llm_ioc_candidates
Extract potential indicators of compromise (IOCs) from network packet captures, including IPs, domains, HTTP hosts, URIs, user agents, and TLS SNI values.
Instructions
Return candidate IPs, domains, HTTP hosts, URIs, user agents, and TLS SNI values.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| capture_path | Yes | ||
| limit | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||