPSS probability, then CVSS base score. Every finding comes from NVD. Where the inventory has no usable firmware version, every CVE for the product is listed — those are flagged so they can be confirmed.
| CVE | Affected Asset | Product | CVSS | EPSS | Exploit Intel | Matched By | |
|---|---|---|---|---|---|---|---|
|
{{ f.cve }}
{{ f.published }}
|
{{ f.host }}
{{ f.zone }} · {{ f.criticality }}
|
{{ f.product }}
{{ f.version }}
|
{{ f.cvss }} | {{ f.epss }} |
|
{{ f.source }} |
{{ sel.summary }}
What each stage returned for this asset.
| CVE | CVSS | EPSS | Exploit Intel | Matched By |
|---|---|---|---|---|
| {{ c.cve }} | {{ c.cvss }} | {{ c.epss }} |
|
{{ c.source }} |
One report per asset is generated in this browser from the latest run.
Pick an asset from the inventory or a row from findings to read its enumeration trace — or take the whole project as a download package.
Every asset is resolved to CPE 2.3 before any CVE search runs. Assets with no model, OS or firmware are held out of the run and listed on the Insufficient Data sheet, so they can't pull in vendor-wide false positives.
| Asset | Source Fields | Proposed CPEs | Evidence | IT/OT | Criticality | Status | ||
|---|---|---|---|---|---|---|---|---|
|
{{ r.host }}
{{ r.ids }}
|
{{ r.vp }}
{{ r.osfw }}
|
{{ c.part }}
{{ c.uri }}
{{ c.conf }}
{{ rc.part }}
{{ rc.uri }}
Removed · insufficient info
|
{{ e.field }} {{ e.value }} · {{ e.col }}
{{ fl }}
|
{{ r.statusLabel }}
{{ r.statusNote }}
|
|
|||
|
CPEs for {{ r.host }}
{{ draftHint }}
|
||||||||
Stage an inventory from the Run Console. Each row gets a proposed CPE here before anything is searched.
Guardian, the internal parser and the pipeline in one de-duplicated CVE set. Devices are matched on asset tag, serial number, MAC address and hostname, in that order. IP addresses are never used to match.
{{ sc.desc }}
Import a Guardian or parser export, or finish a pipeline run for this project. Results de-duplicate as each source lands.
Unique CVEs by the combination of sources that reported them.
Source records linked to an inventory asset, by the first key that matched.
| CVE | Field | Guardian | Internal Parser | Pipeline | Difference | Assets |
|---|---|---|---|---|---|---|
| {{ cf.cve }} | {{ cf.field }} | {{ cf.g }} | {{ cf.p }} | {{ cf.pl }} | {{ cf.diff }} | {{ cf.assets }} |
{{ unmatchedSub }}
| Device | Identifiers | Source | CVEs |
|---|---|---|---|
{{ u.name }} {{ u.product }} |
{{ u.ids }} | {{ u.source }} | {{ u.cves }} |
Descriptions, CWE, KEV date added, known ransomware use, and a short how-it's-exploited summary per CVE.
Exploitation summaries are drafted from NVD and KEV text. Review KEV rows before the workbook goes to the client.
Confirms every CVE ID from the consolidated set has a published record with the CVE Program. IDs that are only reserved by a CNA, rejected, or never assigned carry no vulnerability data, so they are left out of the client workbook unless you confirm them.
Load at least one source on Consolidate Sources. Verification runs on the de-duplicated CVE list.
| CVE | CVE.org Record | Reported By | Assets | In Workbook | Analyst Note | Actions |
|---|---|---|---|---|---|---|
|
{{ vr.cve }}
{{ vr.sub }}
|
{{ vr.stLabel }}
{{ vr.stNote }}
|
{{ vr.sources }} | {{ vr.assets }} |
{{ vr.decLabel }}
{{ vr.decBasis }}
|
|
Status comes from the CVE Program's public ID service (cveawg.mitre.org). Published IDs are kept; reserved, rejected and unassigned IDs are excluded automatically. Include overrides that for a single CVE, for example when a vendor advisory already documents it. Decisions and notes are listed on the CVE Verification sheet.
Client-ready XLSX built from the consolidated set: Armexa cover page, a dashboard with native Excel charts, CVEbyAsset with a live PivotTable, the full de-duplicated CVE list, and the assets held back for insufficient data.
Load at least one source on Consolidate Sources. The workbook is built from the de-duplicated set.
Shown on the Armexa cover and in the file's document properties.
{{ wbFileName }}
API keys for NVD, VulnCheck and VARIoT are held in Azure Key Vault and used only by the Armexa server. They never reach this browser.
Live check of each lookup service the server uses. API keys are held in Azure Key Vault and never reach this browser.
Projects live in this browser only. Download a backup before clearing browser data or changing machines. Restoring replaces projects with the same ID and leaves the rest alone. API keys are never included.
{{ wnPageSub }}
Release notes appear here when a new version ships.
The Microsoft account you are signed in with.
| Name | {{ meName }} |
|---|---|
| {{ meEmail }} | |
| Role |
|
| Sign-in | Microsoft Entra ID |
{{ modalSub }}
{{ deleteDetail }}
Removes the project's staged inventory, findings, per-asset reports and run log from this browser. Other projects and the lookup cache are untouched.
{{ exportSub }}
{{ x.desc }}