ioc-enrichment-workflow

Route IOCs to threat intel tool agents and synthesize enrichment results.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill ioc-enrichment-workflow
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ioc-enrichment-workflow
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/ioc-enrichment-workflow
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill ioc-enrichment-workflow

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automates the enrichment of IOCs by routing indicators to specialized tool agents and synthesising results.

Core Features & Use Cases

  • Routes IPv4/IPv6, domains, URLs, and email indicators to the relevant threat intel tools.
  • Synthesises multi-source results into a unified enrichment record with provenance.
  • Works in CTI pipelines to accelerate investigation and decision-making.

Quick Start

Enrich a list of IOCs by routing them to the appropriate tool agents and synthesising results.

Frequently Asked Questions about ioc-enrichment-workflow

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate IOC enrichment across multiple threat intelligence tools?

Automate IOC enrichment by routing indicators to specialized tool agents and synthesising multi-source results into a unified record with provenance. It orchestrates routing to VirusTotal, AbuseIPDB, GreyNoise, Shodan, OTX, and Censys agents for batch processing and corroborated outputs.

What types of indicators can I enrich within a CTI workflow?

You can enrich IPv4/IPv6 addresses, domains, URLs, file hashes, and emails within CTI workflows. The Skill routes each indicator type to the appropriate threat intelligence tool agent for synthesis and batch processing.

Can I use this Skill to batch process threat intelligence queries?

Yes, you can batch process threat intelligence queries. The Skill orchestrates batch routing of IOCs to relevant tool agents and synthesises the corroborated results into unified enrichment records.

How does IOC synthesis work when querying multiple threat intel sources?

IOC synthesis works by routing indicators to specialized tool agents and combining the multi-source results into a unified enrichment record. This provides corroborated threat intelligence with provenance for accelerated investigation.

What is the best way to enrich a list of IOCs with VirusTotal and Shodan data?

The best way to enrich a list of IOCs is routing them to the appropriate tool agents for synthesis. The Skill orchestrates routing to VirusTotal and Shodan agents alongside other sources, yielding corroborated results with provenance.

Do I need to manually route indicators to different threat intel platforms?

No, manual routing is unnecessary. The Skill automatically routes IPv4/IPv6, domains, URLs, file hashes, and emails to the relevant threat intel tools and synthesises results into a unified enrichment record.