collecting-indicators-of-compromise

Featured

Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. Covers network, host, email, and behavioral indicators using STIX/TAXII formats and threat intelligence platforms. Activates for requests involving IOC collection, indicator extraction, threat indicator sharing, compromise indicators, STIX export, or IOC enrichment.

AI & Automation 12,642 stars 1468 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Collecting Indicators of Compromise ## When to Use - During active incident response to identify and block adversary infrastructure - Post-incident to document all observed adversary artifacts for future detection - When sharing threat intelligence with ISACs, sector partners, or law enforcement - When building detection rules in SIEM, EDR, or network security tools - When enriching IOCs with threat intelligence context for risk scoring **Do not use** for behavioral TTP analysis without accompanying technical indicators; use MITRE ATT&CK mapping for behavioral characterization. ## Prerequisites - Access to incident evidence sources: SIEM logs, EDR telemetry, memory dumps, disk images, network captures - Threat intelligence platform (MISP, OpenCTI, ThreatConnect) for IOC management and sharing - IOC enrichment tools: VirusTotal, OTX (AlienVault Open Threat Exchange), Shodan, DomainTools - STIX 2.1 knowledge for structured IOC representation - Sharing agreements with relevant ISACs (FS-ISAC, H-ISAC, IT-ISAC) or sector partners ## Workflow ### Step 1: Identify IOC Categories Collect indicators across all categories from incident evidence: **Network Indicators:** - IP addresses (C2 servers, staging servers, exfiltration destinations) - Domain names (C2 domains, phishing domains, DGA domains) - URLs (malware download, C2 check-in, exfiltration endpoints) - JA3/JA3S hashes (TLS client/server fingerprints) - User-Agent strings (custom or unusual HTTP headers) - DNS query ...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category