Skip to content
Back to skills

Vulnerability Management

ASecurity

Subdomain routing agent for Vulnerability Management and Attack Surface Management. Covers VM programs, scanner operations, risk scoring (CVSS/EPSS/VPR), remediation workflows, SLA tracking, CNAPP platforms, and EASM tools. WHEN: \"vulnerability management\", \"vuln scan\", \"CVE\", \"CVSS\", \"EPSS\", \"patch prioritization\", \"attack surface\", \"EASM\", \"CNAPP\", \"CSPM\", \"exposure management\". Do NOT use for platform-specific questions -- use the `qualys`, `tenable`, `rapid7`, `snyk`...

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
securitygoawsazureapici/cdsecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill vulnerability-management --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Vulnerability Management?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Vulnerability Management
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-vulnerability-management/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-vulnerability-management)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: vulnerability-management
description: "Subdomain routing agent for Vulnerability Management and Attack Surface Management. Covers VM programs, scanner operations, risk scoring (CVSS/EPSS/VPR), remediation workflows, SLA tracking, CNAPP platforms, and EASM tools. WHEN: \"vulnerability management\", \"vuln scan\", \"CVE\", \"CVSS\", \"EPSS\", \"patch prioritization\", \"attack surface\", \"EASM\", \"CNAPP\", \"CSPM\", \"exposure management\". Do NOT use for platform-specific questions -- use the `qualys`, `tenable`, `rapid7`, `snyk`, or `asm` skill."
license: MIT
---

# Vulnerability Management & Attack Surface Management

This skill covers all vulnerability management (VM) and attack surface management (ASM) disciplines. It provides deep expertise in VM program design, risk-based prioritization, scanner operations, remediation workflows, and cloud security posture. Read the relevant sibling skill for platform implementation details.

## When to Use This Skill vs. a Technology Skill

**Use this skill when the question is cross-tool or programmatic:**
- "How should I design our VM program?"
- "What is the right SLA for critical vulnerabilities?"
- "Compare Tenable vs. Qualys vs. Rapid7"
- "How does CVSS differ from EPSS for prioritization?"
- "What is the difference between CSPM, CWPP, and CNAPP?"
- "Should we use an agent-based or agentless scanner?"
- "How do we measure our attack surface?"

**Read a sibling skill when the question is platform-specific:**
- "Configure a Nessus credentialed scan" --> `tenable`
- "Set up Qualys Cloud Agent" --> `qualys`
- "InsightVM Active Risk Score configuration" --> `rapid7`
- "Snyk CI/CD integration" --> `snyk`
- "Wiz Security Graph query" --> `wiz`
- "Prisma Cloud policy suppression" --> `prisma-cloud`
- "Orca SideScanning setup" --> `orca`
- "Defender for Cloud recommendations" --> `defender-cloud`
- "AWS Security Hub findings" --> `aws-security-hub`
- "Attack surface discovery, Falcon Surface / Xpanse / EASM" --> `asm`

## How to Approach Tasks

When you receive a request:

1. **Classify** the request:
   - **Program design** -- Load `references/concepts.md` for VM fundamentals
   - **Scanner operations** -- Read the appropriate sibling skill
   - **Risk prioritization** -- Apply CVSS + EPSS + threat intelligence context
   - **Remediation management** -- Address SLAs, ticketing integration, exceptions
   - **Cloud security posture** -- Read the CNAPP sibling skill (Wiz, Prisma Cloud, Orca, Defender for Cloud)
   - **Attack surface discovery** -- Read `asm`
   - **Developer security** -- Read `snyk`

2. **Gather context** -- Environment type (cloud/on-prem/hybrid), regulatory requirements, asset inventory size, team maturity, existing tooling, remediation ownership (security vs. IT)

3. **Analyze** -- Apply risk-based prioritization. Not all critical CVEs are equally dangerous. Context (exploitability, asset criticality, exposure) changes the priority order.

4. **Recommend** -- Provide actionable guidance with trade-offs. A mature VM program is a continuous process, not a quarterly scan.

5. **Qualify** -- State coverage gaps, measurement limitations, and conditions where recommendations change.

## Core Concepts

### Risk Scoring Comparison

| Score | Source | What It Measures | Best Used For |
|---|---|---|---|
| **CVSS v3.1** | NVD/vendor | Technical severity (exploitability + impact) | Baseline severity classification |
| **CVSS v4.0** | FIRST | Refined severity + supplemental metrics | New and updated CVE scoring |
| **EPSS** | FIRST | Probability of exploitation in next 30 days | Prioritizing likely-to-be-exploited vulns |
| **CISA KEV** | CISA | Known exploited in the wild (binary: yes/no) | Immediate action -- KEV = patch now |
| **VPR** (Tenable) | Tenable | Threat-intelligence-enriched severity (1-10) | Tenable-specific prioritization |
| **Active Risk** (Rapid7) | Rapid7 | CVSS + threat intel + asset context | Rapid7-specific prioritization |
| **TruRisk** (Qualys) | Qualys | Risk score combining detection confidence + threat | Qualys-specific risk quantification |

**Prioritization framework:**
1. **Immediate (24-48h):** CISA KEV entries on internet-facing or critical systems
2. **Critical SLA (7 days):** CVSS >= 9.0 AND EPSS >= 0.1 AND asset is exposed
3. **High SLA (30 days):** CVSS >= 7.0 with active threat activity
4. **Standard SLA (90 days):** CVSS >= 4.0, no active exploitation evidence
5. **Accept/Schedule (180 days+):** Low severity, compensating controls in place

### Scan Coverage Model

| Method | Best For | Limitations |
|---|---|---|
| **Credentialed network scan** | Deep OS-level detection, missing patches, config audits | Requires credentials management, network access |
| **Uncredentialed network scan** | External perspective, network-exposed services | Misses 40-60% of vulns (no auth to OS/apps) |
| **Agent-based** | Remote/cloud assets, always-on assessment, no network scan required | Agent deployment and maintenance overhead |
| **Agentless (API/snapshot)** | Cloud-native assets, fast deployment, no agent overhead | Point-in-time, may miss ephemeral workloads |
| **Container image scanning** | CI/CD integration, shift-left, image layers | Does not catch runtime misconfigs |
| **DAST/IAST** | Running web application vulnerabilities | Requires running application, scope definition |

### Cloud Security Platform Categories

| Category | Description | Primary Tools |
|---|---|---|
| **CSPM** | Cloud Security Posture Management -- misconfiguration detection, compliance | Wiz, Prisma Cloud, Defender for Cloud, AWS Security Hub |
| **CWPP** | Cloud Workload Protection -- runtime protection for VMs, containers, serverless | Prisma Cloud, Defender for Cloud, Wiz Defend |
| **CIEM** | Cloud Identity Entitlement Management -- overprivileged identities, permissions | Wiz, Prisma Cloud, Defender for Cloud |
| **CNAPP** | Cloud Native Application Protection Platform -- unified CSPM+CWPP+CIEM | Wiz, Prisma Cloud, Orca, Defender for Cloud |
| **DSPM** | Data Security Posture Management -- sensitive data discovery and protection | Wiz, Prisma Cloud |
| **AI-SPM** | AI Security Posture Management -- LLM/AI risk visibility | Wiz, Prisma Cloud |

### VM Program Maturity Model

**Level 1 - Ad Hoc:**
- Periodic scans (quarterly or less)
- No SLAs, no formal remediation tracking
- Single scanner type, uncredentialed or partially credentialed

**Level 2 - Repeatable:**
- Weekly/monthly authenticated scans
- Defined SLAs (even if not consistently met)
- Remediation tracked in scanner or spreadsheet
- Critical/High prioritization in place

**Level 3 - Defined:**
- Continuous scanning / agent-based coverage
- Formal SLAs tied to policy, exceptions process
- ITSM integration (ServiceNow, Jira) for remediation tickets
- Metrics and reporting to management

**Level 4 - Managed:**
- Risk-based prioritization (EPSS/KEV, asset criticality)
- Coverage measurement and gap identification
- Remediation verification/re-scan workflow
- Attack surface management integrated
- SLA compliance > 80% tracked

**Level 5 - Optimized:**
- Threat intelligence-enriched prioritization
- Full CNAPP + developer security (shift-left) integration
- Exposure management (not just vuln management)
- SLA compliance > 95%, exception governance
- Business-aligned risk communication

## Technology Routing

| Request Pattern | Route To |
|---|---|
| Tenable, Nessus, Tenable.io, Tenable One, VPR | `tenable` |
| Qualys, VMDR, QQL, TruRisk, TotalCloud | `qualys` |
| Rapid7, InsightVM, Active Risk, Remediation Hub | `rapid7` |
| Snyk Code, Snyk Open Source, Snyk Container, Snyk IaC | `snyk` |
| Wiz, Security Graph, CNAPP, agentless cloud | `wiz` |
| Prisma Cloud, Cortex Cloud, Bridgecrew | `prisma-cloud` |
| Orca Security, SideScanning | `orca` |
| Microsoft Defender for Cloud, CSPM Azure | `defender-cloud` |
| AWS Security Hub, GuardDuty, Inspector | `aws-security-hub` |
| External attack surface, EASM, internet exposure | `asm` |
| Falcon Surface, Xpanse, Defender EASM, Censys | `asm` |

## Common VM Program Anti-Patterns

1. **Scanning without credentials** -- Uncredentialed scans detect 40-60% fewer vulns. Always use authenticated/credentialed scanning for internal assets.

2. **CVSS-only prioritization** -- A CVSS 9.8 with no public exploit and on an isolated internal host is lower risk than a CVSS 7.5 with a KEV entry on an internet-facing server. Layer EPSS and KEV.

3. **No asset criticality weighting** -- Prioritizing a critical CVE on a dev laptop the same as on a production payment server misallocates remediation effort.

4. **Coverage gaps** -- Cloud workloads, containers, and remote/cloud assets often lack scanner coverage. Agent-based or agentless cloud scanning fills these gaps.

5. **Treating VM as a security-only problem** -- Remediation is owned by IT/dev/cloud teams. VM programs fail without SLA accountability and ITSM integration.

6. **Ignoring attack surface expansion** -- VM programs focus on known assets. Unknown internet-exposed assets (shadow IT, forgotten dev environments, acquired companies) are often the actual attack path.

7. **No re-scan verification** -- Closing tickets on remediation reports without re-scanning leads to a false sense of closure. Verify fixes with targeted rescans.

## Exposure Management vs. Vulnerability Management

Traditional VM focuses on known assets + CVE detection. Modern exposure management (Gartner CTEM) expands the scope:

| Dimension | Vulnerability Management | Exposure Management (CTEM) |
|---|---|---|
| **Scope** | Known assets, CVEs | Known + unknown assets, misconfigs, identity risks, data exposure |
| **Approach** | Find-fix-report cycle | Continuous assessment, attack path analysis |
| **Prioritization** | CVSS + patch availability | Business impact + likelihood of exploitation by real attacker |
| **Output** | Vuln list, patch status | Risk reduction metrics, attack path elimination |
| **Tools** | Tenable, Qualys, Rapid7 | Tenable One, Wiz, Xpanse + VM tools |

## Reference Files

Load these when you need deep foundational knowledge:

- `references/concepts.md` -- VM fundamentals: CVSS/EPSS/KEV scoring, scan types, remediation workflows, SLA frameworks, compliance mapping. Read for "how does X work" or program design questions.

Files in this skill

  • SKILL.md10.1 KB
  • references/concepts.md12.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…