FortiSOAR Knowledge Base
FortiSOAR: Security Orchestration and Response software provides innovative case management, automation, and orchestration. It pulls together all of an organization's tools, helps unify operations, and reduce alert fatigue, context switching, and the mean time to respond to incidents.
Parag
Staff
Staff
Article Id 220043

Summary - FortiSOAR has dedicated module for vulnerability management. Organisations having large setup of VM’s or infrastructure often run vulnerability scans and want to automate the process. The playbook process attached is capable of ingesting vulnerabilities at fixed schedule from Tenable.IO, extract assets, list vulnerabilities, filter them and send email to asset owners for patch management process.

Tasks achieved 

  • Filter assets with High and Critical Vulnerabilities
  • Develop a HTML table with High & Critical Vulnerabilities for email body.
  • Send email with High and Critical Vulnerabilities (at a fixed schedule)

Process-flow:

73b02ef914a94c79949434b1253a743a.png73b02ef914a94c79949434b1253a743a.png

Prerequisite

1. Install and configure Tenable.IO connector. (Should also work with Tenable security centre)
2. Install and configure Exchange for email
3. Use default ingestion playbook for tenable.io, Nessus or other scanner.

Contributors