Runbook Index

Turn Vuln Signal into repeatable operating paths.

Use this page when you know the situation but want a clear route through triage, evidence, handoff, tracking, and reporting without guessing which page comes next.

Use the smallest route that matches the situation

Runbooks are for repeatable work. If you are learning, use Learn or Coach first. If you are responding, start with the situation that is closest.

New learner

Do not start here

Runbooks assume you know the basic vocabulary. Start with Learn or Coach first.

Learn basicsCoach

Daily work

Use the daily operating path

Best when you need a calm morning routine for current vulnerability pressure.

Daily Workflow

Incident-like pressure

Use urgent CVE or SOC paths

Best when exploitation, exposure, public PoC, or owner urgency is driving the day.

Urgent pathSOC path

Site/app cleanup

Use maintainer routes

Best when the work is QA, generated artifacts, app contract, release health, or content governance.

Quality CenterDiagnostics

Runbook rule: start with the smallest path that answers the decision. Open deeper pages only when you need proof, owner handoff, detection support, or leadership reporting.

Runbooks

8situation-first paths for common work

Workflow lanes

8shared intake-to-reference route map

Cadences

4daily, weekly, incident, monthly rhythms

Owners

5patch, SOC, asset, risk, leadership

Output

Cleardecision, evidence, ticket, brief, review

Use runbooks for situations, Workflows for roaming

Open Workflows

Situation-first

Use this index when the problem already has a shape: urgent CVE, patch blocked, scanner noise, SOC request, leadership update, training session, program improvement, or data trust question.

Scenario Library

Lane-first

Use Workflows when you want to move through intake, validation, decision, action, communication, governance, practice, or reference without memorizing page names.

WorkflowsSite Map

Term-first

Use Search when you only know a CVE, vendor, source, product, weak signal, or phrase. Search now marks lane-aware page results where a workflow fit is known.

Search

Choose the closest runbook and follow the path

Open Scenario Library

Use the right rhythm for the work

Open Daily Workflow

Daily 10-minute triage

Briefing Room, Defenders Today, KEV, and Saved. Output: top decisions, immediate blockers, and owners.

Daily Workflow

Daily practice warmup

Coach, Daily Challenge, Guided Practice, and Practice Report. Output: one safe practice route, local progress, and a next learning target.

CoachDaily Challenge

Weekly patch review

Patch Watch, Patch Window, Exception Register, Vendor Analytics, and Action Tracker. Output: patch plan, blockers, and time-bound exceptions.

Patch WatchException Register

Incident hot path

Decision Matrix, Evidence Checklist, Detection Starter Pack, Handoff Center, and Status. Output: fast owner-aligned actions.

Decision Matrix

Monthly maturity review

Operational Readiness, Maturity Model, Quality Center, Status static health, Coverage Map, and Release Notes. Output: one focused improvement batch with release-health evidence.

Maturity ModelStatic Health

Know what artifact you are trying to produce

Decision lane

Patch now, patch soon, mitigate first, detect, validate, monitor, escalate, or accept. Use Decision Matrix.

Open matrix

Evidence note

A compact proof set for exposure, affected version, source confidence, fixed version, and owner context. Use Evidence Checklist.

Open checklist

Owner handoff

A short copy-ready message for patch, SOC, asset, risk, vendor, or leadership owner. Use Stakeholder Matrix and Handoff Center.

Stakeholder MatrixOpen handoffs

Tracked follow-up

A saved item with state, note, owner, deadline, review date, closure evidence, and evidence-quality grade. Use Saved, Action Tracker, Remediation Evidence, and Evidence Quality.

Track workClosure proofEvidence quality

Leadership brief

A plain-English update about what changed, what is owned, what is blocked, and what decision is needed. Use Brief Builder.

Build brief

Practice report

A browser-local summary of practice runs, guided routes, focus lanes, badges, and next recommendation. Use Practice Report.

Open reportProgress

Improvement item

A focused quality or maturity action that prevents the same problem next time. Use Quality Center, Status static health, the release-health brief, and Maturity Model.

Improve workflowStatic Health

Best next move: if you are unsure where to begin, open Daily Workflow for today, Scenario Library for the situation, Coach for safe practice, or Quality Center if the site itself needs tightening.