Ingest, enrich, and track indicators of compromise
Build a workflow that ingests IOCs (IP, domain, URL, hash) from a webhook or form. Enrich each across AbuseIPDB, GreyNoise, Pulsedive, VirusTotal, URLScan.io, Sublime Security, and CrowdStrike in parallel, then store the enriched indicator in a record. On a weekly schedule, create a summary case of notable IOCs for investigation. Deduplicate indicators, handle partial enrichment failures, and respect rate limits. Output the enriched IOC store and the weekly case.
What this prompt builds
Centralize IOC intake, enrich across many intel sources, store them, and get weekly case summaries.
The problem
IOCs arrive from many directions and get analyzed ad hoc, so there's no single enriched, searchable store or consistent follow-up. Valuable intel is lost and repeat indicators are re-investigated.
Solution and impact
This workflow ingests IOCs, enriches them across AbuseIPDB, GreyNoise, Pulsedive, VirusTotal, URLScan, Sublime Security, and CrowdStrike, stores them, and produces weekly summary cases. Threat intel becomes a managed, enriched asset with built-in tracking.
