ArcanaIncident-response documentationBrowse the feedTemplates
Back to feed
Runbook · Triage
RB-TRIAGE-009

Vulnerability Validation

1. Prerequisites

  • Vulnerability alert, advisory, disclosure, or report received
  • CVE, advisory, or finding identifier available
  • Access to vulnerability management platform
  • Access to asset inventory
  • Access to configuration management data
  • Access to SIEM
  • Access to threat intelligence sources
  • Access to affected system information
  • Incident or tracking ticket created

2. Step-by-Step Instructions

  1. Review Vulnerability Information

    • Collect:
      • CVE identifier
      • Vendor advisory
      • Security bulletin
      • Vulnerability description
      • Severity rating
    • Document all available information.
  2. Validate Vulnerability Authenticity

    • Verify the vulnerability through:
      • Vendor advisories
      • Official CVE records
      • Trusted security sources
      • Internal vulnerability management tooling
    • Confirm the vulnerability is legitimate and applicable.
  3. Identify Affected Technologies

    • Determine:
      • Operating systems
      • Applications
      • Services
      • Cloud platforms
      • Network devices
    • Document affected technologies.
  4. Identify Potentially Affected Assets

    • Review asset inventory and vulnerability management data.
    • Identify:
      • Externally exposed assets
      • Internal assets
      • Critical systems
      • Production environments
    • Document potentially affected assets.
  5. Review Existing Vulnerability Data

    • Determine:
      • Existing detections
      • Previous scan results
      • Existing remediation status
      • Previous findings
    • Document relevant findings.
  6. Assess Exposure

    • Determine:
      • Internet exposure
      • Internal exposure
      • Access requirements
      • Exploitation prerequisites
    • Document exposure level.
  7. Review Threat Intelligence

    • Determine whether:
      • Public exploit code exists
      • Active exploitation has been reported
      • Threat actors are targeting the vulnerability
      • Exploitation campaigns are ongoing
    • Document findings.
  8. Assess Preliminary Risk

    • Consider:
      • Severity score
      • Exposure level
      • Asset criticality
      • Exploitation availability
      • Existing mitigations
    • Assign a preliminary risk rating.
  9. Determine Required Response Actions

    • Determine whether:
      • Further analysis is required
      • Immediate containment is required
      • Emergency remediation is required
      • Monitoring should be increased
    • Document recommended actions.
  10. Escalate and Hand Off

    • Provide findings to the Incident Commander and Technical Lead.
    • Escalate to:
      • Vulnerability Exposure Assessment
      • Vulnerable Asset Identification
      • Exploitation Verification
      • Vulnerability Exposure Reduction
    • Update the incident record with all findings.

3. Post-Action

  • Ensure all affected technologies are documented.
  • Ensure all potentially affected assets are recorded.
  • Preserve supporting advisories and intelligence sources.
  • Document the preliminary risk assessment.
  • Attach all validation findings to the incident record.
  • Ensure appropriate analysis and remediation activities have been initiated.

Contributor

Vishal Thakur GitHub: https://github.com/malienist

Contributed to the Arcana Incident Response Documentation Framework.