VerifiedGit
v1.0.0

pivot-on-ioc

by @dandye0 pulls
URLopenbooklet.com/s/pivot-on-ioc
Pinnedopenbooklet.com/s/pivot-on-ioc@1.0.0
APIGET /api/v1/skills/pivot-on-ioc

Explore GTI relationships for an IOC to discover related entities. Use to expand investigation by finding connected domains, IPs, files, or threat actors. Takes an IOC and relationship types to query.

21 skills from this repodandye/ai-runbooks
pivot-on-iocviewing
analyze-content-gapsskills/analyze-content-gaps/SKILL.md

Identify content gaps and organizational opportunities. Analyzes missing content areas, redundancies, and consolidation opportunities.

close-case-artifactskills/close-case-artifact/SKILL.md

Close a case or alert with proper reason and documentation. Use when triage determines an alert is FP/BTP or investigation is complete. Requires artifact ID, type, closure reason, and root cause.

cluster-documentsskills/cluster-documents/SKILL.md

Automated content similarity and grouping analysis. Groups related documents by topic, purpose, or content similarity.

confirm-actionskills/confirm-action/SKILL.md

Ask the user to confirm before taking a significant action. Use before containment, remediation, or other impactful operations to ensure analyst approval. Presents options and waits for response.

correlate-iocskills/correlate-ioc/SKILL.md

Check for existing SIEM alerts and case management entries related to IOCs. Use to understand if an indicator has triggered previous alerts or is part of ongoing investigations. Takes IOC list and returns related alerts and cases.

deep-dive-iocskills/deep-dive-ioc/SKILL.md

Perform exhaustive analysis of a critical IOC. Use when an IOC needs Tier 2+ investigation beyond basic enrichment - includes GTI pivoting, deep SIEM searches, correlation with related entities, and threat attribution. For escalated IOCs requiring comprehensive investigation.

design-metadata-schemaskills/design-metadata-schema/SKILL.md

Design comprehensive metadata frameworks. Develops structured metadata templates and tagging systems.

document-in-caseskills/document-in-case/SKILL.md

Add a comment to a case to document findings, actions, or recommendations. Use to maintain audit trail during investigations. Requires CASE_ID and comment text.

enrich-iocskills/enrich-ioc/SKILL.md

Enrich an IOC (IP, domain, hash, URL) with threat intelligence. Use when you need to look up reputation and context for an indicator using GTI and SIEM. Returns threat intel findings, SIEM entity summary, and IOC match status.

find-relevant-caseskills/find-relevant-case/SKILL.md

Search for existing cases related to specific indicators or entities. Use to find correlation with other investigations before starting new analysis. Takes search terms and returns matching case IDs.

full-investigationskills/_workflows/full-investigation/SKILL.md

Complete Tier 2 investigation workflow. Orchestrates deep investigation of escalated cases: deep-dive-ioc, correlate-ioc, specialized triage (malware/login), pivot-on-ioc, and generate comprehensive report. Use for escalated cases requiring thorough analysis.

full-triage-alertskills/_workflows/full-alert-triage/SKILL.md

Complete Tier 1 triage workflow. Orchestrates the full alert triage process: check-duplicates, triage-alert, enrich-ioc for each entity, and either close (FP/BTP) or escalate (TP/Suspicious). Use for end-to-end alert processing.

generate-reportskills/generate-report/SKILL.md

Save investigation findings to a markdown report file. Use after completing triage, enrichment, or investigation to create a permanent record. Generates timestamped files in ./reports/ directory.

generate-sitemapskills/generate-sitemap/SKILL.md

Generate hierarchical site structure and navigation maps. Creates visual representations of information architecture and content relationships.

generate-taxonomyskills/generate-taxonomy/SKILL.md

Develop hierarchical classification systems. Creates parent-child categorical structures for content organization.

generate-thesaurusskills/generate-thesaurus/SKILL.md

Generate controlled vocabulary thesaurus for content domains. Creates comprehensive thesauri with preferred terms, broader/narrower/related terms.

hunt-credential-accessskills/hunt-credential-access/SKILL.md

Hunt for credential access techniques like LSASS dumping or browser credential theft. Use when searching for evidence of credential harvesting. Takes MITRE technique IDs and searches for behavioral indicators in SIEM.

hunt-lateral-movementskills/hunt-lateral-movement/SKILL.md

Hunt for lateral movement using PsExec, WMI, or similar techniques. Use when proactively searching for attackers moving through your network using admin tools. Searches for service installations, remote process execution, and suspicious network correlations.

hunt-threatskills/hunt-threat/SKILL.md

Conduct proactive, hypothesis-driven threat hunting. Use when performing advanced hunting based on threat intelligence, TTPs, or anomalies. For Tier 3 analysts or dedicated threat hunters. Supports iterative search, pivoting, and comprehensive documentation.

inventory-contentskills/inventory-content/SKILL.md

Systematic cataloging of information assets. Creates comprehensive inventories of all content with metadata and characteristics.

Auto-indexed from dandye/ai-runbooks

Are you the author? Claim this skill to take ownership and manage it.

Related Skills

@openbooklet

graceful-error-recovery

Use this skill when a tool call, command, or API request fails. Diagnose the root cause systematically before retrying or changing approach. Do not retry the same failing call without first understanding why it failed.

1.1K0
@openbooklet

audience-aware-communication

Use this skill when writing any explanation, documentation, or response that will be read by someone else. Match vocabulary, depth, and format to the audience's expertise level before writing.

1.1K0
@openbooklet

Refactoring Expert

Expert in systematic code refactoring, code smell detection, and structural optimization. Use PROACTIVELY when encountering duplicated code, long methods, complex conditionals, or any code quality issues. Detects code smells and applies proven refactoring techniques without changing external behavior.

600
@openbooklet

Research Expert

Specialized research expert for parallel information gathering. Use for focused research tasks with clear objectives and structured output requirements.

600
@openbooklet

clarify-ambiguous-requests

Use this skill when the user's request is ambiguous, under-specified, or could be interpreted in multiple ways. If proceeding with a wrong assumption would waste significant work, always ask exactly one focused clarifying question before doing anything.

1.1K0
@openbooklet

structured-step-by-step-reasoning

Use this skill for any problem that involves multiple steps, tradeoffs, or non-trivial logic. Think out loud before answering to improve accuracy and transparency. Apply whenever the answer is not immediately obvious.

1.1K0