Infrastructure Pivots
get_infrastructure_pivotsIdentify shared infrastructure linking a threat to other campaigns via common IPs, domains, and DNS overlaps. Expand from a single threat to its broader infrastructure network.
Instructions
For a given threat, surface cross-threat infrastructure links — shared IPs/domains and DNS-derived overlaps that tie it to other campaigns. Use to widen from a single threat to its infrastructure neighborhood; use get_similar_threats for TTP/actor-based similarity instead.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| threat_id | Yes | Threat ID (e.g. TL-2026-0042) |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| dns_trail | No | ||
| threat_id | Yes | ||
| pivot_count | No | ||
| dns_record_count | No | ||
| infrastructure_pivots | No |