Vulnerability Prioritization

SkillMonitoring & ops

Prioritize Wazuh vulnerability-detector findings with CISA KEV, FIRST EPSS, CVSS and asset context into CISA SSVC decisions and remediation SLAs; use for vulnerability sweeps, CVE alerts or patch-priority questions.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Vulnerability Prioritization skill

What this skill tells your AI

The instructions your AI receives, as published by gensecaihq/wazuh-autopilot in backend/app/skills/vulnerability-prioritization/SKILL.md and read by ahel’s review.

CVSS alone ranks too many things "critical". Prioritize by exploitation evidence, then likelihood, then impact in this environment. Aligns with NIST CSF 2.0 ID.RA, NIST SP 800-53r5 RA-5 / SI-2, CIS Controls v8.1 Control 7 (Continuous Vulnerability Management), and NIST SP 800-40r4 (enterprise patch management as preventive maintenance).

What Wazuh gives you

The vulnerability detector matches the syscollector package inventory against CVE feeds and raises one alert per CVE and package, with fields under data.vulnerability.*: cve, severity, cvss.cvss3.base_score (or score.base), package.name, package.version, status (Active / Solved), published, reference.

RuleLevelMeaning
rule 235035Active, severity Low
rule 235047Active, severity Medium or Untriaged
rule 2350510Active, severity High
rule 2350613Active, severity Critical
rule 235023CVE no longer affects the package (solved, e.g. after an upgrade)
rule 235073vulnerabilities cleared for the agent

So the alert level is just the vendor severity. It says nothing about exploitation or exposure, and that's what this skill adds. rules 23502 and 23507 are good remediation evidence: use them to confirm a fix instead of re-scanning. Detection lags the package scan interval, so note data freshness.

For configuration weaknesses on the same hosts (open services, weak SSH settings), load wazuh-sca-hardening. SCA failures often turn a Track item into Attend.

Data gathering

  1. get_wazuh_vulnerability_summary — counts by severity and top CVEs.
  2. get_wazuh_critical_vulnerabilities — the critical/high set with affected agents.
  3. get_wazuh_vulnerabilities(agent_id=...) — per-host detail when scoping.
  4. get_wazuh_vulnerabilities(agent_id=..., severity="critical") per host for scoping (vulnerability_assessment on the MCP server is a prompt template, not a callable tool). get_agent_ports(agent_id) shows whether the vulnerable service is actually listening. That's your Exposure input.
  5. For exploitation data use search_external_context with the CVE id only: "CVE-XXXX-YYYY CISA KEV", "CVE-XXXX-YYYY EPSS". Never send hostnames.

Decision order

  1. CISA KEV — listed in the Known Exploited Vulnerabilities catalog? Exploitation in the wild is confirmed. (KEV entries also carry a federal due date.)
  2. FIRST EPSS — probability of exploitation activity in the next 30 days (0–1) and percentile. EPSS ≥ 0.1 (or ≥ 90th percentile) is a strong signal.
  3. CVSS (v4.0 where available, else v3.1) base score, adjusted for environment: internet exposure, compensating controls, asset criticality.

SSVC decision (CISA Deployer tree, simplified)

Decision points: Exploitation (none / public PoC / active), Exposure (small / controlled / open — i.e. internet-facing), Automatable (yes/no — can an attacker reliably exploit at scale), Mission & Well-being impact (low / medium / high).

OutcomeTypical conditionsMeaning
Actactive exploitation (KEV) + open exposure or high impactremediate immediately, escalate
Attendactive exploitation with controlled exposure, or PoC + open exposure + automatableremediate sooner than standard; supervisor attention
Track*PoC or high EPSS but limited exposure/impacttrack closely; standard timeline, re-check often
Trackno known exploitation, low exposurestandard patch cycle

Remediation SLAs (org defaults — adjust to policy)

SSVCTarget
Act48 hours (or KEV due date if sooner), mitigate same day if patch unavailable
Attend7 days
Track*30 days
Tracknext regular maintenance cycle (≤ 90 days)

Mitigations when patching is not possible: disable the vulnerable service, restrict exposure (firewall / host_deny via a human-approved plan), virtual patching, increased monitoring (hand off to detection-engineer).

Output table

| CVE | Package | Hosts | KEV | EPSS (pct) | CVSS | Exposure | SSVC | SLA | Action |

Group by CVE, list affected host counts, top 25 rows. Note data freshness (last vulnerability scan time per agent).

Output

  • save_report(kind="vulnerability", title, body_md) with the table and summary for sweeps; for a spike tied to a case, add_finding titled Vulnerability priorities.
  • create_case for any Act item on an internet-facing or critical asset (severity high/critical), with CVE, hosts and recommended mitigation.
  • standard_refs: CISA-KEV, FIRST-EPSS, CISA-SSVC, NIST-800-53r5:RA-5, NIST-800-53r5:SI-2, CIS-v8.1:7.

Signals

GitHub stars
57
Forks
16
Last commit
Sep 2026
Advanced
Item type
skill
Key
vulnerability-prioritization
Source
github.com/gensecaihq/wazuh-autopilot