This workflow template assists organizations with Threat Intelligence Enrichment by automating the process of monitoring and reporting new entries in the NIST National Vulnerability Database (NVD). Upon triggering, it searches the NVD for new Common Vulnerabilities and Exposures (CVEs) since the last check and posts updates to a designated Slack channel, including impact details when available. Reference information for each CVE is threaded under the main Slack message, enhancing team awareness and facilitating a proactive response to emerging threats.
Optional Triggers
Schedule,Webhook
Use Cases
Threat Intelligence Enrichment
Workflow Breakdown
When triggered, search the NIST NVD for new CVEs since the last run
Update a Slack channel on all new CVEs that are found with CVE details including Impact if available
If CVE reference information is found, supply information in a thread
Vendors
Slack, Utils, Torq, NIST NVD
Workflow Output
Slack message with CVE details and reference information
Tips
Add additional steps or nested workflows to search for CVEs in other platforms