用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/dandye/adk_runbooks --skill proactive-hunt-gti-campaign命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
| name | proactive-hunt-gti-campaign |
| description | Use when initiating threat hunting operations driven by GTI threat campaign intelligence. |
| category | hunting |
| version | 1.0.0 |
| type | Skill |
| title | Skill: Proactive Threat Hunting based on GTI Campaign/Actor |
| generated | {"by":"process:google-labs-jules","at":"2026-08-20T02:00:00Z"} |
Objective: Given a GTI Campaign or Threat Actor Collection ID (${GTI_COLLECTION_ID}), proactively search the local environment (SIEM) for related IOCs and TTPs (approximated by searching related entities). If any IOCs from the report are also found in the SecOps tenant (confirmed presence), perform deeper enrichment on those specific IOCs using GTI and check for related SIEM alerts or SOAR cases. Once done, summarize findings in a markdown report. Provide as much detail as possible.
Uses Tools:
gti-mcp_get_collection_reportgti-mcp_get_entities_related_to_a_collection (Initial IOC gathering)gti-mcp_get_collection_timeline_events (for TTP context)secops-mcp_get_ioc_matches (Initial SIEM check)secops-mcp_lookup_entity (SIEM check for specific IOCs)secops-mcp_search_security_events (SIEM check for specific IOCs)gti-mcp_get_domain_report / get_file_report / get_ip_address_report / get_url_report (Deeper GTI enrichment for found IOCs)gti-mcp_get_entities_related_to_a_domain/file/ip/url (Pivot on found IOCs)secops-mcp_get_security_alerts (Check related SIEM alerts for found IOCs/hosts)gti-mcp_get_file_behavior_summary (For found file hashes)write_report (for report generation)secops-soar: post_case_comment (optional), list_casescommon_steps/find_relevant_soar_case </run_books/common_steps/find_relevant_soar_case>graph TD
START(["START"]) --> extract_proactive_payload_node["1. extract_proactive_payload_node<br/><i>(Extract Campaign/Actor Scope Payload)</i>"]
extract_proactive_payload_node --> correlate_gti_campaign_siem_node["2. correlate_gti_campaign_siem_node<br/><i>(Correlate GTI Campaign IOCs against SIEM)</i>"]
correlate_gti_campaign_siem_node --> proactive_gti_hunt_router{"3. proactive_gti_hunt_router<br/><i>(Event.actions.route)</i>"}
proactive_gti_hunt_router -- "CAMPAIGN_SIEM_MATCH_FOUND" --> handle_campaign_match_found_branch["4a. handle_campaign_match_found_branch<br/><i>(Escalate Active Campaign Matches to IR)</i>"]
proactive_gti_hunt_router -- "NO_CAMPAIGN_ACTIVITY" --> handle_no_campaign_activity_branch["4b. handle_no_campaign_activity_branch<br/><i>(Document Clean Hunt Outcome)</i>"]
handle_campaign_match_found_branch --> document_proactive_hunt_report_node["5. document_proactive_hunt_report_node<br/><i>(SOAR Comment & Report Summary)</i>"]
handle_no_campaign_activity_branch --> document_proactive_hunt_report_node
sequenceDiagram
participant User
participant AutomatedAgent as Automated Agent (MCP Client)
participant GTI as gti-mcp
participant SIEM as secops-mcp
participant SOAR as secops-soar
participant FindCase as skills/common/find-relevant-soar-case/SKILL.md
User->>AutomatedAgent: Hunt for Campaign/Actor: `${GTI_COLLECTION_ID}`
AutomatedAgent->>GTI: get_collection_report(id=`${GTI_COLLECTION_ID}`)
GTI-->>AutomatedAgent: Collection Details (Name, Type, Description)
AutomatedAgent->>GTI: get_collection_timeline_events(id=`${GTI_COLLECTION_ID}`)
GTI-->>AutomatedAgent: Timeline Events (TTP Context)
Note over AutomatedAgent: Identify relevant IOC relationships (files, domains, ips, urls)
loop For each IOC Relationship R
AutomatedAgent->>GTI: get_entities_related_to_a_collection(id=`${GTI_COLLECTION_ID}`, relationship_name=R)
GTI-->>AutomatedAgent: List of IOCs (e.g., Hashes H1, Domains D1, IPs IP1...)
end
Note over AutomatedAgent: Initialize local_hunt_findings
AutomatedAgent->>SIEM: get_ioc_matches(hours_back=72)
SIEM-->>AutomatedAgent: Recent IOC Matches in SIEM (Matches M1, M2...)
Note over AutomatedAgent: Identify key IOCs from GTI (I1, I2...) and SIEM matches (M1, M2...)
Note over AutomatedAgent: Phase 1: Lookup key/prioritized IOCs
loop For each prioritized IOC Ii (from GTI/SIEM Matches)
AutomatedAgent->>SIEM: lookup_entity(entity_value=Ii, hours_back=72)
SIEM-->>AutomatedAgent: SIEM Summary for Ii
Note over AutomatedAgent: Record IOCs with confirmed presence (P1, P2...)
end
Note over AutomatedAgent: Phase 2: Deeper investigation for IOCs with confirmed presence (P1, P2...)
loop For each Present IOC Pi
Note over AutomatedAgent: Search SIEM Events
AutomatedAgent->>SIEM: search_security_events(text="Events involving Pi", hours_back=72)
SIEM-->>AutomatedAgent: Relevant SIEM Events for Pi (Note involved hosts Hi)
Note over AutomatedAgent: Store significant event findings
Note over AutomatedAgent: Deeper GTI Enrichment & Pivoting
alt IOC Pi is Domain
AutomatedAgent->>GTI: get_domain_report(domain=Pi)
GTI-->>AutomatedAgent: Detailed Domain Report
AutomatedAgent->>GTI: get_entities_related_to_a_domain(domain=Pi, relationship_name="resolutions")
GTI-->>AutomatedAgent: Related IPs
AutomatedAgent->>GTI: get_entities_related_to_a_domain(domain=Pi, relationship_name="communicating_files")
GTI-->>AutomatedAgent: Related Files
else IOC Pi is File Hash
AutomatedAgent->>GTI: get_file_report(hash=Pi)
GTI-->>AutomatedAgent: Detailed File Report
AutomatedAgent->>GTI: get_entities_related_to_a_file(hash=Pi, relationship_name="contacted_domains")
GTI-->>AutomatedAgent: Related Domains
AutomatedAgent->>GTI: get_entities_related_to_a_file(hash=Pi, relationship_name="contacted_ips")
GTI-->>AutomatedAgent: Related IPs
%% Optional: AutomatedAgent->>GTI: get_file_behavior_summary(hash=Pi)
%% GTI-->>AutomatedAgent: Behavior Summary
else IOC Pi is IP Address
AutomatedAgent->>GTI: get_ip_address_report(ip_address=Pi)
GTI-->>AutomatedAgent: Detailed IP Report
AutomatedAgent->>GTI: get_entities_related_to_an_ip_address(ip_address=Pi, relationship_name="resolutions")
GTI-->>AutomatedAgent: Related Domains
AutomatedAgent->>GTI: get_entities_related_to_an_ip_address(ip_address=Pi, relationship_name="communicating_files")
GTI-->>AutomatedAgent: Related Files
end
Note over AutomatedAgent: Store enrichment and pivot findings
Note over AutomatedAgent: Check Related SIEM Alerts & SOAR Cases
AutomatedAgent->>SIEM: get_security_alerts(query="alert contains Pi or involves host Hi", hours_back=72)
SIEM-->>AutomatedAgent: Related SIEM Alerts (Store findings)
Note over AutomatedAgent: Prepare search terms (Pi + Hi)
AutomatedAgent->>FindCase: Execute(Input: SEARCH_TERMS=[Pi, Hi], CASE_STATUS_FILTER="Opened")
FindCase-->>AutomatedAgent: Results: RELATED_SOAR_CASES (Store findings)
end
Note over AutomatedAgent: Synthesize GTI context, IOCs, TTPs, SIEM findings, Enrichment, Related Alerts & Cases
AutomatedAgent->>User: Confirm: "Hunt found potential activity related to `${GTI_COLLECTION_ID}`. Create/Update SOAR Case or Generate Report? (Create New Case/Update Case [ID]/Generate Report/Do Nothing)"
User->>AutomatedAgent: Response (e.g., "Generate Report")
alt Output Action Confirmed
alt Create/Update Case
Note over AutomatedAgent: Prepare summary comment for SOAR
AutomatedAgent->>SOAR: post_case_comment(case_id=[New/Existing ID], comment="Proactive Hunt Summary for `${GTI_COLLECTION_ID}`: Found IOCs [...] in SIEM. Events [...] observed. GTI Context: [...].")
SOAR-->>AutomatedAgent: Comment confirmation
AutomatedAgent->>AutomatedAgent: attempt_completion(result="Proactive threat hunt for `${GTI_COLLECTION_ID}` complete. Findings summarized. SOAR case created/updated.")
else Generate Report
Note over AutomatedAgent: Synthesize report content
AutomatedAgent->>AutomatedAgent: write_report(report_name="proactive_hunt_report_${GTI_COLLECTION_ID}_${timestamp}.md", report_contents=ReportContent)
Note over AutomatedAgent: Report file created.
AutomatedAgent->>AutomatedAgent: attempt_completion(result="Proactive threat hunt for `${GTI_COLLECTION_ID}` complete. Report generated.")
else Do Nothing
AutomatedAgent->>AutomatedAgent: attempt_completion(result="Proactive threat hunt for `${GTI_COLLECTION_ID}` complete. Findings summarized. No output action taken.")
end
end
## Rubrics
The following rubric is used to evaluate the execution of this **Threat Hunt/Analysis** runbook by an LLM agent.
### Grading Scale (0-100 Points)
| Criteria | Points | Description |
| :--- | :--- | :--- |
| **Scope & Query** | 25 | Defined a clear scope and executed effective queries (UDM, search). |
| **Data Analysis** | 30 | Analyzed results to identify patterns, anomalies, or malicious behavior. |
| **Findings** | 15 | Accurately identified and filtered findings (True Positives vs. False Positives). |
| **Documentation** | 15 | Documented the hunt methodology and results clearly. |
| **Operational Artifacts** | 15 | Produced required artifacts: Sequence diagram, execution metadata (date/cost), and summary. |
### Evaluation Criteria Details
#### 1. Scope & Query (25 Points)
- **10 pts**: Correctly defined the time range and entities/indicators for the hunt.
- **15 pts**: Constructed and executed valid, efficient queries to retrieve relevant data.
#### 2. Data Analysis (30 Points)
- **15 pts**: Effectively analyzed the returned data for the hypothesized threat.
- **15 pts**: Correlated events or indicators to strengthen the analysis.
#### 3. Findings (15 Points)
- **15 pts**: Correctly classified the findings and provided evidence for the conclusion.
#### 4. Documentation (15 Points)
- **15 pts**: Recorded the hunt process, queries used, and findings in the system of record.
#### 5. Operational Artifacts (15 Points)
- **5 pts**: **Sequence Diagram**: Produced a Mermaid sequence diagram visualizing the steps taken.
- **5 pts**: **Execution Metadata**: Recorded the date, duration, and estimated token cost.
- **5 pts**: **Summary Report**: Generated a concise summary of the actions and outcomes.