Turbine Schema Reference (VRM)
Turbine Schema was formerly known as Turbine Extensible Data Schema, or TEDS.
This document describes the Turbine Schema objects used by the Vulnerability Response Management (VRM) solution. For general concepts, best practices, and troubleshooting, see Working with Turbine SchemaWorking with Turbine Schema.
For VRM interface contracts, see VRM InterfacesVRM Interfaces. For general information about how interfaces work, see Working with InterfacesWorking with Interfaces.
Vulnerability Finding Object
The Vulnerability Finding object captures vulnerability scan results from vulnerability management tools (such as Tenable, Qualys, and Rapid7). It includes fields for vulnerability identification, severity scoring, exploit intelligence, asset context, and remediation tracking.
Name | Key | Type | Description |
|---|---|---|---|
Vulnerability ID | vulnerability-id | String | CVE or vendor-specific vulnerability identifier |
Vulnerability Description | vulnerability-description | String | Description of the vulnerability |
Vulnerability Status | vulnerability-status | String | Current status of the vulnerability (such as Open, Fixed, or Accepted) |
Vulnerability References | vulnerability-references | String | External references and advisories related to the vulnerability |
Vulnerability Published Date | vulnerability-published-date | String | Date the vulnerability was first published |
Vulnerability Last Modified Date | vulnerability-last-modified-date | String | Date the vulnerability record was last modified |
CVSS Base Score | vulnerability-cvss-base-score | Integer | Common Vulnerability Scoring System base score |
CVSS Temporal/Threat Score | vulnerability-cvss-temporal-threat-score | Integer | CVSS temporal or threat score reflecting current exploit activity |
CVSS Version | vulnerability-cvss-version | String | CVSS specification version used for scoring (such as 3.1 or 4.0) |
CVSS Vector String | vulnerability-cvss-vector-string | String | Full CVSS vector string describing the vulnerability characteristics |
EPSS Score | vulnerability-epss-score | Integer | Exploit Prediction Scoring System probability score |
EPSS Percentile | vulnerability-epss-percentile | Integer | EPSS percentile ranking relative to all scored vulnerabilities |
Weaknesses (CWEs) | vulnerability-weaknesses-(cwes) | String | Common Weakness Enumeration identifiers associated with the vulnerability |
Vulnerable CPEs | vulnerability-vulnerable-cpes | String | Common Platform Enumeration identifiers for affected products |
Related Attack Patterns | vulnerability-related-attack-patterns | String | Known attack patterns associated with the vulnerability |
Exploits | vulnerability-exploits | String | Known exploit details for the vulnerability |
Exploits Trending on GitHub | vulnerability-exploits-trending-on-github | String | Whether exploit code is currently trending on GitHub |
First Exploit Published | vulnerability-first-exploit-published | String | Date the first public exploit was published |
Max Exploit Maturity | vulnerability-max-exploit-maturity | String | Highest maturity level among known exploits (such as Proof of Concept, Functional, or Weaponized) |
Public Exploit Found | vulnerability-public-exploit-found | String | Whether a public exploit exists |
Commercial Exploit Found | vulnerability-commercial-exploit-found | String | Whether a commercial exploit tool is available |
Weaponized Exploit Found | vulnerability-weaponized-exploit-found | String | Whether a weaponized exploit exists |
Reported Exploited | vulnerability-reported-exploited | String | Whether the vulnerability has been reported as actively exploited |
Reported Exploitation | vulnerability-reported-exploitation | String | Details of reported exploitation activity |
Reported Exploited by Ransomware | vulnerability-reported-exploited-by-ransomware | String | Whether ransomware campaigns are exploiting this vulnerability |
Reported Exploited by Botnets | vulnerability-reported-exploited-by-botnets | String | Whether botnets are exploiting this vulnerability |
Reported Exploited by Threat Actors | vulnerability-reported-exploited-by-threat-actors | String | Whether known threat actor groups are exploiting this vulnerability |
In Known Exploited Vulnerabilities | vulnerability-in-known-exploited-vulnerabilities | String | Whether the vulnerability is in CISA Known Exploited Vulnerabilities catalog |
MITRE ATT&CK Techniques | vulnerability-finding-mitre-attack-techniques | String | MITRE ATT&CK techniques associated with the vulnerability finding |
Finding Unique ID | vulnerability-finding-unique-id | String | Unique identifier for this specific vulnerability finding instance |
Finding Grouping ID | vulnerability-finding-grouping-id | String | Identifier used to group related findings across scans |
Finding Summary | vulnerability-finding-summary | String | Summary description of the finding |
Finding Primary Asset Identifier | vulnerability-finding-primary-asset-identifier | String | Primary identifier for the asset where the vulnerability was found |
Finding Primary Asset Type | vulnerability-finding-primary-asset-type | String | Type of asset (such as Server, Workstation, or Network Device) |
Finding Hostnames | vulnerability-finding-hostnames | String Array | Hostnames associated with the finding |
Finding IP Addresses | vulnerability-finding-ip-addresses | String Array | IP addresses associated with the finding |
Finding MAC Addresses | vulnerability-finding-mac-addresses | String Array | MAC addresses associated with the finding |
Finding Sources | vulnerability-finding-sources | String Array | Vulnerability scanners or tools that reported this finding |
Finding Scan ID | vulnerability-finding-scan-id | String | Identifier of the scan that produced this finding |
Finding Scan Type | vulnerability-finding-scan-type | String | Type of scan performed (such as Authenticated, Unauthenticated, or Agent) |
Finding Raw Risk Score | vulnerability-finding-raw-risk-score | Integer | Risk score as reported by the source scanner |
Finding Turbine Risk Score | vulnerability-finding-turbine-risk-score | Integer | Normalized risk score calculated by Turbine |
Merged Risk Scores | merged-risk-scores | String | Combined risk scores from multiple scanners |
Finding Raw JSON | vulnerability-finding-raw-json | String | Raw JSON data from the source vulnerability scanner |
Finding Remediation | vulnerability-finding-remediation | String | Recommended remediation action for the vulnerability |
Finding Remediation Status | vulnerability-finding-remediation-status | String | Current status of remediation efforts |
Finding Remediation Owner | vulnerability-finding-remediation-owner | String | Party responsible for remediating the vulnerability |
Finding Last Ingested | vulnerability-finding-last-ingested | String | Timestamp when the finding was last ingested into Turbine |
Finding Last Enriched | vulnerability-finding-last-enriched | String | Timestamp when the finding was last enriched with threat intelligence |
Finding Exception Reason | vulnerability-finding-exception-reason | String | Reason for any exception applied to this finding |
Finding Exception Reference | vulnerability-finding-exception-reference | String Array | References to exception records |
Asset Zone | vulnerability-finding-asset-zone | String | Network zone where the affected asset resides |
Asset Reference | vulnerability-finding-asset-reference | String Array | References to asset records in the asset inventory |
Enriched Vulnerability Finding Object
The Enriched Vulnerability Finding extends the base Vulnerability Finding with additional asset-context fields populated during the enrichment phase. It includes all fields from the Vulnerability Finding object plus the following:
Name | Key | Type | Description |
|---|---|---|---|
Finding Asset Criticality | vulnerability-finding-asset-criticality | Integer | Business criticality rating of the asset where the vulnerability was found |
Finding Asset Zone Criticality | vulnerability-finding-asset-zone-criticality | Integer | Criticality rating of the network zone where the asset resides |
Finding Asset Remediation Channel | vulnerability-finding-asset-remedation-channel | String | Communication channel for reaching the remediation owner |
Finding Asset Remediation Owner | vulnerability-finding-asset-remedation-owner | String | Party responsible for vulnerability remediation on the asset |
Finding Asset Reference | vulnerability-finding-asset-reference | Array | References to the asset record in the asset inventory |
Finding Asset Zone | vulnerability-finding-asset-zone | String | Network zone of the asset |
Finding Unique ID Type | vulnerability-finding-unique-id-type | String | Type or scheme of the unique identifier |
Asset Object
The Asset object represents a managed asset in the asset inventory. It is used by the Asset to Tracking ID interface to look up or create remediation tracking records for assets.
Name | Key | Type | Description |
|---|---|---|---|
Primary Asset Identifier | primary-asset-identifier | String | Primary identifier for the asset |
Hostnames | hostnames | String Array | Hostnames associated with the asset |
IP Addresses | ip-addresses | String Array | IP addresses associated with the asset |
MAC Addresses | mac-addresses | String Array | MAC addresses associated with the asset |
Operating System | operating-system | String | Operating system installed on the asset |
Asset Owner | asset-owner | String | Email of the asset owner |
Asset Stakeholders | asset-stakeholders | String Array | Emails of all stakeholders responsible for the asset |
Asset Criticality | asset-criticality | Number | Business criticality rating of the asset |
Asset Zone | asset-zone | String | Network zone where the asset resides |
Asset Zone Criticality | assset-zone-criticality | Number | Criticality rating of the asset network zone |
Remediation Owner | remediation-owner | String | Email of the party responsible for vulnerability remediation on this asset |
Compensating Controls | asset-compensating-controls | String | Compensating controls applied to the asset |
Risk Scores | asset-risk-scores | Object | Aggregate risk scores for the asset |
SBOM | asset-sbom | String Array | Software bill of materials present on the asset |
Highest Risk Vulnerability Finding | highest-risk-vulnerability-finding | String | The vulnerability finding attached to the asset with the highest risk score |
Remediation Item Object
The Remediation Item object provides the input data for ITSM ticket creation and status checking. Two interfaces use this object:
Remediation Item to Ticket (ticket creation):
Name | Key | Type | Description |
|---|---|---|---|
Remediation Owner | remediation_owner | String | Party responsible for remediating the findings |
Remediation Channel | remediation_channel | String | Communication channel for reaching the remediation owner |
Remediation Item Tracking ID | remediation_item_tracking_id | String | Tracking ID of the remediation item record |
Outbound Message | outbound_message | String | Message to attach to the ITSM ticket |
Remediation Item Check (ticket status checking):
Name | Key | Type | Description |
|---|---|---|---|
Remediation Owner | remediation_owner | String | Party responsible for remediating the findings |
Remediation Channel | remediation_channel | String | Communication channel for reaching the remediation owner |
Remediation Item Tracking ID | remediation_item_tracking_id | String | Tracking ID of the remediation item record |
ITSM Ticket ID | itsm_ticket_id | String | Ticket ID in the remote or internal ITSM |
Ticket Object
The Ticket object represents the ITSM ticket data returned by remediation interfaces.
Remediation Item to Ticket output:
Name | Key | Type | Description |
|---|---|---|---|
Ticket ID | ticket_id | String | Ticket ID from the ITSM system |
Ticket Status | ticket_status | String | Status of the ticket (Open, Closed, or Error) |
Ticket Opened | ticket_opened | String | Timestamp when the ticket was opened |
Ticket Status Updated | ticket_status_updated | String | Timestamp when the ticket status was last updated |
Ticket Status Message | ticket_status_message | String | Message about the status of ticket creation |
Remediation Item Check output:
Name | Key | Type | Description |
|---|---|---|---|
Ticket Status | ticket_status | String | Current status of the ticket |
Ticket Status Updated | ticket_status_updated | String | Timestamp when the ticket status was last checked and updated |
Inbound Messages | inbound_messages | String | Replies or other inbound messages from the ITSM |
Example: Vulnerability Finding Object
{
"vulnerability_finding": {
"vulnerability-id": "CVE-2024-3400",
"vulnerability-description": "PAN-OS: OS Command Injection Vulnerability in GlobalProtect Gateway",
"vulnerability-status": "Open",
"vulnerability-published-date": "2024-04-12",
"vulnerability-last-modified-date": "2024-04-15",
"vulnerability-cvss-base-score": 10,
"vulnerability-cvss-temporal-threat-score": 9,
"vulnerability-cvss-version": "3.1",
"vulnerability-cvss-vector-string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"vulnerability-epss-score": 97,
"vulnerability-epss-percentile": 99,
"vulnerability-weaknesses-(cwes)": "CWE-77",
"vulnerability-vulnerable-cpes": "cpe:2.3:o:paloaltonetworks:pan-os:11.1.2:h3:*:*:*:*:*:*",
"vulnerability-max-exploit-maturity": "Weaponized",
"vulnerability-public-exploit-found": "Yes",
"vulnerability-weaponized-exploit-found": "Yes",
"vulnerability-reported-exploited": "Yes",
"vulnerability-reported-exploited-by-threat-actors": "UTA0218",
"vulnerability-in-known-exploited-vulnerabilities": "Yes",
"vulnerability-finding-unique-id": "vuln-finding-001",
"vulnerability-finding-primary-asset-identifier": "fw-gw-prod-01.example.com",
"vulnerability-finding-primary-asset-type": "Network Device",
"vulnerability-finding-hostnames": ["fw-gw-prod-01.example.com"],
"vulnerability-finding-ip-addresses": ["10.0.1.1"],
"vulnerability-finding-sources": ["Tenable.io"],
"vulnerability-finding-scan-type": "Authenticated",
"vulnerability-finding-raw-risk-score": 100,
"vulnerability-finding-turbine-risk-score": 98,
"vulnerability-finding-remediation": "Upgrade PAN-OS to 11.1.2-h3 or apply the hotfix",
"vulnerability-finding-remediation-status": "In Progress",
"vulnerability-finding-remediation-owner": "[email protected]",
"vulnerability-finding-last-ingested": "2026-03-29T10:00:00Z",
"vulnerability-finding-last-enriched": "2026-03-29T10:05:00Z",
"vulnerability-finding-asset-zone": "DMZ",
"vulnerability-finding-asset-reference": ["asset-fw-gw-prod-01"]
}
}Example: Enriched Vulnerability Finding Object
{
"finding": {
"vulnerability-id": "CVE-2024-3400",
"vulnerability-description": "PAN-OS: OS Command Injection Vulnerability in GlobalProtect Gateway",
"vulnerability-cvss-base-score": 10,
"vulnerability-epss-score": 97,
"vulnerability-finding-unique-id": "vuln-finding-001",
"vulnerability-finding-primary-asset-identifier": "fw-gw-prod-01.example.com",
"vulnerability-finding-turbine-risk-score": 98,
"vulnerability-finding-remediation-status": "In Progress",
"vulnerability-finding-asset-criticality": 10,
"vulnerability-finding-asset-zone-criticality": 9,
"vulnerability-finding-asset-remedation-owner": "[email protected]",
"vulnerability-finding-asset-remedation-channel": "Jira",
"vulnerability-finding-asset-zone": "DMZ",
"vulnerability-finding-asset-reference": ["asset-fw-gw-prod-01"]
}
}Example: Remediation Ticket Workflow
// Step 1: Create a ticket (Remediation Item to Ticket input)
{
"remediation_owner": "[email protected]",
"remediation_channel": "Jira",
"remediation_item_tracking_id": "RI-2026-0042",
"outbound_message": "Critical vulnerability CVE-2024-3400 on fw-gw-prod-01. Upgrade PAN-OS to 11.1.2-h3."
}
// Step 2: Ticket creation response (Remediation Item to Ticket output)
{
"ticket_id": "VULN-1234",
"ticket_status": "Open",
"ticket_opened": "2026-03-29T10:15:00Z",
"ticket_status_updated": "2026-03-29T10:15:00Z",
"ticket_status_message": "Ticket created successfully"
}
// Step 3: Check ticket status (Remediation Item Check input)
{
"remediation_owner": "[email protected]",
"remediation_channel": "Jira",
"remediation_item_tracking_id": "RI-2026-0042",
"itsm_ticket_id": "VULN-1234"
}
// Step 4: Status check response (Remediation Item Check output)
{
"ticket_status": "Closed",
"ticket_status_updated": "2026-03-30T14:30:00Z",
"inbound_messages": "Patch applied and verified. Vulnerability remediated."
}