get_chains
Known Chained Vulnerabilities™: pairs of CVEs that a cited source reports were used together in one exploit chain (VulnCheck KEV entry text, Metasploit modules, SigmaHQ rules, press, research or academic sentences, community text judged by a local model). Each row carries both CVEs with their CISA KEV status, the claim kind (observed: the source reports attacks; potential: the source reports they can be chained), the quoted evidence with its source, URL and date, and community discussion counts, which show discussion and are not chain claims. The per-CVE record carries chains.known and chains.candidates (KCV Watch: possible chains for teams to research, pairs whose extracted exploit capabilities connect or whose records tie them together, derived and never confirmed, each with its tier, lane, reasons, basis, product, bridge, grade, a caption and the entry step where one is extracted); search_cves accepts chained=1 and chainability=1. Filters: source (vulncheck_kev, metasploit, sigma, press, research, community), since (YYYY-MM-DD, first seen), claim (observed|potential), limit (1..500).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| claim | No | observed: the source reports attacks that chained them; potential: the source reports they can be chained | |
| limit | No | 1..500 (default 100) | |
| since | No | Pairs first seen on or after this day (YYYY-MM-DD) | |
| source | No | Evidence lane: vulncheck_kev, metasploit, sigma, press, research, academic, community, github_poc, exploitdb or exploit_code |