Atomic Runbook: Search Domain-Related Network Traffic in Chronicle
SkillSearchUse when querying Chronicle for network connections, HTTP requests, or
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Atomic Runbook: Search Domain-Related Network Traffic in Chronicle skill
What this skill tells your AI
The instructions your AI receives, as published by dandye/adk_runbooks in skills/atomic/domain-search-network-traffic-chronicle/SKILL.md and read by ahel’s review.
ID: RB-ATOM-DOMAIN-005
Version: 1.0
Last_Updated: 2025-05-30
Purpose: To perform a detailed search for network traffic events potentially related to a specific domain/FQDN. This often involves searching for connections to/from IP addresses previously resolved from the domain.
Parent_Runbook(s)/Protocol(s): rules-bank/indicator_handling_protocols.md#2-atomic-indicator-domain-name--fqdn, rb_domain_search_dns_chronicle.md
Trigger: When network connection details related to a domain are needed, typically after identifying IPs resolved from the domain or if direct domain logging is sparse.
Inputs Required
domain_name: string - The domain name or FQDN under investigation.- Source Example: Alert field, output from other enrichment runbooks.
resolved_ips(optional): list - A list of IP addresses known to be associated with thedomain_name(e.g., fromrb_domain_get_gti_report.mdorrb_domain_search_dns_chronicle.md).- Source Example: Output from
rb_domain_search_dns_chronicle.md.
- Source Example: Output from
hours_back(optional): integer - How many hours of historical data to search. Defaults to 24.max_events(optional): integer - Maximum event records to return. Defaults to 100.additional_query_terms(optional): string - Additional UDM filter conditions.
Execution Steps
- Tool Selection:
- Primary_Tool_MCP_Server:
secops-mcp - Primary_Tool_Name:
search_security_events
- Primary_Tool_MCP_Server:
- Query Construction (for
textparameter of the tool):- Strategy 1 (Direct Domain in URL/Hostname):
- Query: "Network traffic where target.hostname CONTAINS '{domain_name}' OR target.url CONTAINS '{domain_name}'"
- Strategy 2 (Using Resolved IPs - if
resolved_ipslist is provided and not empty):- Construct an IP list string:
"{ip1}", "{ip2}", ... - Query: "Network traffic where target.ip IN ({ip_list_string}) OR principal.ip IN ({ip_list_string})"
- Construct an IP list string:
- AI Agent Note: Prioritize Strategy 2 if
resolved_ipsare available, as it's often more direct for network traffic. If not, use Strategy 1. Combine if necessary. - Append time window: "... in the last {hours_back} hours"
- Append additional terms: " {additional_query_terms}" (if provided).
- Example
text(Strategy 2): "Network traffic where target.ip IN ('1.2.3.4', '5.6.7.8') OR principal.ip IN ('1.2.3.4', '5.6.7.8') in the last 24 hours"
- Strategy 1 (Direct Domain in URL/Hostname):
- Parameter Mapping:
- Map constructed query to
text. - Map
hours_backtohours_back. - Map
max_eventstomax_events.
- Map constructed query to
- Execute Tool: Call
search_security_events.- AI Agent Note: Refer to
rules-bank/mcp_tool_best_practices.md.
- AI Agent Note: Refer to
- Data Transformation/Extraction:
- Focus on
events.events. Extract connection details:principal.ip,target.ip,target.port,network.application_protocol,network.direction.
- Focus on
Outputs Expected
network_traffic_events: list - List of UDM network event records.translated_udm_query: string.total_events_matched: integer.contacted_ips_ports: list - Unique list of (target.ip, target.port) tuples from events.source_ips_contacting: list - Unique list ofprincipal.ipfrom events.output_status: string - ["Success", "NoEventsFound", "Failure", "PartialSuccess_NoResolvedIPs"]- "PartialSuccess_NoResolvedIPs" if
resolved_ipswas empty and only Strategy 1 could be attempted.
- "PartialSuccess_NoResolvedIPs" if
output_message: string (if Failure).
Decision Logic / Next Steps (If Applicable)
- IF
output_statusis "Success":- Log key findings.
- Analyze events for suspicious patterns (e.g., specific ports, protocols, data volumes to/from IPs associated with the domain).
- If new suspicious IPs are identified in
contacted_ips_portsorsource_ips_contactingthat were not in the initialresolved_ipslist, consider initiating IP-specific atomic runbooks for them. - Escalate if high-risk activity confirmed.
- IF
output_statusis "NoEventsFound" or "PartialSuccess_NoResolvedIPs":- Log result. This might indicate the domain is not actively being connected to/from, or only Strategy 1 was possible and yielded no results.
- ELSE (
output_statusis "Failure"):- Log error:
output_message. - Escalate: "Failed to search network traffic for domain {domain_name} in Chronicle."
- Log error:
AI Agent Execution Notes
- If the
resolved_ipslist is very long, the AI might need to batch queries or summarize, as UDM query length can be a constraint. - Correlate findings with
network_map.mdandasset_inventory_guidelines.md.
Metrics Collection Points
- Log execution time.
- Log
output_status, number ofnetwork_traffic_eventsreturned. - (Reference
rules-bank/ai_performance_logging_requirements.md)
References
rules-bank/mcp_tool_best_practices.mdrules-bank/indicator_handling_protocols.mdrules-bank/analytical_query_patterns.mdrules-bank/ai_performance_logging_requirements.md
Signals
- GitHub stars
- 84
- Forks
- 14
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
domain-search-network-traffic-chronicle- Source
- github.com/dandye/adk_runbooks