Use when this skill covers performing vulnerability assessments in OT
Scanned 9/8/2026
Install to Claude Code
npx -y skills add oyi77/1ai-skills --skill performing-ot-vulnerability-assessment-with-claroty --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Performing Ot Vulnerability Assessment With Claroty?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/oyi77-performing-ot-vulnerability-assessment-with-clarot)More formats (shields.io, HTML) on the badges page.
---
name: performing-ot-vulnerability-assessment-with-claroty
description: Use when this skill covers performing vulnerability assessments in OT
environments using the Claroty xDome platform for comprehensive asset discovery,
risk scoring, vulnerability correlation, and remediation prioritization. It addresses
passive vulnerability identification through traffic analysis, active safe querying
of OT devices, integration with CVE databases and ICS-CERT advisories, and risk-based
prioritization that accounts for operational impact and compensating controls.
domain: cybersecurity
tags:
- ot-security
- ics
- scada
- industrial-control
- iec62443
- vulnerability-assessment
- claroty
subdomain: ot-ics-security
version: 1.0.0
author: oyi77
license: Apache-2.0
nist_csf:
- PR.IR-01
- DE.CM-01
- ID.AM-05
- GV.OC-02
category: cybersecurity
---
# Performing Ot Vulnerability Assessment With Claroty
## Overview
Cybersecurity skill for performing ot vulnerability assessment with claroty. Follows industry best practices and security standards.
## When to Use
**Trigger phrases:**
- "performing ot vulnerability assessment with claroty"
- "This skill covers performing vulnerability assessments in OT environments using "
- When conducting scheduled OT vulnerability assessments per IEC 62443 or NERC CIP requirements
- When deploying Claroty xDome for the first time and performing initial asset discovery and risk assessment
- When correlating newly published ICS-CERT advisories against your OT asset inventory
- When prioritizing OT vulnerability remediation with limited maintenance windows
- When generating compliance evidence for CIP-010-4 vulnerability assessment requirements
**Do not use** for active vulnerability scanning of PLCs and safety systems (see performing-ot-network-security-assessment for passive approaches), for IT-only vulnerability management (see standard vulnerability scanners), or for penetration testing (see performing-ics-penetration-testing).
## When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
## Prerequisites
- Claroty xDome or CTD (Continuous Threat Detection) deployed with sensors on OT network
- Network SPAN/TAP access for passive asset discovery
- CISA ICS-CERT advisory subscription for vulnerability tracking
- Asset inventory with firmware versions for all OT devices
- Change management process for patch deployment during maintenance windows
## Workflow
```python
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
```
1. **Plan Operations** — Define objectives, scope, and success criteria for ot vulnerability assessment operations.
2. **Prepare Environment** — Set up tools, access, and data sources required for ot vulnerability assessment.
3. **Execute Core Workflow** — Use claroty to perform ot vulnerability assessment operations following established procedures.
4. **Validate Results** — Verify that results meet quality standards and objectives.
5. **Report Findings** — Document results, observations, and recommendations.
6. **Follow Up** — Track remediation actions and verify fixes where applicable.
## Tools
- **claroty** — Primary tool for this skill
- **Analysis Platform** — Data processing and visualization
- **Collaboration Tools** — Team coordination and knowledge sharing
## Process
1. **Reconnaissance** — Gather target information, identify attack surface, enumerate services
1. **Analysis/Exploitation** — Execute the technique, analyze results, document findings
1. **Reporting** — Document IOCs, write findings, provide remediation recommendations
## Verification
- [ ] All ot vulnerability assessment procedures executed completely and documented
- [ ] Findings validated against multiple data sources
- [ ] False positives identified and filtered
- [ ] Results documented with evidence and timestamps
- [ ] Recommendations provided with risk-based prioritization
## Anti-Rationalization Table
| Rationalization | Reality |
|---|---|
| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |
| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!