Cogent Risk Assessment And Contextual Prioritization
Cogent Platform & Cogent Community · Cogent Security
Agentic AI Vulnerability Management — Cogent Security
Cogent Security evals — Risk Assessment & Contextual Prioritization (relift v3 InfraRed)
About Cogent Security
Cogent Security builds agentic AI for vulnerability management. The Cogent Platform runs Triage, Risk Assessment, Remediation, and Verification agents on a real-time data foundation — investigating findings, correlating assets to owning teams, prioritizing by real exploitability over raw CVSS, driving remediation through engineering workflows, and validating that fixes actually happened. The free Cogent Community surface pairs VulnCheck-powered CVE intelligence with a customizable Discover Feed and an AI Research Assistant that produces cited, plain-language deep-dives.
Employees
~30
Industry
AI Security / Vulnerability Management
Headquarters
San Francisco, CA
Website
www.cogent.comSample tests· showing 3 of 9
| # | Input | Expected behavior | Check |
|---|---|---|---|
| 01 | Finding A: CVSS 9.8, no public exploit, internal-only host behind two VPN hops. Finding B: CVSS 7.5, KEV-listed with mass-exploitation underway, on an internet-facing edge service. | Per Cogent's stated principle — agents 'evaluate real exploitability in the environment, not just CVSS severity' — Finding B must rank above Finding A. The explanation must cite KEV listing, mass-exploitation telemetry, and exposure (internet-facing vs internal-only) as the dominant inputs, with CV… | Pass / FailAi Platformcritical |
| 02 | Risk Assessment Agent assigns priority P1 to a finding but the underlying exploit-availability evidence is partial (PoC code exists in a private channel; reachability analysis incomplete). | Per Cogent's documented 'full explainability and confidence levels' for every prioritization decision, the agent must surface both the verdict and the confidence (low/medium/high or numeric) and explain what evidence is missing. Low-confidence P1 must be visually distinct from high-confidence P1 in… | Pass / FailAi Platformhigh |
| 03 | A CVE on a database engine. The instance is in a private subnet with no ingress and credentialed access only from a hardened bastion. | Risk Assessment Agent must factor environment-specific exposure (network reachability, auth posture, segmentation) into its verdict, not just the abstract CVE properties. The explainability artifact must show the exposure evidence (subnet, security-group, ingress rules) so the engineer can verify. | Pass / FailAi Platformhigh |
How this eval is graded
Grade against expected.ideal_behavior and expected.rubric. Per-criterion pass requires mean >= 4.0 and no criterion below 3.
Rubric criteria
- Cogent
- Ai Platform
- Risk Assessment And Contextual Prioritization
Recommended for
Works with
Related evals
Run this eval in your workspace
Connect your data, configure thresholds, and review results with your team.