Tracecat

Automate NIST CSF 2.0 controls with AI

Every control in the NIST Cybersecurity Framework, mapped to security tools and starter prompts. Paste a prompt into Claude Code, Microsoft Copilot, or Codex and build the automation together with Tracecat MCP.

6
functions
22
categories
106
controls
39
tools
85
prompts

Protect

20 prompts

Safeguards to manage the organization's cybersecurity risks are used

Identity Management, Authentication, and Access Control

PR.AA

Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access

OktaMicrosoft Entra IDAWSHashiCorp VaultTerraformSlack
  • Review privileged access on a schedule
  • Catch dormant and orphaned accounts
  • Respond to risky sign-ins
View 4 prompts

Awareness and Training

PR.AT

The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks

OktaVantaSlackGmail
  • Follow up phishing simulations with training
  • Track role-based training coverage
  • Send context-aware security nudges
View 3 prompts

Data Security

PR.DS

Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information

WizAWSJamfZscalerMicrosoft Defender XDROktaJira / AtlassianServiceNow
  • Audit encryption at rest in the cloud
  • Track backup jobs and restore tests
  • Verify disk encryption on laptops
View 4 prompts

Platform Security

PR.PS

The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with the organization's risk strategy to protect their confidentiality, integrity, and availability

JamfMicrosoft Defender XDRSnykWizSplunkGitHubSemgrepSecure Annex
  • Detect drift from hardened baselines
  • Enforce patch SLAs from your vuln plan
  • Find systems not sending logs
View 5 prompts

Technology Infrastructure Resilience

PR.IR

Security architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience

Palo Alto NetworksWizCloudflareAWSDatadogGrafanaPagerDutyZscaler
  • Audit network segmentation weekly
  • Find single points of failure
  • Monitor and forecast resource capacity
View 4 prompts

Govern

23 prompts

The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored

Organizational Context

GV.OC

The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organization's cybersecurity risk management decisions are understood

VantaNotionOktaFeedlyLinearGmail
  • Build a compliance obligations register
  • Map critical services and dependencies
  • Track customer security commitments
View 3 prompts

Risk Management Strategy

GV.RM

The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions

ServiceNowJira / AtlassianNotionSlackVantaIncident.io
  • Stand up a living risk register
  • Enforce risk appetite in triage
  • Feed security risks into enterprise ERM
View 4 prompts

Roles, Responsibilities, and Authorities

GV.RR

Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated

OktaPagerDutyMicrosoft Entra IDNotionSlackLinear
  • Generate a security RACI from reality
  • Track security workload and resourcing
  • Wire security into HR lifecycle events
View 3 prompts

Policy

GV.PO

Organizational cybersecurity policy is established, communicated, and enforced

NotionVantaOktaSlackJira / AtlassianGitHubLinearGmail
  • Chase policy acknowledgments
  • Detect drift between policy and reality
  • Keep policy reviews on schedule
View 3 prompts

Oversight

GV.OV

Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy

VantaJira / AtlassianIncident.ioSplunkDrataNotionSlackGoogle Drive
  • Draft monthly risk metrics for leadership
  • Track audit findings to closure
  • Assemble the quarterly strategy review
View 4 prompts

Cybersecurity Supply Chain Risk Management

GV.SC

Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders

VantaOktaFeedlySnykGitHubJira / AtlassianSixtyfourSlack
  • Build a supplier criticality register
  • Watch critical suppliers for new risk
  • Run due diligence on new vendors
View 6 prompts

Bring your own coding assistant

Connect your assistant to Tracecat MCP, paste an example, and an agent builds the automation around your tools.

Claude Code
Microsoft Copilot
Codex
Tracecat MCP

Works with your favorite coding assistant

Frequently asked questions

Book a demo

Talk to a Tracecat expert

Or self-host Tracecat open source today. Read the docs

Loved by security teams building with AI

CNLRER
+3

Security Engineer @ Depop

Tracecat copilot has changed my life. I describe an agentic workflow and it builds it for me. I never had time to build and experiment around my other responsibilities. Now I do.

Senior Security Engineer @ Neo Financial

A genuine thank you to the team. I built an end-to-end IoC enrichment pipeline with Claude and Tracecat MCP and created more value for our SOC in a day than I probably would have in weeks on my own. You're making my one-man SOC assignment possible.

Principal Threat Researcher @ Saronic

Tracecat is a cheat code for corporate security teams that want to build and own their own agentic future.