Triage vulnerabilities and threat intelligence
Match threat reports to your software inventory with an AI agent. Prioritize vulnerability findings using asset criticality and exploitation evidence, and track exceptions with expiry dates.
Tools for risk assessment
MCP servers for the tools used in these examples.
Automation examples and starter prompts
Paste a prompt into Claude Code, Microsoft Copilot, or Codex connected to Tracecat MCP. Adapt it to your tools and test before deployment. Human tool approvals and advanced case features require Enterprise.
Triage new vulnerability findings
Build me a vulnerability triage workflow in Tracecat. Pull new findings from Snyk and Wiz, dedupe by CVE and asset, enrich each with asset criticality from our inventory table and exploitation evidence from GreyNoise, and rank what to fix first. Open Jira tickets for the top tier with the evidence attached and SLA dates set by severity. First help me understand how this maps to ID.RA-01 and why validation and recording matter as much as discovery. Ask me what remediation SLAs we have promised. Talk me through the ranking rubric before we automate it.
Assess threat intelligence with an AI agent
Build me a threat intel pipeline in Tracecat. Ingest advisories and reports from Feedly, have an AI agent match each against our actual stack from the software inventory, and discard what does not apply. For relevant threats, open a case with the affected systems listed and post a short plain-language summary to the security channel. First help me understand how this maps to ID.RA-02 and why most intel feeds fail by skipping the relevance filter. Ask me which sources we already subscribe to. Talk me through tuning the relevance matching so we neither drown nor miss.
Record and score threat scenarios
Build me a threat scenario register in Tracecat. Keep a table of internal and external threat scenarios, each scored for likelihood and impact against our environment, with the evidence behind the score. When new intel or an incident touches a scenario, update its score and log why. Have an AI agent draft new scenario entries from incident patterns for my review. First help me understand how this maps to ID.RA-03 and ID.RA-04, and how recorded scenarios turn vague worry into comparable risks. Ask me which threat actors and failure modes worry us most today. Talk me through review cadence and what evidence should move a score.
Manage risk exceptions with expiry dates
Build me an exception register in Tracecat. Every accepted risk and policy exception gets a table row with the owner, the compensating controls, and a hard expiry date. Before expiry, ping the owner in Slack to renew or remediate, with a documented decision either way. Escalate exceptions that pass expiry without a decision and report totals monthly. First help me understand how this maps to ID.RA-07 and why exceptions without expiry dates quietly become permanent architecture. Ask me what exception types we grant today. Talk me through reasonable expiry windows by risk level.
Run a vulnerability disclosure intake
Build me a disclosure intake workflow in Tracecat. Watch our security@ inbox in Gmail, have an AI agent separate genuine vulnerability reports from beg bounties and spam, extract the affected asset and claimed impact, and open a case with a severity estimate. Draft the acknowledgment reply for my approval and track the response deadline per our disclosure policy. First help me understand how this maps to ID.RA-08 and what a credible disclosure process owes the reporter. Ask me what our published response timelines promise. Talk me through which replies can send automatically and which need a human.
NIST CSF 2.0 mapping: ID.RA
Official NIST category: Risk Assessment. The cybersecurity risk to the organization, assets, and individuals is understood by the organization
The controls and implementation examples below are NIST source material. The automation prompts above are Tracecat-authored starting points, not evidence of compliance or full control coverage.
- ID.RA-01CA-2CA-7CA-8RA-3RA-5SA-11(2)SA-15(7)SA-15(8)SI-4SI-5
Vulnerabilities in assets are identified, validated, and recorded
- Use vulnerability management technologies to identify unpatched and misconfigured software
- Assess network and system architectures for design and implementation weaknesses that affect cybersecurity
- Review, analyze, or test organization-developed software to identify design, coding, and default configuration vulnerabilities
- Assess facilities that house critical computing assets for physical vulnerabilities and resilience issues
- Monitor sources of cyber threat intelligence for information on new vulnerabilities in products and services
- Review processes and procedures for weaknesses that could be exploited to affect cybersecurity
- ID.RA-02PM-15PM-16SI-5
Cyber threat intelligence is received from information sharing forums and sources
- Configure cybersecurity tools and technologies with detection or response capabilities to securely ingest cyber threat intelligence feeds
- Receive and review advisories from reputable third parties on current threat actors and their tactics, techniques, and procedures (TTPs)
- Monitor sources of cyber threat intelligence for information on the types of vulnerabilities that emerging technologies may have
- ID.RA-03PM-12PM-16RA-3SI-5
Internal and external threats to the organization are identified and recorded
- Use cyber threat intelligence to maintain awareness of the types of threat actors likely to target the organization and the TTPs they are likely to use
- Perform threat hunting to look for signs of threat actors within the environment
- Implement processes for identifying internal threat actors
- ID.RA-04PM-9PM-11RA-2RA-3RA-8RA-9
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
- Business leaders and cybersecurity risk management practitioners work together to estimate the likelihood and impact of risk scenarios and record them in risk registers
- Enumerate the potential business impacts of unauthorized access to the organization's communications, systems, and data processed in or by those systems
- Account for the potential impacts of cascading failures for systems of systems
- ID.RA-05PM-16RA-2RA-3RA-7
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
- Develop threat models to better understand risks to the data and identify appropriate risk responses
- Prioritize cybersecurity resource allocations and investments based on estimated likelihoods and impacts
- ID.RA-06PM-9PM-18PM-30RA-7
Risk responses are chosen, prioritized, planned, tracked, and communicated
- Apply the vulnerability management plan's criteria for deciding whether to accept, transfer, mitigate, or avoid risk
- Apply the vulnerability management plan's criteria for selecting compensating controls to mitigate risk
- Track the progress of risk response implementation (e.g., plan of action and milestones [POA&M], risk register, risk detail report)
- Use risk assessment findings to inform risk response decisions and actions
- Communicate planned risk responses to affected stakeholders in priority order
- ID.RA-07CA-7CM-3CM-4
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
- Implement and follow procedures for the formal documentation, review, testing, and approval of proposed changes and requested exceptions
- Document the possible risks of making or not making each proposed change, and provide guidance on rolling back changes
- Document the risks related to each requested exception and the plan for responding to those risks
- Periodically review risks that were accepted based upon planned future actions or milestones
- ID.RA-08RA-5
Processes for receiving, analyzing, and responding to vulnerability disclosures are established
- Conduct vulnerability information sharing between the organization and its suppliers following the rules and protocols defined in contracts
- Assign responsibilities and verify the execution of procedures for processing, analyzing the impact of, and responding to cybersecurity threat, vulnerability, or incident disclosures by suppliers, customers, partners, and government cybersecurity organizations
- ID.RA-09SA-4SA-5SA-10SA-11SA-15SA-17SI-7SR-5SR-6SR-10SR-11
The authenticity and integrity of hardware and software are assessed prior to acquisition and use
- Assess the authenticity and cybersecurity of critical technology products and services prior to acquisition and use
- ID.RA-10SR-6
Critical suppliers are assessed prior to acquisition
- Conduct supplier risk assessments against business and applicable cybersecurity requirements, including the supply chain
Control text and SP 800-53 Rev 5 references from the official NIST CSF 2.0 and OLIR releases.
Build your own security automation
Adapt a starter prompt with your coding assistant, choose where AI agents or fixed workflows fit, and test with your tools.