Dt Sec Contextualization

作者 Dynatrace9529e72715d9Apache-2.0161 个星标收录于 2026年10月8日更新于 2026年10月8日仓库7天前更新

Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities and connect findings on different entity levels through a shared runtime entity. Covers identity-to-Smartscape mapping (incl. container-image digest/ID to workload), cross-level topology (K8s pod detection vs. node CVE via pod-to-node), per-entity risk summarization, and coverage match recipes shared by dt-sec-insights. Trigger: "map these findings to workloads/hosts", "which workload does this container image run as", "do these findings relate through the same runtime entity", "enrich this IoC match with entity context", "which threat report mentions this IoC". Queries security.events ONLY for THREAT_REPORT IoC enrichment (matched IoC to attributing reports); Do NOT use for broad security.events posture/overview (use dt-sec-insights), general DQL (use dt-dql-essentials), IoC hunting in logs/spans (use dt-sec-ioc-hunting), or K8s observability outside the security cross-level context (use dt-obs-kubernetes).

仅含说明Security

仅公开文件列表。将技能安装到工作区后即可查看文件内容。

路径大小类型
references/correlation-and-coverage.md27.2 KBtext/markdown
references/entity-enrichment.md21.6 KBtext/markdown
references/identity-mapping.md19.4 KBtext/markdown
references/ioc-enrichment.md9.6 KBtext/markdown
SKILL.md8.4 KBtext/markdown

来源与署名

来源:Dynatrace/dynatrace-for-ai位于skills/dt-sec-contextualization提交9529e72

许可证: Apache-2.0

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架