‹ 首页

deep-dive-ioc

@dandye · 收录于 5 天前 · 上游提交 3 个月前

Perform exhaustive analysis of a critical IOC. Use when an IOC needs Tier 2+ investigation beyond basic enrichment - includes GTI pivoting, deep SIEM searches, correlation with related entities, and threat attribution. For escalated IOCs requiring comprehensive investigation.

适合你,如果需要对IOC进行深入调查和威胁归因

/ 通过 npx 安装 校验哈希
npx oh-my-skill add dandye/ai-runbooks/deep-dive-ioc
/ 通过 bash 安装
curl -fsSL https://oh-my-skill.com/install.sh | bash -s -- dandye/ai-runbooks/deep-dive-ioc
/ 已经装过?验证本机副本,不用重装
npx oh-my-skill verify dandye/ai-runbooks/deep-dive-ioc
安装目标可用 --agent / --scope 或 --to 明确指定;省略时只会在唯一已存在的 agent 目录上自动选择,零命中或多命中会停止并提示。content_hash 缺失或不一致均拒装。
119GitHub stars
~780上下文体积 · 单文件
索引托管

怎么用

商店整理自技能原文 · 版本 086cbf6 · 表述以原文为准
它做什么

对单个关键IOC(IP、域名、哈希或URL)进行深入的威胁情报分析。它会查询GTI报告、进行威胁实体关联、搜索SIEM事件、关联相关告警与案件,最终输出综合报告及行动建议。

什么时候触发

当IOC需要Tier2+级深度调查(超越基础富化),或由Tier1升级、或在调查中识别出关键IOC时触发。

装好后可以这样说
触发指定IP的完整分析流程。
对哈希进行GTI查询、行为分析和SIEM搜索。
技能原文 SKILL.md作者撰写 · Apache-2.0 · 086cbf6

Deep Dive IOC Analysis Skill

Perform exhaustive analysis of a single, potentially critical Indicator of Compromise escalated from Tier 1 or identified during an investigation.

Inputs
  • IOC_VALUE - The IOC to analyze (IP, domain, hash, or URL)
  • IOC_TYPE - The type: "IP Address", "Domain", "File Hash", or "URL"
  • CASE_ID - case ID for documentation (optional)
  • TIME_FRAME_HOURS - Lookback period (default: 168 = 7 days)
Workflow
Step 1: Get Case Context (if CASE_ID provided)
secops-soar.get_case_full_details(case_id=CASE_ID)
Step 2: Detailed GTI Report

Get comprehensive threat intelligence:

| IOC Type | Tool | |----------|------| | IP | gti-mcp.get_ip_address_report(ip_address=IOC_VALUE) | | Domain | gti-mcp.get_domain_report(domain=IOC_VALUE) | | Hash | gti-mcp.get_file_report(hash=IOC_VALUE) | | URL | gti-mcp.get_url_report(url=IOC_VALUE) |

Record:

  • Reputation and classifications
  • First/last seen dates
  • Associated threats (malware families, actors) → ASSOCIATED_THREAT_IDS
  • Key behaviors (for file hashes)
Step 3: GTI Pivoting

Use /pivot-on-ioc or directly call GTI relationship tools:

Recommended relationships by type:

  • IP: communicating_files, downloaded_files, resolutions
  • Domain: resolutions, communicating_files, subdomains
  • Hash: contacted_domains, contacted_ips, dropped_files
  • URL: communicating_files, downloaded_files

For file hashes, also get behavior summary:

gti-mcp.get_file_behavior_summary(hash=IOC_VALUE)
Step 4: Deep SIEM Search

Search for activity involving the IOC and its related entities:

secops-mcp.search_security_events(
    text="UDM query for IOC_VALUE",
    hours_back=TIME_FRAME_HOURS
)

Identify OBSERVED_RELATED_IOCS - IOCs from GTI pivoting that actually appear in SIEM results.

Step 5: SIEM Enrichment & Correlation

For the IOC and each OBSERVED_RELATED_IOC:

  • Use /enrich-ioc for enrichment
  • Use /correlate-ioc for alert/case correlation
  • Use /find-relevant-case for broader case search
Step 6: Enrich Associated Threats (Optional)

If ASSOCIATED_THREAT_IDS were found (malware families, actors):

gti-mcp.get_collection_report(id=THREAT_ID)
Step 7: Synthesize & Report

Combine all findings:

  • GTI report details
  • Related entities from pivoting
  • SIEM search results
  • Observed related IOCs with enrichment
  • Related alerts and cases
  • Associated threat context

Document in Case (if CASE_ID provided):

Use /document-in-case with comprehensive findings summary

Or generate standalone report:

Use /generate-report with REPORT_TYPE="deep_dive_ioc"
Required Outputs

After completing this skill, you MUST report these outputs:

| Output | Description | |--------|-------------| | GTI_DEEP_FINDINGS | Comprehensive GTI analysis (reputation, classification, behaviors) | | SIEM_DEEP_CONTEXT | Extended SIEM event context (hosts, users, timelines) | | RELATED_ENTITIES | Related IOCs from GTI pivoting (infrastructure connections) | | DISCOVERED_IOCS | All IOCs discovered during analysis | | THREAT_ATTRIBUTION | Threat actor/campaign attribution if found |

Additionally provide:

  • Impact assessment and scope identification
  • Recommendations (escalate, contain, monitor)
  • Documentation in case or standalone report
When to Use This vs Basic Enrichment

| Use /enrich-ioc | Use /deep-dive-ioc | |-------------------|----------------------| | Initial triage | Escalated from Tier 1 | | Quick context needed | Comprehensive investigation | | Single IOC lookup | Full infrastructure mapping | | Tier 1 workflow | Tier 2+ investigation |

按 Apache-2.0 许可原样转载,未经改动 · 在 GitHub 查看 →

评论

登录即可评论;带「已验证安装」的,是发布者名下有本店的安装或持有记录。