ioc-investigation

Investigate IP addresses, domains, URLs, and file hashes with threat intelligence correlation.

2|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/msandbu/sentinelday --skill ioc-investigation-msandbu
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ioc-investigation
Source: https://github.com/msandbu/sentinelday/tree/main/.github/skills/ioc-investigation
Command: npx skills add https://github.com/msandbu/sentinelday --skill ioc-investigation-msandbu

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill automates the comprehensive investigation of Indicators of Compromise (IoCs), providing deep insights into potential threats and their impact on your organization.

Core Features & Use Cases

  • Multi-faceted IoC Analysis: Investigates IP addresses, domains, URLs, and file hashes.
  • Threat Intelligence Correlation: Integrates Microsoft Defender Threat Intelligence, Sentinel Threat Intel tables, and external enrichment sources.
  • Organizational Exposure Assessment: Identifies affected devices and correlates vulnerabilities (CVEs).
  • Use Case: When a suspicious IP address is flagged, this Skill will automatically check its reputation, trace its network activity within your environment, identify any associated malware, and determine if any of your devices are vulnerable to known exploits linked to that IP.

Quick Start

Investigate the IP address 203.0.113.42 for any malicious activity.

Frequently Asked Questions about ioc-investigation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate an IP address for malicious activity in Microsoft Defender?

IoC investigation automates data collection from DeviceNetworkEvents and Defender APIs, correlating IP addresses with Microsoft Defender Threat Intelligence and Sentinel Threat Intel to assess reputation and trace network activity within your environment.

What is the best way to enrich file hashes and URLs using threat intelligence?

IoC investigation correlates file hashes and URLs with Microsoft Defender Threat Intelligence, Sentinel Threat Intel tables, and external enrichment services to uncover threat actor activity and associated malware.

Can I assess organizational exposure to CVEs when analyzing threat intelligence?

Yes, IoC investigation identifies affected devices and correlates organizational asset exposure to known CVEs linked to the analyzed indicators to assess vulnerability impact.

Does this IoC analysis work with Microsoft Sentinel and Defender XDR?

Yes, IoC investigation integrates with Defender XDR and Microsoft Sentinel, querying AlertEvidence and DeviceNetworkEvents tables to provide comprehensive threat analysis.

How do I trace network activity for a suspicious domain in my environment?

IoC investigation automates data collection from DeviceNetworkEvents to trace domain network activity, check reputation, and identify associated malware or vulnerable devices in your organization.

When do I need automated IoC investigation for threat analysis?

Automated IoC investigation is needed when suspicious indicators are flagged and you must quickly check reputation, trace network activity, identify malware, and determine device vulnerability to known exploits.