ioc-hunter
Installation
SKILL.md
IOC Hunter
Source discipline and TLP respect: IOCs come with a share policy (TLP-RED/AMBER/GREEN/CLEAR). Forwarding to parties the feed contract does not allow is a breach of trust and, in some contracts, of license. Sharing where permitted (intra-industry ISAC, CSIRT-NL, sector PAC) is a net-positive habit.
When to use
IOCs (Indicators of Compromise) are the tactical layer of threat intel: hashes, IPs, domains, URLs, mutexes, certificate fingerprints, JA3/JA4 strings. This skill helps manage feeds, dedup and confidence-score them, plug them into SIEM/EDR, and retro-hunt.
Triggers on:
- A question like "add this IOC feed to our stack", "is this hash known", "retro-hunt the last 30 days against these IOCs", "how do we score IOC confidence", "set up a MISP instance".
- A handoff from
detection-engineer(rule needs IOC input),log-triageor thethreat-huntcommand (enrichment of findings),malware-triage(extracted IOCs to be integrated). - A new APT-campaign publication whose IOCs need processing.
- A periodic (quarterly) feed-hygiene review: which feeds deliver value, which do not.