Agent skill

Building Patch Tuesday Response Process

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Establish a repeatable operational process for triaging, testing, and deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL Server, Azure) via WSUS/SCCM within…

Apache-2.0Auto-check passedSecurity

Install Building Patch Tuesday Response Process

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-patch-tuesday-response-process -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills building-patch-tuesday-response-process --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/building-patch-tuesday-response-process .claude/skills/building-patch-tuesday-response-process && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
building-patch-tuesday-response-process
GitHub stars
34k
Token cost
~2.3k tokens
SKILL.md length
551 words
Files
8 (incl. scripts, references, assets)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Establish a repeatable operational process for triaging, testing, and deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL Server, Azure) via WSUS/SCCM within…

  • Works in 5 steps: Pre-Patch Tuesday Preparation (Monday… → Day-of Triage (Patch Tuesday) → Scan and Gap Analysis → …
  • Improving a monthly patch management workflow
  • SKILL.md covers Overview, When to Use, Prerequisites and Core Concepts, plus 4 more sections
  • Runs Python scripts from its folder; reaches msrc.microsoft.com

What it does

Building Patch Tuesday Response Process is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Establish a repeatable operational process for triaging, testing, and deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL Server, Azure) via WSUS/SCCM within risk-based remediation SLAs, from advisory review through validation. Use when building or improving a monthly patch management workflow or prioritizing which CVEs to remediate first.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Vulnerability scanning. It works with Microsoft Azure and Microsoft SQL Server. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Improving a monthly patch management workflow
  • Prioritizing which CVEs to remediate first

Example prompts

  • “/building-patch-tuesday-response-process”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Pre-Patch Tuesday Preparation (Monday before)
  2. Day-of Triage (Patch Tuesday)
  3. Scan and Gap Analysis
  4. Ring-Based Deployment Strategy
  5. Validation and Reporting

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • msrc.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Building Patch Tuesday Response Process loads about 2.3k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 103 tokens; SKILL.md has 551 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 551 words, ~2,343 tokens.

Download SKILL.mdSave it as .claude/skills/building-patch-tuesday-response-process/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
building-patch-tuesday-response-process
description
Establish a repeatable operational process for triaging, testing, and deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL Server, Azure) via WSUS/SCCM within risk-based remediation SLAs, from advisory review through validation. Use when building or improving a monthly patch management workflow or prioritizing which CVEs to remediate first.
domain
cybersecurity
subdomain
vulnerability-management
tags
patch-management, patch-tuesday, microsoft, wsus, sccm, vulnerability-remediation, windows-update
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
ID.RA-01, ID.RA-02, ID.IM-02, ID.RA-06
mitre_attack
T1190, T1203, T1068, T1210, T1588.006

Building Patch Tuesday Response Process

Overview

Microsoft releases security updates on the second Tuesday of each month ("Patch Tuesday"), addressing vulnerabilities across Windows, Office, Exchange, SQL Server, Azure services, and other products. In 2025, Microsoft patched over 1,129 vulnerabilities across the year -- an 11.9% increase from 2024 -- making a structured response process critical. The leading risk types include elevation of privilege (49%), remote code execution (34%), and information disclosure (7%). This skill covers building a repeatable Patch Tuesday response workflow from initial advisory review through testing, deployment, and validation.

When to Use

  • When deploying or configuring building patch tuesday response process capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Access to Microsoft Security Response Center (MSRC) update guide
  • Vulnerability management platform (Qualys VMDR, Rapid7, Tenable)
  • Patch deployment infrastructure (WSUS, SCCM/MECM, Intune, or third-party)
  • Test environment mirroring production configurations
  • Change management process (ITIL-based or equivalent)
  • Communication channels for cross-team coordination

Core Concepts

Patch Tuesday Timeline
DayActivityOwner
T+0 (Tuesday 10 AM PT)Microsoft releases patches and advisoriesMicrosoft
T+0 (Tuesday afternoon)Security team reviews advisories and triagesSecurity Ops
T+1 (Wednesday)Qualys/vendor scan signatures updatedVM Platform
T+1-T+2Emergency patches deployed for zero-daysIT Operations
T+2-T+5Test patches in staging environmentQA/IT Ops
T+5-T+7Deploy to Pilot group (5-10% of fleet)IT Operations
T+7-T+14Deploy to Production Ring 1 (servers)IT Operations
T+14-T+21Deploy to Production Ring 2 (workstations)IT Operations
T+21-T+30Validation scanning and compliance reportingSecurity Ops
Patch Categorization Framework
CategoryCriteriaResponse SLA
Zero-Day / ExploitedActive exploitation confirmed, CISA KEV listed24-48 hours
Critical RCECVSS >= 9.0, remote code execution, no auth required3-5 days
Critical with ExploitPublic exploit code or EPSS > 0.77 days
High SeverityCVSS 7.0-8.9, privilege escalation14 days
Medium SeverityCVSS 4.0-6.930 days
Low / InformationalCVSS < 4.0, defense-in-depthNext maintenance window
Show full SKILL.md (228 more words)Show less
Microsoft Product Categories to Monitor
CategoryProductsRisk Level
Windows OSWindows 10, 11, Server 2016-2025Critical
Exchange ServerExchange 2016, 2019, OnlineCritical
SQL ServerSQL 2016-2022High
Office SuiteMicrosoft 365, Office 2019-2024High
.NET Framework.NET 4.x, .NET 6-9Medium
Azure ServicesAzure AD, Entra ID, Azure StackHigh
Edge/BrowserEdge Chromium, IE modeMedium
Development ToolsVisual Studio, VS CodeLow

Workflow

Step 1: Pre-Patch Tuesday Preparation (Monday before)
Preparation Checklist:
  [ ] Confirm WSUS/SCCM sync schedules are active
  [ ] Verify test environment is available and current
  [ ] Review outstanding patches from previous month
  [ ] Confirm monitoring dashboards are operational
  [ ] Pre-stage communication templates
  [ ] Ensure rollback procedures are documented
  [ ] Verify backup jobs ran successfully on critical servers
Step 2: Day-of Triage (Patch Tuesday)
Triage Process:
  1. Monitor MSRC Update Guide (https://msrc.microsoft.com/update-guide)
  2. Review Microsoft Security Blog for advisory summaries
  3. Cross-reference with CISA KEV additions (same day)
  4. Check vendor advisories (Qualys, Rapid7, CrowdStrike analysis)
  5. Identify zero-day and actively exploited vulnerabilities
  6. Classify each CVE by severity and applicability
  7. Determine deployment rings and timeline for each patch
  8. Submit emergency change request for zero-day patches
  9. Communicate triage results to IT Operations and management
Step 3: Scan and Gap Analysis
python
# Post-Patch-Tuesday scan workflow
def run_patch_tuesday_scan(scanner_api, target_groups):
    """Trigger vulnerability scans after Patch Tuesday updates."""
    for group in target_groups:
        print(f"[*] Scanning {group['name']}...")
        scan_id = scanner_api.launch_scan(
            target=group["targets"],
            template="patch-tuesday-focused",
            credentials=group["creds"]
        )
        print(f"    Scan launched: {scan_id}")

    # Wait for scan completion, then generate report
    results = scanner_api.get_scan_results(scan_id)
    missing_patches = [r for r in results if r["status"] == "missing"]

    # Categorize by Patch Tuesday release
    current_month = [p for p in missing_patches
                     if p["vendor_advisory_date"] >= patch_tuesday_date]

    return {
        "total_missing": len(missing_patches),
        "current_month": len(current_month),
        "zero_day": [p for p in current_month if p.get("actively_exploited")],
        "critical": [p for p in current_month if p["cvss"] >= 9.0],
    }
Step 4: Ring-Based Deployment Strategy
Ring 0 - Emergency (0-48 hours):
    Scope:     Zero-day and actively exploited CVEs only
    Method:    Manual or targeted push (SCCM expedite)
    Targets:   Internet-facing servers, critical infrastructure
    Approval:  Emergency change, verbal CISO approval
    Rollback:  Immediate rollback if service degradation

Ring 1 - Pilot (Day 2-7):
    Scope:     All critical and high patches
    Method:    WSUS/SCCM automatic deployment
    Targets:   IT department machines, test group (5-10%)
    Approval:  Standard change with CAB notification
    Monitoring: 48-hour soak period, check for BSOD, app crashes

Ring 2 - Production Servers (Day 7-14):
    Scope:     All security patches
    Method:    SCCM maintenance windows (off-hours)
    Targets:   Production servers by tier
    Approval:  Standard change with CAB approval
    Monitoring: Application health checks, performance baseline

Ring 3 - Workstations (Day 14-21):
    Scope:     All security patches + quality updates
    Method:    Windows Update for Business / Intune
    Targets:   All managed workstations
    Approval:  Pre-approved standard change
    Monitoring: Help desk ticket monitoring for issues

Ring 4 - Stragglers (Day 21-30):
    Scope:     Catch remaining unpatched systems
    Method:    Forced deployment with restart
    Targets:   Systems that missed prior rings
    Approval:  Compliance-driven enforcement
Step 5: Validation and Reporting
Post-Deployment Validation:
  1. Re-scan environment with updated vulnerability signatures
  2. Compare pre-patch and post-patch scan results
  3. Calculate patch compliance rate per ring and department
  4. Identify failed patches and investigate root causes
  5. Generate compliance report for management review
  6. Update risk register with residual unpatched vulnerabilities
  7. Document exceptions and compensating controls

Best Practices

  1. Subscribe to MSRC notifications and vendor analysis blogs for early intelligence
  2. Maintain a dedicated Patch Tuesday war room or Slack/Teams channel
  3. Always patch zero-day vulnerabilities outside the normal ring schedule
  4. Test patches against critical business applications before broad deployment
  5. Track patch compliance metrics month-over-month for trend analysis
  6. Maintain rollback procedures for every deployment ring
  7. Coordinate with application owners for compatibility testing
  8. Document all exceptions with compensating controls and review dates

Common Pitfalls

  • Deploying all patches simultaneously without ring-based testing
  • Not scanning after patching to validate remediation
  • Treating all patches equally without risk-based prioritization
  • Ignoring cumulative update dependencies causing patch failures
  • Not accounting for server reboot requirements in maintenance windows
  • Failing to communicate patch status to business stakeholders
  • implementing-rapid7-insightvm-for-scanning
  • performing-cve-prioritization-with-kev-catalog
  • implementing-vulnerability-remediation-sla
  • implementing-patch-management-workflow

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/building-patch-tuesday-response-process of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Building Patch Tuesday Response Process next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Building Patch Tuesday Response Process compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Building Patch Tuesday Response Process this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Security Analysismicrosoft/haste107—~1kAutomated safety check: PassMIT
Recon Osinthypnguyen1209/offensive-claude386—~2.2kAutomated safety check: PassMIT
Remediate Image Cveskubernetes-sigs/cloud-provider-azure294—~3.9kAutomated safety check: PassApache-2.0
Agent BomLeoYeAI/openclaw-master-skills2.2k—~4.4kAutomated safety check: PassApache-2.0
Defender For Endpointvinayaklatthe/microsoft-security-skills175—~2.3kAutomated safety check: PassMIT

Similar skills

  • Security Analysis

    microsoft/haste

    Official

    Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.

    107 GitHub stars~1k tokensUpdated today
    SecurityAuto-check passed
  • Recon Osint

    hypnguyen1209/offensive-claude

    A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

    386 GitHub stars~2.2k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Remediate Image Cves

    kubernetes-sigs/cloud-provider-azure

    Official

    Orchestrate end-to-end CVE remediation for the Linux CCM, CNM, and health-probe-proxy images on cloud-provider-azure master or a release-X.Y branch, including builds, repeated Trivy verification…

    294 GitHub stars~3.9k tokensUpdated today
    SecurityAuto-check passed
  • Agent Bom

    LeoYeAI/openclaw-master-skills

    Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS…

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Defender For Endpoint

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation…

    175 GitHub stars~2.3k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Defender For Containers

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender for Containers — Kubernetes and container security across AKS, Azure Arc-enabled Kubernetes, EKS, GKE, and OpenShift.

    175 GitHub stars~2.1k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Building Patch Tuesday Response Process

What does Building Patch Tuesday Response Process do?

Establish a repeatable operational process for triaging, testing, and deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL Server, Azure) via WSUS/SCCM within…. Building Patch Tuesday Response Process is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Establish a repeatable operational process for triaging, testing, and deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL Server, Azure) via WSUS/SCCM within risk-based remediation SLAs, from advisory review through validation.

When should I use Building Patch Tuesday Response Process?

Building Patch Tuesday Response Process fits situations like: improving a monthly patch management workflow; prioritizing which CVEs to remediate first.

How do I install Building Patch Tuesday Response Process in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-patch-tuesday-response-process -a claude-code`. Or copy the skill folder (skills/building-patch-tuesday-response-process in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/building-patch-tuesday-response-process in your project. Claude Code loads it when a task matches its description.

How do I install Building Patch Tuesday Response Process in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-patch-tuesday-response-process -a codex`. Or copy the skill folder (skills/building-patch-tuesday-response-process in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/building-patch-tuesday-response-process in your project. Codex loads it when a task matches its description.

Can I use Building Patch Tuesday Response Process in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-patch-tuesday-response-process -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/building-patch-tuesday-response-process, .gemini/skills/building-patch-tuesday-response-process, .github/skills/building-patch-tuesday-response-process and .opencode/skills/building-patch-tuesday-response-process in your project.

What does Building Patch Tuesday Response Process need to run?

Going by SKILL.md and its folder, Building Patch Tuesday Response Process needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Building Patch Tuesday Response Process access the network?

SKILL.md names 1 domain. In commands or code: msrc.microsoft.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Building Patch Tuesday Response Process safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Building Patch Tuesday Response Process use?

Building Patch Tuesday Response Process is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Building Patch Tuesday Response Process use?

About 2.3k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Building Patch Tuesday Response Process?

Skills that share tags, products or a category with Building Patch Tuesday Response Process: Security Analysis (microsoft/haste, 107 stars), Recon Osint (hypnguyen1209/offensive-claude, 386 stars), Remediate Image Cves (kubernetes-sigs/cloud-provider-azure, 294 stars) and Agent Bom (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Building Patch Tuesday Response Process?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.