pivot-on-ioc

Pivot on an IOC to discover related GTI entities and relationships.

120|34|Updated May 9, 2025
One-click install
npx skills add https://github.com/dandye/ai-runbooks --skill pivot-on-ioc
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pivot-on-ioc
Source: https://github.com/dandye/ai-runbooks/tree/main/skills/pivot-on-ioc
Command: npx skills add https://github.com/dandye/ai-runbooks --skill pivot-on-ioc

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Pivot on an IOC within Google Threat Intelligence (GTI) to quickly identify related entities and context, enabling faster expansion of security investigations beyond a single indicator.

Core Features & Use Cases

  • Relationship expansion: Discover connected domains, IPs, files, threat actors, and campaigns related to a given IOC.
  • Multi-type support: Works with IPs, domains, file hashes, URLs, and collections to surface diverse context.
  • Structured outputs: Produces a consistent set of related entities and threat context to feed downstream analysis and decision making.

Quick Start

Provide IOC_VALUE, IOC_TYPE, and RELATIONSHIP_NAMES to initiate the pivot and retrieve related entities.

Frequently Asked Questions about pivot-on-ioc

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I pivot on an IOC to find related threat intelligence entities?

To pivot on an IOC, provide the indicator value, type, and desired relationship names to retrieve connected domains, IPs, files, threat actors, and campaigns from Google Threat Intelligence for expanded security investigations.

What types of indicators of compromise can I use to expand threat intelligence investigations?

Threat intelligence investigations can be expanded using multiple IOC types, including IPs, domains, file hashes, URLs, and collections to surface connected entities and diverse threat context.

How do I discover related threat actors and campaigns from a single file hash or domain?

Discover related threat actors and campaigns by pivoting on a file hash or domain to query Google Threat Intelligence relationships, which returns a structured result set of connected entities.

Can I use Google Threat Intelligence to find connected IPs and domains for a specific URL?

Yes, you can use Google Threat Intelligence to find connected IPs and domains by pivoting on a specific URL, which reveals associated entities and threat context for downstream analysis.

What inputs do I need to start a threat intelligence pivot and retrieve related entities?

Starting a threat intelligence pivot requires three explicit inputs: the IOC value, the IOC type, and the relationship names, which together initiate the query and retrieve a structured set of related entities.