Skip to main content

soc-ip-lookup

Standard operating procedure for triaging a single suspicious IP address in a SOC. Use when an IP arrives from an alert, firewall log, or threat feed and an analyst must decide whether it is malicious, whether it touched any asset in the estate, and whether to escalate or contain. Uses enrich_ioc for the reputation verdict and asset_lookup to establish whether the IP relates to a known host, keeps the verdict deterministic, applies collateral-damage checks for shared infrastructure, and human-gates any block or containment.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
aws-samples/sample-sentinel-harness
آخر نشاط في المصدر
٧ يوليو ٢٠٢٦ في ٠٥:٤٧
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٣
التفرعات
١

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.