Skip to content

re-ioc-extraction

Extract and normalize defensive IOCs (domains, IPs, URLs, file hashes, mutexes, registry paths, file paths, user agents) from analyst-provided evidence such as strings output, sandbox logs, network logs, or reverse engineering notes. Use when the user wants IOCs for detection, blocking, hunting, or reporting.

Repository Source folder

Details

Path
.agents/skills/re-ioc-extraction/SKILL.md

FAQ