smithery/dandye

pivot-on-ioc

Explore GTI relationships for an IOC to discover related entities. Use to expand investigation by finding connected domains, IPs, files, or threat actors. Takes an IOC and relationship types to query.

Installation

$ npx skills add smithery/dandye --skill pivot-on-ioc

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery/dandye · top by installs.

npx skills add smithery/dandye

Browse all from smithery/dandye

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,757 B
  • docs SUMMARY.md 220 B

History

  1. First recorded snapshot · 0 installs

SKILL.md

Pivot on IOC Skill

Explore relationships connected to an IOC within Google Threat Intelligence (GTI) to discover related entities for investigation expansion.

Inputs

  • IOC_VALUE - The indicator value to pivot from
  • IOC_TYPE - The type: "IP Address", "Domain", "File Hash", "URL", or "Collection"
  • RELATIONSHIP_NAMES - List of relationships to query (see table below)

Available Relationships by IOC Type

IOC Type Common Relationships
IP Address communicatingfiles, downloadedfiles, referrer_files, resolutions
Domain resolutions, communicatingfiles, downloadedfiles, subdomains, siblings
File Hash contacteddomains, contactedips, contactedurls, droppedfiles, embedded_domains
URL communicatingfiles, downloadedfiles, lastservingip_address
Collection malwarefamilies, attacktechniques, threat_actors, indicators

Workflow

Step 1: Select GTI Tool

Based on IOC_TYPE:

IOC Type Tool
IP Address gti-mcp.getentitiesrelatedtoanipaddress
Domain gti-mcp.getentitiesrelatedtoa_domain
File Hash gti-mcp.getentitiesrelatedtoa_file
URL gti-mcp.getentitiesrelatedtoan_url
Collection gti-mcp.getentitiesrelatedtoa_collection

Step 2: Query Each Relationship

For each relationship in RELATIONSHIP_NAMES:

[selected_tool](
    identifier=IOC_VALUE,
    relationship_name=relationship
)

Store results keyed by relationship name.

Required Outputs

After completing this skill, you MUST report these outputs:

Output Description
RELATED_ENTITIES Dictionary of entities found per relationship
EXPANDED_IOCS Flattened list of all discovered IOCs (IPs, domains, hashes)
THREAT_CONTEXT Threat actor/campaign context if found during pivoting
PIVOT_STATUS Success/failure status of the pivoting

Example Usage

File Hash Investigation:

IOC_VALUE: "abcdef123456..."
IOC_TYPE: "File Hash"
RELATIONSHIP_NAMES: ["contacted_domains", "contacted_ips", "dropped_files"]

Domain Investigation:

IOC_VALUE: "suspicious-domain.com"
IOC_TYPE: "Domain"
RELATIONSHIP_NAMES: ["resolutions", "communicating_files", "subdomains"]