building-patch-tuesday-response-process skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Establish a repeatable operational process for triaging, testing, and Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/building-patch-tuesday-response-process/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-patch-tuesday-response-process, or copy the skill folder into ~/.claude/skills/building-patch-tuesday-response-process/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/building-patch-tuesday-response-process/SKILL.md

SKILL.md (verbatim)

name: building-patch-tuesday-response-process
description: Establish a repeatable operational process for triaging, testing, and
  deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL
  Server, Azure) via WSUS/SCCM within risk-based remediation SLAs, from advisory review
  through validation. Use when building or improving a monthly patch management workflow
  or prioritizing which CVEs to remediate first.
domain: cybersecurity
subdomain: vulnerability-management
tags:
- patch-management
- patch-tuesday
- microsoft
- wsus
- sccm
- vulnerability-remediation
- windows-update
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- ID.RA-01
- ID.RA-02
- ID.IM-02
- ID.RA-06
mitre_attack:
- T1190
- T1203
- T1068
- T1210
- T1588.006

Building Patch Tuesday Response Process

Overview

Microsoft releases security updates on the second Tuesday of each month ("Patch Tuesday"), addressing vulnerabilities across Windows, Office, Exchange, SQL Server, Azure services, and other products. In 2025, Microsoft patched over 1,129 vulnerabilities across the year -- an 11.9% increase from 2024 -- making a structured response process critical. The leading risk types include elevation of privilege (49%), remote code execution (34%), and information disclosure (7%). This skill covers building a repeatable Patch Tuesday response workflow from initial advisory review through testing, deployment, and validation.

When to Use

  • When deploying or configuring building patch tuesday response process capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Access to Microsoft Security Response Center (MSRC) update guide
  • Vulnerability management platform (Qualys VMDR, Rapid7, Tenable)
  • Patch deployment infrastructure (WSUS, SCCM/MECM, Intune, or third-party)
  • Test environment mirroring production configurations
  • Change management process (ITIL-based or equivalent)
  • Communication channels for cross-team coordination

Core Concepts

Patch Tuesday Timeline

Day Activity Owner
T+0 (Tuesday 10 AM PT) Microsoft releases patches and advisories Microsoft
T+0 (Tuesday afternoon) Security team reviews advisories and triages Security Ops
T+1 (Wednesday) Qualys/vendor scan signatures updated VM Platform
T+1-T+2 Emergency patches deployed for zero-days IT Operations
T+2-T+5 Test patches in staging environment QA/IT Ops
T+5-T+7 Deploy to Pilot group (5-10% of fleet) IT Operations
T+7-T+14 Deploy to Production Ring 1 (servers) IT Operations
T+14-T+21 Deploy to Production Ring 2 (workstations) IT Operations
T+21-T+30 Validation scanning and compliance reporting Security Ops

Patch Categorization Framework

Category Criteria Response SLA
Zero-Day / Exploited Active exploitation confirmed, CISA KEV listed 24-48 hours
Critical RCE CVSS >= 9.0, remote code execution, no auth required 3-5 days
Critical with Exploit Public exploit code or EPSS > 0.7 7 days
High Severity CVSS 7.0-8.9, privilege escalation 14 days
Medium Severity CVSS 4.0-6.9 30 days
Low / Informational CVSS < 4.0, defense-in-depth Next maintenance window

Microsoft Product Categories to Monitor

Category Products Risk Level
Windows OS Windows 10, 11, Server 2016-2025 Critical
Exchange Server Exchange 2016, 2019, Online Critical
SQL Server SQL 2016-2022 High
Office Suite Microsoft 365, Office 2019-2024 High
.NET Framework .NET 4.x, .NET 6-9 Medium
Azure Services Azure AD, Entra ID, Azure Stack High
Edge/Browser Edge Chromium, IE mode Medium
Development Tools Visual Studio, VS Code Low

Workflow

Step 1: Pre-Patch Tuesday Preparation (Monday before)

Preparation Checklist:
  [ ] Confirm WSUS/SCCM sync schedules are active
  [ ] Verify test environment is available and current
  [ ] Review outstanding patches from previous month
  [ ] Confirm monitoring dashboards are operational
  [ ] Pre-stage communication templates
  [ ] Ensure rollback procedures are documented
  [ ] Verify backup jobs ran successfully on critical servers

Step 2: Day-of Triage (Patch Tuesday)

Triage Process:
  1. Monitor MSRC Update Guide (https://msrc.microsoft.com/update-guide)
  2. Review Microsoft Security Blog for advisory summaries
  3. Cross-reference with CISA KEV additions (same day)
  4. Check vendor advisories (Qualys, Rapid7, CrowdStrike analysis)
  5. Identify zero-day and actively exploited vulnerabilities
  6. Classify each CVE by severity and applicability
  7. Determine deployment rings and timeline for each patch
  8. Submit emergency change request for zero-day patches
  9. Communicate triage results to IT Operations and management

Step 3: Scan and Gap Analysis

# Post-Patch-Tuesday scan workflow
def run_patch_tuesday_scan(scanner_api, target_groups):
    """Trigger vulnerability scans after Patch Tuesday updates."""
    for group in target_groups:
        print(f"[*] Scanning {group['name']}...")
        scan_id = scanner_api.launch_scan(
            target=group["targets"],
            template="patch-tuesday-focused",
            credentials=group["creds"]
        )
        print(f"    Scan launched: {scan_id}")

    # Wait for scan completion, then generate report
    results = scanner_api.get_scan_results(scan_id)
    missing_patches = [r for r in results if r["status"] == "missing"]

    # Categorize by Patch Tuesday release
    current_month = [p for p in missing_patches
                     if p["vendor_advisory_date"] >= patch_tuesday_date]

    return {
        "total_missing": len(missing_patches),
        "current_month": len(current_month),
        "zero_day": [p for p in current_month if p.get("actively_exploited")],
        "critical": [p for p in current_month if p["cvss"] >= 9.0],
    }

Step 4: Ring-Based Deployment Strategy

Ring 0 - Emergency (0-48 hours):
    Scope:     Zero-day and actively exploited CVEs only
    Method:    Manual or targeted push (SCCM expedite)
    Targets:   Internet-facing servers, critical infrastructure
    Approval:  Emergency change, verbal CISO approval
    Rollback:  Immediate rollback if service degradation

Ring 1 - Pilot (Day 2-7):
    Scope:     All critical and high patches
    Method:    WSUS/SCCM automatic deployment
    Targets:   IT department machines, test group (5-10%)
    Approval:  Standard change with CAB notification
    Monitoring: 48-hour soak period, check for BSOD, app crashes

Ring 2 - Production Servers (Day 7-14):
    Scope:     All security patches
    Method:    SCCM maintenance windows (off-hours)
    Targets:   Production servers by tier
    Approval:  Standard change with CAB approval
    Monitoring: Application health checks, performance baseline

Ring 3 - Workstations (Day 14-21):
    Scope:     All security patches + quality updates
    Method:    Windows Update for Business / Intune
    Targets:   All managed workstations
    Approval:  Pre-approved standard change
    Monitoring: Help desk ticket monitoring for issues

Ring 4 - Stragglers (Day 21-30):
    Scope:     Catch remaining unpatched systems
    Method:    Forced deployment with restart
    Targets:   Systems that missed prior rings
    Approval:  Compliance-driven enforcement

Step 5: Validation and Reporting

Post-Deployment Validation:
  1. Re-scan environment with updated vulnerability signatures
  2. Compare pre-patch and post-patch scan results
  3. Calculate patch compliance rate per ring and department
  4. Identify failed patches and investigate root causes
  5. Generate compliance report for management review
  6. Update risk register with residual unpatched vulnerabilities
  7. Document exceptions and compensating controls

Best Practices

  1. Subscribe to MSRC notifications and vendor analysis blogs for early intelligence
  2. Maintain a dedicated Patch Tuesday war room or Slack/Teams channel
  3. Always patch zero-day vulnerabilities outside the normal ring schedule
  4. Test patches against critical business applications before broad deployment
  5. Track patch compliance metrics month-over-month for trend analysis
  6. Maintain rollback procedures for every deployment ring
  7. Coordinate with application owners for compatibility testing
  8. Document all exceptions with compensating controls and review dates

Common Pitfalls

  • Deploying all patches simultaneously without ring-based testing
  • Not scanning after patching to validate remediation
  • Treating all patches equally without risk-based prioritization
  • Ignoring cumulative update dependencies causing patch failures
  • Not accounting for server reboot requirements in maintenance windows
  • Failing to communicate patch status to business stakeholders
  • implementing-rapid7-insightvm-for-scanning
  • performing-cve-prioritization-with-kev-catalog
  • implementing-vulnerability-remediation-sla
  • implementing-patch-management-workflow

Other files in this skill

assets/template.md (verbatim)

Patch Tuesday Response Report Template

Monthly Patch Summary

Field Value
Patch Tuesday Date [YYYY-MM-DD]
Total CVEs Released [N]
Zero-Days [N]
Critical [N]
Important [N]
Moderate [N]

Deployment Status by Ring

Ring Name SLA Patches Deployed Compliance
0 Emergency 48h [N] [N] [%]
1 Pilot 7 days [N] [N] [%]
2 Production 14 days [N] [N] [%]
3 Workstations 21 days [N] [N] [%]
4 Stragglers 30 days [N] [N] [%]

Zero-Day / Actively Exploited Patches

CVE Product CVSS KEV Status Deployed
[CVE-ID] [Product] [N.N] [Y/N] [Deployed/Pending] [Date]

Exceptions and Deferrals

CVE Reason Compensating Control Review Date Approver
[CVE-ID] [Reason] [Control] [Date] [Name]

references/api-reference.md (verbatim)

2 placeholder credentials shortened to pass the site's secret filter.

API Reference: Patch Tuesday Response Process

MSRC Security Update API

GET https://api.msrc.microsoft.com/cvrf/v3.0/Updates('{yyyy-Mon}')
api-key: YOUR_KEY
Accept: application/json

CVRF Vulnerability Fields

Field Description
CVE CVE identifier
Title.Value Vulnerability title
Threats[].Description.Value Severity, exploitation status
CVSSScoreSets[].BaseScore CVSS v3 base score
ProductStatuses[].ProductID Affected product IDs
Remediations[].URL KB article / patch URL

CISA Known Exploited Vulnerabilities (KEV)

GET https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

KEV Entry Fields

Field Description
cveID CVE identifier
vendorProject Vendor name
product Product name
dateAdded Date added to KEV
dueDate Remediation due date

Patch Priority Matrix

Priority Criteria SLA
Emergency Exploited + KEV + CVSS >= 9.0 24 hours
Critical Exploited OR KEV + CVSS >= 7.0 72 hours
Standard CVSS >= 7.0, no exploitation 7 days
Routine CVSS < 7.0, no exploitation 30 days

NVD API v2

GET https://services.nvd.nist.gov/rest/json/cves/2.0?cveId={CVE-ID}
apiKey: YOUR_KEY

WSUS Deployment API (PowerShell)

$wsus = Get-WsusServer
$update = $wsus.SearchUpdates("KB5034441")
$group = $wsus.GetComputerTargetGroup("Production")
$update.Approve("Install", $group)

Deployment Phase Timeline

Phase Window Targets
Emergency 0-24h Critical servers, exploited CVEs
Pilot 24-72h Test group (5% of fleet)
Broad 3-7d All production systems
Cleanup 7-30d Exceptions, rollback monitoring

references/standards.md (verbatim)

Standards and References - Patch Tuesday Response Process

Microsoft Resources

Industry Standards

  • NIST SP 800-40 Rev 4: Guide to Enterprise Patch Management Planning
  • CIS Controls v8.1 Control 7.4: Perform Automated Patch Management
  • PCI DSS v4.0 Req 6.3.3: Install security patches within one month of release
  • ISO 27001:2022 A.8.8: Management of technical vulnerabilities

Patch Tuesday Statistics (2025)

Metric Value
Total CVEs patched in 2025 1,129
Year-over-year increase 11.9%
Average CVEs per month ~94
Top category: Elevation of Privilege ~49%
Top category: Remote Code Execution ~34%
Zero-days patched in 2025 Multiple per quarter

Vendor Analysis Resources

references/workflows.md (verbatim)

Workflows - Patch Tuesday Response Process

Workflow 1: Monthly Patch Tuesday Lifecycle

Week 1 (Patch Tuesday):
  Mon: Pre-staging, verify infrastructure readiness
  Tue: Patch release, triage, zero-day emergency deployment
  Wed: Scan environment, update signatures, gap analysis
  Thu: Begin pilot deployment (Ring 1)
  Fri: Monitor pilot, document issues

Week 2:
  Mon-Wed: Production server deployment (Ring 2)
  Thu-Fri: Monitor server health, rollback if needed

Week 3:
  Mon-Fri: Workstation deployment (Ring 3)

Week 4:
  Mon-Wed: Catch stragglers (Ring 4)
  Thu: Validation scanning
  Fri: Compliance report, close change tickets

Workflow 2: Zero-Day Emergency Response

┌──────────────────┐     ┌──────────────────┐     ┌──────────────────┐
│ Zero-Day CVE     │────>│ CISO Approves    │────>│ Emergency Change │
│ Identified       │     │ Emergency Patch  │     │ Ticket Created   │
└──────────────────┘     └──────────────────┘     └──────────────────┘
                                                          │
        ┌────────────────────────────────────────────────┘
        v
┌──────────────────┐     ┌──────────────────┐     ┌──────────────────┐
│ Quick Smoke Test │────>│ Deploy to Ring 0 │────>│ Monitor for      │
│ (1-2 hours)      │     │ (Critical Assets)│     │ Issues (4 hours) │
└──────────────────┘     └──────────────────┘     └──────────────────┘
        │
        v
┌──────────────────┐     ┌──────────────────┐
│ Broader Rollout  │────>│ Validation Scan  │
│ (All Rings)      │     │ & Report         │
└──────────────────┘     └──────────────────┘

Workflow 3: Patch Compliance Tracking

Metric Target Measurement
Zero-day patch rate 100% in 48 hours SCCM compliance report
Critical patch rate 95% in 7 days Vulnerability scan delta
High patch rate 90% in 14 days Vulnerability scan delta
Overall compliance 95% in 30 days Monthly compliance dashboard
Exception documentation 100% documented GRC platform audit

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.