Skip to main content

ankra security

Read the organisation’s Security Center - the same data the portal shows, for your own reporting and automation. Every finding carries its exploitation intelligence: whether CISA lists the CVE in its Known Exploited Vulnerabilities (KEV) catalog, with CISA’s remediation deadline and required action, and the FIRST EPSS probability that it is exploited in the next 30 days. Findings sort by exploitability by default - CISA listing first, then EPSS, then severity - so the top of the list is what is actually being exploited, not what merely has the highest CVSS score. Pass -o json (or yaml) for the full API document.

ankra security advisory

Show the platform’s advisory for one CVE: the parsed NVD/OSV record, CISA’s guidance and your exposure
Flags

ankra security clusters

Per-cluster security posture and scanner freshness
Flags

ankra security finding

Show one finding with CISA’s guidance and every current occurrence
Flags

ankra security findings

List the organisation’s logical findings (one row per CVE and package, deduplicated across clusters and workloads). By default the list is the actionable set (open and acknowledged findings) sorted by exploitability. Narrow it with —known-exploited to the CVEs CISA lists as exploited in the wild, or with —severity, —status, —fixable, —cluster, —addon and —namespace. Examples: ankra security findings —known-exploited ankra security findings —severity critical —fixable true —sort epss ankra security findings —cluster production —status any -o json
Flags

ankra security overview

Fleet security summary: totals, CISA KEV exposure, scanner coverage and remediation candidates
Flags