performing-endpoint-vulnerability-remediation skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki
Contents
  1. Install
  2. SKILL.md (verbatim)
  3. When to Use
  4. Prerequisites
  5. Workflow
  6. Step 1: Import and Prioritize Vulnerability Findings
  7. Step 2: Identify Remediation Actions
  8. Step 3: Deploy Patches via WSUS/SCCM
  9. Step 4: Apply Configuration-Based Remediations
  10. Step 5: Handle Zero-Day Vulnerabilities (No Patch Available)
  11. Step 6: Validate Remediation
  12. Step 7: Report and Track
  13. Key Concepts
  14. Tools & Systems
  15. Common Pitfalls
  16. Other files in this skill
  17. assets/template.md (verbatim)
  18. Scan Information
  19. Remediation Priority Summary
  20. CISA KEV Vulnerabilities (Mandatory Remediation)
  21. Remediation Actions
  22. Patch Deployment Schedule
  23. Risk Acceptance Register
  24. Validation Results
  25. Metrics
  26. Sign-Off
  27. references/api-reference.md (verbatim)
  28. Libraries Used
  29. CLI Interface
  30. Core Functions
  31. parsescanreport(csvfile) — Parse and prioritize vulnerabilities by severity
  32. checkwindowspatches() — List installed Windows hotfixes via WMIC
  33. validateremediation(host, port) — TCP connect to verify port closure
  34. generateremediationreport(scanfile, output) — Group vulns by host for remediation
  35. Output Format
  36. Dependencies
  37. references/standards.md (verbatim)
  38. Primary Standards
  39. NIST SP 800-40 Rev 4 - Guide to Enterprise Patch Management Planning
  40. CISA Binding Operational Directive 22-01 - Known Exploited Vulnerabilities
  41. FIRST CVSS v3.1 Specification
  42. FIRST EPSS Model
  43. Compliance Mappings
  44. Remediation SLA Benchmarks
  45. Supporting References
  46. references/workflows.md (verbatim)
  47. Workflow 1: Standard Vulnerability Remediation Cycle
  48. Workflow 2: Emergency Zero-Day Response
  49. Workflow 3: Patch Deployment Pipeline
  50. Workflow 4: SLA Compliance Tracking

What it does. 'Performs vulnerability remediation on endpoints by prioritizing CVEs Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/performing-endpoint-vulnerability-remediation/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-endpoint-vulnerability-remediation, or copy the skill folder into ~/.claude/skills/performing-endpoint-vulnerability-remediation/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/performing-endpoint-vulnerability-remediation/SKILL.md

SKILL.md (verbatim)

name: performing-endpoint-vulnerability-remediation
description: 'Performs vulnerability remediation on endpoints by prioritizing CVEs
  based on risk scoring, deploying patches, applying configuration changes, and validating
  fixes. Use when remediating findings from vulnerability scans, responding to critical
  CVE advisories, or maintaining endpoint compliance with patch management SLAs. Activates
  for requests involving vulnerability remediation, CVE patching, endpoint vulnerability
  management, or security fix deployment.

  '
domain: cybersecurity
subdomain: endpoint-security
tags:
- endpoint
- vulnerability-management
- patching
- CVE
- remediation
- CVSS
version: 1.0.0
author: mahipal
license: Apache-2.0
nist_csf:
- PR.PS-01
- PR.PS-02
- DE.CM-01
- PR.IR-01
mitre_attack:
- T1055
- T1547
- T1059
- T1036

Performing Endpoint Vulnerability Remediation

When to Use

Use this skill when:

  • Remediating vulnerabilities identified by scanners (Nessus, Qualys, Rapid7)
  • Responding to zero-day CVE advisories requiring immediate patching
  • Maintaining compliance with patch management SLAs (critical within 14 days, high within 30 days)
  • Building a prioritized remediation plan from vulnerability scan results

Do not use this skill for vulnerability scanning itself (use scanning tools) or for application-layer vulnerability remediation (use DevSecOps processes).

Prerequisites

  • Vulnerability scan results (Nessus, Qualys, or Rapid7 export in CSV/XML format)
  • Patch management platform (WSUS, SCCM, Intune, or third-party like Automox)
  • Administrative access to target endpoints or deployment infrastructure
  • Change management process for production endpoint patching
  • Testing environment for patch validation before production rollout

Workflow

Step 1: Import and Prioritize Vulnerability Findings

Priority scoring combines:
1. CVSS Base Score (0-10)
2. EPSS (Exploit Prediction Scoring System) - probability of exploitation
3. CISA KEV (Known Exploited Vulnerabilities) catalog membership
4. Asset criticality (business impact of affected endpoint)
5. Network exposure (internet-facing vs. internal)

Priority Matrix:
  P1 (Critical - 14 days SLA):
    - CVSS >= 9.0 OR
    - Listed in CISA KEV OR
    - Active exploitation in the wild + CVSS >= 7.0

  P2 (High - 30 days SLA):
    - CVSS 7.0-8.9 AND
    - EPSS > 0.5 (50% probability of exploitation)

  P3 (Medium - 60 days SLA):
    - CVSS 4.0-6.9 OR
    - CVSS 7.0-8.9 with EPSS < 0.1

  P4 (Low - 90 days SLA):
    - CVSS < 4.0 AND
    - No known exploit

Step 2: Identify Remediation Actions

For each vulnerability, determine the appropriate remediation:

Remediation Types:
1. Patch: Apply vendor security update (most common)
2. Configuration change: Modify settings to mitigate (registry, GPO)
3. Upgrade: Update to newer software version
4. Workaround: Apply temporary mitigation when patch unavailable
5. Compensating control: Network segmentation, WAF rule, EDR rule
6. Accept risk: Document accepted risk with CISO sign-off

Step 3: Deploy Patches via WSUS/SCCM

# WSUS: Approve patches for deployment
# 1. Open WSUS Console
# 2. Navigate to Updates → Security Updates
# 3. Approve selected KBs for target computer groups

# SCCM: Create Software Update Group
# 1. Software Library → Software Updates → All Software Updates
# 2. Select required KBs → Create Software Update Group
# 3. Deploy to target collection with maintenance window

# Intune: Create Windows Update Ring
# Devices → Windows → Update rings
# Configure: Quality updates deferral = 0 days (for critical)
# Feature updates deferral = per policy

# PowerShell: Force Windows Update check
Install-Module PSWindowsUpdate -Force
Get-WindowsUpdate -KBArticleID "KB5034441" -Install -AcceptAll -AutoReboot

# Verify patch installation
Get-HotFix -Id "KB5034441"
systeminfo | findstr "KB5034441"

Step 4: Apply Configuration-Based Remediations

# Example: Disable SMBv1 (CVE-2017-0144 - EternalBlue)
Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force
Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -NoRestart

# Example: Disable Print Spooler on non-print servers (CVE-2021-34527 - PrintNightmare)
Stop-Service -Name Spooler -Force
Set-Service -Name Spooler -StartupType Disabled

# Example: Disable LLMNR (credential theft mitigation)
# Via GPO: Computer Configuration → Admin Templates → Network → DNS Client
# Turn off multicast name resolution: Enabled
New-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" `
  -Name EnableMulticast -Value 0 -PropertyType DWORD -Force

# Example: Restrict NTLM authentication
# Via GPO: Security Settings → Local Policies → Security Options
# Network security: Restrict NTLM: Audit/Deny

Step 5: Handle Zero-Day Vulnerabilities (No Patch Available)

When vendor patch is not yet available:

1. Check vendor advisory for workarounds
   - Microsoft: https://msrc.microsoft.com/update-guide
   - Adobe: https://helpx.adobe.com/security.html
   - Linux: Distribution security trackers

2. Apply temporary mitigations:
   - Disable vulnerable feature/service
   - Deploy EDR detection rule for exploitation attempt
   - Apply network-level blocking (WAF/firewall rules)
   - Restrict access to vulnerable application

3. Monitor for patch release:
   - Subscribe to vendor security mailing list
   - Monitor CISA KEV additions
   - Set calendar reminder for next Patch Tuesday

4. Document workaround with expiration date

Step 6: Validate Remediation

# Re-scan remediated endpoints to confirm vulnerability closure
# Option 1: Targeted vulnerability scan
nessuscli scan --target 192.168.1.0/24 --plugin-id 12345

# Option 2: PowerShell verification
# Check specific KB is installed
$kb = Get-HotFix -Id "KB5034441" -ErrorAction SilentlyContinue
if ($kb) {
    Write-Host "PASS: KB5034441 installed on $(hostname)" -ForegroundColor Green
} else {
    Write-Host "FAIL: KB5034441 missing on $(hostname)" -ForegroundColor Red
}

# Check service is disabled
$svc = Get-Service -Name Spooler
if ($svc.StartType -eq 'Disabled') {
    Write-Host "PASS: Print Spooler disabled" -ForegroundColor Green
}

# Check registry configuration
$val = Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" `
  -Name SMB1 -ErrorAction SilentlyContinue
if ($val.SMB1 -eq 0) {
    Write-Host "PASS: SMBv1 disabled" -ForegroundColor Green
}

Step 7: Report and Track

Generate remediation status report:

Remediation Metrics:
  - Total vulnerabilities: X
  - Remediated: Y (Z%)
  - Pending (within SLA): A
  - Overdue (past SLA): B
  - Accepted risk: C
  - Mean time to remediate (MTTR): D days
  - SLA compliance rate: E%

Key Concepts

Term Definition
CVSS Common Vulnerability Scoring System; 0-10 severity scale for vulnerabilities
EPSS Exploit Prediction Scoring System; probability (0-1) that a CVE will be exploited in the wild within 30 days
CISA KEV CISA Known Exploited Vulnerabilities catalog; federal mandate to patch these CVEs within specified timeframes
SLA Service Level Agreement for remediation timelines based on vulnerability severity
MTTR Mean Time To Remediate; average days from vulnerability discovery to confirmed fix
Compensating Control Alternative security measure when direct remediation is not feasible

Tools & Systems

  • Nessus/Tenable.io: Vulnerability scanning and remediation tracking
  • Qualys VMDR: Vulnerability management, detection, and response platform
  • Rapid7 InsightVM: Vulnerability assessment with live dashboards
  • WSUS/SCCM/Intune: Microsoft patch deployment infrastructure
  • Automox: Cloud-native patch management for Windows, macOS, Linux
  • CISA KEV Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Common Pitfalls

  • Patching without testing: Apply patches to a test group first. Some patches cause application compatibility issues or BSOD.
  • Ignoring EPSS scores: A CVSS 9.8 vulnerability with EPSS 0.01 may be less urgent than a CVSS 7.5 with EPSS 0.95 (actively exploited).
  • Not validating remediation: Deploying a patch does not guarantee installation. Always re-scan to confirm closure.
  • Excluding critical servers from patching: Servers that "cannot be rebooted" accumulate critical vulnerabilities. Schedule maintenance windows.
  • Treating all CVEs equally: Risk-based prioritization (CVSS + EPSS + asset criticality + exposure) is more effective than patching all criticals first.

Other files in this skill

assets/template.md (verbatim)

Endpoint Vulnerability Remediation Template

Scan Information

Field Value
Scanner Nessus / Qualys / Rapid7
Scan Date
Scope
Total Findings
Scan Policy

Remediation Priority Summary

Priority Count SLA Deadline Status
P1 (Critical) 14 days
P2 (High) 30 days
P3 (Medium) 60 days
P4 (Low) 90 days

CISA KEV Vulnerabilities (Mandatory Remediation)

CVE Affected Hosts CVSS Due Date Remediation Status

Remediation Actions

CVE/Plugin Host(s) Action Type Details Assigned To Status
Patch
Config change
Workaround
Accept risk

Patch Deployment Schedule

Phase Target Date Maintenance Window Rollback Plan
Test ring 5% endpoints
Pilot ring 20% endpoints
Production Remaining

Risk Acceptance Register

CVE Host CVSS Business Justification Compensating Control Approved By Expiry

Validation Results

CVE/Plugin Host Pre-Remediation Post-Remediation Verified By
Vulnerable Fixed / Still Vulnerable

Metrics

Metric Value
Total vulnerabilities
Remediated
Remediation rate %
MTTR (Mean Time to Remediate) days
SLA compliance %
Overdue count

Sign-Off

Role Name Date
Vulnerability Analyst
Patch Manager
Security Manager

references/api-reference.md (verbatim)

API Reference — Performing Endpoint Vulnerability Remediation

Libraries Used

Library Purpose
csv Parse vulnerability scan CSV exports (Nessus, Qualys, Rapid7)
subprocess Check installed Windows patches via wmic qfe and PowerShell
socket Validate port-based remediation via TCP connect
json Read/write remediation plans and reports
argparse CLI argument parsing for scan file and host parameters
datetime Track patch dates and SLA deadlines

CLI Interface

python agent.py parse --scan-file scan.csv
python agent.py patches
python agent.py validate --host 10.0.0.1 --port 445
python agent.py report --scan-file scan.csv [--output plan.json]

Core Functions

parse_scan_report(csv_file) — Parse and prioritize vulnerabilities by severity

def parse_scan_report(csv_file):
    """Parse Nessus/Qualys CSV export, group by host, sort by severity."""
    with open(csv_file, newline="") as f:
        reader = csv.DictReader(f)
        vulns = []
        for row in reader:
            vulns.append({
                "host": row.get("Host", row.get("IP")),
                "plugin_id": row.get("Plugin ID", row.get("QID")),
                "severity": row.get("Risk", row.get("Severity", "Info")),
                "name": row.get("Name", row.get("Title")),
                "cve": row.get("CVE", ""),
                "solution": row.get("Solution", row.get("Fix", "")),
            })
    severity_order = {"Critical": 0, "High": 1, "Medium": 2, "Low": 3, "Info": 4}
    return sorted(vulns, key=lambda v: severity_order.get(v["severity"], 5))

check_windows_patches() — List installed Windows hotfixes via WMIC

def check_windows_patches():
    """Query installed patches on a Windows endpoint."""
    result = subprocess.run(
        ["wmic", "qfe", "get", "HotFixID,InstalledOn,Description", "/format:csv"],
        capture_output=True, text=True, timeout=30,
    )
    patches = []
    for line in result.stdout.strip().split("\n")[1:]:
        parts = line.strip().split(",")
        if len(parts) >= 4:
            patches.append({
                "hotfix_id": parts[1],
                "description": parts[2],
                "installed_on": parts[3],
            })
    return patches

validate_remediation(host, port) — TCP connect to verify port closure

def validate_remediation(host, port):
    """Verify that a vulnerable port has been closed after remediation."""
    sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
    sock.settimeout(5)
    try:
        result = sock.connect_ex((host, int(port)))
        return {
            "host": host,
            "port": port,
            "status": "open" if result == 0 else "closed",
            "remediated": result != 0,
        }
    finally:
        sock.close()

generate_remediation_report(scan_file, output) — Group vulns by host for remediation

def generate_remediation_report(scan_file, output=None):
    """Generate a prioritized remediation plan from scan results."""
    vulns = parse_scan_report(scan_file)
    by_host = {}
    for v in vulns:
        by_host.setdefault(v["host"], []).append(v)

    report = {
        "total_vulns": len(vulns),
        "hosts_affected": len(by_host),
        "by_severity": {},
        "remediation_plan": [],
    }
    for severity in ["Critical", "High", "Medium", "Low"]:
        count = sum(1 for v in vulns if v["severity"] == severity)
        report["by_severity"][severity] = count

    for host, host_vulns in sorted(by_host.items()):
        report["remediation_plan"].append({
            "host": host,
            "vuln_count": len(host_vulns),
            "critical": sum(1 for v in host_vulns if v["severity"] == "Critical"),
            "patches": [v["name"] for v in host_vulns[:10]],
        })

    if output:
        with open(output, "w") as f:
            json.dump(report, f, indent=2)
    return report

Output Format

{
  "total_vulns": 245,
  "hosts_affected": 42,
  "by_severity": {
    "Critical": 8,
    "High": 35,
    "Medium": 112,
    "Low": 90
  },
  "remediation_plan": [
    {
      "host": "10.0.0.50",
      "vuln_count": 12,
      "critical": 2,
      "patches": ["MS17-010: EternalBlue", "CVE-2024-21887: Ivanti RCE"]
    }
  ]
}

Dependencies

No external packages — Python standard library only.

references/standards.md (verbatim)

Standards & References - Performing Endpoint Vulnerability Remediation

Primary Standards

NIST SP 800-40 Rev 4 - Guide to Enterprise Patch Management Planning

CISA Binding Operational Directive 22-01 - Known Exploited Vulnerabilities

FIRST CVSS v3.1 Specification

FIRST EPSS Model

  • Publisher: FIRST
  • URL: https://www.first.org/epss/
  • Scope: Machine learning model predicting probability of CVE exploitation within 30 days

Compliance Mappings

Framework Requirement Remediation Coverage
PCI DSS 4.0 6.3.3 - Patch within one month of release Patch SLA tracking and compliance
PCI DSS 4.0 11.3.1 - Internal vulnerability scans quarterly Scan-remediate-validate cycle
NIST 800-53 SI-2 Flaw Remediation Vulnerability identification and patching
NIST 800-53 RA-5 Vulnerability Monitoring and Scanning Ongoing scan-remediate process
HIPAA 164.308(a)(1)(ii)(B) - Risk Management Vulnerability remediation as risk reduction
ISO 27001 A.12.6.1 - Management of technical vulnerabilities Systematic vulnerability remediation
SOC 2 CC7.1 - Detect and address vulnerabilities Vulnerability management program

Remediation SLA Benchmarks

Severity CVSS Range Industry Standard SLA CISA KEV Timeline
Critical 9.0-10.0 14 days Per directive (usually 14 days)
High 7.0-8.9 30 days Per directive
Medium 4.0-6.9 60 days N/A unless in KEV
Low 0.1-3.9 90 days N/A

Supporting References

references/workflows.md (verbatim)

Workflows - Performing Endpoint Vulnerability Remediation

Workflow 1: Standard Vulnerability Remediation Cycle

[Vulnerability Scan Complete]
    │
    ▼
[Import scan results into tracking system]
    │
    ▼
[Risk-based prioritization]
    │
    ├── CVSS + EPSS + CISA KEV + Asset criticality
    │
    ▼
[Assign priorities: P1/P2/P3/P4]
    │
    ▼
[Identify remediation action per CVE]
    │
    ├── Patch available ──► [Schedule patch deployment]
    ├── Config change needed ──► [Create change request]
    ├── No patch available ──► [Apply workaround/compensating control]
    └── Accept risk ──► [Document with CISO approval]
    │
    ▼
[Test patches in staging environment]
    │
    ▼
[Deploy to production (phased rollout)]
    │
    ▼
[Re-scan to validate remediation]
    │
    ├── Vulnerability closed ──► [Mark resolved in tracker]
    │
    └── Still open ──► [Investigate failure, re-remediate]

Workflow 2: Emergency Zero-Day Response

[Zero-day CVE announced (CISA alert / vendor advisory)]
    │
    ▼
[Assess exposure: How many endpoints affected?]
    │
    ▼
[Is patch available?]
    │
    ├── Yes ──► [Emergency patch deployment (skip staging)]
    │               │
    │               ▼
    │          [Monitor for deployment failures]
    │               │
    │               ▼
    │          [Validate patch across fleet]
    │
    └── No ──► [Apply vendor workaround immediately]
                    │
                    ├── Disable vulnerable service/feature
                    ├── Deploy network-level mitigation
                    ├── Create EDR detection rule
                    │
                    ▼
               [Monitor for patch release]
                    │
                    ▼
               [Deploy patch when available]
                    │
                    ▼
               [Remove workaround, validate fix]

Workflow 3: Patch Deployment Pipeline

[Patch Tuesday (or vendor release)]
    │
    ▼
[Download and catalog new patches]
    │
    ▼
[Risk assessment: Which patches are critical?]
    │
    ▼
[Deploy to test ring (5% of fleet) - Day 1-3]
    │
    ├── Test application compatibility
    ├── Monitor for BSOD, crashes, performance issues
    │
    ▼
[Deploy to pilot ring (20% of fleet) - Day 4-7]
    │
    ├── Broader application testing
    ├── User feedback collection
    │
    ▼
[Deploy to production ring (remaining fleet) - Day 8-14]
    │
    ▼
[Generate compliance report]
    │
    ├── Endpoints patched: X%
    ├── Pending reboot: Y
    └── Failed deployments: Z (investigate)

Workflow 4: SLA Compliance Tracking

[Weekly SLA Review]
    │
    ▼
[Query open vulnerabilities grouped by SLA status]
    │
    ├── Within SLA ──► [Track progress, no action needed]
    │
    ├── Approaching SLA (7 days) ──► [Escalate to endpoint team]
    │
    └── Overdue (past SLA) ──► [Escalate to management]
                                     │
                                     ├── Remediation feasible ──► [Emergency remediation]
                                     │
                                     └── Blocked (dependency) ──► [Document exception, compensating control]

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.