| name | performing-ot-vulnerability-assessment-with-claroty |
| description | Use when this skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for comprehensive asset discovery, risk scoring, vulnerability correlation, and remediation prioritization. It addresses passive vulnerability identification through traffic analysis, active safe querying of OT devices, integration with CVE databases and ICS-CERT advisories, and risk-based prioritization that accounts for operational impact and compensating controls. |
| domain | cybersecurity |
| tags | ["ot-security","ics","scada","industrial-control","iec62443","vulnerability-assessment","claroty"] |
| subdomain | ot-ics-security |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","DE.CM-01","ID.AM-05","GV.OC-02"] |
Performing Ot Vulnerability Assessment With Claroty
Overview
Cybersecurity skill for performing ot vulnerability assessment with claroty. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"performing ot vulnerability assessment with claroty"
-
"This skill covers performing vulnerability assessments in OT environments using "
-
When conducting scheduled OT vulnerability assessments per IEC 62443 or NERC CIP requirements
-
When deploying Claroty xDome for the first time and performing initial asset discovery and risk assessment
-
When correlating newly published ICS-CERT advisories against your OT asset inventory
-
When prioritizing OT vulnerability remediation with limited maintenance windows
-
When generating compliance evidence for CIP-010-4 vulnerability assessment requirements
Do not use for active vulnerability scanning of PLCs and safety systems (see performing-ot-network-security-assessment for passive approaches), for IT-only vulnerability management (see standard vulnerability scanners), or for penetration testing (see performing-ics-penetration-testing).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Claroty xDome or CTD (Continuous Threat Detection) deployed with sensors on OT network
- Network SPAN/TAP access for passive asset discovery
- CISA ICS-CERT advisory subscription for vulnerability tracking
- Asset inventory with firmware versions for all OT devices
- Change management process for patch deployment during maintenance windows
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def () -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}