SKILL.md
Pivot on IOC Skill
Explore relationships connected to an IOC within Google Threat Intelligence (GTI) to discover related entities for investigation expansion.
Inputs
IOC_VALUE- The indicator value to pivot fromIOC_TYPE- The type: "IP Address", "Domain", "File Hash", "URL", or "Collection"RELATIONSHIP_NAMES- List of relationships to query (see table below)
Available Relationships by IOC Type
| IOC Type | Common Relationships |
|---|---|
| IP Address | communicatingfiles, downloadedfiles, referrer_files, resolutions |
| Domain | resolutions, communicatingfiles, downloadedfiles, subdomains, siblings |
| File Hash | contacteddomains, contactedips, contactedurls, droppedfiles, embedded_domains |
| URL | communicatingfiles, downloadedfiles, lastservingip_address |
| Collection | malwarefamilies, attacktechniques, threat_actors, indicators |
Workflow
Step 1: Select GTI Tool
Based on IOC_TYPE:
| IOC Type | Tool |
|---|---|
| IP Address | gti-mcp.getentitiesrelatedtoanipaddress |
| Domain | gti-mcp.getentitiesrelatedtoa_domain |
| File Hash | gti-mcp.getentitiesrelatedtoa_file |
| URL | gti-mcp.getentitiesrelatedtoan_url |
| Collection | gti-mcp.getentitiesrelatedtoa_collection |
Step 2: Query Each Relationship
For each relationship in RELATIONSHIP_NAMES:
[selected_tool](
identifier=IOC_VALUE,
relationship_name=relationship
)
Store results keyed by relationship name.
Required Outputs
After completing this skill, you MUST report these outputs:
| Output | Description |
|---|---|
RELATED_ENTITIES |
Dictionary of entities found per relationship |
EXPANDED_IOCS |
Flattened list of all discovered IOCs (IPs, domains, hashes) |
THREAT_CONTEXT |
Threat actor/campaign context if found during pivoting |
PIVOT_STATUS |
Success/failure status of the pivoting |
Example Usage
File Hash Investigation:
IOC_VALUE: "abcdef123456..."
IOC_TYPE: "File Hash"
RELATIONSHIP_NAMES: ["contacted_domains", "contacted_ips", "dropped_files"]
Domain Investigation:
IOC_VALUE: "suspicious-domain.com"
IOC_TYPE: "Domain"
RELATIONSHIP_NAMES: ["resolutions", "communicating_files", "subdomains"]