Agent skill

Deep Dive Ioc

by dandye in dandye/ai-runbooks

Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks.

Apache-2.0Auto-check passedSecurity

Install Deep Dive Ioc

skills CLI
$ npx skills add dandye/ai-runbooks --skill deep-dive-ioc -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dandye/ai-runbooks deep-dive-ioc --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dandye/ai-runbooks.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deep-dive-ioc .claude/skills/deep-dive-ioc && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deep-dive-ioc
GitHub stars
127
Token cost
~1.1k tokens
SKILL.md length
348 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
Apache-2.0

At a glance

Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks.

  • Works in 7 steps: Get Case Context (if CASE_ID provided) → Detailed GTI Report → GTI Pivoting → …
  • An IOC needs Tier 2+ investigation beyond basic enrichment - includes GTI pivoting
  • SKILL.md covers Inputs, Workflow, Required Outputs and When to Use This vs Basic…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Deep Dive Ioc is an agent skill from dandye/ai-runbooks. Perform exhaustive analysis of a critical IOC. Use when an IOC needs Tier 2+ investigation beyond basic enrichment - includes GTI pivoting, deep SIEM searches, correlation with related entities, and threat attribution. For escalated IOCs requiring comprehensive investigation.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security operations. It works with Model Context Protocol. The licence is Apache-2.0.

When your agent uses it

  • An IOC needs Tier 2+ investigation beyond basic enrichment - includes GTI pivoting
  • Deep SIEM searches
  • Correlation with related entities
  • Threat attribution

Example prompts

  • “/deep-dive-ioc”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Get Case Context (if CASE_ID provided)
  2. Detailed GTI Report
  3. GTI Pivoting
  4. Deep SIEM Search
  5. SIEM Enrichment & Correlation
  6. Enrich Associated Threats (Optional)
  7. Synthesize & Report

What it can do on your machine

Read from SKILL.md and the folder at commit 72a6863. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deep Dive Ioc loads about 1.1k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 348 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dandye/ai-runbooks at commit 72a6863, republished under its Apache-2.0 licence (© dandye). 348 words, ~1,072 tokens.

Download SKILL.mdSave it as .claude/skills/deep-dive-ioc/SKILL.md (or your agent's skills folder).
name
deep-dive-ioc
description
Perform exhaustive analysis of a critical IOC. Use when an IOC needs Tier 2+ investigation beyond basic enrichment - includes GTI pivoting, deep SIEM searches, correlation with related entities, and threat attribution. For escalated IOCs requiring comprehensive investigation.
type
Skill
required_roles.chronicle
roles/chronicle.editor
required_roles.soar
roles/chronicle.editor
required_roles.gti
GTI Enterprise
personas
tier2-analyst, tier3-analyst, threat-hunter, incident-responder
generated.by
human:dandye
generated.at
2026-02-04T06:27:43-05:00

Deep Dive IOC Analysis Skill

Perform exhaustive analysis of a single, potentially critical Indicator of Compromise escalated from Tier 1 or identified during an investigation.

Inputs

  • IOC_VALUE - The IOC to analyze (IP, domain, hash, or URL)
  • IOC_TYPE - The type: "IP Address", "Domain", "File Hash", or "URL"
  • CASE_ID - case ID for documentation (optional)
  • TIME_FRAME_HOURS - Lookback period (default: 168 = 7 days)

Workflow

Step 1: Get Case Context (if CASE_ID provided)
secops-soar.get_case_full_details(case_id=CASE_ID)
Step 2: Detailed GTI Report

Get comprehensive threat intelligence:

IOC TypeTool
IPgti-mcp.get_ip_address_report(ip_address=IOC_VALUE)
Domaingti-mcp.get_domain_report(domain=IOC_VALUE)
Hashgti-mcp.get_file_report(hash=IOC_VALUE)
URLgti-mcp.get_url_report(url=IOC_VALUE)

Record:

  • Reputation and classifications
  • First/last seen dates
  • Associated threats (malware families, actors) → ASSOCIATED_THREAT_IDS
  • Key behaviors (for file hashes)
Step 3: GTI Pivoting

Use /pivot-on-ioc or directly call GTI relationship tools:

Recommended relationships by type:

  • IP: communicating_files, downloaded_files, resolutions
  • Domain: resolutions, communicating_files, subdomains
  • Hash: contacted_domains, contacted_ips, dropped_files
  • URL: communicating_files, downloaded_files

For file hashes, also get behavior summary:

gti-mcp.get_file_behavior_summary(hash=IOC_VALUE)

Search for activity involving the IOC and its related entities:

secops-mcp.search_security_events(
    text="UDM query for IOC_VALUE",
    hours_back=TIME_FRAME_HOURS
)

Identify OBSERVED_RELATED_IOCS - IOCs from GTI pivoting that actually appear in SIEM results.

Step 5: SIEM Enrichment & Correlation

For the IOC and each OBSERVED_RELATED_IOC:

  • Use /enrich-ioc for enrichment
  • Use /correlate-ioc for alert/case correlation
  • Use /find-relevant-case for broader case search
Step 6: Enrich Associated Threats (Optional)

If ASSOCIATED_THREAT_IDS were found (malware families, actors):

gti-mcp.get_collection_report(id=THREAT_ID)
Step 7: Synthesize & Report

Combine all findings:

  • GTI report details
  • Related entities from pivoting
  • SIEM search results
  • Observed related IOCs with enrichment
  • Related alerts and cases
  • Associated threat context

Document in Case (if CASE_ID provided):

Use /document-in-case with comprehensive findings summary

Or generate standalone report:

Use /generate-report with REPORT_TYPE="deep_dive_ioc"

Required Outputs

After completing this skill, you MUST report these outputs:

OutputDescription
GTI_DEEP_FINDINGSComprehensive GTI analysis (reputation, classification, behaviors)
SIEM_DEEP_CONTEXTExtended SIEM event context (hosts, users, timelines)
RELATED_ENTITIESRelated IOCs from GTI pivoting (infrastructure connections)
DISCOVERED_IOCSAll IOCs discovered during analysis
THREAT_ATTRIBUTIONThreat actor/campaign attribution if found

Additionally provide:

  • Impact assessment and scope identification
  • Recommendations (escalate, contain, monitor)
  • Documentation in case or standalone report

When to Use This vs Basic Enrichment

Use /enrich-iocUse /deep-dive-ioc
Initial triageEscalated from Tier 1
Quick context neededComprehensive investigation
Single IOC lookupFull infrastructure mapping
Tier 1 workflowTier 2+ investigation

© dandye, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/deep-dive-ioc of dandye/ai-runbooks.

Open the folder on GitHubat commit 72a6863

Compare with similar skills

Deep Dive Ioc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deep Dive Ioc compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deep Dive Ioc this skilldandye/ai-runbooks127—~1.1kAutomated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Ecs Operation Reviewaws/tools-for-devops-agent103—~4.8kAutomated safety check: PassApache-2.0
Threat Intelligence OSINTzhaoxuya520/reverse-skill41k1 repos~1kAutomated safety check: PassMIT
Threat Database UpdateFlorianBruniaux/claude-code-ultimate-guide6.1k—~680Automated safety check: PassCC-BY-SA-4.0
Canary Tripwire Responsedeonmenezes/mantishack503—~376Automated safety check: PassApache-2.0

Similar skills

  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated today
    SecurityAuto-check: notes
  • Ecs Operation Review

    aws/tools-for-devops-agent

    Official

    Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

    103 GitHub stars~4.8k tokensUpdated today
    SecurityAuto-check passed
  • Threat Intelligence OSINT

    zhaoxuya520/reverse-skill

    Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence.

    41k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check passed
  • Threat Database Update

    FlorianBruniaux/claude-code-ultimate-guide

    Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed.

    6.1k GitHub stars~680 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Canary Tripwire Response

    deonmenezes/mantishack

    What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result

    503 GitHub stars~376 tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Secops Cases

    google/skills

    Official

    Manage Google Security Operations (SecOps) SOAR cases throughout their lifecycle.

    21k GitHub stars~3.2k tokensUpdated today
    SecurityAuto-check: warnings

More from dandye/ai-runbooks

All 27 skills in this repo
  • Close Case Artifact

    dandye/ai-runbooks

    Close a case or alert with proper reason and documentation. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~615 tokensUpdated 1 mo ago
    Auto-check passed
  • Correlate Ioc

    dandye/ai-runbooks

    Check for existing SIEM alerts and case management entries related to IOCs.

    127 GitHub stars~624 tokensUpdated 1 mo ago
    Auto-check passed
  • Enrich Ioc

    dandye/ai-runbooks

    Enrich an IOC (IP, domain, hash, URL) with threat intelligence.

    127 GitHub stars~702 tokensUpdated 1 mo ago
    Auto-check passed
  • Find Relevant Case

    dandye/ai-runbooks

    Search for existing cases related to specific indicators or entities.

    127 GitHub stars~562 tokensUpdated 1 mo ago
    Auto-check passed
  • Full Alert Triage

    dandye/ai-runbooks

    Complete Tier 1 triage workflow. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Hunt Apt

    dandye/ai-runbooks

    Hunt for a specific APT/threat actor in your environment. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Deep Dive Ioc

What does Deep Dive Ioc do?

Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks. Deep Dive Ioc is an agent skill from dandye/ai-runbooks. Perform exhaustive analysis of a critical IOC.

When should I use Deep Dive Ioc?

Deep Dive Ioc fits situations like: an IOC needs Tier 2+ investigation beyond basic enrichment - includes GTI pivoting; deep SIEM searches; correlation with related entities; threat attribution.

How do I install Deep Dive Ioc in Claude Code?

Run `npx skills add dandye/ai-runbooks --skill deep-dive-ioc -a claude-code`. Or copy the skill folder (skills/deep-dive-ioc in dandye/ai-runbooks) into .claude/skills/deep-dive-ioc in your project. Claude Code loads it when a task matches its description.

How do I install Deep Dive Ioc in Codex?

Run `npx skills add dandye/ai-runbooks --skill deep-dive-ioc -a codex`. Or copy the skill folder (skills/deep-dive-ioc in dandye/ai-runbooks) into .agents/skills/deep-dive-ioc in your project. Codex loads it when a task matches its description.

Can I use Deep Dive Ioc in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dandye/ai-runbooks --skill deep-dive-ioc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deep-dive-ioc, .gemini/skills/deep-dive-ioc, .github/skills/deep-dive-ioc and .opencode/skills/deep-dive-ioc in your project.

What does Deep Dive Ioc need to run?

SKILL.md names no scripts, command-line tools or credentials: Deep Dive Ioc is instructions for the agent only.

Does Deep Dive Ioc access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Deep Dive Ioc safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Deep Dive Ioc use?

Deep Dive Ioc is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deep Dive Ioc use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Deep Dive Ioc?

Skills that share tags, products or a category with Deep Dive Ioc: Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Ecs Operation Review (aws/tools-for-devops-agent, 103 stars), Threat Intelligence OSINT (zhaoxuya520/reverse-skill, 41k stars) and Threat Database Update (FlorianBruniaux/claude-code-ultimate-guide, 6.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deep Dive Ioc?

dandye (a GitHub user) maintains it in dandye/ai-runbooks, which has 127 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on August 14, 2026.

Source: dandye/ai-runbooks on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.