Paste rule hit counts as name,count or name count (one per line). Accepts show rule-hit-count / diagnose firewall iprope output too. Match is by rule name, falling back to rule number.
Note: a backup / exported config does not contain hit counts — pull these from the live device (Palo Alto: show rulebase security rules hit-count, Fortinet: get firewall policy, Cisco: show access-list).
Correlates services your rules expose (RDP, SMB, SSL-VPN, databases…) with the CISA Known Exploited Vulnerabilities catalog. Privacy: fetching downloads a public file only — your configuration is never sent anywhere. Air-gapped? Download the JSON from cisa.gov yourself and load it here. Context only — does not change the score.
set rulebase security rules … CLI (set-format), plus set address / set service objects for resolution.config firewall policy blocks, plus config firewall address / service custom for resolution.access-list … extended permit/deny & IOS ip access-list extended, with object / object-group resolution and ACL-scoped ordering.Name, Source, Destination, Service, Action, Track columns (header auto-detected).config.xml backup — <filter><rule> rules with aliases resolved (host / network / port), plus OPNsense plugin rules.