smithery.ai

enrich-ioc

Enrich an IOC (IP, domain, hash, URL) with threat intelligence. Use when you need to look up reputation and context for an indicator using GTI and SIEM. Returns threat intel findings, SIEM entity summary, and IOC match status.

First seen Mar 20, 2026

Installation

$ npx skills add https://smithery.ai

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery.ai · top by installs.

npx skills add https://smithery.ai

Browse all from smithery.ai

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,806 B
  • docs SUMMARY.md 244 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

Enrich IOC Skill

Perform standardized enrichment for a single Indicator of Compromise (IOC) using Google Threat Intelligence (GTI) and Chronicle SIEM.

Inputs

  • IOC_VALUE - The indicator value (e.g., "198.51.100.10", "evil-domain.com", "abcdef123456...", "http://bad.url/path";)
  • IOC_TYPE - The type: "IP Address", "Domain", "File Hash", or "URL"

Workflow

Step 1: GTI Enrichment

Based on IOC_TYPE, call the appropriate GTI tool:

IOC Type Tool Example
IP Address gti-mcp.getipaddress_report getipaddressreport(ipaddress="198.51.100.10")
Domain gti-mcp.getdomainreport getdomainreport(domain="evil-domain.com")
File Hash gti-mcp.getfilereport getfilereport(hash="abcdef123...")
URL gti-mcp.geturlreport geturlreport(url="http://bad.url/path";)

Store key findings in GTI_FINDINGS:

  • Reputation score
  • Classification (malicious, suspicious, clean)
  • Key relationships (contacted domains, IPs, etc.)
  • Associated malware families or campaigns

Error Handling: If GTI fails (quota exceeded, IOC not found), note the limitation and proceed with SIEM enrichment.

Step 2: SIEM Entity Lookup

secops-mcp.lookup_entity(entity_value=IOC_VALUE)

Store in SIEMENTITYSUMMARY:

  • First/last seen timestamps
  • Related alerts
  • Associated assets/users

Step 3: SIEM IOC Match Check

secops-mcp.get_ioc_matches()

Check if IOCVALUE appears in results. Store Yes/No in SIEMIOCMATCHSTATUS.

Required Outputs

After completing this skill, you MUST report these outputs:

Output Description
GTI_FINDINGS Summary of GTI report (reputation, classification, relationships)
SIEM_SUMMARY SIEM entity context (first/last seen, related alerts)
IOCMATCHSTATUS Yes/No - whether IOC appears in recent threat feed matches
THREAT_SCORE Numerical threat score (0-100) based on GTI reputation
MALICIOUS_CONFIDENCE Confidence level: high, medium, low, or none

Quick Reference

GTI Tools:

  • getipaddressreport(ipaddress)
  • getdomainreport(domain)
  • getfilereport(hash)
  • geturlreport(url)

SIEM Tools:

  • lookupentity(entityvalue)
  • getiocmatches()