Tracecat
Book a demo
Identify
ID.RA

Triage vulnerabilities and threat intelligence

Match threat reports to your software inventory with an AI agent. Prioritize vulnerability findings using asset criticality and exploitation evidence, and track exceptions with expiry dates.

Tools for risk assessment

MCP servers for the tools used in these examples.

Automation examples and starter prompts

Paste a prompt into Claude Code, Microsoft Copilot, or Codex connected to Tracecat MCP. Adapt it to your tools and test before deployment. Human tool approvals and advanced case features require Enterprise.

Triage new vulnerability findings

Build me a vulnerability triage workflow in Tracecat. Pull new findings from Snyk and Wiz, dedupe by CVE and asset, enrich each with asset criticality from our inventory table and exploitation evidence from GreyNoise, and rank what to fix first. Open Jira tickets for the top tier with the evidence attached and SLA dates set by severity. First help me understand how this maps to ID.RA-01 and why validation and recording matter as much as discovery. Ask me what remediation SLAs we have promised. Talk me through the ranking rubric before we automate it.

Assess threat intelligence with an AI agent

Build me a threat intel pipeline in Tracecat. Ingest advisories and reports from Feedly, have an AI agent match each against our actual stack from the software inventory, and discard what does not apply. For relevant threats, open a case with the affected systems listed and post a short plain-language summary to the security channel. First help me understand how this maps to ID.RA-02 and why most intel feeds fail by skipping the relevance filter. Ask me which sources we already subscribe to. Talk me through tuning the relevance matching so we neither drown nor miss.

Record and score threat scenarios

Build me a threat scenario register in Tracecat. Keep a table of internal and external threat scenarios, each scored for likelihood and impact against our environment, with the evidence behind the score. When new intel or an incident touches a scenario, update its score and log why. Have an AI agent draft new scenario entries from incident patterns for my review. First help me understand how this maps to ID.RA-03 and ID.RA-04, and how recorded scenarios turn vague worry into comparable risks. Ask me which threat actors and failure modes worry us most today. Talk me through review cadence and what evidence should move a score.

Manage risk exceptions with expiry dates

Build me an exception register in Tracecat. Every accepted risk and policy exception gets a table row with the owner, the compensating controls, and a hard expiry date. Before expiry, ping the owner in Slack to renew or remediate, with a documented decision either way. Escalate exceptions that pass expiry without a decision and report totals monthly. First help me understand how this maps to ID.RA-07 and why exceptions without expiry dates quietly become permanent architecture. Ask me what exception types we grant today. Talk me through reasonable expiry windows by risk level.

Run a vulnerability disclosure intake

Build me a disclosure intake workflow in Tracecat. Watch our security@ inbox in Gmail, have an AI agent separate genuine vulnerability reports from beg bounties and spam, extract the affected asset and claimed impact, and open a case with a severity estimate. Draft the acknowledgment reply for my approval and track the response deadline per our disclosure policy. First help me understand how this maps to ID.RA-08 and what a credible disclosure process owes the reporter. Ask me what our published response timelines promise. Talk me through which replies can send automatically and which need a human.

NIST CSF 2.0 mapping: ID.RA

Official NIST category: Risk Assessment. The cybersecurity risk to the organization, assets, and individuals is understood by the organization

The controls and implementation examples below are NIST source material. The automation prompts above are Tracecat-authored starting points, not evidence of compliance or full control coverage.

  • ID.RA-01
    CA-2
    CA-7
    CA-8
    RA-3
    RA-5
    SA-11(2)
    SA-15(7)
    SA-15(8)
    SI-4
    SI-5

    Vulnerabilities in assets are identified, validated, and recorded

  • ID.RA-02
    PM-15
    PM-16
    SI-5

    Cyber threat intelligence is received from information sharing forums and sources

  • ID.RA-03
    PM-12
    PM-16
    RA-3
    SI-5

    Internal and external threats to the organization are identified and recorded

  • ID.RA-04
    PM-9
    PM-11
    RA-2
    RA-3
    RA-8
    RA-9

    Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded

  • ID.RA-05
    PM-16
    RA-2
    RA-3
    RA-7

    Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization

  • ID.RA-06
    PM-9
    PM-18
    PM-30
    RA-7

    Risk responses are chosen, prioritized, planned, tracked, and communicated

  • ID.RA-07
    CA-7
    CM-3
    CM-4

    Changes and exceptions are managed, assessed for risk impact, recorded, and tracked

  • ID.RA-08
    RA-5

    Processes for receiving, analyzing, and responding to vulnerability disclosures are established

  • ID.RA-09
    SA-4
    SA-5
    SA-10
    SA-11
    SA-15
    SA-17
    SI-7
    SR-5
    SR-6
    SR-10
    SR-11

    The authenticity and integrity of hardware and software are assessed prior to acquisition and use

  • ID.RA-10
    SR-6

    Critical suppliers are assessed prior to acquisition

Control text and SP 800-53 Rev 5 references from the official NIST CSF 2.0 and OLIR releases.

Build your own security automation

Adapt a starter prompt with your coding assistant, choose where AI agents or fixed workflows fit, and test with your tools.