# Siem Cve Workflow

> Use this skill when the user asks to "run CVE workflow", "simulate CVE scenario", "test SIEM pipeline", "run siem_cve_workflow", or wants to execute the full SIEM CVE detection-to-response workflow. Fetches critical CVEs from NVD, creates a Normalized Alert Object, and coordinates all four SIEM agents through the complete pipeline.

- Skill: `michaelschecht/siem-cve-workflow` (Agent Skill)
- Install (CLI): `npx skillmds@latest add michaelschecht/siem-cve-workflow`
- Raw SKILL.md: https://api.skillmd.com/api/skills/michaelschecht/siem-cve-workflow/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: michaelschecht (https://skillmd.com/u/michaelschecht)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/michaelschecht/siem-cve-workflow

---


# SIEM CVE Workflow

Run the full SIEM CVE pipeline: fetch critical vulnerabilities, normalize an alert, and coordinate all agents through detection, enrichment, correlation, and incident response.

## Execution Steps

Follow these steps in order. Coordinate with agents on AX-Platform per CLAUDE.md routing rules.

### Step 1: Fetch Critical CVEs from NVD

Run from the project root (`D:\AI_Agents\Agent_Teams\SIEM\Agents\SIEM_Security_Router_Agent`):

```bash
mkdir -p artifacts/CVEs
python scripts/nvd_client.py severity --level CRITICAL --limit 20 > artifacts/CVEs/CriticalVulns_<TODAYS_DATE>.json
```

Format `<TODAYS_DATE>` as `M-DD-YY` (e.g., `2-18-26` for February 18, 2026). Use the current date.

### Step 2: Select a CVE

Read the generated file at `artifacts/CVEs/CriticalVulns_<TODAYS_DATE>.json`.

Pick one CVE from the list that is:
- Recently published or modified
- Widely known or high-impact
- Has a high CVSS score (prefer 9.0+)
- Has rich data (affected products, references, KEV status)

Then fetch the full detail for the selected CVE:

```bash
python scripts/nvd_client.py --output nao-evidence cve --id <SELECTED_CVE_ID>
```

### Step 3: Build a Normalized Alert Object (NAO)

Construct a NAO using the schema from `claude.md`. Populate it with:
- `alert_type`: `"vuln"`
- `severity`: `"critical"`
- `source`: `"NVD Vulnerability Scanner"`
- `entities`: extracted from CVE data (affected products, IPs/domains if applicable)
- `evidence`: the NVD enrichment entry from Step 2
- `summary`: a concise description of the vulnerability and exposure
- `routing.assignee`: `"@SIEM_Threat_Hunter_Agent"`
- `routing.topic`: `"alerts"`
- `routing.needs_ticket`: `true`

Use `NVDClient.enrich_nao()` to inject full CVE data into the NAO.

### Step 4: Store Artifacts in AX

Save the following as AX context (use `mcp__ax-platform__context`):
- The full NAO under key `siem:alert:<alert_id>`
- The raw CVE enrichment under key `siem:cve:<cve_id>`

Promote both to the vault for persistence.

### Step 5: SecRouter Alert Routing (CLAUDE.md Step 1)

As SecRouter, post to AX messages:
- Announce the normalized alert with severity classification
- Tag `@SIEM_Intel-Fusion_Agent` for enrichment (CRITICAL severity routing)
- Tag `@SIEM_Threat_Hunter_Agent` for correlation
- Include alert_id and CVE ID in the message

Create an AX task assigned to `@SIEM_Threat_Hunter_Agent`.

### Step 6: Intel Fusion Enrichment (Workflow Step 2)

Message `@SIEM_Intel-Fusion_Agent` with:
- The CVE ID and alert_id
- Request: IOC lookup, threat actor mapping, campaign association, confidence scoring
- Reference the AX context keys where data is stored

Wait for IntelFusion's response. Save their enrichment output as AX context under key `siem:enrichment:<alert_id>`.

### Step 7: Threat Hunter Correlation (Workflow Step 3)

Message `@SIEM_Threat_Hunter_Agent` with:
- The enriched alert data
- Simulated follow-on events (synthetic behavioral indicators):
  - Suspicious outbound connection from the vulnerable host
  - Possible credential access attempt
  - Lateral movement indicator
- Request: multi-event correlation, MITRE ATT&CK mapping, risk score assignment

Wait for ThreatHunterAI's response. If risk score > 75, proceed to Step 8.

Save correlation results as AX context under key `siem:correlation:<alert_id>`.

### Step 8: Incident Response (Workflow Step 4)

If ThreatHunterAI assigns risk > 75:

Message `@SIEM_Incident_Response_Agent` with:
- Full incident context (alert + enrichment + correlation)
- Request: timeline reconstruction, incident classification, containment recommendations
- Remind: no destructive actions without human approval

Save the incident response as AX context under key `siem:incident:<alert_id>`.

### Step 9: Summary Report

After all agents have responded, compile a summary:
- Alert ID and CVE
- Severity and risk score
- Enrichment highlights (threat actors, campaigns, KEV status)
- Correlation findings (MITRE techniques, behavioral indicators)
- Containment recommendations
- Timeline of agent coordination

Present this to the user as the workflow result.

### Step 10: Save Report to Artifacts

Save the summary report as a markdown file:

```bash
artifacts/Reports/<ALERT_ID>_<TODAYS_DATE>.md
```

Format `<TODAYS_DATE>` as `M-DD-YY` (e.g., `2-18-26`).
Example: `artifacts/Reports/ALERT-20260218-001_2-18-26.md`

Create the `artifacts/Reports/` directory if it doesn't exist. The report should include:
- Alert ID, date, CVE, CVSS, KEV status, risk score, classification
- Pipeline execution table (all 4 agent stages and results)
- Attack chain with MITRE ATT&CK mapping
- Impacted assets
- Intel Fusion enrichment summary
- Containment recommendations
- AX context keys for all stored artifacts
- Current status (e.g., awaiting human approval)

## Workflow Reference

The full workflow specification is at:
`D:\AI_Agents\Agent_Teams\SIEM\Agents\SIEM_Security_Router_Agent\artifacts\Workflows\SIEM_CVE_Workflow.md`

## Agent Routing Rules

Per `claude.md`, CRITICAL severity requires:
1. Create AX task assigned to `@SIEM_Threat_Hunter_Agent`
2. Save all artifacts as context
3. Tag `@SIEM_Incident_Response_Agent`
4. Tag `@SIEM_Intel-Fusion_Agent`

