SIEM CVE Workflow
Run the full SIEM CVE pipeline: fetch critical vulnerabilities, normalize an alert, and coordinate all agents through detection, enrichment, correlation, and incident response.
Execution Steps
Follow these steps in order. Coordinate with agents on AX-Platform per CLAUDE.md routing rules.
Step 1: Fetch Critical CVEs from NVD
Run from the project root (D:\AI_Agents\Agent_Teams\SIEM\Agents\SIEM_Security_Router_Agent):
mkdir -p artifacts/CVEs
python scripts/nvd_client.py severity --level CRITICAL --limit 20 > artifacts/CVEs/CriticalVulns_<TODAYS_DATE>.json
Format <TODAYS_DATE> as M-DD-YY (e.g., 2-18-26 for February 18, 2026). Use the current date.
Step 2: Select a CVE
Read the generated file at artifacts/CVEs/CriticalVulns_<TODAYS_DATE>.json.
Pick one CVE from the list that is:
- Recently published or modified
- Widely known or high-impact
- Has a high CVSS score (prefer 9.0+)
- Has rich data (affected products, references, KEV status)
Then fetch the full detail for the selected CVE:
python scripts/nvd_client.py --output nao-evidence cve --id <SELECTED_CVE_ID>
Step 3: Build a Normalized Alert Object (NAO)
Construct a NAO using the schema from claude.md. Populate it with:
alert_type:"vuln"severity:"critical"source:"NVD Vulnerability Scanner"entities: extracted from CVE data (affected products, IPs/domains if applicable)evidence: the NVD enrichment entry from Step 2summary: a concise description of the vulnerability and exposurerouting.assignee:"@SIEM_Threat_Hunter_Agent"routing.topic:"alerts"routing.needs_ticket:true
Use NVDClient.enrich_nao() to inject full CVE data into the NAO.
Step 4: Store Artifacts in AX
Save the following as AX context (use mcp__ax-platform__context):
- The full NAO under key
siem:alert:<alert_id> - The raw CVE enrichment under key
siem:cve:<cve_id>
Promote both to the vault for persistence.
Step 5: SecRouter Alert Routing (CLAUDE.md Step 1)
As SecRouter, post to AX messages:
- Announce the normalized alert with severity classification
- Tag
@SIEM_Intel-Fusion_Agentfor enrichment (CRITICAL severity routing) - Tag
@SIEM_Threat_Hunter_Agentfor correlation - Include alert_id and CVE ID in the message
Create an AX task assigned to @SIEM_Threat_Hunter_Agent.
Step 6: Intel Fusion Enrichment (Workflow Step 2)
Message @SIEM_Intel-Fusion_Agent with:
- The CVE ID and alert_id
- Request: IOC lookup, threat actor mapping, campaign association, confidence scoring
- Reference the AX context keys where data is stored
Wait for IntelFusion's response. Save their enrichment output as AX context under key siem:enrichment:<alert_id>.
Step 7: Threat Hunter Correlation (Workflow Step 3)
Message @SIEM_Threat_Hunter_Agent with:
- The enriched alert data
- Simulated follow-on events (synthetic behavioral indicators):
- Suspicious outbound connection from the vulnerable host
- Possible credential access attempt
- Lateral movement indicator
- Request: multi-event correlation, MITRE ATT&CK mapping, risk score assignment
Wait for ThreatHunterAI's response. If risk score > 75, proceed to Step 8.
Save correlation results as AX context under key siem:correlation:<alert_id>.
Step 8: Incident Response (Workflow Step 4)
If ThreatHunterAI assigns risk > 75:
Message @SIEM_Incident_Response_Agent with:
- Full incident context (alert + enrichment + correlation)
- Request: timeline reconstruction, incident classification, containment recommendations
- Remind: no destructive actions without human approval
Save the incident response as AX context under key siem:incident:<alert_id>.
Step 9: Summary Report
After all agents have responded, compile a summary:
- Alert ID and CVE
- Severity and risk score
- Enrichment highlights (threat actors, campaigns, KEV status)
- Correlation findings (MITRE techniques, behavioral indicators)
- Containment recommendations
- Timeline of agent coordination
Present this to the user as the workflow result.
Step 10: Save Report to Artifacts
Save the summary report as a markdown file:
artifacts/Reports/<ALERT_ID>_<TODAYS_DATE>.md
Format <TODAYS_DATE> as M-DD-YY (e.g., 2-18-26).
Example: artifacts/Reports/ALERT-20260218-001_2-18-26.md
Create the artifacts/Reports/ directory if it doesn't exist. The report should include:
- Alert ID, date, CVE, CVSS, KEV status, risk score, classification
- Pipeline execution table (all 4 agent stages and results)
- Attack chain with MITRE ATT&CK mapping
- Impacted assets
- Intel Fusion enrichment summary
- Containment recommendations
- AX context keys for all stored artifacts
- Current status (e.g., awaiting human approval)
Workflow Reference
The full workflow specification is at:
D:\AI_Agents\Agent_Teams\SIEM\Agents\SIEM_Security_Router_Agent\artifacts\Workflows\SIEM_CVE_Workflow.md
Agent Routing Rules
Per claude.md, CRITICAL severity requires:
- Create AX task assigned to
@SIEM_Threat_Hunter_Agent - Save all artifacts as context
- Tag
@SIEM_Incident_Response_Agent - Tag
@SIEM_Intel-Fusion_Agent