Анализ индикаторов компрометации IOC
★ 8.4 · security
analyzing-indicators-of-compromise is a Claude Code skill that enriches and triages indicators of compromise — IP addresses, domains, file hashes, URLs, and email artifacts — using VirusTotal, AbuseIPDB, MalwareBazaar, and MISP. It normalizes each IOC type, runs parallel API lookups across these platforms, and applies a tiered confidence framework: block at ≥70% confidence (≥15 AV detections or AbuseIPDB score ≥70), monitor at 40–69%, or whitelist below 40%. Campaign attribution is performed via MISP event correlation, and findings are exported as STIX indicator objects with confidence scores, timestamps, and disposition rationale. The skill is designed for SOC analysts, threat intelligence teams, and incident responders who need to rapidly score IOCs from phishing emails, automated threat feeds, or security alerts before ingesting them into blocking controls.
- #threat-intelligence
- #ioc-enrichment
- #virustotal
- #abuseipdb
- #malware-bazaar
- #misp