Explore OpenCTI or OpenAEV platform with 30 days Free Trial!
XTM Hub by Filigran
Sign Up

Vulnerability Promotion — IR Case Creation

Vulnerability & Exploit Awareness
Detection & Response Enablement
A picture of RG9jdW1lbnQ6MGEzYTM0NTEtNTNiMy00NTQ3LWJiMDAtODRkOGZhOWE4NDA4

Overview

Promote High / P1 vulnerabilities to an incident response case

Overview

This playbook automatically promotes Vulnerabilities into an Incident Response (IR) Case when they reach a specified workflow status. Once triggered, the Vulnerability is wrapped in an existing IR Case, which is then updated with a target workflow status, a severity of High, and a priority of P1. It is designed for security teams that want to automate the escalation of vulnerabilities into their incident response process based on triage decisions.


Dependencies

  • Standard OpenCTI platform access with the Manage Playbooks permission.
  • Two workflow statuses must exist in the OpenCTI environment before import:
    • A trigger status — the Vulnerability workflow status that fires the playbook.
    • A target status — the IR Case workflow status applied after promotion (labelled "Monitor" in the original configuration).

How to Use It

A. Import and configure

  1. Import the playbook JSON file via Automation > Playbooks > Import.
  2. Open the Listen for Vulnerability Workflow Updates node and select the workflow status that should trigger the playbook (the status a Vulnerability must reach to be promoted).
  3. Open the Set Case Status, Severity and Priority node and select the target workflow status to apply to the IR Case after promotion.

B. Activate

  1. Save all changes and activate the playbook.
  2. No further interaction is required. The playbook fires automatically whenever a Vulnerability is updated to the configured trigger workflow status.

C. Expected outcome

When a Vulnerability is updated to the trigger workflow status, the following should occur:

StepActionResult
1Trigger firesVulnerability matching the trigger workflow status is detected
2Wrap in IR CaseVulnerability is added to an existing Incident Response Case
3Set Case Status, Severity and PriorityIR Case workflow status updated to target status; severity set to High; priority set to P1
4Send to KnowledgeUpdated Case is ingested into the OpenCTI knowledge base

Basic information

Filigran
Toby Butler
July 07, 2026
10+
0

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".