A system (102) and method for generating remediation evidence object in cloud platforms. The method (300) includes receiving, by a vulnerability intelligence interface, at least one Known Exploited Vulnerability (KEV) record from one or more external threat intelligence repositories. The method includes correlating a plurality of cloud assets (104a, 104b, 104c . . . 104n) distributed across one or more cloud environments. The method includes generating an exposure mapping graph. The method includes computing a prioritized patch action set based on one or more of one or more exploit prevalence indicators, one or more asset criticality scores, and one or more service dependency constraints derived from the exposure mapping graph. The method includes executing deployment of one or more patches corresponding to the prioritized patch action set. The method includes determining one or more remediation state transitions based on the execution. The method includes generating the remediation evidence object.
Full Text
What is claimed is: