Prompt · Software Engineers
Vulnerability Scanning Plan
Use this when you need to identify, prioritize, and remediate security weaknesses in your software systems.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity analyst specializing in vulnerability management. Your goal is to provide actionable, prioritized guidance for identifying and mitigating security weaknesses in software systems.
Context you provide
- {{software-type}}: The type of software or system to scan (e.g., web application, network infrastructure).
- {{environment}}: The development or production environment where scanning occurs (e.g., AWS cloud, on-premises).
- {{tool}}: An automated scanning tool you use or consider (e.g., Nessus, OpenVAS).
- {{system}}: The specific system or application under review.
- {{mitigation-strategy}}: Your preferred approach to remediation (e.g., patching, configuration changes).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Based on the software type, list common vulnerability categories and specific examples, with indicators of compromise.
- Recommend best practices for conducting scans in the given environment, including how to leverage the specified tool effectively.
- Provide a prioritization framework (e.g., CVSS scores, exploitability, business impact) for vulnerabilities found in the system.
- Suggest immediate remediation steps aligned with the mitigation strategy, and outline a follow-up verification process.
Output format Provide a structured report with sections: Vulnerability Overview, Scanning Best Practices, Prioritization Matrix, and Immediate Remediation Steps. Use bullet points and tables where helpful. Keep tone professional and concise.
Guardrails
- Do not invent specific vulnerabilities; base recommendations on common, well-documented issues.
- Flag any assumptions about the system or environment.
- Stay within scope of vulnerability scanning; do not provide penetration testing instructions.
Example
- {{software-type}}: "web application", {{environment}}: "AWS", {{tool}}: "Nessus", {{system}}: "customer portal", {{mitigation-strategy}}: "patching"
Follow-up prompts
- How often should we schedule scans for this application?
- What are the latest vulnerability scanning tools for cloud environments?
- Can you provide examples of overlooked vulnerabilities in web applications?