Skip to content

Hermes for Security Analysts & DFIR Teams

1. Observe What changed? โ†’
2. Understand Why does it matter? โ†’
3. Track How does risk evolve? โ†’
4. Predict What happens next? โ†’
5. Decide What to do? โ†’
6. Verify What happened? โ†’
7. Remember Persistent memory

  • Fragmented Context: Manually correlating an exploit payload to MITRE ATT&CK techniques, threat actor syndicates, and affected software packages is tedious and error-prone.
  • Missing Historical Progression: Static advisories do not show how an incident developed over time (e.g. Day 0 zero-day disclosure vs Day 14 mass automated scanning).
  • Surface-Level Descriptions: Standard CVE summaries describe the vulnerability symptom rather than the underlying structural software chromosome failure.

Knowledge Graph (556+ Entities)

Instantly traverse relationships linking vulnerabilities to threat actors, campaigns, malware families, and MITRE ATT&CK / ATLAS techniques.

Historical Replay (Day 0 to Day 90)

Replay the exact telemetry visible at discrete intervals to understand how threat actors evolved their weaponization strategies.

Vulnerability Genome

Dissect vulnerabilities across 8 structural chromosomes to categorize recurring root-cause patterns and exploitability profiles.

OASIS STIX 2.1 & TAXII 2.1 Feeds

Native machine-readable exports directly consumable by OpenCTI, MISP, and Microsoft Sentinel threat intelligence platforms.


3. Dynamic Trajectory Analysis: Velocity & Acceleration (Section 23)

Section titled โ€œ3. Dynamic Trajectory Analysis: Velocity & Acceleration (Section 23)โ€
Hermes Trajectory Engine

How Risk Trajectory Works

Legacy scanners give you a frozen number. Hermes computes the dynamic vector of exploitation.

Evaluated Vector: CVE-2026-90770 (Spug Unauthenticated Command Injection)
1. Current Risk ๐Ÿ“
88 / 100 HTS

Static severity & weaponization right now

Critical Exposure
2. Risk Velocity โšก
+22 pts / 24h

Rate of change over time (ฮ”R / ฮ”t)

Rapid Surge
3. Risk Acceleration ๐Ÿš€
ฮ”ยฒR > 0

Critical (positive ฮ”ยฒR/ฮ”tยฒ)

Non-Linear Escalation
4. Trajectory ๐Ÿ“ˆ
Critical Acceleration

Predictive curve & systemic archetype

Immediate T0 Action
๐Ÿ“ Mathematical Formalization & Archetypes View R(t) equation & gradients โ–พ
Risk Vector Equation: R(t) = Rโ‚€ + โˆซ (v(t) + a(t)ยทt) dt

Hermes continuously samples KEV weaponization timestamps, EPSS percentiles, and public exploit commits to calculate real derivatives.

Archetype Exploit Behavior Decision Directive
Critical Acceleration v > +10, a > 0 (KEV rรฉcent + PoC public actif) T0 Confinement immรฉdiat (< 24h)
Exponential Inflexion v > +5, a > 0 (Armement en cours d'outillage) T1 Patch planifiรฉ (< 7 jours)
Plateaued Risk v โ‰ˆ 0, a โ‰ˆ 0 (Exploit stable, pas de nouveau vecteur) Cycle de maintenance standard
Dormant / Theoretical v = 0, a ≤ 0 (CVSS thรฉorique, 0 exploit in the wild) Surveillance passive sans alerte bloquante

4. Probabilistic Incident Forecast: What Happens Next? (Section 24)

Section titled โ€œ4. Probabilistic Incident Forecast: What Happens Next? (Section 24)โ€
๐Ÿ”ฎ FORWARD FORECAST (FALSIFIABLE)
Brier Calibration V4.0

What happens next?

Evaluated Asset: CVE-2026-90770 / Spug DevSecOps Infrastructure
Probability of increased exploitation
78%
Probabilistic estimate, not certainty
Time horizon
30 days
Active resolution window
Confidence level
High
Brier score calibrated
Corroborating Primary Evidence:
  • โœ“ Automated wormable botnet spreading observed in honeypot telemetry
  • โœ“ MITRE ATT&CK T1059.004 (Unix Shell) payload automated in initial access broker channels
  • โœ“ Active CISA KEV exploitation campaign underway
  • โœ“ Zero-day to weaponized exploit transition completed in under 72h

1. Alert Ingestion:
SOC receives an alert involving CVE-2026-90770 (Spug command concatenation).
2. Graph Traversal in Hermes:
Query Knowledge Graph: reveal links to automated botnet propagation,
T1059.004 (Unix Shell), and initial access broker reconnaissance.
3. Trajectory & Inflection Inspection:
Risk curve reveals an inflection point: +22 pts velocity in 24 hours,
shifting from isolated research to active wormable spreading.
4. Forensic Autopsy Correlation:
Compare with similar past incidents in the Hermes Autopsy Catalog
to apply verified containment playbooks immediately.