Skip to content

Findings, Threats, and Vulnerabilities

Studio separates findings, threats, and vulnerabilities so teams can distinguish audit issues, external threat context, and technical remediation work.

How They Differ

Area Use it for Typical source
Findings Issues that need review, ownership, comments, and resolution Auditors, AI analysis, endpoint scans, cloud scans, manual creation
Threats Threat intelligence and business/security context Curated feeds, seeded threat templates, dashboard banners
Vulnerabilities Technical weaknesses and remediation status FleetDM, osquery, Prowler, manual security review

Findings Workflow

  1. Open Findings.
  2. Filter by severity, source, status, customer, or project.
  3. Open a finding and review details, comments, and linked evidence.
  4. Add investigation or remediation notes.
  5. Link the finding to evidence, controls, or projects when relevant.
  6. Resolve the finding after remediation is verified.

Threat Workflow

  1. Open Threats.
  2. Review severity, timeline, source, and affected themes.
  3. Compare threat context against current risks and controls.
  4. Use relevant threat context to prioritize findings or vulnerabilities.
  5. Reference threat context in reports when it affects compliance posture.

Vulnerability Workflow

  1. Open Vulnerabilities.
  2. Review critical and high vulnerabilities first.
  3. Check affected systems, software, or cloud resources.
  4. Confirm linked evidence or scan output.
  5. Assign remediation work through findings, tasks, or external tools.
  6. Re-scan or refresh source data to confirm closure.

Prioritization

  1. Critical vulnerabilities with known exploitation.
  2. High findings linked to compliance controls.
  3. Cloud or endpoint issues affecting sensitive systems.
  4. Repeated findings that indicate process failure.
  5. Medium and low issues grouped by remediation effort.

Reporting Guidance

  • Include verified issues in formal conclusions.
  • Separate active vulnerabilities from resolved historical items.
  • Link findings to evidence wherever possible.
  • Explain accepted risk decisions clearly.
  • Use threat context to support prioritization, not to inflate severity without evidence.