What problem does it solve?
Security teams managing OT, IoT, and IoMT environments face a constant stream of Claroty xDome alerts and CVE findings that must be triaged, correlated, and dispositioned under change control. This Skill unifies alert and vulnerability triage into one workflow, computing blast radius, correlating with NVD CVE data, and enforcing ITSM gating on every write operation.
Core Features & Use Cases
- Alert Triage & Investigation: List and filter alerts by severity, status, site, or assignee, and retrieve an alert together with every affected device in a single call.
- Vulnerability Blast Radius: Filter CVE findings by CVSS score, list all devices affected by a specific vulnerability, and correlate with NVD for full CVSS vector decomposition.
- ITSM-Gated Write Actions: Acknowledge alerts, apply labels, assign owners, and mark CVEs as not-relevant per device, all requiring a valid ServiceNow change request (CHG) number.
- Use Case: During a ransomware hunt, an analyst lists open high-severity alerts at a warehouse site, labels them 'ransomware-candidate', assigns them to an investigator under CHG0013002, then pivots to the affected devices' CVE lists to assess combined risk.
Quick Start
Ask the agent to list all open high-severity Claroty alerts at a specific site and show every device each alert touches.