indicator-pivoting

Pivot IPs, domains, and hashes to map related infrastructure and attack patterns.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill indicator-pivoting
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: indicator-pivoting
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/indicator-pivoting
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill indicator-pivoting

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Pivoting indicators to reveal related infrastructure and attack patterns, enabling faster threat understanding and attribution.

Core Features & Use Cases

  • Build cross-link pivot chains from IP addresses, domains, and file hashes to map infrastructure.
  • Apply a multi-path decision-tree approach to discover related artifacts (DNS, WHOIS, certificates, subdomains, C2 activity).
  • Document pivot results with confidence scoring and traceable methodology for repeatable investigations.

Quick Start

Provide an indicator to generate a pivot chain and map related infrastructure.

Frequently Asked Questions about indicator-pivoting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I pivot threat intelligence indicators to map related infrastructure?

Pivoting threat intelligence indicators builds cross-link chains from a single IP, domain, or hash to reveal related infrastructure and attack patterns using open-source intelligence sources. This maps containment, attribution, and infrastructure networks quickly.

What is the best way to trace C2 activity from a single domain indicator?

Tracing C2 activity from a single domain uses a multi-path decision-tree approach to discover related artifacts like DNS records, WHOIS data, and certificates. This structured pivot taxonomy ensures repeatable investigations with traceable methodology.

Can I use OSINT pivoting for file hashes to discover attack patterns?

OSINT pivoting applies to file hashes to reveal related infrastructure and attack patterns across open-source intelligence sources. It builds cross-link pivot chains to map infrastructure and attribute threats using a repeatable methodology.

Does indicator pivoting provide confidence scoring for mapped infrastructure?

Indicator pivoting documents pivot results with confidence scoring and a traceable methodology. The Pivot Quality Assessment section ensures analysts can evaluate the reliability of mapped infrastructure networks and related artifacts.

How do I map threat infrastructure using a pivot decision tree?

Mapping threat infrastructure uses a pivot decision tree to guide multi-path discovery across DNS, WHOIS, certificates, and subdomains. Tool routing directs the investigation, ensuring structured and repeatable cross-linking from the initial indicator.