Supported Fields
exploitable and reachability are on the vulnerability model and accepted as filters on List Vulnerabilities. Every connector above except SentinelOne VMS now reports exploitable, each from its own vendor’s exploit signal — the notes in the capabilities block say which, and they differ: Tenable’s exploit_available, Wiz’s known-exploit and CISA KEV flags, AWS Inspector’s exploit-available assertion. reachability is a different question — whether the vulnerable code is called — which no VMS vendor answers, so it stays null on every record and matches no filter value.
Both are tri-state: a record the vendor did not assess carries null and matches neither filter value. The capabilities block on List Integration Details declares support per integration and carries those notes, along with the values each vendor emits for severity, state and category, and whether it populates port, protocol and cve.
For any additional information about our field mappings or integrations please contact us.