Vulnerability analysis is the systematic process of discovering, characterising, and prioritising weaknesses in software, systems, or networks that could be exploited to compromise confidentiality, integrity, or availability. It combines static and dynamic code inspection, configuration review, and exploitability assessment to feed remediation and risk decisions. Unlike threat modelling, which is attacker-centric and design-stage, vulnerability analysis focuses on concrete flaws in deployed or candidate artefacts.
Content
- Techniques span static application security testing (SAST), dynamic analysis (DAST), fuzzing, dependency scanning, and manual code audit, with findings scored via frameworks like CVSS. Effective analysis depends on accurate asset context to distinguish theoretically exploitable flaws from those reachable and impactful in the actual deployment, avoiding alert fatigue from unprioritised output.