CtrlK
BlogDocsLog inGet started
Tessl Logo

dt-sec-ioc-hunting

Hunt threat-intelligence indicators of compromise (IoCs) across Dynatrace logs and spans and produce a 0-100 threat-exposure score. Extracts and normalizes IoCs — IPs, Domains (hostnames included), URLs, Emails, CVEs, File hashes (md5/sha1/sha256), MITRE TTPs — from unstructured reports, advisories, advisory URLs, pasted text, or STIX, then hunts them in fetch logs and fetch spans. Trigger: hunt these IoCs, am I exposed to this threat, check these indicators in my logs and traces, threat exposure report, extract IoCs from this advisory URL, search these hashes/domains/IPs in my environment. Routes CVE-to-vulnerability, IP/Domain/URL/MITRE-to-detection legs to dt-sec-insights. Do NOT use for: querying security.events directly (vulnerabilities, detections, compliance, THREAT_REPORT — use dt-sec-insights); general log queries not tied to an IoC hunt (use dt-obs-logs); general span/trace analysis (use dt-obs-tracing); explaining DQL syntax (use dt-dql-essentials).

75

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-engineered router skill: tight operational rules, a gated three-leg hunt procedure with explicit validation and retry semantics, and clean one-level-deep disclosure into an existing, well-organized reference bundle. The only weaknesses are mildly wordy rule explanations and the absence of any complete inline DQL query.

DimensionReasoningScore

Conciseness

The body is dense and operative — no filler, no explaining concepts Claude already knows, and every rule carries Dynatrace-specific facts Claude cannot infer (e.g. "there is no `threat.observables.hosts` field", retry ladder "15m then 5m"). It falls short of the lean "every token earns its place" anchor only in wordy passages such as the summarize-first rule ("Summarize-first ≠ truncation: the rollup preserves every affected entity...") and the rule-10 carve-out justification, which could be trimmed without losing guidance.

4 / 5

Actionability

Concrete, executable fragments appear throughout — `matchesPhrase(content, "<ioc>")`, `iAny(contains(content, allObservables[]))`, `in(ip(actor.ips), array(...))`, `lower(url.*)`, `from:now()-30m`, chunk sizes ("default 25 IoCs; 10 for long URLs/emails/hashes") — plus exact per-leg file loads. It is not 5 because the body deliberately routes full copy-paste DQL queries into the reference files rather than including any complete executable query inline, leaving minor gaps if a reference were unavailable.

4 / 5

Workflow Clarity

The "Mandatory Hunt Procedure" gives an explicit ordered three-leg sequence with a hard gate ("Do not proceed to `exposure-scoring.md` until all three legs are done"), per-leg outcomes (zero rows = valid no-match; `FETCH_EXEC_TIME_LIMIT` = INCONCLUSIVE), an automatic retry ladder (30m → 15m → 5m) with approval gating for widening, and a completeness rule ("A no-match conclusion is valid only if every chunk completes cleanly"). This matches the anchor with explicit validation steps, feedback loops, and error-recovery paths.

5 / 5

Progressive Disclosure

The body is a router/overview pointing to seven one-level-deep reference files, all of which exist in `references/` (verified: hunt-logs.md, hunt-spans.md, hunt-security-events.md, ioc-intake.md, exposure-scoring.md, timeframe-gating.md, secondary-observable-extraction.md). Navigation is well-signaled via the IoC-type routing table, the "When to Use This Skill" intent→reference table, and inline references; detailed DQL is correctly deferred to those files. No nesting or dangling paths.

5 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: concrete and comprehensive on capabilities, explicit and natural on triggers, third-person voice, and with explicit negative routing to sibling skills that minimizes mis-triggering. No fluff or over-claims.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — "Extracts and normalizes IoCs", "hunts them in fetch logs and fetch spans", "produce a 0-100 threat-exposure score", "Routes CVE-to-vulnerability, IP/Domain/URL/MITRE-to-detection legs" — with comprehensive, enumerated coverage of IoC types ("IPs, Domains (hostnames included), URLs, Emails, CVEs, File hashes (md5/sha1/sha256), MITRE TTPs") and input formats ("reports, advisories, advisory URLs, pasted text, or STIX"). This matches the anchor "Lists multiple specific concrete actions; comprehensive coverage"; it is not score 4 because there are no meaningful gaps in action coverage.

5 / 5

Completeness

Both "what" (hunt/extract/normalize/score IoCs across Dynatrace logs and spans) and "when" are explicitly answered with a literal "Trigger:" clause of concrete phrases, plus negative triggers ("Do NOT use for: querying security.events directly..."). This is the anchor "Clearly and explicitly answers both what AND when with concrete trigger phrases"; a missing or merely implied 'when' would cap it at 3, which is not the case.

5 / 5

Trigger Term Quality

It includes a dense set of natural user phrases: "hunt these IoCs", "am I exposed to this threat", "check these indicators in my logs and traces", "threat exposure report", "extract IoCs from this advisory URL", "search these hashes/domains/IPs in my environment" — covering synonyms (logs/traces, indicators/IoCs) and concrete type names users would actually say. This matches the comprehensive-synonyms anchor; score 4 would apply only if natural variants were missing, and none are.

5 / 5

Distinctiveness Conflict Risk

The niche (IoC hunting in Dynatrace logs/spans) is distinct and the description actively de-conflicts by routing adjacent intents to named sibling skills ("use dt-sec-insights", "use dt-obs-logs", "use dt-obs-tracing", "use dt-dql-essentials"). Minimal conflict risk, matching the "clear niche with distinct triggers" anchor; it is above anchor 4 because overlap risks are explicitly disclaimed rather than merely minor.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
Dynatrace/dynatrace-for-ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.