Subdomain routing agent for Vulnerability Management and Attack Surface Management. Covers VM programs, scanner operations, risk scoring (CVSS/EPSS/VPR), remediation workflows, SLA tracking, CNAPP platforms, and EASM tools. WHEN: \"vulnerability management\", \"vuln scan\", \"CVE\", \"CVSS\", \"EPSS\", \"patch prioritization\", \"attack surface\", \"EASM\", \"CNAPP\", \"CSPM\", \"exposure management\". Do NOT use for platform-specific questions -- use the `qualys`, `tenable`, `rapid7`, `snyk`...
Pro scans all 2 files and shows the line behind each finding
Scanned 9/24/2026
npx -y skills add chrishuffman5/domain-expert --skill vulnerability-management --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Vulnerability Management?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/chrishuffman5-vulnerability-management)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: vulnerability-management
description: "Subdomain routing agent for Vulnerability Management and Attack Surface Management. Covers VM programs, scanner operations, risk scoring (CVSS/EPSS/VPR), remediation workflows, SLA tracking, CNAPP platforms, and EASM tools. WHEN: \"vulnerability management\", \"vuln scan\", \"CVE\", \"CVSS\", \"EPSS\", \"patch prioritization\", \"attack surface\", \"EASM\", \"CNAPP\", \"CSPM\", \"exposure management\". Do NOT use for platform-specific questions -- use the `qualys`, `tenable`, `rapid7`, `snyk`, or `asm` skill."
license: MIT
---
# Vulnerability Management & Attack Surface Management
This skill covers all vulnerability management (VM) and attack surface management (ASM) disciplines. It provides deep expertise in VM program design, risk-based prioritization, scanner operations, remediation workflows, and cloud security posture. Read the relevant sibling skill for platform implementation details.
## When to Use This Skill vs. a Technology Skill
**Use this skill when the question is cross-tool or programmatic:**
- "How should I design our VM program?"
- "What is the right SLA for critical vulnerabilities?"
- "Compare Tenable vs. Qualys vs. Rapid7"
- "How does CVSS differ from EPSS for prioritization?"
- "What is the difference between CSPM, CWPP, and CNAPP?"
- "Should we use an agent-based or agentless scanner?"
- "How do we measure our attack surface?"
**Read a sibling skill when the question is platform-specific:**
- "Configure a Nessus credentialed scan" --> `tenable`
- "Set up Qualys Cloud Agent" --> `qualys`
- "InsightVM Active Risk Score configuration" --> `rapid7`
- "Snyk CI/CD integration" --> `snyk`
- "Wiz Security Graph query" --> `wiz`
- "Prisma Cloud policy suppression" --> `prisma-cloud`
- "Orca SideScanning setup" --> `orca`
- "Defender for Cloud recommendations" --> `defender-cloud`
- "AWS Security Hub findings" --> `aws-security-hub`
- "Attack surface discovery, Falcon Surface / Xpanse / EASM" --> `asm`
## How to Approach Tasks
When you receive a request:
1. **Classify** the request:
- **Program design** -- Load `references/concepts.md` for VM fundamentals
- **Scanner operations** -- Read the appropriate sibling skill
- **Risk prioritization** -- Apply CVSS + EPSS + threat intelligence context
- **Remediation management** -- Address SLAs, ticketing integration, exceptions
- **Cloud security posture** -- Read the CNAPP sibling skill (Wiz, Prisma Cloud, Orca, Defender for Cloud)
- **Attack surface discovery** -- Read `asm`
- **Developer security** -- Read `snyk`
2. **Gather context** -- Environment type (cloud/on-prem/hybrid), regulatory requirements, asset inventory size, team maturity, existing tooling, remediation ownership (security vs. IT)
3. **Analyze** -- Apply risk-based prioritization. Not all critical CVEs are equally dangerous. Context (exploitability, asset criticality, exposure) changes the priority order.
4. **Recommend** -- Provide actionable guidance with trade-offs. A mature VM program is a continuous process, not a quarterly scan.
5. **Qualify** -- State coverage gaps, measurement limitations, and conditions where recommendations change.
## Core Concepts
### Risk Scoring Comparison
| Score | Source | What It Measures | Best Used For |
|---|---|---|---|
| **CVSS v3.1** | NVD/vendor | Technical severity (exploitability + impact) | Baseline severity classification |
| **CVSS v4.0** | FIRST | Refined severity + supplemental metrics | New and updated CVE scoring |
| **EPSS** | FIRST | Probability of exploitation in next 30 days | Prioritizing likely-to-be-exploited vulns |
| **CISA KEV** | CISA | Known exploited in the wild (binary: yes/no) | Immediate action -- KEV = patch now |
| **VPR** (Tenable) | Tenable | Threat-intelligence-enriched severity (1-10) | Tenable-specific prioritization |
| **Active Risk** (Rapid7) | Rapid7 | CVSS + threat intel + asset context | Rapid7-specific prioritization |
| **TruRisk** (Qualys) | Qualys | Risk score combining detection confidence + threat | Qualys-specific risk quantification |
**Prioritization framework:**
1. **Immediate (24-48h):** CISA KEV entries on internet-facing or critical systems
2. **Critical SLA (7 days):** CVSS >= 9.0 AND EPSS >= 0.1 AND asset is exposed
3. **High SLA (30 days):** CVSS >= 7.0 with active threat activity
4. **Standard SLA (90 days):** CVSS >= 4.0, no active exploitation evidence
5. **Accept/Schedule (180 days+):** Low severity, compensating controls in place
### Scan Coverage Model
| Method | Best For | Limitations |
|---|---|---|
| **Credentialed network scan** | Deep OS-level detection, missing patches, config audits | Requires credentials management, network access |
| **Uncredentialed network scan** | External perspective, network-exposed services | Misses 40-60% of vulns (no auth to OS/apps) |
| **Agent-based** | Remote/cloud assets, always-on assessment, no network scan required | Agent deployment and maintenance overhead |
| **Agentless (API/snapshot)** | Cloud-native assets, fast deployment, no agent overhead | Point-in-time, may miss ephemeral workloads |
| **Container image scanning** | CI/CD integration, shift-left, image layers | Does not catch runtime misconfigs |
| **DAST/IAST** | Running web application vulnerabilities | Requires running application, scope definition |
### Cloud Security Platform Categories
| Category | Description | Primary Tools |
|---|---|---|
| **CSPM** | Cloud Security Posture Management -- misconfiguration detection, compliance | Wiz, Prisma Cloud, Defender for Cloud, AWS Security Hub |
| **CWPP** | Cloud Workload Protection -- runtime protection for VMs, containers, serverless | Prisma Cloud, Defender for Cloud, Wiz Defend |
| **CIEM** | Cloud Identity Entitlement Management -- overprivileged identities, permissions | Wiz, Prisma Cloud, Defender for Cloud |
| **CNAPP** | Cloud Native Application Protection Platform -- unified CSPM+CWPP+CIEM | Wiz, Prisma Cloud, Orca, Defender for Cloud |
| **DSPM** | Data Security Posture Management -- sensitive data discovery and protection | Wiz, Prisma Cloud |
| **AI-SPM** | AI Security Posture Management -- LLM/AI risk visibility | Wiz, Prisma Cloud |
### VM Program Maturity Model
**Level 1 - Ad Hoc:**
- Periodic scans (quarterly or less)
- No SLAs, no formal remediation tracking
- Single scanner type, uncredentialed or partially credentialed
**Level 2 - Repeatable:**
- Weekly/monthly authenticated scans
- Defined SLAs (even if not consistently met)
- Remediation tracked in scanner or spreadsheet
- Critical/High prioritization in place
**Level 3 - Defined:**
- Continuous scanning / agent-based coverage
- Formal SLAs tied to policy, exceptions process
- ITSM integration (ServiceNow, Jira) for remediation tickets
- Metrics and reporting to management
**Level 4 - Managed:**
- Risk-based prioritization (EPSS/KEV, asset criticality)
- Coverage measurement and gap identification
- Remediation verification/re-scan workflow
- Attack surface management integrated
- SLA compliance > 80% tracked
**Level 5 - Optimized:**
- Threat intelligence-enriched prioritization
- Full CNAPP + developer security (shift-left) integration
- Exposure management (not just vuln management)
- SLA compliance > 95%, exception governance
- Business-aligned risk communication
## Technology Routing
| Request Pattern | Route To |
|---|---|
| Tenable, Nessus, Tenable.io, Tenable One, VPR | `tenable` |
| Qualys, VMDR, QQL, TruRisk, TotalCloud | `qualys` |
| Rapid7, InsightVM, Active Risk, Remediation Hub | `rapid7` |
| Snyk Code, Snyk Open Source, Snyk Container, Snyk IaC | `snyk` |
| Wiz, Security Graph, CNAPP, agentless cloud | `wiz` |
| Prisma Cloud, Cortex Cloud, Bridgecrew | `prisma-cloud` |
| Orca Security, SideScanning | `orca` |
| Microsoft Defender for Cloud, CSPM Azure | `defender-cloud` |
| AWS Security Hub, GuardDuty, Inspector | `aws-security-hub` |
| External attack surface, EASM, internet exposure | `asm` |
| Falcon Surface, Xpanse, Defender EASM, Censys | `asm` |
## Common VM Program Anti-Patterns
1. **Scanning without credentials** -- Uncredentialed scans detect 40-60% fewer vulns. Always use authenticated/credentialed scanning for internal assets.
2. **CVSS-only prioritization** -- A CVSS 9.8 with no public exploit and on an isolated internal host is lower risk than a CVSS 7.5 with a KEV entry on an internet-facing server. Layer EPSS and KEV.
3. **No asset criticality weighting** -- Prioritizing a critical CVE on a dev laptop the same as on a production payment server misallocates remediation effort.
4. **Coverage gaps** -- Cloud workloads, containers, and remote/cloud assets often lack scanner coverage. Agent-based or agentless cloud scanning fills these gaps.
5. **Treating VM as a security-only problem** -- Remediation is owned by IT/dev/cloud teams. VM programs fail without SLA accountability and ITSM integration.
6. **Ignoring attack surface expansion** -- VM programs focus on known assets. Unknown internet-exposed assets (shadow IT, forgotten dev environments, acquired companies) are often the actual attack path.
7. **No re-scan verification** -- Closing tickets on remediation reports without re-scanning leads to a false sense of closure. Verify fixes with targeted rescans.
## Exposure Management vs. Vulnerability Management
Traditional VM focuses on known assets + CVE detection. Modern exposure management (Gartner CTEM) expands the scope:
| Dimension | Vulnerability Management | Exposure Management (CTEM) |
|---|---|---|
| **Scope** | Known assets, CVEs | Known + unknown assets, misconfigs, identity risks, data exposure |
| **Approach** | Find-fix-report cycle | Continuous assessment, attack path analysis |
| **Prioritization** | CVSS + patch availability | Business impact + likelihood of exploitation by real attacker |
| **Output** | Vuln list, patch status | Risk reduction metrics, attack path elimination |
| **Tools** | Tenable, Qualys, Rapid7 | Tenable One, Wiz, Xpanse + VM tools |
## Reference Files
Load these when you need deep foundational knowledge:
- `references/concepts.md` -- VM fundamentals: CVSS/EPSS/KEV scoring, scan types, remediation workflows, SLA frameworks, compliance mapping. Read for "how does X work" or program design questions.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!