Pull-Based Monitoring Checklist Template

Structured checklist for weekly and monthly pull-based OSINT monitoring. This template supports the Module 5 workflow.

Download: Monitoring Checklist Template (Word) – includes checkboxes, finding log tables, and cycle summary tracking.

NRECA Example: NRECA Monitoring Checklist (Word) – pre-filled example showing what a completed checklist looks like.

Instructions: Copy this template and customize the queries, baseline references, and finding criteria for your organization. Use the checklist format during each monitoring cycle to ensure consistent execution.


Weekly Monitoring Checklist

Target time: Under 30 minutes Schedule: Every [day] Owner: [name]

Checks ordered by OT relevance – remote access and edge device checks first.

Check 1: Shodan/Censys Remote Access Review

Date New Findings Classification Action Taken
       

OT-relevant finding: Any change to VPN login page, new port on firewall management IP, version change on edge device. Version downgrade or unexpected service warrants immediate investigation.

Expected noise: Minor HTTP header changes, certificate renewals on same service.


Check 2: CISA KEV Review

Date New KEV Entries Match to Inventory Priority Action Taken
    Yes/No P0-P3  

OT-relevant finding: Any KEV entry matching a product/vendor in your asset inventory. P0 if the asset is internet-exposed.


Check 3: Certificate Transparency

Date New Subdomains Classification Action Taken
       

OT-relevant finding: New subdomains suggesting remote access (vpn, ras, remote*), new OT-adjacent applications, or shadow IT.

Expected noise: Certificate renewals for existing subdomains (same name, new serial).


Check 4: Breach Database

Date Personnel Affected Breach Name Data Exposed Priority Action Taken
           

OT-relevant finding: Tier 1 or Tier 2 personnel in new breach with password/hash exposure.


Check 5: Alert Backlog Processing

Date Items in Backlog Items Closed Items Escalated
       

Rule: No item remains in backlog longer than one week.


Check 6: Baseline Update

Date Section Updated Change Description
     

Monthly Monitoring Checklist

Target time: 60-90 minutes Schedule: [first Monday / last Friday] Owner: [name]

Check 1: Full Subdomain Re-enumeration (20 min)

Date New Subdomains Removed Subdomains Service Changes Action Taken
         

Check 2: Deep Shodan/Censys Scan (15 min)

Date New Services Changed Services Action Taken
       

Check 3: Vulnerability Re-correlation (20 min)

Date New CVEs KEV Changes Priority Updates Action Taken
         

Check 4: Personnel Exposure Refresh (15 min)

Date New Breaches Personnel Changes Action Taken
       

Check 5: Alert Configuration Review (10 min)

Date Alerts Verified Changes Made
     

Cycle Summary

Complete this section at the end of each monitoring cycle.

Cycle Date Type Total Findings P0/P1 Baseline Updates Time Spent Analyst
  Weekly          
  Monthly