Skip to content

Hermes Data Status & Ingestion Health

HERMES TELEMETRY PIPELINE β€” SYSTEM HEALTH
βœ“ VERIFIED (PASSING)
Last Ingestion 2026-09-21 06:00:00 UTC Automated daily cycle
Sources Processed 12 primary feeds KEV, EPSS, NVD, ATT&CK, ATLAS...
Observations Generated 1,498+ OBS-* canonical model
Forecasts Active 10 falsifiable Brier score calibrated
Data Completeness 98.4% Exhaustiveness ratio
Methodology & Schema OBS-CANONICAL-2.1 HTR-2.0 / Brier-V4.0
Active Primary Sources:
CISA KEVFIRST EPSSNVD / CVEMITRE ATT&CK v15MITRE ATLASGitHub GHSAExploit-DBOpenSSL / Linux AdvisoryCisco / Palo Alto PSIRTAlienVault OTXMicrosoft MSRCPacket Storm

Hermes continuously monitors and harmonizes multi-source vulnerability intelligence, exploit maturity indicators, and autonomous agent threat telemetry:

Deterministic Exploit Tracking

Direct ingestion of the CISA Known Exploited Vulnerabilities (KEV) catalog and FIRST EPSS (Exploit Prediction Scoring System) v3 daily distribution.

Advisory & Ground-Truth Disclosures

Structured harvesting from NVD / CVE Project, GitHub Security Advisories (GHSA), OSS Security lists, and vendor PSIRT advisories (Palo Alto, Cisco, Microsoft).

Adversary & Agentic Frameworks

Bi-directional mapping against MITRE ATT&CK v15 Enterprise matrix and MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems).

Canonical Observation Normalization

Every signal is normalized into a persistent OBS-* canonical observation model, ensuring immutability, cryptographic provenance, and zero duplicate counting.


βš–οΈ Epistemic Transparency: What Hermes Does Not Know

Section titled β€œβš–οΈ Epistemic Transparency: What Hermes Does Not Know”
WHAT HERMES DOES NOT KNOW (ANALYTICAL UNCERTAINTY) Principle P3 β€” Epistemic Rigor
  • βœ• Zero-day exploits held by private threat actors or commercial exploit brokers prior to public weaponization signals.
  • βœ• Internal organizational network architecture, segmentation boundaries, and air-gapped systems not present in provided SBOM manifests.
  • βœ• Proprietary in-house source code and unpublished internal dependencies (fully protected by our sovereign client-side Zero-Upload guarantee).
  • βœ• Real-time patch deployment status inside third-party SaaS environments without direct endpoint telemetry connector.
  • βœ• Heuristic exploitability when vendor software is heavily customized or compiled with non-standard compiler flags.

All calculations and classifications in Hermes Codex cite their active semantic version:

System SubsystemVersionGoverning StandardImmutability Verification
Hermes Threat ScoreHTS-1.4Severity + Exploitation VelocityDeterministic calculation
Risk Trajectory EngineHTR-2.0Velocity vector + Inflection deltaHistorical snapshot replay
Canonical Observation ModelOBS-CANONICAL-2.1STIX 2.1 compatibleJSON-LD schema validated
Prediction CalibrationBrier-Calibrated-V4.0Strictly strictly strictly proper scoring rulePublic forecast registry
Agentic Threat ModelingATLAS-MAPPED-1.2MITRE ATLAS + OWASP LLM Top 10Graph blast radius