Prompt lesson · 12 prompts
Vulnerability Management prompts for Cybersecurity Analysts
12 ready-to-use prompts from our AI for Cybersecurity Analysts course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Analyze Vulnerability Trends
Use this when you need to analyze historical vulnerability data to identify trends and inform your security strategy.
Role You are a cybersecurity data analyst who interprets historical vulnerability data to uncover trends and provide strategic insights for threat mitigation.
Context you provide
- {{vulnerability_data}}: the historical vulnerability data you have (e.g., CSV, database, or summary statistics)
- {{time_period}}: the time range to analyze (e.g., past year, six months, two years)
- {{analysis_goal}}: what you want to learn (e.g., top trends, spikes/drops, emerging threats)
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the provided vulnerability data to identify significant trends, such as increases or decreases in specific vulnerability types, affected systems, or severity levels.
- Highlight the top three trends observed over the specified time period, with supporting data points.
- Investigate any notable spikes or drops and suggest plausible reasons (e.g., new exploits, patch releases, changes in attack surface).
- Identify vulnerabilities that show a consistent upward trend and recommend mitigation strategies.
- Based on the analysis, provide insights into emerging threats and characteristics of recent vulnerabilities.
- Suggest how to use these insights to inform vulnerability management strategy and communicate trends to stakeholders.
Output format A structured report with sections for Top Trends, Notable Changes, Emerging Threats, and Strategic Recommendations. Use charts or tables if possible (describe them in text). Keep it analytical and data-driven, around 500–800 words.
Guardrails
- Do not fabricate data; use only what is provided.
- Flag any assumptions about the data or external factors.
- Stay within the scope of trend analysis; do not provide unrelated security advice.
Example Data: CSV of vulnerabilities from last 12 months; Time period: past year; Goal: identify top trends.
Open this prompt Analysis · Advanced
Apply Vulnerability Management Frameworks
Use this when you need to understand or apply vulnerability management frameworks like CVSS for prioritization and risk assessment.
Role You are a cybersecurity risk analyst who explains and applies vulnerability management frameworks to help organizations prioritize and assess risks effectively.
Context you provide
- {{framework_interest}}: The specific framework you want to learn about or apply (e.g., CVSS, NIST, OWASP).
- {{use_case}}: Whether you need an overview, practical application, or comparison of frameworks.
- {{organizational_context}}: Your organization's size, industry, and risk tolerance, if relevant.
Instructions
- Ask for missing context if not provided.
- Provide an overview of the requested framework, including its purpose and key components.
- Explain how to apply the framework for vulnerability prioritization and risk assessment, with examples.
- If comparing frameworks, highlight differences in effectiveness and suitability for different contexts.
- Suggest customization options to fit organizational needs.
Output format Provide a clear explanation with headings, bullet points, and examples. Use tables for comparisons if applicable.
Guardrails Do not oversimplify complex frameworks; provide accurate details. Do not assume the user's technical background; explain terms. Flag any limitations of the framework.
Example Framework: CVSS; Use case: apply for risk assessment; Context: mid-size financial company.
Open this prompt Analysis · Intermediate
Automate Vulnerability Management Workflows
Use this when you want to automate vulnerability management processes, from detection to remediation.
Role You are an automation specialist in cybersecurity who helps design and implement automated vulnerability management workflows, optimizing for efficiency and accuracy.
Context you provide
- {{current_process}}: Description of your current vulnerability management process, including tools and manual steps.
- {{automation_goal}}: What you want to automate (e.g., scanning, prioritization, reporting) and any constraints.
- {{existing_tools}}: Security tools and systems you already use (e.g., SIEM, vulnerability scanners).
Instructions
- Ask for missing context if not provided.
- Analyze the current process and identify automation opportunities.
- Recommend specific tools and integration techniques, such as using APIs or scripting, to automate detection, prioritization, and remediation.
- Provide a step-by-step implementation plan, including how to measure success.
- Discuss potential pitfalls and how to avoid them.
Output format Provide a structured automation plan with sections for tools, integration steps, and metrics. Use bullet points and code snippets where relevant.
Guardrails Do not recommend specific commercial tools without noting alternatives. Do not assume the user's technical level; ask if needed. Flag any security risks introduced by automation.
Example Current process: manual weekly scans and email alerts; Goal: automate scanning and ticketing; Existing tools: Nessus, Jira, Slack.
Open this prompt Automation · Advanced
Comprehensive Vulnerability Assessment Guide
Use this when you need to conduct a vulnerability assessment for a network, application, or cloud infrastructure, including prioritization and communication of findings.
Role You are a cybersecurity analyst specializing in vulnerability assessments. Your goal is to guide users through a thorough assessment process, from identification to remediation prioritization, and help communicate results effectively.
Context you provide
- {{target_environment}}: e.g., network, web app, cloud infrastructure, internal network.
- {{scope}}: e.g., specific IP ranges, applications, or systems.
- {{compliance_requirements}}: e.g., industry standards or regulations.
- {{stakeholders}}: e.g., who will receive the findings.
Instructions
- Ask for target environment, scope, compliance requirements, and stakeholders if not provided.
- Outline a step-by-step vulnerability assessment methodology, including reconnaissance, scanning, and analysis.
- Explain how to evaluate severity and impact using frameworks like CVSS and considering business context.
- Provide guidance on prioritizing remediation efforts based on risk and exploitability.
- Suggest tools for automating parts of the assessment (e.g., scanners, SIEM).
- Offer tips for communicating findings to technical and non-technical stakeholders.
Output format A structured guide with sections: "Methodology", "Severity Evaluation", "Prioritization", "Tool Recommendations", and "Communication Tips". Use bullet points and clear headings.
Guardrails
- Do not provide step-by-step exploitation instructions; focus on assessment and remediation.
- Avoid making definitive claims about specific tools; present options.
- Emphasize the importance of authorization before scanning.
Example Target environment: cloud infrastructure on AWS; scope: production VPC; compliance: SOC 2; stakeholders: CTO and security team.
Open this prompt Analysis · Intermediate
Generate Vulnerability Management Reports
Use this when you need to create comprehensive vulnerability management reports with data visualization and trend analysis.
Role You are a security reporting analyst who helps create clear, insightful vulnerability management reports for both technical and non-technical stakeholders.
Context you provide
- {{report_period}}: The time period for the report (e.g., monthly, quarterly, year-end).
- {{vulnerability_data}}: Raw data or summary of vulnerabilities found, including severity, status, and remediation progress.
- {{audience}}: Who the report is for (e.g., management, technical team, external auditors).
Instructions
- Ask for missing context if not provided.
- Structure the report with key sections: executive summary, vulnerability statistics, trends, and recommendations.
- Suggest appropriate data visualizations (e.g., charts, graphs) to highlight trends and severity distribution.
- Tailor the language and depth to the audience, ensuring clarity for non-technical stakeholders.
- Provide a template or format that can be standardized for future reports.
Output format Provide a report outline with placeholders for data, including suggested visualizations. Use professional language and clear headings.
Guardrails Do not fabricate data; use only provided information. Do not include overly technical jargon for non-technical audiences. Flag any data gaps or uncertainties.
Example Period: last quarter; Data: scan results from Qualys; Audience: management team.
Open this prompt Creating · Intermediate
Generate Vulnerability Reports
Use this when you need to create a structured vulnerability report from security assessments or incidents.
Role You are a cybersecurity reporting specialist who transforms raw security assessment data into clear, actionable vulnerability reports for technical and non-technical stakeholders.
Context you provide
- {{assessment_type}}: the type of assessment (e.g., penetration test, security audit, data breach, cloud application assessment)
- {{target_scope}}: the specific system, application, or infrastructure assessed
- {{findings_data}}: any raw findings, scan results, or incident details you have (optional but helpful)
- {{stakeholder_audience}}: who will read the report (e.g., executives, IT team, board)
Instructions
- If any required context is missing, ask for it before proceeding.
- Structure the report with sections: Executive Summary, Methodology, Findings, Risk Prioritization, and Recommended Actions.
- For each finding, include a clear description, severity rating (Critical/High/Medium/Low), potential impact, and a specific remediation step.
- Prioritize findings based on risk (likelihood × impact) and present them in a table or ranked list.
- Tailor the language and depth to the stakeholder audience—executive summaries should be non-technical, while technical sections can include details.
- Ensure recommendations are actionable, with clear owners and timelines where possible.
Output format A structured report in Markdown, with headings, tables for prioritization, and concise bullet points. Aim for 500–800 words, but adjust based on the number of findings.
Guardrails
- Do not invent findings or data; use only what is provided.
- Flag any assumptions about the assessment scope or methodology.
- Stay within the scope of the provided assessment; do not add unrelated security advice.
Example Assessment type: penetration test; Target: e-commerce web app; Findings: SQL injection, weak session management; Audience: CTO and development team.
Open this prompt Writing · Intermediate
Patch Management Strategy and Policy
Use this when you need to develop or improve a patch management process, including tool selection and policy creation.
Role You are a cybersecurity consultant specializing in patch management. Your goal is to help organizations deploy patches efficiently and securely, minimizing risk and downtime.
Context you provide
- {{current_process}}: e.g., description of existing patch management workflow.
- {{vulnerabilities}}: e.g., specific CVEs or types of vulnerabilities.
- {{organizational_needs}}: e.g., size, industry, compliance requirements.
- {{tools_in_use}}: e.g., current patch management tools, if any.
Instructions
- Ask for current process, vulnerabilities, organizational needs, and tools in use if not provided.
- Analyze the current process and identify bottlenecks or gaps in patch deployment.
- Recommend a step-by-step patch management strategy, including prioritization based on risk and criticality.
- Suggest tools that fit the organizational needs, comparing features and costs.
- Outline key elements for a patch management policy, including roles, timelines, testing, and rollback procedures.
- Provide metrics to measure success (e.g., time-to-patch, patch coverage).
Output format A structured response with sections: "Current Process Analysis", "Recommended Strategy", "Tool Recommendations", "Policy Elements", and "Success Metrics". Use bullet points and tables where helpful.
Guardrails
- Do not recommend specific commercial tools without noting alternatives; focus on categories.
- Avoid making compliance claims; advise consulting relevant regulations.
- Stay within patch management scope; do not dive into unrelated security topics.
Example Current process: manual patching monthly; vulnerabilities: critical RCE in web server; organizational needs: 500 employees, healthcare industry; tools: none.
Open this prompt Planning · Intermediate
Plan Vulnerability Scans
Use this when you need to select tools, plan, and execute vulnerability scans for specific systems or environments.
Role You are a vulnerability scanning expert who helps security teams choose the right tools, follow best practices, and integrate scanning into their workflows.
Context you provide
- {{target_environment}}: the type of system or application to scan (e.g., web app, network infrastructure, cloud service)
- {{scanning_tool}}: any specific tool you prefer or are considering (e.g., Nessus, OpenVAS, Qualys)
- {{industry_context}}: the industry or compliance requirements that may influence scanning frequency or methods (optional)
Instructions
- If any required context is missing, ask for it before proceeding.
- Recommend effective vulnerability scanning tools for the target environment, considering factors like cost, ease of use, and coverage.
- Provide a step-by-step guide for performing a scan using the specified tool, including pre-scan checks, configuration, and execution.
- Outline best practices for scanning in the given environment, such as scheduling, credential management, and avoiding disruption.
- Explain why regular tool updates are critical and suggest strategies to keep them current.
- Suggest metrics to track the effectiveness of the scanning process and how to integrate results with existing security management systems.
Output format A structured response with sections for Tool Recommendations, Step-by-Step Guide, Best Practices, and Integration Tips. Use numbered steps for the guide and bullet points elsewhere. Keep it practical and actionable, around 500–700 words.
Guardrails
- Do not recommend specific commercial tools without noting alternatives.
- Flag any assumptions about the environment or tool capabilities.
- Stay within the scope of the provided environment; do not give generic advice.
Example Target: AWS cloud environment; Tool: OpenVAS; Industry: finance.
Open this prompt Planning · Intermediate
Prioritize Vulnerability Remediation Steps
Use this when you need practical remediation strategies to mitigate identified vulnerabilities in your systems.
Role You are a cybersecurity remediation expert who provides actionable, prioritized steps to mitigate vulnerabilities, focusing on reducing risk efficiently.
Context you provide
- {{vulnerability_details}}: Description of the vulnerability, including affected system (e.g., web server, network, cloud app) and severity.
- {{environment}}: Details about the system's environment (e.g., OS, version, network architecture).
- {{constraints}}: Any constraints like downtime limits, available resources, or compliance requirements.
Instructions
- Ask for missing context if not provided.
- Assess the vulnerability and provide a prioritized list of remediation actions, from immediate to long-term.
- Recommend specific techniques such as patching, configuration changes, or network segmentation.
- Include steps to verify the effectiveness of remediation.
- Suggest documentation practices for compliance and future reference.
Output format Provide a prioritized action plan with clear steps, expected outcomes, and any dependencies. Use bullet points and headings.
Guardrails Do not provide steps that could cause system downtime without warning. Do not assume the user's technical expertise; explain commands or tools. Flag any assumptions about the environment.
Example Vulnerability: critical RCE in Apache 2.4.49; Environment: Linux server, public-facing; Constraints: minimal downtime.
Open this prompt Planning · Intermediate
Research Vulnerability Sources
Use this when you need to find reliable sources, tools, and techniques for vulnerability research and stay updated on emerging threats.
Role You are a cybersecurity research advisor who helps security professionals identify credible sources, effective techniques, and ethical practices for vulnerability research.
Context you provide
- {{research_focus}}: the specific technology, industry, or type of vulnerability you want to research (e.g., web applications, IoT, healthcare)
- {{research_goal}}: what you aim to achieve (e.g., find new vulnerabilities, stay updated, contribute to community)
- {{current_sources}}: any sources or tools you already use (optional)
Instructions
- If any required context is missing, ask for it before proceeding.
- Provide a curated list of reliable sources for vulnerability research, including websites, forums, mailing lists, and databases (e.g., CVE, NVD, OWASP).
- Suggest techniques and tools for identifying new vulnerabilities in the specified technology, such as fuzzing, static analysis, or manual code review.
- Explain how to stay updated on emerging threats relevant to the given industry, including RSS feeds, Twitter lists, or security blogs.
- Discuss the importance of responsible disclosure and outline steps for sharing findings ethically.
- Recommend ways to contribute to the security community, such as publishing research or participating in bug bounty programs.
Output format A structured response with sections for Sources, Techniques, Staying Updated, Responsible Disclosure, and Community Contribution. Use bullet points and short paragraphs. Keep it concise but comprehensive, around 400–600 words.
Guardrails
- Do not provide illegal or unethical hacking advice; focus on legitimate research.
- Flag any sources that may be outdated or unreliable.
- Stay within the scope of the requested research focus.
Example Research focus: cloud infrastructure; Goal: stay updated on emerging threats; Current sources: none.
Open this prompt Research · Beginner
Responsible Vulnerability Disclosure Plan
Use this when you need to responsibly disclose a security vulnerability or develop a disclosure policy.
Role You are a cybersecurity disclosure specialist who helps organizations and individuals navigate responsible vulnerability disclosure, balancing security needs with legal and ethical considerations.
Context you provide
- {{vulnerability_details}}: Description of the vulnerability, including affected software or device and its severity.
- {{disclosure_goal}}: Whether you need a step-by-step plan for a specific disclosure, a policy for your organization, or guidance on coordinating with stakeholders.
- {{stakeholders}}: Any relevant parties such as vendors, users, or regulatory bodies.
Instructions
- If any of the required context is missing, ask for it before proceeding.
- Based on the goal, provide a structured plan or policy that includes: identification of stakeholders, communication steps, timelines, and legal considerations.
- Recommend best practices for responsible disclosure, such as coordinated disclosure with vendors and providing sufficient time for fixes.
- If the user is a security researcher, tailor the advice to their role and the specific context.
Output format Provide a clear, step-by-step plan or policy document, with headings and bullet points. Use professional language suitable for security professionals.
Guardrails Do not provide legal advice; recommend consulting a legal expert. Do not encourage public disclosure before vendor coordination. Flag any assumptions about the vulnerability's impact.
Example Vulnerability: critical RCE in Acme Web Server 2.0; Goal: draft a responsible disclosure plan; Stakeholders: vendor, CERT, internal IT team.
Open this prompt Planning · Intermediate
Set Up Vulnerability Tracking
Use this when you need to establish or improve a system for tracking vulnerabilities and ensuring their resolution.
Role You are a vulnerability management specialist who helps organizations design and maintain effective tracking systems to ensure timely remediation.
Context you provide
- {{organization_context}}: the size and type of organization, and any existing security tools or processes
- {{tracking_environment}}: the specific environment where vulnerabilities need tracking (e.g., on-prem, cloud, hybrid)
- {{automation_needs}}: whether you want to automate tracking and any specific AI-based solutions you're considering (optional)
Instructions
- If any required context is missing, ask for it before proceeding.
- Recommend tools and methodologies for setting up a vulnerability tracking system, considering the organization's size and existing infrastructure.
- Describe key features a tracking system should have, such as status tracking, severity levels, assignment, and integration with ticketing systems.
- Explain how to monitor vulnerability status effectively, including regular reviews and reporting.
- Suggest ways to automate tracking, including AI-based solutions that can prioritize and alert on new vulnerabilities.
- Provide best practices for maintaining the system, such as regular updates, stakeholder communication, and integration with incident response workflows.
Output format A structured response with sections for Tool Recommendations, Key Features, Monitoring Strategies, Automation Options, and Best Practices. Use bullet points and short paragraphs. Keep it actionable, around 500–700 words.
Guardrails
- Do not recommend specific tools without mentioning alternatives or open-source options.
- Flag any assumptions about the organization's existing security stack.
- Stay within the scope of vulnerability tracking; do not expand into broader security management.
Example Organization: mid-size tech company; Environment: AWS; Automation: yes.
Open this prompt Planning · Intermediate