Platform · Validate

Evidence grading

A finding is only worth as much as the trust you can put in it. Verskop marks every one by how firmly it has been proven. The number at the top of the report reflects only what was proven, and anything doubtful stays clearly labeled.

The concept

Evidence grading is the practice of marking every finding by how firmly it has been proven, so a reader can see at a glance how much weight it can carry. Verskop uses two grades. A finding earns the confirmed grade only when Verskop has observed it on the live host and can point to the evidence behind it. Anything inferred from indirect signals but never actually proven is graded assessed, which lands it in a separate verify tier, held out of the risk total and the financial figures until a person confirms it.

The practice predates security tooling. Serious analysis has always attached a level of confidence to a claim and named the source it rests on, so the reader can weigh it properly. A finding handed over without that grade asks to be believed on the tool's say-so. Verskop attaches a grade to every finding so a reader can weigh it for themselves.

Where the industry falls short

The industry tends to over-report. Findings are cheap to generate and a longer list looks more thorough, so tools hand over a heap of maybes with the certain items and the doubtful ones blurred together. The cost of that habit is now well measured. In the 2025 SANS Detection and Response Survey, security teams named false positives their single biggest detection problem, and Devo's SOC performance research has put the share of alerts that turn out to be false at close to half.

The deeper damage is to trust. When a tool raises too many false alarms, people stop believing it and start waving away whole categories of its output, and a genuine critical can get missed in the noise. For anyone answering to a board, an auditor, or an insurer, the stakes are higher: a false positive presented as a confirmed fact puts a number that may not hold up on review in front of a decision-maker, and one number that fails review makes the reader doubt the rest.

The Verskop difference

The grade travels with every finding.

Verskop grades every finding and keeps all of them on the page. A weakness proven on the live host is marked confirmed and carries its citation, drawn from sources like CISA, the National Vulnerability Database, and MITRE ATT&CK. When the evidence only points to a weakness without confirming it, the finding is marked assessed and waits in a verify tier until a person confirms it. A genuine weakness still keeps its place on the list, with its grade shown next to it.

UNGRADED FINDINGS EVIDENCE GATE CONFIRMED Observed and cited Counts in the risk total ASSESSED Inferred, unproven Held out of the total

Every finding meets the same gate: was it observed on the live host, with a citation to back it? A finding that clears the gate is graded confirmed and counts toward the totals. Anything that falls short waits in the assessed tier, out of the totals, until a person checks it.

Confirmed

Observed on the live host

A confirmed finding is one Verskop actually saw on the live host, and it does not travel without the evidence that supports it. The citation points to a recognized source, so a reader can check the claim against a source outside Verskop.

  • Observed directly on the live host
  • Carries a citation to CISA, the NVD, or MITRE ATT&CK
  • Counts toward the risk total and the financial exposure
Assessed

Inferred from indirect signals

An assessed finding is something the evidence hints at without confirming, a technology guessed from a header, or a version that was never disclosed. Verskop keeps it on the page so nothing is quietly lost, and files it in a verify tier where it waits for a person to confirm or dismiss it. Until that happens, it stays out of every number that carries weight.

  • Inferred from indirect signals, and labeled plainly as such
  • Held in a verify tier for a person to check
  • Excluded from the risk total until it is checked
The rule

What keeps the number honest

One rule governs the rest: a finding with no confirmed version, or no observed evidence, never enters the confirmed tier. That is why the figure at the top of a Verskop brief holds up in front of an auditor or a contracting officer, because everything behind the figure was genuinely seen.

  • Version-less and unproven findings never enter the confirmed tier
  • The headline figure reflects only what was observed

The standards this rests on

SANS · 2025 Detection and Response Survey Devo · SOC Performance Report CISA Known Exploited Vulnerabilities National Vulnerability Database (NIST) MITRE ATT&CK

Every figure above is sourced. The only claim that is ours is what Rampart Cybersecurity LLC and Verskop do.

See it on your domain

See a brief where every finding is graded.

Give us a target you're cleared to test, and we will show you which findings Verskop confirmed on the live host and which it held back as assessed for a person to verify.