VRM Playbooks and Components
Use this reference to identify the playbooks, flows, and reusable components included in the VRM solution.
Choose Your Path
Goal | Go To |
|---|---|
Review core enrichment, case, and remediation flows | |
Review ingestion and export flows | |
Review scheduled reporting flows | |
Find reusable automation logic |
Solution Playbooks
Solution Playbook | Purpose |
|---|---|
VRM - Vulnerability Response Management | Runs finding enrichment, scoring, exceptions, grouping, cases, remediation, IT service management synchronization, and automation-health checks. |
VRM - Utilities | Imports assets and findings, creates and processes ingestion pages, and maintains known-finding exports. |
VRM - Reporting | Creates reporting records for assets, exceptions, findings, and remediation items. |
How Playbooks and Components Connect
Use this map to identify the playbook flow, supporting components, required records or configuration, and resulting VRM record for each workflow stage.
Stage | Primary Flows | Major Components | Dependencies | Result |
|---|---|---|---|---|
Finding ingestion | Ingest CSV (Button), Ingestion Page to Enrichment Pipeline, or Ingest Vulnerability Finding via Webhook | Write CSV Ingestion Pages, VRM - Map Raw JSON to TEDS Findings, VRM - Inbound Findings Filter, and Filter - Remove Known Findings | VRM - CSV Import, VRM - Ingestion Page, and the current known-finding export | Normalized findings submitted to the enrichment pipeline |
Asset ingestion and association | Ingest Asset CSV, Write Assets, and Update Findings from Asset | VRM - Map Asset to Finding, VRM - Update Enrichment with Found Asset, and VRM - Calculate Asset Metadata | Asset identifiers, criticality, zone, owner, and remediation channel | Vulnerability Asset records and associated finding context |
Finding enrichment | Enrichment Pipeline, Swimlane Intelligence Retrieval, and Re-Enrich Finding | VRM - Enrich - Vulnerability, VRM - Calculate Turbine Risk Score, VRM - Manage - Vulnerability Exceptions, and VRM - Write - Create/Update Vulnerability Finding | Normalized finding, asset context, vulnerability intelligence, and active exceptions | Created or updated Vulnerability Finding record |
Grouping and case creation | Case Creation, Manual Case Creation, and Create New Case | VRM - Automate Grouping, VRM - Automated Vulnerability Finding Grouping, and VRM - Update Case With Highest Risk Score | Eligible findings, grouping configuration, and finding risk scores | Vulnerability Case Management record linked to grouped findings |
Remediation and ticketing | Create Remediation Items, automatic or manual ticket creation, and Check ITSM Ticket Status | VRM - Create Remediation Items, VRM - Route and Submit Ticket to ITSM, and VRM - Update Findings With Ticket Status | Case, grouped findings, remediation owner, remediation channel, and ITSM configuration | Vulnerability Remediation Item and synchronized ticket status |
Reporting | Asset Reporting, Exceptions Reporting, Findings Reporting, and Remediation Items Reporting | Get Application Fields Schema and VRM - Calculate Reporting Metrics | Turbine Tenant Credentials and operational application data | VRM - Reporting records used by reporting dashboards |
Use component names to locate the action that produced an output or error in a playbook run. Configure documented assets and workflow settings rather than modifying packaged components unless the component is identified as a supported customization point.
Core VRM Playbook Flows
The VRM - Vulnerability Response Management playbook contains the following flows.
Flow | Trigger | Purpose |
|---|---|---|
Ingest Vulnerability Finding via Webhook | Sensor | Receives a finding and emits it to the standard finding-processing flow. |
Enrichment Pipeline | Flow event | Extends, deduplicates, maps, enriches, scores, checks exceptions, groups, and writes a vulnerability finding. |
Swimlane Intelligence Retrieval | Subflow | Retrieves vulnerability metadata and exploit data for supported vulnerability identifiers and updates the finding. |
Re-Enrich Finding | Button or subflow | Runs enrichment, risk scoring, exceptions, grouping, finding writing, and asset metadata refresh again. |
Close Finding | Flow event | Deduplicates the closure request and writes the resolved finding state. |
Case Creation | Schedule | Finds automatically grouped findings and creates the required cases. |
Manual Case Creation | Record event | Assigns a temporary random group ID when an analyst starts manual case creation. |
Manual Case Creation - Case Tracking ID updated | Record event | Replaces the temporary group ID after the new case receives its tracking ID. |
Create New Case | Button or subflow | Creates a case and updates selected findings with the case tracking ID. |
Case Tracking-ID Changed | Record event | Updates finding status when the finding becomes associated with a case. |
Update Case Risk Score | Button or subflow | Sets one case to the highest risk score among its associated findings. |
Update Case Risk Scores | Schedule | Recalculates risk scores for open cases. |
Create Remediation Items | Button or subflow | Creates remediation work from a case and its grouped findings. |
Automatically Create ITSM Ticket | Record event | Routes and submits an eligible remediation item automatically. |
Manually Create ITSM Ticket | Button or subflow | Routes and submits a remediation item after a user initiates the action. |
Check ITSM Ticket Status | Schedule | Finds stale open remediation items and retrieves current ticket status. |
Close ITSM Ticket | Button or subflow | Updates the remediation item when external ticket work is closed. |
Update Finding/Case Status from Remediation Item | Record event | Propagates remediation ticket state to associated findings and the parent case. |
Calculate Asset Risk Scores | Schedule | Processes stale assets and recalculates aggregate asset risk. |
Update Findings from Asset | Record event | Propagates relevant asset changes to associated open findings. |
Save Finding SLA Calculated Fields | Record event | Calculates and saves finding SLA values and related timestamps. |
Update Requires Attention Flag: Asset | Record event | Evaluates missing or invalid asset data and updates Requires Attention. |
Update Requires Attention Flag: Case | Record event | Evaluates case automation state and updates Requires Attention. |
Update Requires Attention Flag: Finding | Record event | Evaluates finding data and processing state and updates Requires Attention. |
Update Requires Attention Flag: Remediation Item | Record event | Evaluates remediation routing and ticket state and updates Requires Attention. |
Utility Playbook Flows
The VRM - Utilities playbook contains the following flows.
Flow | Trigger | Purpose |
|---|---|---|
Ingest CSV (Button) | Button or subflow | Creates ingestion pages from a finding CSV attachment. |
Write Ingestion Page | Flow event | Creates one ingestion page record and its JSON page file. |
Process Ingestion Page Records | Schedule | Selects queued ingestion pages and submits each page for conversion and enrichment. |
Ingestion Page to Enrichment Pipeline | Flow event | Filters raw findings, maps them to the Turbine Schema, and submits each finding to enrichment. |
Ingest Asset CSV | Button or subflow | Reads, maps, and pages asset CSV rows. |
Write Assets | Flow event | Creates or updates normalized assets from one submitted page. |
Generate Fresh Export | Record event | Creates a current known-finding export and marks prior exports stale. |
Reporting Playbook Flows
The VRM - Reporting playbook contains the following scheduled flows.
Flow | Purpose |
|---|---|
Asset Reporting | Queries asset fields and metrics and writes asset reporting records. |
Exceptions Reporting | Queries exception fields and metrics and writes exception reporting records. |
Findings Reporting | Queries finding fields and metrics and writes finding reporting records. |
Remediation Items Reporting | Queries remediation item fields and metrics and writes remediation reporting records. |
Configure the Turbine Tenant Credentials
Component Reference
Components are grouped by the workflow stage they support.
Remediation and Ticketing Components
Component | Purpose |
|---|---|
VRM - Create Remediation Items | Creates remediation item records from a case and grouped findings. |
VRM - Automate Remediation | Starts remediation automatically for findings configured for automated grouping and remediation. |
VRM - Route and Submit Ticket to ITSM | Selects the configured remediation route and submits the ticket. |
VRM - Submit Ticket to Turbine ITSM | Creates a ticket through the default Turbine remediation path. |
VRM - Check ITSM Ticket Status VRM - Check Ticket Status | Retrieves current status for open external tickets. |
VRM - Get Remediation Status from Turbine | Retrieves remediation status from the default internal ticket path. |
VRM - Update Findings With Ticket Status | Propagates ticket status to associated findings. |
VRM - Update Vulnerability Response Record | Updates the parent case from remediation results. |
Grouping and Case Components
Component | Purpose |
|---|---|
VRM - Automate Grouping | Evaluates grouping settings and prepares related findings for case creation. |
VRM - Automated Vulnerability Finding Grouping | Groups findings by configured criteria and promotes eligible groups to cases. |
VRM - Update Case With Highest Risk Score | Sets case risk to the highest score among associated findings. |
Generate Random Group ID | Creates a temporary group identifier for manual case creation. |
Update Group ID From Case Tracking ID | Replaces a temporary grouping value with the created case tracking ID. |
Finding Enrichment and Risk Components
Component | Purpose |
|---|---|
VRM - Extend Vulnerability Finding Schema | Adds solution-specific objects to the normalized finding. |
VRM - Enrich - Vulnerability | Enriches supported vulnerability identifiers with Swimlane Intelligence data. |
VRM - Calculate Turbine Risk Score | Calculates the combined finding risk score from vulnerability and asset factors. |
VRM - Manage - Vulnerability Exceptions VRM - Manage - Vulnerability Exceptions (Reprocess Finding) | Finds applicable active exceptions and applies the correct finding state. The reprocess variant supports finding re-enrichment. |
VRM - Identify - Deduplicate Finding | Identifies an existing finding before create or update operations. |
VRM - Write - Create/Update Vulnerability Finding | Creates a new finding or updates the matching existing finding. |
VRM - Re-Enrich Update Finding | Writes finding changes produced by a re-enrichment run. |
Asset and Normalization Components
Component | Purpose |
|---|---|
VRM - Map Raw JSON to TEDS Findings | Maps scanner-specific source fields to the Turbine Schema vulnerability finding format. |
VRM - Normalize - TEDS Vulnerability Finding | Provides the normalization stage for TEDS vulnerability findings. |
VRM - Map Asset to Finding | Finds the associated asset by primary identifier, MAC address, hostname, or IP address. |
VRM - Update Enrichment with Found Asset | Adds asset context to the finding being enriched. |
VRM - Calculate Asset Metadata | Calculates asset risk and metadata from current findings. |
Refresh Asset Metadata | Refreshes stored asset metadata after finding changes. |
Ingestion and Filtering Components
Component | Purpose |
|---|---|
Write CSV Ingestion Pages | Divides finding CSV data into ingestion pages. |
VRM - Get Findings CSV Export | Retrieves the current known-finding export or generates a replacement. |
VRM - Inbound Findings Filter | Coordinates comparison of incoming findings with known findings. |
Filter - Remove Known Findings | Removes findings already present in the known-finding export and applies exclusions. |
Reporting Components
Component | Purpose |
|---|---|
Get Application Fields Schema | Retrieves application field metadata used to map reporting queries. |
VRM - Calculate Reporting Metrics | Calculates metric values from reporting query results. |
Trace a Workflow
When troubleshooting a record:
- Identify the application and current record status.
- Find the corresponding stage in Vulnerability Response Management WorkflowsVulnerability Response Management Workflows.
- Locate the responsible solution playbook and flow in this reference.
- Review the flow run and the component action that produced the current state.
- Check Requires Attention, the supporting status message, and the relevant utility application for processing errors.
Next Steps
- Use Installing and ConfiguringInstalling and Configuring for solution and integration setup.
- Use VRM Applications and DashboardsVRM Applications and Dashboards to identify the records affected by each flow.
- Use Monitoring Ingestion and EnrichmentMonitoring Ingestion and Enrichment to review ingestion operations.