BigHugger
sk Skill · meltedinhex

scoping-an-incident-from-a-single-indicator

Expands one indicator into the full scope of an incident: pivoting across data sources to find related hosts, accounts, and infrastructure, building a timeline, and bounding what is and is not affected. Activates for requests to scope an incident, pivot from a single IOC, or determine the blast radius of a detection.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashPythontimelinepivotingscopingincident-responselab-foundations
Host repository
meltedinhex/analyst-ai-pack
Version
1.0.0
Licence
Apache-2.0
Host stars
22
Host language
Python