PCI DSS 4.0.1 - New CVEs in the CDE
This rule identifies critical or high-severity software vulnerabilities affecting devices tagged as part of a PCI-CDE (Payment Card Industry Cardholder Data Environment) scope. It summarizes the findings by CVE, severity level, count of affected devices, and specific assets involved, prioritizing remediation for PCI compliance.
Microsoft Sentinel (KQL)

