Skip to content

Vulnerability Libraries

NEURO integrates with industry-leading vulnerability databases and intelligence platforms to enrich findings and discover assets.

The National Vulnerability Database (NVD) provides CVE details, CVSS scores, and references.

  • Automatic CVE Lookup - CVEs in findings are automatically enriched
  • CVSS Scores - CVSS 3.1 and 4.0 scores from NVD
  • References - Links to advisories, patches, and exploits
  • CPE Matching - Common Platform Enumeration for affected products

NVD integration works out of the box - no API key required for basic lookups.

For higher rate limits:

  1. Go to SettingsIntegrationsAPI Keys
  2. Enter your NVD API key
  3. Click Save

Shodan provides internet-wide scanning data for asset discovery and exposure monitoring.

  • Host Lookup - Query IP addresses for open ports and services
  • Vulnerability Detection - Known CVEs affecting discovered services
  • Banner Grabbing - Service version and configuration details
  • Historical Data - Track changes over time
  1. Go to SettingsIntegrationsAPI Keys
  2. Enter your Shodan API key
  3. Click Test Connection
  4. Click Save
  • Asset Discovery - Search by IP, domain, or organization
  • Finding Enrichment - Add context to network findings
  • Exposure Monitoring - Track internet-facing assets

Censys provides certificate transparency and host scanning data.

  • Certificate Search - Find certificates by domain, issuer, or fingerprint
  • Host Discovery - Discover hosts and their exposed services
  • Protocol Analysis - TLS/SSL configuration details
  • Historical Records - View changes over time
  1. Go to SettingsIntegrationsAPI Keys
  2. Enter your Censys API ID and Secret
  3. Click Test Connection
  4. Click Save
  • Certificate Inventory - Track SSL/TLS certificates
  • Subdomain Discovery - Find hosts via certificate data
  • Compliance Checking - Verify TLS configurations

DeHashed provides access to breach data for credential exposure monitoring.

  • Email Search - Find breached credentials by email
  • Domain Search - Discover all breached accounts for a domain
  • Password Exposure - Check if passwords were exposed (hashed)
  • Breach Source - Identify which breaches affected accounts
  1. Go to SettingsIntegrationsAPI Keys
  2. Enter your DeHashed Email and API Key
  3. Click Test Connection
  4. Click Save
  • Credential Audit - Check client domains for exposed credentials
  • Risk Assessment - Identify accounts at risk
  • Breach Notification - Alert clients to compromised accounts

All API keys are:

  • Encrypted at rest using AES-256
  • Tenant-isolated - Each tenant manages their own keys
  • Audited - Key usage is logged
  1. Navigate to SettingsIntegrationsAPI Keys
  2. Select the integration
  3. Enter credentials
  4. Test the connection
  5. Save
  1. Navigate to SettingsIntegrationsAPI Keys
  2. Click the trash icon next to the integration
  3. Confirm removal

Next: Enterprise Integrations