deep-dive-ioc

Aggregate GTI reports, SIEM findings, and related entities for a single IOC.

120|34|Updated May 9, 2025
One-click install
npx skills add https://github.com/dandye/ai-runbooks --skill deep-dive-ioc
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: deep-dive-ioc
Source: https://github.com/dandye/ai-runbooks/tree/main/skills/deep-dive-ioc
Command: npx skills add https://github.com/dandye/ai-runbooks --skill deep-dive-ioc

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Exhaustive analysis of a potentially critical IOC escalated from Tier 1, enabling deeper threat context, GTI pivoting, and SIEM correlation to drive informed decisions.

Core Features & Use Cases

  • GTI pivoting and comprehensive threat intelligence enrichment for a single IOC
  • Deep SIEM searches correlating IOC with related entities and behaviors
  • Threat attribution and reporting to inform incident response and case documentation

Quick Start

Provide IOC_VALUE and IOC_TYPE to initiate the deep-dive IOC analysis and compile GTI pivot data, SIEM context, and threat attribution.

Frequently Asked Questions about deep-dive-ioc

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a deep-dive IOC analysis for escalated incident response?

Deep-dive IOC analysis aggregates GTI reports, SIEM findings, and related entities to identify full threat context for a single escalated indicator. You provide an IOC value and type to initiate comprehensive threat intelligence enrichment and SIEM correlation.

What is threat attribution and how does GTI pivoting work during threat analysis?

Threat attribution identifies the actors behind an indicator by pivoting through Google Threat Intelligence relationships. It aggregates related entities and GTI reports to provide comprehensive threat context for a single IOC requiring investigation.

Can I use SIEM searches to correlate an IOC with related entities and behaviors?

Yes, you can use SIEM searches to correlate an IOC with related entities and behaviors. The analysis performs deep SIEM searches to gather, correlate, and report findings for informed incident response decisions.

Do I need access to GTI MCP to investigate escalated IOCs?

Yes, you need access to GTI MCP, SIEM search tools, and enrichment capabilities to investigate escalated IOCs. These tools gather, correlate, and report comprehensive threat context and related entity findings.

What is the best way to aggregate threat intelligence for a single critical indicator?

The best way to aggregate threat intelligence for a single critical indicator is to combine GTI pivoting with SIEM enrichment. This approach correlates related entities and behaviors to drive informed incident response decisions.