Findings, Threats, and Vulnerabilities¶
Studio separates findings, threats, and vulnerabilities so teams can distinguish audit issues, external threat context, and technical remediation work.
How They Differ¶
| Area | Use it for | Typical source |
|---|---|---|
| Findings | Issues that need review, ownership, comments, and resolution | Auditors, AI analysis, endpoint scans, cloud scans, manual creation |
| Threats | Threat intelligence and business/security context | Curated feeds, seeded threat templates, dashboard banners |
| Vulnerabilities | Technical weaknesses and remediation status | FleetDM, osquery, Prowler, manual security review |
Findings Workflow¶
- Open Findings.
- Filter by severity, source, status, customer, or project.
- Open a finding and review details, comments, and linked evidence.
- Add investigation or remediation notes.
- Link the finding to evidence, controls, or projects when relevant.
- Resolve the finding after remediation is verified.
Threat Workflow¶
- Open Threats.
- Review severity, timeline, source, and affected themes.
- Compare threat context against current risks and controls.
- Use relevant threat context to prioritize findings or vulnerabilities.
- Reference threat context in reports when it affects compliance posture.
Vulnerability Workflow¶
- Open Vulnerabilities.
- Review critical and high vulnerabilities first.
- Check affected systems, software, or cloud resources.
- Confirm linked evidence or scan output.
- Assign remediation work through findings, tasks, or external tools.
- Re-scan or refresh source data to confirm closure.
Prioritization¶
- Critical vulnerabilities with known exploitation.
- High findings linked to compliance controls.
- Cloud or endpoint issues affecting sensitive systems.
- Repeated findings that indicate process failure.
- Medium and low issues grouped by remediation effort.
Reporting Guidance¶
- Include verified issues in formal conclusions.
- Separate active vulnerabilities from resolved historical items.
- Link findings to evidence wherever possible.
- Explain accepted risk decisions clearly.
- Use threat context to support prioritization, not to inflate severity without evidence.