Tracecat
Book a demo

Security automation examples

Build AI agents and workflows for alert triage, threat hunting, incident response, and more—with starter prompts mapped to NIST CSF 2.0.

6
functions
22
categories
106
controls
38
tools
85
prompts

Respond

13 prompts

Actions regarding a detected cybersecurity incident are taken

Triage and coordinate security incidents

RS.MA

An AI agent can validate incoming reports and classify cases from the evidence. Workflows route the case to its owner, page on-call, and track the criteria for escalation or recovery.

PagerDutyIncident.ioSlackJira / AtlassianServiceNowGmail
  • Triage and validate incident reports
  • Categorize and prioritize incidents
  • Escalate incidents on clear criteria
View 4 prompts

Investigate incidents with AI agents

RS.AN

Query Splunk, CrowdStrike, and Okta to build a source-linked incident timeline. Have an AI agent propose root cause hypotheses, then assess scope and preserve the investigation record.

SplunkCrowdStrike FalconOktaAWSWiz
  • Build incident timelines with an AI agent
  • Preserve investigation records and evidence
  • Estimate and validate incident magnitude
View 3 prompts

Coordinate incident notifications and reports

RS.CO

Draft regulator and customer notices from confirmed case facts, notify stakeholders by severity, and prepare indicators for sharing. Keep external drafts with the people authorized to approve them.

SlackMicrosoft TeamsGmailPagerDutyNotion
  • Notify stakeholders when incidents declare
  • Draft regulator and customer notices
  • Share indicators with trusted partners
View 3 prompts

Automate incident containment and mitigation

RS.MI

From a confirmed incident, coordinate endpoint isolation, session revocation, and indicator blocking. Record approvals and results on the case, with rollback steps for blocks that disrupt legitimate activity.

CrowdStrike FalconMicrosoft Defender XDROktaCloudflareZscalerPalo Alto Networks
  • Contain compromised endpoints
  • Eradicate attacker footholds
  • Block attacker infrastructure
View 3 prompts

Protect

20 prompts

Safeguards to manage the organization's cybersecurity risks are used

Automate access reviews and account checks

PR.AA

Collect privileged access grants for owners to review, find accounts that outlive their purpose, and investigate risky sign-ins. AI agents can also draft tighter cloud policies as pull requests.

OktaMicrosoft Entra IDAWSHashiCorp VaultTerraformSlack
  • Review privileged access on a schedule
  • Catch dormant and orphaned accounts
  • Respond to risky sign-ins
View 4 prompts

Automate security training follow-up

PR.AT

Follow up phishing simulations while the event is still fresh. Track required training by role, remind people about unfinished modules, and give owners a record of completion.

OktaVantaSlackGmail
  • Follow up phishing simulations with training
  • Track role-based training coverage
  • Send context-aware security nudges
View 3 prompts

Automate data protection checks

PR.DS

Find encryption gaps, collect context for data-loss alerts, and follow up failed backup jobs. Record findings with the affected resource and an owner so each gap has a next step.

WizAWSJamfZscalerMicrosoft Defender XDROktaJira / AtlassianServiceNow
  • Audit encryption at rest in the cloud
  • Track backup jobs and restore tests
  • Verify disk encryption on laptops
View 4 prompts

Track configuration drift and patch deadlines

PR.PS

Compare systems against approved baselines and track overdue patches. Find silent log sources and use an AI agent to sort software findings into risks, policy violations, and review requests.

JamfMicrosoft Defender XDRSnykWizSplunkGitHubSemgrepSecure Annex
  • Detect drift from hardened baselines
  • Track patch deadlines from your vulnerability plan
  • Find systems not sending logs
View 5 prompts

Check infrastructure resilience and segmentation

PR.IR

Compare firewall rules with documented trust boundaries and look for single points of failure. Collect capacity trends and provider evidence for infrastructure reviews.

Palo Alto NetworksWizCloudflareAWSDatadogGrafanaPagerDutyZscaler
  • Audit network segmentation weekly
  • Find single points of failure
  • Monitor and forecast resource capacity
View 4 prompts

Govern

23 prompts

The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored

Track security commitments and dependencies

GV.OC

Connect customer security promises to the controls behind them. Keep obligations, owners, and critical service dependencies in records your team can review when something changes.

VantaNotionOktaFeedlyLinearGmail
  • Build a compliance obligations register
  • Map critical services and dependencies
  • Track customer security commitments
View 3 prompts

Automate security risk tracking

GV.RM

Keep risk scores, owners, and review dates in one register. Route exceptions for a documented decision and prepare digests for the people accountable for each risk.

ServiceNowJira / AtlassianNotionSlackVantaIncident.io
  • Stand up a living risk register
  • Enforce risk appetite in triage
  • Feed security risks into enterprise ERM
View 4 prompts

Automate security ownership and access checks

GV.RR

Use case assignments, on-call schedules, and admin roles to draft a security responsibility map. Check for gaps when people join, change roles, or leave.

OktaPagerDutyMicrosoft Entra IDNotionSlackLinear
  • Generate a security RACI from reality
  • Track security workload and resourcing
  • Wire security into HR lifecycle events
View 3 prompts

Keep security policies connected to practice

GV.PO

Compare written policies with settings in Okta and GitHub, chase outstanding acknowledgments, and prepare policy reviews with a record of what changed.

NotionVantaOktaSlackJira / AtlassianGitHubLinearGmail
  • Chase policy acknowledgments
  • Detect drift between policy and reality
  • Keep policy reviews on schedule
View 3 prompts

Prepare security metrics and audit reviews

GV.OV

Pull incident trends, failed controls, and overdue findings into leadership reports. An AI agent can assemble the evidence and draft commentary for the next strategy review.

VantaJira / AtlassianIncident.ioSplunkDrataNotionSlackGoogle Drive
  • Draft monthly risk metrics for leadership
  • Track audit findings to closure
  • Assemble the quarterly strategy review
View 4 prompts

Automate vendor security reviews

GV.SC

Give an AI agent the sources and requirements for a first-pass vendor assessment. Track supplier risks and access changes from onboarding through offboarding.

VantaOktaFeedlySnykGitHubJira / AtlassianSixtyfourSlack
  • Build a supplier criticality register
  • Watch critical suppliers for new risk
  • Use an AI agent for vendor due diligence
View 6 prompts

Agentic security automation in practice

An AI agent can interpret evidence and decide what to investigate next. A workflow can collect alerts on a schedule, apply fixed thresholds, and route the results. In agentic security automation, the agent chooses its next step from the evidence, while workflows handle the parts you have already defined.

In the incident timeline example, an agent queries Splunk, CrowdStrike, and Okta, links events to their sources, and proposes root cause hypotheses. Analysts review those hypotheses and gaps in the evidence. The threat intelligence example uses an agent to decide which Feedly reports apply to your software inventory, then records relevant threats in cases and notifies the team.

Your team chooses the tools an agent can use and the decisions that need analyst review. Start with an investigation you understand, inspect the evidence the agent collects, and refine its instructions before expanding its responsibilities.

Bring your own coding assistant

Connect your assistant to Tracecat MCP, paste a starter prompt, and build an AI agent or workflow around your tools.

Claude Code
Microsoft Copilot
Codex
Tracecat MCP

Works with your favorite coding assistant

FAQ

Book a demo

Talk to a Tracecat expert

Or self-host Tracecat open source today. Read the docs

Loved by security teams building with AI

CNLRER
+3

Security Engineer @ Depop

Tracecat copilot has changed my life. I describe an agentic workflow and it builds it for me. I never had time to build and experiment around my other responsibilities. Now I do.

Senior Security Engineer @ Neo Financial

A genuine thank you to the team. I built an end-to-end IoC enrichment pipeline with Claude and Tracecat MCP and created more value for our SOC in a day than I probably would have in weeks on my own. You're making my one-man SOC assignment possible.

Principal Threat Researcher @ Saronic

Tracecat is a cheat code for corporate security teams that want to build and own their own agentic future.