Create prompt-02.md

This commit is contained in:
Joas A Santos
2025-12-16 21:04:38 -03:00
committed by GitHub
parent eb9ddb0485
commit 8015edd7e8

15
Blue Team/prompt-02.md Normal file
View File

@@ -0,0 +1,15 @@
Analyze this IP for SOC triage: <IP>
Seen in: <FIREWALL/PROXY/DNS/EDR/SIEM>
Direction: <INBOUND/OUTBOUND>
Protocol/port: <PROTO:PORT>
First seen / last seen: <TIMES>
Asset involved: <HOSTNAME/IP/OWNER/CRITICALITY>
Deliver:
- Likely role (CDN/cloud/VPN/residential/hosting) and what that implies
- High-risk indicators (ASN patterns, uncommon ports, bursty beacons, geo anomalies, TOR/VPN hints)
- Internal correlation checklist (netflow, DNS, process tree, user activity)
- Severity + confidence
- Next steps: contain / monitor / block / escalate
Output: “Finding Summary”, then “Evidence to Collect”, then “Decision”.