OpenCTI または OpenAEV プラットフォームを 30 日間お試しいただけます。 無料トライアル
XTMハブ by フィリグラン
サインアップ

Vulnerability Promotion — IR Case Creation

Vulnerability & Exploit Awareness
Detection & Response Enablement
A picture of RG9jdW1lbnQ6MGEzYTM0NTEtNTNiMy00NTQ3LWJiMDAtODRkOGZhOWE4NDA4

概要

Promote High / P1 vulnerabilities to an incident response case

Overview

This playbook automatically promotes Vulnerabilities into an Incident Response (IR) Case when they reach a specified workflow status. Once triggered, the Vulnerability is wrapped in an existing IR Case, which is then updated with a target workflow status, a severity of High, and a priority of P1. It is designed for security teams that want to automate the escalation of vulnerabilities into their incident response process based on triage decisions.


Dependencies

  • Standard OpenCTI platform access with the Manage Playbooks permission.
  • Two workflow statuses must exist in the OpenCTI environment before import:
    • A trigger status — the Vulnerability workflow status that fires the playbook.
    • A target status — the IR Case workflow status applied after promotion (labelled "Monitor" in the original configuration).

How to Use It

A. Import and configure

  1. Import the playbook JSON file via Automation > Playbooks > Import.
  2. Open the Listen for Vulnerability Workflow Updates node and select the workflow status that should trigger the playbook (the status a Vulnerability must reach to be promoted).
  3. Open the Set Case Status, Severity and Priority node and select the target workflow status to apply to the IR Case after promotion.

B. Activate

  1. Save all changes and activate the playbook.
  2. No further interaction is required. The playbook fires automatically whenever a Vulnerability is updated to the configured trigger workflow status.

C. Expected outcome

When a Vulnerability is updated to the trigger workflow status, the following should occur:

StepActionResult
1Trigger firesVulnerability matching the trigger workflow status is detected
2Wrap in IR CaseVulnerability is added to an existing Incident Response Case
3Set Case Status, Severity and PriorityIR Case workflow status updated to target status; severity set to High; priority set to P1
4Send to KnowledgeUpdated Case is ingested into the OpenCTI knowledge base

基本情報

Filigran
Toby Butler
2026年7月07日
10+
0

    XTM Hubの運営にはクッキーを使用しています。必須のクッキーは常に有効になっていますが、オプションのクッキー(機能、分析、マーケティング)は、お客様の同意を得た上で使用されます。「クッキー設定」から、いつでも「すべて受け入れる」、「すべて拒否する」、または設定を管理することができます。