Viper VR: CVE correlation that respects your patch queue
Viper VR is Dual-Strike XISEM’s vulnerability correlation surface. It ingests CVE data, agent software inventory, and EDR exposure signals to answer: *“Which of my assets are affected, and what should I patch first?”*
Route: /vulnerabilities · Support wiki → Viper VR
What you see
• CVE list — Severity, EPSS-style prioritization where available
• Affected assets — Hostname, OS, installed version proof
• Patch status — Installed KB / package vs. required
• Threat Center link — Elevated CVE + active exploitation → detection
• Compliance — Vulnerability management control evidence
Prioritization logic (conceptual)
Viper VR ranks higher when:
• Asset is internet-facing or user workstation with browsing risk
• Exploit activity in threat intel feeds (when enabled)
• ASPIRE Security pillar already weak
• Duplicate EDR confirmation of vulnerable process running
It ranks lower when:
• Server is isolated segment with compensating controls documented
• Patch already staged in RMM but not yet rebooted (agent shows pending)
MSP weekly patch ritual
1. Sort Critical CVEs by affected asset count per client
2. Export top 10 to PSA project or change ticket batch
3. After patch window, verify agent harvest shows new version
4. Close loop in Threat Center if CVE-elevated detection was open
Pair with agent 8.7.x
Modern agent harvest includes installed software inventory depth required for accurate CVE matching. Keep agents on 8.7.0.17 GA or current store release.
Related: Threat Center · ASPIRE Security pillar · Reports
Downloads: dual-strike.com/downloads
CVE IDs in demos are illustrative — live feed uses current NVD/vendor sources.


