Analyzing Indicators Of Compromise:网络安全 skill: analyzing-indicators-of-compromise,适用于安全分析、取证与威胁排查场景。
Analyzing Indicators Of Compromise:网络安全 skill: analyzing-indicators-of-compromise,适用于安全分析、取证与威胁排查场景。
> 来源: mukul975/Anthropic-Cybersecurity-Skills (18k stars) — 网络安全专业技能集
> 原文件: skills/analyzing-indicators-of-compromise/SKILL.md
> 模型推荐: claude-opus-4-7 (安全分析深度推理)
mukul975 整理的 100+ 个网络安全专业 skill,覆盖渗透测试 / 取证 / 威胁情报 / 合规审计 / 云安全 / 移动安全 等领域。每个 skill 对应一个具体的安全分析任务。
michael 强调"skill 要有相应的指导功能,指导用户使用",所以加了下面两节让 Agent 和用户对接。
---
1. 用户提到"分析 X 日志 / 取证 / 检测威胁 / 渗透测试 / 安全审计"时,触发对应 skill
2. skill 会按操作步骤一步步执行(取证镜像 / 解析日志 / 跑威胁情报 / etc.)
3. 涉及破坏性操作(rm/drop/format)前必须 ask user 确认
4. 完工后让 Agent 跑自检 step
5. 如果用户要求做"防御性分析" — 区分恶意代码审计 vs 渗透测试
1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)
2. 如果需要提供文件/镜像/日志/哈希,按 Agent 提示提供
3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"
4. 全程 Agent 自动化,你只需提供数据 + 回答决策点
---
---
name: analyzing-indicators-of-compromise
description: 'Analyzes indicators of compromise (IOCs) including IP addresses, domains,
file hashes, URLs, and email artifacts to determine maliciousness confidence, campaign
attribution, and blocking priority. Use when triaging IOCs from phishing emails,
security alerts, or external threat feeds; enriching raw IOCs with multi-source
intelligence; or making block/monitor/whitelist decisions. Activates for requests
involving VirusTotal, AbuseIPDB, MalwareBazaar, MISP, or IOC enrichment pipelines.
'
domain: cybersecurity
subdomain: threat-intelligence
tags:
version: 1.0.0
author: mahipal
license: Apache-2.0
atlas_techniques:
nist_csf:
mitre_attack:
mitre_f3:
version: '1.1'
tactics:
techniques:
name: Phishing for Information
tactic: reconnaissance
source: attack
name: Phishing
tactic: initial-access
source: attack
name: 'Acquire Infrastructure: Domains'
tactic: resource-development
source: attack
name: 'Create Fake Materials: Fake Website'
tactic: resource-development
source: f3
---
Use this skill when:
**Do not use** this skill in isolation for high-stakes blocking decisions — always combine automated enrichment with analyst judgment, especially for shared infrastructure (CDNs, cloud providers).
Before enriching, classify each IOC:
Defang IOCs in documentation (replace `.` with `[.]` and `://` with `[://]`) to prevent accidental clicks.
**VirusTotal (file hash, URL, IP, domain)**:
import vt
client = vt.Client("YOUR_VT_API_KEY")
# File hash lookup
file_obj = client.get_object(f"/files/{sha256_hash}")
detections = file_obj.last_analysis_stats
print(f"Malicious: {detections['malicious']}/{sum(detections.values())}")
# Domain analysis
domain_obj = client.get_object(f"/domains/{domain}")
print(domain_obj.last_analysis_stats)
print(domain_obj.reputation)
client.close()
**AbuseIPDB (IP addresses)**:
import requests
response = requests.get(
"https://api.abuseipdb.com/api/v2/check",
headers={"Key": "YOUR_KEY", "Accept": "application/json"},
params={"ipAddress": "1.2.3.4", "maxAgeInDays": 90}
)
data = response.json()["data"]
print(f"Confidence: {data['abuseConfidenceScore']}%, Reports: {data['totalReports']}")
**MalwareBazaar (file hashes)**:
response = requests.post(
"https://mb-api.abuse.ch/api/v1/",
data={"query": "get_info", "hash": sha256_hash}
)
result = response.json()
if result["query_status"] == "ok":
print(result["data"][0]["tags"], result["data"][0]["signature"])
Query MISP for existing events matching the IOC:
from pymisp import PyMISP
misp = PyMISP("https://misp.example.com", "API_KEY")
results = misp.search(value="evil-domain.com", type_attribute="domain")
for event in results:
print(event["Event"]["info"], event["Event"]["threat_level_id"])
Check Shodan for IP context (hosting provider, open ports, banners) to identify if the IP belongs to bulletproof hosting or a legitimate cloud provider (false positive risk).
Apply a tiered decision framework:
Record findings in TIP/MISP with:
Export to STIX indicator object with confidence field set appropriately.
| Term | Definition |
|------|-----------|
| **IOC** | Indicator of Compromise — observable network or host artifact indicating potential compromise |
| **Enrichment** | Process of adding contextual data to a raw IOC from multiple intelligence sources |
| **Defanging** | Modifying IOCs (replacing `.` with `[.]`) to prevent accidental activation in documentation |
| **False Positive Rate** | Percentage of benign artifacts incorrectly flagged as malicious; critical for tuning block thresholds |
| **Sinkhole** | DNS server redirecting malicious domain lookups to a benign IP for detection without blocking traffic entirely |
| **TTL** | Time-to-live for an IOC in blocking controls; IP indicators should expire after 30 days, domains after 90 days |
本 skill 专注于Analyzing Indi,网络安全 skill: analyzing-indicators-of-compromise。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。
当你需要在Analyzing Indicators Of Compromise相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。
需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。
1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)
2. 如果需要提供文件/镜像/日志/哈希,按 Agent 提示提供
3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"
4. 全程 Agent 自动化,你只需提供数据 + 回答决策点
---
本 skill 专注于Analyzing Indi,网络安全 skill: analyzing-indicators-of-compromise。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。
当你需要在Analyzing Indicators Of Compromise相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。
需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。