check_staging
Check if an IP or domain is staging infrastructure for attacks before weaponization. Returns cluster details, confidence scores, and AI threat assessments to identify pre-attack activity.
Instructions
Check if an IP or domain is associated with a GhostWatch pre-attack staging cluster.
GhostWatch detects infrastructure being staged for attacks before it's weaponized — the quiet window when attackers spin up C2s, register domains, and issue certs. Returns cluster details, confidence score, signal count, and AI threat assessment.
Args: indicator: IP address or domain to check for staging activity
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| indicator | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |