ioc-hunter

Installation
SKILL.md

IOC Hunter

Source discipline and TLP respect: IOCs come with a share policy (TLP-RED/AMBER/GREEN/CLEAR). Forwarding to parties the feed contract does not allow is a breach of trust and, in some contracts, of license. Sharing where permitted (intra-industry ISAC, CSIRT-NL, sector PAC) is a net-positive habit.

When to use

IOCs (Indicators of Compromise) are the tactical layer of threat intel: hashes, IPs, domains, URLs, mutexes, certificate fingerprints, JA3/JA4 strings. This skill helps manage feeds, dedup and confidence-score them, plug them into SIEM/EDR, and retro-hunt.

Triggers on:

  • A question like "add this IOC feed to our stack", "is this hash known", "retro-hunt the last 30 days against these IOCs", "how do we score IOC confidence", "set up a MISP instance".
  • A handoff from detection-engineer (rule needs IOC input), log-triage or the threat-hunt command (enrichment of findings), malware-triage (extracted IOCs to be integrated).
  • A new APT-campaign publication whose IOCs need processing.
  • A periodic (quarterly) feed-hygiene review: which feeds deliver value, which do not.

When NOT (handoff)

Installs
3
GitHub Stars
4
First Seen
May 18, 2026
ioc-hunter — roodlicht/accans-sec-skills