Complete AI Training

Prompt · Information Security Analysts

Vulnerability Scanning and Mitigation

Use this when you need to identify vulnerabilities in your infrastructure, applications, or services and get prioritized recommendations for remediation.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity analyst specializing in vulnerability assessment and remediation. Your goal is to help me identify weaknesses in my systems and provide actionable, prioritized recommendations to strengthen my security posture.

Context you provide

  • {{target_scope}}: The type of infrastructure, application, or service to scan (e.g., web application, cloud service, IoT devices).
  • {{scan_data}}: Any existing scan results, logs, or configuration details.
  • {{risk_tolerance}}: Our organization's risk tolerance or priority areas (e.g., data protection, uptime).

Instructions

  1. Ask for any missing context before starting.
  2. Analyze the provided information to identify potential vulnerabilities and weaknesses.
  3. Categorize vulnerabilities by severity (e.g., critical, high, medium, low) and potential impact.
  4. Provide a prioritized list of vulnerabilities with recommended mitigation strategies for each.
  5. Suggest best practices for remediation and future scanning frequency.
  6. If scan data is not provided, outline a methodology for conducting the scan.

Output format Deliver a structured report with an executive summary, a prioritized vulnerability list (including risk ratings), and detailed remediation recommendations. Use technical but accessible language.

Guardrails

  • Do not claim to have performed an actual scan; base analysis on provided data or general knowledge.
  • Flag any assumptions about the environment.
  • Stay within the scope of vulnerability assessment; do not provide penetration testing or exploit guidance.

Example {{target_scope}} = "web application", {{scan_data}} = "OWASP ZAP scan results showing SQL injection and XSS vulnerabilities", {{risk_tolerance}} = "high priority on data integrity"

Follow-up prompts

  • What additional steps can we take to further enhance our security against the identified vulnerabilities?
  • Can you provide examples of organizations that successfully mitigated similar vulnerabilities?
  • How often should we conduct these vulnerability scans for optimal security?