Overview
CVE Shield is the free tier of Contrast Application Detection and Response (ADR). It monitors your running applications and APIs to detect active attacks targeting known CVEs, giving you real-time visibility into exploits against your software before they can succeed.
Contrast CVE Shield monitors your running applications and APIs to detect real, active known CVEs, giving you real-time visibility into which vulnerabilities are actually reachable and under attack in your software.
Most static scanners flag every CVE in your dependency tree whether it's reachable or not. CVE Shield narrows that down to what can actually hurt you, and can stop the ones that try.
You can try CVE Shield for free. See CVE Shield Free Tier for details.
What CVE Shield watches
Static SCA tools tell you which CVEs exist in your dependencies. CVE Shield tells you which ones are being actively used, and attacked, in your running application right now.
That's the core difference: it's runtime detection, not a code or dependency scan.
What CVE Shield gives you
CVE Shield covers four core capabilities:
Reachability: Know in seconds if a CVE touches code you actually run, not just code you happen to depend on.
Monitoring: Get alerted the moment an attacker probes a vulnerable path, not after the fact.
Protection: Block exploitation attempts automatically on supported CVEs, so you patch on your schedule, not an attacker's.
Prioritization: Skip the noise. See the short list of what's actually exposed and fix that first.
(Insert screenshot: CVE Shield dashboard showing exposed, protecting, and blocked CVEs)
Who it's built for
CVE Shield serves several roles:
Application Security Engineers who need to know which code-time findings are real once runtime context is applied, so they can prioritize what's actually worth acting on.
Developers who need one specific, runtime-verified answer: is the CVE flagged in my code actually reachable, and do I need to fix it right now.
Security Operations teams who need to know the moment a CVE is being actively exploited, so they can contain it.
CISOs who need a periodic, rolled-up view of which CVEs are driving overall exposure and whether it's trending up or down.
What CVE Shield is not
It's not a static scanner. It doesn't scan code repositories or binaries.
It's not a network-layer tool. CVE Shield operates at the application runtime layer, watching what your application actually does, not traffic at the network perimeter.
It's not a full ADR solution. Advanced features like virtual patches, IP management, and SIEM integrations live in Contrast's broader ADR product.
It's monitoring first. CVE Shield Free Tier tells you what's happening, what's reachable, what's being used, what's under attack, so you know where to focus. You can upgrade to a paid tier to block attacks or replace patching the underlying vulnerability.
Where CVE Shield findings fit in Contrast's data model
Northstar organizes what it detects into three layers, all visible from the Insights dashboard and the new CVE Shield table under Explorer:
Observations are a raw signal of individual vulnerability detections or attack events as they're captured.
Issues group related observations together when they share the same rule and the same route (location in the app), so you're looking at one problem instead of a hundred duplicate alerts.
Incidents are a higher-level view for attacks that need SOC-level attention. Exploited CVE Shield attacks are visible under Observations, and Incidents will be available soon.
You'll find Explorer, Observations, and Issues as separate items in Northstar's left navigation, with Incidents following once available.
Expected Outcome
You can explain what CVE Shield does and doesn't do today, you know how an Observation becomes an Issue, and what to expect from Incidents as that capability rolls out.
Related Resources
- Community: Understanding Capacity Limits
- Community: Data Retention Policies
- Community: How to Interpret Vulnerability Findings
- Contrast Documentation: Welcome to Northstar, CVE shields (docs.contrastsecurity.com)
Escalation path
Free: Post your question in the Gather Community Forum.
Related to
Comments
0 comments
Please sign in to leave a comment.