If we were to talk about best practices from a SanerNow POV, there’s no official documentation now. However, we can make use of the EM, RP and PA modules to gain further traction in combating Zero-Day and Critical vulnerabilities. Please refer to the blog below for additional information regarding SanerNow and Zero-Day Attacks. https://www.secpod.com/blog/custom-scripting-in-sanernow-to-remediate-zero-day-vulnerabilities/