Indicator Pivoting

Indicator pivoting methodology — how to use one known indicator to discover related infrastructure across the IOC graph. Decision tree by indicator type with concrete `/lookup-*` commands per pivot, a worked multi-hop example, pivot-quality scoring, and routing into the rigor pipeline. Use when the user asks "what else is connected to this IP / domain / hash / cert / actor?", needs to expand a single seed IOC into a campaign cluster, or wants the canonical reference for graph-walking IOCs.

Liberty91LTD aa72824 23.8 KB Updated

File contents

Liberty91LTD/cti-skills/tree/main/skills/indicator-pivoting commit aa7282430f

Frequently asked questions

npx skillmds@latest add liberty91ltd/indicator-pivoting