[
  {
    "slug": "aristaeus-threat-to-board",
    "name": "Aristaeus Consulting: Threat-to-Board Playbook",
    "author": "aristaeus-consulting",
    "github_url": "https://github.com/jtbuchanan-tenb/aristaeus-playbook",
    "description": "Delivers a continuously-updated security program maturity score with board-ready reporting, powered by live threat intelligence and exposure data mapped against NIST CSF and CIS Controls v8.",
    "license": "Proprietary",
    "tier": "contributed",
    "tags": [
      "security-program-maturity",
      "nist-csf",
      "cis-controls",
      "board-reporting",
      "threat-intelligence",
      "exposure-management"
    ],
    "integrations": [
      "Tenable",
      "Anthropic"
    ],
    "date_added": "2026-06-25T00:00:00.000Z",
    "visibility": "example",
    "playbook_type": "sponsored",
    "agents_used": [
      {
        "name": "Daily Threat Intelligence Briefing",
        "role": "Gathers the day's threat landscape from tiered open-source intelligence and correlates active exploits against the customer's Tenable environment",
        "type": "exchange",
        "ref": "skills/threat-intel-daily"
      },
      {
        "name": "Remediation Priority & Impact Agent",
        "role": "Prioritizes what to fix today using Tenable exposure scores, confirmed exploitation status, and MITRE ATT&CK attack-path positioning",
        "type": "exchange",
        "ref": "skills/remediation-priority-impact-agent"
      },
      {
        "name": "Tenable ATT&CK Mapper",
        "role": "Maps the full vulnerability surface to MITRE ATT&CK techniques, producing a scored coverage heatmap that reveals exploitable-but-undetected gaps",
        "type": "exchange",
        "ref": "mcp-servers/tenable-attack-mapper"
      },
      {
        "name": "Aristaeus Maturity Advisor",
        "role": "Ingests tactical outputs from upstream agents and maps them against NIST CSF and CIS Controls v8 to produce a quantified maturity score with gap analysis",
        "type": "vendor",
        "ref": "https://github.com/jtbuchanan-tenb/aristaeus-playbook/blob/main/aristaeus-maturity-advisor.md"
      },
      {
        "name": "Aristaeus Program Intelligence",
        "role": "Provides historical trending, peer benchmarking, and automated executive report generation via a hosted MCP server with persistent data layer",
        "type": "vendor",
        "ref": "https://github.com/jtbuchanan-tenb/aristaeus-playbook/blob/main/aristaeus-program-intelligence.md"
      },
      {
        "name": "CISO Review & Board Briefing",
        "role": "Human checkpoint — CISO reviews maturity findings, approves narrative framing, and delivers board-ready briefing with Aristaeus-generated supporting materials",
        "type": "info"
      }
    ],
    "logo": "https://raw.githubusercontent.com/jtbuchanan-tenb/aristaeus-playbook/main/aristaeus-agentic-ai-consulting-logo.png",
    "url": "https://exchange.tenable.com/playbooks/aristaeus-threat-to-board"
  },
  {
    "slug": "chokepoint-remediation-playbook",
    "name": "Chokepoint Remediation Playbook",
    "author": "tarhou",
    "github_url": "https://github.com/tarhou/chokepoint-finder-playbook",
    "description": "An eight-stage remediation chain from thousands of findings to a handful of proven fixes, with a human checkpoint before every external mutation and a runner that enforces the contract offline.",
    "license": "MIT",
    "tier": "contributed",
    "tags": [
      "vuln-management",
      "exposure-management",
      "remediation",
      "change-management",
      "human-in-the-loop",
      "verification",
      "claude-code"
    ],
    "integrations": [
      "AWS",
      "Tenable"
    ],
    "date_added": "2026-08-05T00:00:00.000Z",
    "contribution_agreement_date": "2026-08-05T02:04:27.000Z",
    "last_reviewed": "2026-08-05T00:00:00.000Z",
    "works_with_tenable_hexa_mcp": false,
    "playbook_type": "standard",
    "agents_used": [
      {
        "name": "Chokepoint Finder",
        "role": "Carries the loop end to end: collapses findings into shared fixes, ranks them, gates unsafe targets, and holds no external write tools.",
        "type": "exchange",
        "ref": "agents/chokepoint-finder"
      },
      {
        "name": "Chokepoint Finder MCP Server",
        "role": "Provides the typed tools the chain binds to: ingest, rank, pre-flight, plan hashing, execution accounting and verification.",
        "type": "exchange",
        "ref": "mcp-servers/chokepoint-finder-mcp"
      },
      {
        "name": "Chokepoint Finder Skill",
        "role": "The portable, dependency-free form of the same ranking method, for operators who run the chain without the MCP server.",
        "type": "exchange",
        "ref": "skills/chokepoint-finder-skill"
      },
      {
        "name": "Tenable MCP Server (Tenable One)",
        "role": "Read-only collection of findings and asset context, and the authoritative re-scan the verification stage diffs against.",
        "type": "exchange",
        "ref": "mcp-servers/tenable-mcp-server"
      },
      {
        "name": "AWS MCP Server (Agent Toolkit for AWS)",
        "role": "Read-only cloud posture collection, and the execution path for approved cloud changes under the operator's own credentials.",
        "type": "info",
        "ref": "https://docs.aws.amazon.com/agent-toolkit/latest/userguide/mcp-server.html"
      }
    ],
    "url": "https://exchange.tenable.com/playbooks/chokepoint-remediation-playbook"
  },
  {
    "slug": "knowbe4-phisher-email-analysis",
    "name": "KnowBe4 PhishER Email Analysis",
    "author": "disassembledd",
    "github_url": "https://github.com/disassembledd/knowbe4-phisher-email-analysis",
    "description": "Agent-empowered n8n workflow that pulls outstanding reported emails from PhishER for AI-driven analysis, tagging, and comment submission.",
    "license": "MIT",
    "tier": "contributed",
    "tags": [
      "knowbe4",
      "phisher",
      "email-analysis",
      "n8n"
    ],
    "integrations": [
      "KnowBe4"
    ],
    "date_added": "2026-07-01T00:00:00.000Z",
    "playbook_type": "n8n",
    "workflow_diagram": "flowchart LR\n  A[Scheduled Trigger] --> B[Retrieve Messages]\n  B --> C[Filter Unresolved]\n  C --> D[AI Email Analysis]\n  D --> E[Post Comment]\n  D --> F[Apply Tag]\n",
    "url": "https://exchange.tenable.com/playbooks/knowbe4-phisher-email-analysis"
  },
  {
    "slug": "the-hounds-navi-agents",
    "name": "The Hounds — navi-agents",
    "author": "packetchaos",
    "github_url": "https://github.com/packetchaos/the-hounds-repo",
    "description": "The executable harness for The Hounds — a local console that runs the exposure-management agent pack over Tenable navi.",
    "license": "MIT",
    "tier": "contributed",
    "tags": [
      "tenable",
      "exposure-management",
      "navi",
      "playbook",
      "python",
      "console",
      "vulnerability-management"
    ],
    "integrations": [
      "Tenable",
      "Anthropic"
    ],
    "date_added": "2026-07-15T00:00:00.000Z",
    "contribution_agreement_date": "2026-07-15T18:28:19.000Z",
    "last_reviewed": "2026-07-17T00:00:00.000Z",
    "playbook_type": "standard",
    "agents_used": [
      {
        "name": "Laelaps",
        "role": "Finds and tags CISA KEV (known exploited) exposure.",
        "type": "info"
      },
      {
        "name": "Certania",
        "role": "Tracks certificate expiry and weak crypto.",
        "type": "info"
      },
      {
        "name": "Heimdall",
        "role": "Assesses post-quantum readiness.",
        "type": "info"
      },
      {
        "name": "Fenrir",
        "role": "Chains signals into ranked attack paths (foothold to crown jewel).",
        "type": "info"
      },
      {
        "name": "Cerberus",
        "role": "Confidence-scored IoT / OT / embedded device discovery.",
        "type": "info"
      },
      {
        "name": "Pythia",
        "role": "Discovers and governs AI/ML inventory across five sources.",
        "type": "info"
      },
      {
        "name": "Atlas",
        "role": "Establishes asset ownership.",
        "type": "info"
      },
      {
        "name": "Mimir",
        "role": "Software inventory.",
        "type": "info"
      },
      {
        "name": "Charon",
        "role": "Flags end-of-life / unsupported software.",
        "type": "info"
      },
      {
        "name": "Anubis",
        "role": "Calibrates Asset Criticality Rating (ACR).",
        "type": "info"
      },
      {
        "name": "Chronos",
        "role": "Scan health monitoring.",
        "type": "info"
      },
      {
        "name": "Sirius",
        "role": "Agent group analysis.",
        "type": "info"
      },
      {
        "name": "Garmr",
        "role": "Tag removal and cleanup.",
        "type": "info"
      },
      {
        "name": "Orthrus",
        "role": "Maps findings to MITRE ATT&CK.",
        "type": "info"
      },
      {
        "name": "Argus",
        "role": "Custom application discovery.",
        "type": "info"
      },
      {
        "name": "Argos",
        "role": "Single-asset deep-dive.",
        "type": "info"
      },
      {
        "name": "Sphinx",
        "role": "'On the Scent' environment overview.",
        "type": "info"
      },
      {
        "name": "Covenant",
        "role": "Enforces the AI Contract governance policy.",
        "type": "info"
      }
    ],
    "url": "https://exchange.tenable.com/playbooks/the-hounds-navi-agents"
  },
  {
    "slug": "the-hounds-pack-playbook",
    "name": "The Hounds — Pack Playbook",
    "author": "packetchaos",
    "github_url": "https://github.com/packetchaos/the-hounds-harness",
    "description": "A skill-packaged playbook for The Hounds — 18 exposure-management specialists that hunt, tag, and calibrate risk over Tenable navi.",
    "license": "MIT",
    "tier": "contributed",
    "tags": [
      "tenable",
      "exposure-management",
      "navi",
      "playbook",
      "claude-skills",
      "asset-tagging",
      "vulnerability-management"
    ],
    "integrations": [
      "Tenable",
      "Anthropic"
    ],
    "date_added": "2026-07-15T00:00:00.000Z",
    "contribution_agreement_date": "2026-07-15T18:28:14.000Z",
    "last_reviewed": "2026-07-17T00:00:00.000Z",
    "playbook_type": "standard",
    "agents_used": [
      {
        "name": "Laelaps",
        "role": "Finds and tags CISA KEV (known exploited) exposure.",
        "type": "info"
      },
      {
        "name": "Certania",
        "role": "Tracks certificate expiry and weak crypto.",
        "type": "info"
      },
      {
        "name": "Heimdall",
        "role": "Assesses post-quantum readiness.",
        "type": "info"
      },
      {
        "name": "Fenrir",
        "role": "Chains signals into ranked attack paths (foothold to crown jewel).",
        "type": "info"
      },
      {
        "name": "Cerberus",
        "role": "Confidence-scored IoT / OT / embedded device discovery.",
        "type": "info"
      },
      {
        "name": "Pythia",
        "role": "Discovers and governs AI/ML inventory across five sources.",
        "type": "info"
      },
      {
        "name": "Atlas",
        "role": "Establishes asset ownership.",
        "type": "info"
      },
      {
        "name": "Mimir",
        "role": "Software inventory.",
        "type": "info"
      },
      {
        "name": "Charon",
        "role": "Flags end-of-life / unsupported software.",
        "type": "info"
      },
      {
        "name": "Anubis",
        "role": "Calibrates Asset Criticality Rating (ACR).",
        "type": "info"
      },
      {
        "name": "Chronos",
        "role": "Scan health monitoring.",
        "type": "info"
      },
      {
        "name": "Sirius",
        "role": "Agent group analysis.",
        "type": "info"
      },
      {
        "name": "Garmr",
        "role": "Tag removal and cleanup.",
        "type": "info"
      },
      {
        "name": "Orthrus",
        "role": "Maps findings to MITRE ATT&CK.",
        "type": "info"
      },
      {
        "name": "Argus",
        "role": "Custom application discovery.",
        "type": "info"
      },
      {
        "name": "Argos",
        "role": "Single-asset deep-dive.",
        "type": "info"
      },
      {
        "name": "Sphinx",
        "role": "'On the Scent' environment overview.",
        "type": "info"
      },
      {
        "name": "Covenant",
        "role": "Enforces the AI Contract governance policy.",
        "type": "info"
      }
    ],
    "url": "https://exchange.tenable.com/playbooks/the-hounds-pack-playbook"
  }
]