Armexa Armexa
VEC Tool
by Armexa
Workspace
Pipeline
Deliverable
Platform
{{ meInitials }} {{ meName }}
{{ versionLabel }}
Project
{{ runBadgeLabel }}
This view hit an error
{{ fatalMsg }} — your saved projects are untouched. Go back to Projects to continue; download a backup if it happens again.
{{ storeIssueTitle }}
{{ storeIssueMsg }}

Projects

Each project is its own scope: staged inventory, run state, findings, per-asset reports and runner log. No project data crosses between projects — only your account API keys, which apply everywhere. Projects are saved in this browser, so they survive a refresh.

{{ projectResultLabel }}
Project Site Assets Findings KEV Run State Inventory Source
{{ p.name }}
{{ p.slug }} · created {{ p.created }}
{{ p.site }} {{ p.assets }} {{ p.findings }} {{ p.kev }} {{ p.stateLabel }}
{{ p.source }}
{{ p.stagedAt }}

No projects

Create a project to stage an inventory and look it up against NVD, CISA KEV and EPSS through the Armexa server.

Run Console

Asset inventory to exploit intelligence in one pass: each asset's vendor and model is resolved to NVD CPE names, CVEs are matched from NVD, then CISA KEV and EPSS are layered on.

Lookup Source
{{ lookupNote }}
{{ lookupKeysNote }}
No inventory staged for this project
New projects start empty — nothing is inherited from other projects. Stage one below: upload a CSV/CMDB export, paste rows, or add a single asset.
Assets In Scope
{{ kpiAssets }}
{{ kpiAssetsSub }}
CPEs Resolved
{{ kpiCpes }}
{{ kpiCpesSub }}
CVE Matches
{{ kpiCves }}
{{ kpiCvesSub }}
Known Exploited
{{ kpiKev }}
{{ kpiKevSub }}

Stage Progress

Results are cached in this browser. Pausing keeps everything fetched so far.

{{ elapsedLabel }}
{{ s.label }} {{ s.service }} {{ s.countText }} {{ s.badgeLabel }}

Runner Log

Run log
{{ l.t }} {{ l.text }}

Inventory Source

{{ stagedStatus }}

Columns are matched by header name — Master Asset Inventory exports (Name, Vendor, Product Name/Model Number, Zones, Est. Purdue Level), consolidated CPE sheets (Asset Name, Vendor (raw), CPE columns) and plain host,vendor,product,version files all work. Banner rows above the header are skipped, quoted multi-IP cells take the first address, a CPE column is used as-is, and zones fall back to Purdue level or device type when absent.
{{ manualHint }}

Asset Inventory

{{ inventorySub }}

{{ invResultLabel }}
Host Vendor / Product Version Lifecycle Zone Resolved CPE CVEs Status
{{ r.host }}
{{ r.ip }}
{{ r.product }}
{{ r.vendor }}
{{ r.version }} {{ r.lcLabel }}
{{ r.lcSub }}
{{ r.zone }} {{ r.cpe }} {{ r.cveText }} {{ r.statusLabel }}

Nothing staged in this project

Inventory lives inside the project. Stage a CSV, paste rows or pull a discovery export from the Run Console.

{{ invPageLabel }}

Findings

Ordered CISA KEV first, then EPSS probability, then CVSS base score. Every finding comes from NVD. Where the inventory has no usable firmware version, every CVE for the product is listed — those are flagged so they can be confirmed.

KEV Listed
{{ fKev }}
Patch or compensate first
EPSS > 10%
{{ fEpss }}
30-day exploitation likelihood
Public PoC
{{ fPoc }}
{{ fPocSub }}
Version Not Pinned
{{ fUnpinned }}
Confirm firmware to narrow
{{ findResultLabel }}
CVE Affected Asset Product CVSS EPSS Exploit Intel Matched By
{{ f.cve }}
{{ f.published }}
{{ f.host }}
{{ f.zone }} · {{ f.criticality }}
{{ f.product }}
{{ f.version }}
{{ f.cvss }} {{ f.epss }}
{{ tg.label }}
{{ f.source }}
{{ findPageLabel }}
Per-asset report · {{ sel.runId }}

{{ sel.host }}

{{ sel.summary }}

Enumeration Trace

What each stage returned for this asset.

{{ t.stage }}
{{ t.ms }}
{{ t.out }}
{{ t.note }}

CVEs On This Asset

{{ sel.cveCountLabel }}
CVE CVSS EPSS Exploit Intel Matched By
{{ c.cve }} {{ c.cvss }} {{ c.epss }}
{{ tg.label }}
{{ c.source }}

Asset Facts

{{ f.k }} {{ f.v }}

sploitscan --json

top finding
{{ sel.json }}

Asset Reports

One report per asset is generated in this browser from the latest run.

No report selected

Pick an asset from the inventory or a row from findings to read its enumeration trace — or take the whole project as a download package.

CPE Mapping

Every asset is resolved to CPE 2.3 before any CVE search runs. Assets with no model, OS or firmware are held out of the run and listed on the Insufficient Data sheet, so they can't pull in vendor-wide false positives.

Ready
{{ mapReady }}
Specific CPE, searched as-is
Needs Review
{{ mapReview }}
Searched, but check the CPE
Insufficient Data
{{ mapInsufficient }}
Held out of CVE search
CPEs In Scope
{{ mapCpes }}
Hardware, OS / firmware and application
{{ mapResultLabel }}
{{ mapSelLabel }} Set status:
Asset Source Fields Proposed CPEs Evidence IT/OT Criticality Status
{{ r.host }}
{{ r.ids }}
{{ r.vp }}
{{ r.osfw }}
{{ c.part }} {{ c.uri }} {{ c.conf }}
No CPE — {{ r.reason }}
{{ rc.part }} {{ rc.uri }} Removed · insufficient info
{{ e.field }} {{ e.value }} · {{ e.col }}
{{ fl }}
{{ r.statusLabel }}
{{ r.statusNote }}
CPEs for {{ r.host }}
{{ draftHint }}

Nothing to map yet

Stage an inventory from the Run Console. Each row gets a proposed CPE here before anything is searched.

{{ mapPageLabel }}

Consolidate Sources

Guardian, the internal parser and the pipeline in one de-duplicated CVE set. Devices are matched on asset tag, serial number, MAC address and hostname, in that order. IP addresses are never used to match.

Real data only
{{ mixRealNote }}

{{ sc.name }}

{{ sc.desc }}

{{ sc.statusLabel }}
{{ fm }}
{{ fi.name }} {{ fi.meta }}

No sources loaded

Import a Guardian or parser export, or finish a pipeline run for this project. Results de-duplicate as each source lands.

Raw CVE Rows
{{ mRaw }}
{{ mRawSub }}
Asset–CVE Pairs
{{ mPairs }}
{{ mPairsSub }}
Unique CVEs
{{ mCves }}
{{ mCvesSub }}
Devices With Findings
{{ mDevices }}
{{ mDevicesSub }}

Where Each CVE Came From

Unique CVEs by the combination of sources that reported them.

{{ o.label }}
{{ o.count }}

How Devices Were Matched

Source records linked to an inventory asset, by the first key that matched.

{{ mr.label }} {{ mr.note }} {{ mr.count }}
Source Conflicts
Where sources disagree on the same CVE, each value is kept side by side and carried into FullCVEList.
{{ conflictLabel }}
CVE Field Guardian Internal Parser Pipeline Difference Assets
{{ cf.cve }} {{ cf.field }} {{ cf.g }} {{ cf.p }} {{ cf.pl }} {{ cf.diff }} {{ cf.assets }}
{{ conflictPageLabel }}

Unmatched Source Records

{{ unmatchedSub }}

DeviceIdentifiersSourceCVEs
{{ u.name }}
{{ u.product }}
{{ u.ids }} {{ u.source }} {{ u.cves }}

NVD + CISA KEV Enrichment

Descriptions, CWE, KEV date added, known ransomware use, and a short how-it's-exploited summary per CVE.

{{ enrichLabel }}
{{ es.label }} {{ es.value }}

Exploitation summaries are drafted from NVD and KEV text. Review KEV rows before the workbook goes to the client.

Verify CVEs

Confirms every CVE ID from the consolidated set has a published record with the CVE Program. IDs that are only reserved by a CNA, rejected, or never assigned carry no vulnerability data, so they are left out of the client workbook unless you confirm them.

No CVEs to verify

Load at least one source on Consolidate Sources. Verification runs on the de-duplicated CVE list.

Checking {{ vRunLabel }}
Checked
{{ vChecked }}
{{ vCheckedSub }}
Published
{{ vPublished }}
Real, public CVE records
Reserved by CNA
{{ vReserved }}
ID assigned, no details published
Not Assigned or Rejected
{{ vBad }}
{{ vBadSub }}
{{ vResultLabel }}
CVE CVE.org Record Reported By Assets In Workbook Analyst Note Actions
{{ vr.cve }}
{{ vr.sub }}
{{ vr.stLabel }}
{{ vr.stNote }}
{{ vr.sources }} {{ vr.assets }} {{ vr.decLabel }}
{{ vr.decBasis }}
cve.org NVD
{{ vPageLabel }}

Status comes from the CVE Program's public ID service (cveawg.mitre.org). Published IDs are kept; reserved, rejected and unassigned IDs are excluded automatically. Include overrides that for a single CVE, for example when a vendor advisory already documents it. Decisions and notes are listed on the CVE Verification sheet.

Client Workbook

Client-ready XLSX built from the consolidated set: Armexa cover page, a dashboard with native Excel charts, CVEbyAsset with a live PivotTable, the full de-duplicated CVE list, and the assets held back for insufficient data.

{{ rd.state }}
{{ rd.label }}
{{ rd.note }}

Nothing to package yet

Load at least one source on Consolidate Sources. The workbook is built from the de-duplicated set.

Armexa
{{ cvTitle }}
{{ cvClientSite }}
{{ cvAssessment }} · Achievable Industrial Cybersecurity™
{{ cp.k }} {{ cp.v }}
{{ t.label }}
{{ t.value }}
{{ t.note }}
CVEs by Severity
{{ sv.count }}
{{ sv.label }}
Exploited vs Theoretical
{{ ds.label }} {{ ds.count }} {{ ds.share }}
Top 10 Riskiest Assets
AssetIT/OTCriticalityCVEsKEVMax CVSS
{{ tp.host }}
{{ tp.vp }}
{{ tp.itot }} {{ tp.crit }} {{ tp.total }} {{ tp.kev }} {{ tp.max }}

The sheet also carries the full KEV table and the top CWE categories.

AssetIdentifying CharacteristicsTotal CVEsKEV CVEsCriticalityIT/OTKEV CVE IDsNon-KEV CVE IDsKEV Hyperlinks
{{ pa.host }} {{ pa.chars }} {{ pa.total }} {{ pa.kev }} {{ pa.crit }} {{ pa.itot }} {{ pa.kevIds }} {{ pa.nonKev }}
{{ lk.label }}None

{{ pAssetsNote }}

IT/OT(All)page filter
Criticality / Asset Total CVEs (sum) KEV CVEs (sum) {{ pv.label }} {{ pv.t }} {{ pv.k }}

A real Excel PivotTable sourced from CVEbyAsset. It refreshes when the workbook opens; drag fields or change the IT/OT filter as usual.

CVE IDSeverityCVSSKEVExploitationHow It's ExploitedAssets
{{ pc.cve }} {{ pc.sev }} {{ pc.cvss }} {{ pc.kev }} {{ pc.status }} {{ pc.how }} {{ pc.assets }}

{{ pCvesNote }}

AssetVendorProduct / ModelReasonCVEs Held
{{ pi.host }}
{{ pi.ids }}
{{ pi.vendor }} {{ pi.product }} {{ pi.reason }} {{ pi.held }}

{{ pInsNote }}

Cover Page

Shown on the Armexa cover and in the file's document properties.

Sheets

{{ wbFileName }}

{{ ws.name }}{{ ws.meta }}
{{ ws.desc }}

Settings

API keys for NVD, VulnCheck and VARIoT are held in Azure Key Vault and used only by the Armexa server. They never reach this browser.

Connections

Live check of each lookup service the server uses. API keys are held in Azure Key Vault and never reach this browser.

{{ healthCheckedLabel }}
Could not load connection status.
Checking connections…
{{ h.name }}
{{ h.detail }}
{{ h.keyNote }}
{{ h.latency }} {{ h.badgeLabel }}

Backup & Storage

Projects live in this browser only. Download a backup before clearing browser data or changing machines. Restoring replaces projects with the same ID and leaves the rest alone. API keys are never included.

{{ storageLabel }}

What's New

{{ wnPageSub }}

No release notes yet

Release notes appear here when a new version ships.

{{ a.title }}

{{ a.meta }}
  • {{ b }}

My Profile

The Microsoft account you are signed in with.

Name{{ meName }}
Email{{ meEmail }}
Role {{ r.label }} Loading… No app role assigned. Ask an administrator for the User role. Unavailable. Reload the page to try again.
Sign-in Microsoft Entra ID

{{ modalTitle }}

{{ modalSub }}

{{ nHintText }}

Delete This Project?

{{ deleteDetail }}

Removes the project's staged inventory, findings, per-asset reports and run log from this browser. Other projects and the lookup cache are untouched.

Download Project Reports

{{ exportSub }}

{{ x.name }} {{ x.kind }}

{{ x.desc }}

{{ x.filename }}
{{ exportSelLabel }}

What's new in VEC Tool

{{ a.title }} {{ a.meta }}
  • {{ b }}
{{ toastTitle }}
{{ toastMsg }}