Collecting Indicators Of Compromise
Overview
Cybersecurity skill for collecting indicators of compromise. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"collecting indicators of compromise"
"Systematically collects, categorizes, and distributes indicators of compromise ("
During active incident response to identify and block adversary infrastructure
Post-incident to document all observed adversary artifacts for future detection
When sharing threat intelligence with ISACs, sector partners, or law enforcement
When building detection rules in SIEM, EDR, or network security tools
When enriching IOCs with threat intelligence context for risk scoring
Do not use for behavioral TTP analysis without accompanying technical indicators; use MITRE ATT&CK mapping for behavioral characterization.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Access to incident evidence sources: SIEM logs, EDR telemetry, memory dumps, disk images, network captures
- Threat intelligence platform (MISP, OpenCTI, ThreatConnect) for IOC management and sharing
- IOC enrichment tools: VirusTotal, OTX (AlienVault Open Threat Exchange), Shodan, DomainTools
- STIX 2.1 knowledge for structured IOC representation
- Sharing agreements with relevant ISACs (FS-ISAC, H-ISAC, IT-ISAC) or sector partners
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Objectives — Clarify the goals and scope for indicators of compromise.
- Gather Resources — Collect tools, data, and access needed for indicators of compromise.
- Execute Process — Carry out indicators of compromise operations methodically.
- Verify Quality — Check results against acceptance criteria.
- Document Outcomes — Record findings, decisions, and next steps.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Prepare — Gather requirements, verify prerequisites, set up environment
- Execute — Run collecting indicators of compromise workflow with configured parameters
- Verify — Validate output meets requirements, document results
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: collecting-indicators-of-compromise3description: Use when systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. Covers network, host, email, and behavioral indicators using STIX/TAXII formats and threat intelligence platforms. Activates for requests involving IOC collection, indicator extraction, threat indicator sharing, compromise indicators, STIX export, or IOC enrichment.4license: Apache-2.05---67# Collecting Indicators Of Compromise89## Overview1011Cybersecurity skill for collecting indicators of compromise. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "collecting indicators of compromise"16- "Systematically collects, categorizes, and distributes indicators of compromise ("171819- During active incident response to identify and block adversary infrastructure20- Post-incident to document all observed adversary artifacts for future detection21- When sharing threat intelligence with ISACs, sector partners, or law enforcement22- When building detection rules in SIEM, EDR, or network security tools23- When enriching IOCs with threat intelligence context for risk scoring2425**Do not use** for behavioral TTP analysis without accompanying technical indicators; use MITRE ATT&CK mapping for behavioral characterization.262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- Access to incident evidence sources: SIEM logs, EDR telemetry, memory dumps, disk images, network captures38- Threat intelligence platform (MISP, OpenCTI, ThreatConnect) for IOC management and sharing39- IOC enrichment tools: VirusTotal, OTX (AlienVault Open Threat Exchange), Shodan, DomainTools40- STIX 2.1 knowledge for structured IOC representation41- Sharing agreements with relevant ISACs (FS-ISAC, H-ISAC, IT-ISAC) or sector partners4243## Workflow4445```python46# Example: IOC detection47import re4849IOC_PATTERNS = {50 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",51 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",52 "hash_md5": r"\b[a-f0-9]{32}\b",53 "hash_sha256": r"\b[a-f0-9]{64}\b",54}5556def extract_iocs(text: str) -> dict:57 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}58```59601. **Define Objectives** — Clarify the goals and scope for indicators of compromise.612. **Gather Resources** — Collect tools, data, and access needed for indicators of compromise.623. **Execute Process** — Carry out indicators of compromise operations methodically.634. **Verify Quality** — Check results against acceptance criteria.645. **Document Outcomes** — Record findings, decisions, and next steps.6566## Tools6768- **Analysis Platform** — Data processing and visualization69- **Collaboration Tools** — Team coordination and knowledge sharing707172## Process73741. **Prepare** — Gather requirements, verify prerequisites, set up environment751. **Execute** — Run collecting indicators of compromise workflow with configured parameters761. **Verify** — Validate output meets requirements, document results7778## Verification7980- [ ] All indicators of compromise procedures executed completely and documented81- [ ] Findings validated against multiple data sources82- [ ] False positives identified and filtered83- [ ] Results documented with evidence and timestamps84- [ ] Recommendations provided with risk-based prioritization8586## Anti-Rationalization Table8788| Rationalization | Reality |89|---|---|90| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |91| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |92| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |