Create prompt-01.md

This commit is contained in:
Joas A Santos
2025-12-16 21:04:25 -03:00
committed by GitHub
parent 085eb0a040
commit eb9ddb0485

14
Blue Team/prompt-01.md Normal file
View File

@@ -0,0 +1,14 @@
Triage this URL as a SOC Threat Hunter: <URL>
Context (if any): <HOW_IT_WAS_SEEN: email/proxy/EDR/user_report>
Time observed: <UTC_TIME>
Source host/user: <HOSTNAME>/<USERNAME>
Deliver:
1) Normalization (final URL after redirects if known, domain, path, params)
2) Immediate risk signals (brand impersonation, unusual TLD, punycode, URL shortener, auth bait, file download, tracking params)
3) What internal logs to check next (DNS, proxy, firewall, EDR, email gateway)
4) Hypotheses (phishing / malware delivery / C2 / benign)
5) Severity + confidence (with brief justification)
6) Recommended actions (block/allow, isolate host, reset creds, user comms)
Format: bullet points + a small table of “Signal | Why it matters | Evidence needed”.