> For the complete documentation index, see [llms.txt](https://davin-hong3.gitbook.io/d/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davin-hong3.gitbook.io/d/incident-response-playbook/vulnerability-response-playbook.md).

# Vulnerability Response Playbook

High-level process to urgent and high-priority vulnerabilities being actively exploited in the wild

Most vulnerabilities will have common vulnerabilities and exposures (CVE) descriptors. In other cases, agencies might encounter new vulnerabilities that do not yet have a CVE (e.g., zero-days) or vulnerabilities resulting from misconfigurations.

<figure><img src="https://2068334946-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fow1iM27u7disHeJiSlBC%2Fuploads%2FI7wYi2Hb9V56A2m3mK55%2Fimage.png?alt=media&amp;token=7b1489f6-efab-4510-8109-05372cbc0e0b" alt=""><figcaption></figcaption></figure>

#### Identification

Proactively identify reports of vulnerabilities in the wild being actively exploited by monitoring threat feeds and info sources

#### Evaluation

* A sweep for known IOCs associated with exploitation of the vulnerability.
* Investigation of any abnormal activity associated with vulnerable systems or services, including anomalous access attempts and behavior.
* Begin IR reponse if vulnerability is being exploited in environment

#### Remediation

* Patch management --> patch all vulnerabilities
* Disable unused services
* Reconfigure firewalls to block access to known IOCs
* Increasing monitoring (Alert levels)
