Reference B: Exposure determination matrix
This appendix details how Cortex Cloud determines whether the organization is exposed to an attack. Exposure is evaluated within the viewing user's SBAC scope (see SBAC).
Compromised package associated with the attack
Yes
Impacted assets show affected repositories/assets; attack is active
Compromised tool associated with the attack
Yes
Impacted assets show affected pipelines; attack is active. A tool-only attack produces no findings (tools do not generate findings in this release) — exposure surfaces through pipelines
CVE associated with the attack
Yes
Impacted assets reflect the CVE footprint (findings, repositories, and images); attack is active
Open issue related to the attack
Yes
Attack is active; issue is linked for remediation
None of the above
No
Sidecar shows no exposure detected / no-longer-exposed; no affected assets
Last updated
Was this helpful?
