@dynatrace/dt-sec-contextualization
@dynatrace/dt-sec-contextualization — AI coding skill
No skills found in this collection.
SKILL.md
| name | dt-sec-contextualization |
| description | >- |
| license | Apache-2.0 |
Security Contextualization Skill
Resolve security signals and entity attribute sets to runtime Dynatrace
Smartscape entities, summarize findings across entity levels, and connect
signals that land on different levels (e.g. a detection on a K8S_POD vs.
a CVE on a KUBERNETES_NODE) via a shared runtime entity.
What This Skill Covers
- Identity → Smartscape mapping — given a row carrying any of
dt.smartscape_source.id,container_image.digest,container_image.id,host.ip,dt.entity.*, ork8s.*fields, resolve it to a Smartscape entity at any requested level (CONTAINER / K8S_POD / workload / K8S_NODE / HOST / cloud /GENAI_SERVICE— AI/GenAI workloads). - Artifact → runtime bridge —
container_image.digest→smartscapeNodes CONTAINER→is_part_of.*→ parent workload orruns_on.host→ HOST. Works without pre-enricheddt.smartscape_source.id. - Cross-level correlation — tiered entity matching to determine whether two findings (e.g. a detection and a CVE from different legs) relate through a shared runtime entity. Tier 1: exact entity id match; Tier 2: same workload/pod/host by name; Tier 3: same namespace/cluster (context-only — does not contribute to scoring).
- Pod → node topology — resolve
K8S_PODto itsK8S_NODEviak8s.node.name(co-projected field) or Smartscape edge traversal. Enables "detection hit pod X — does that pod run on a vulnerable node?" - Coverage match recipes — 2-way and 3-way container→workload match patterns shared across dt-sec-insights coverage counting queries.
- Entity enrichment — given findings, IoC matches, or raw Smartscape nodes, produce per-entity risk-level breakdowns and entity-key bundles for downstream scoring.
- IoC enrichment — attribute an already-matched IoC (IP / domain / URL /
email / CVE / hash / MITRE TTP) with adversary context (actor, malware family,
MITRE technique, targeting, provider) by reverse-looking-up the ingested
THREAT_REPORTevents whose observable arrays contain that IoC.
When to Use This Skill
| Intent / trigger | Reference |
|---|---|
| Map findings / IoC matches to workloads, hosts, or cloud entities | identity-mapping.md -> entity-enrichment.md |
| Which Smartscape entity does this container image / digest run as? | identity-mapping.md § Mapping Primitive (Path 2 - container digest) |
| Do this detection and this CVE relate via a shared entity? | correlation-and-coverage.md § Correlation |
| Pod X fired - does it run on a vulnerable node? | correlation-and-coverage.md § Correlation (Pod->Node Topology) |
| Per-entity risk summary (Critical/High/Medium/Low) | entity-enrichment.md |
| Coverage match recipe - which workloads are covered by product Y? | correlation-and-coverage.md § Coverage |
| Which entity-identity fields are relevant to a finding type? | identity-mapping.md § Data Model |
| Enrich a matched IoC (IP/domain/hash/CVE/...) with threat-report adversary context | ioc-enrichment.md |
| Scope findings to AI/GenAI workloads; which processes belong to an AI service; resolve a process to its AI service | identity-mapping.md § Mapping Primitive (Path 4 - GENAI_SERVICE -> SERVICE -> PROCESS) |
How This Skill Is Organized
- SKILL.md (this file) — entry point and routing.
- references/
- identity-mapping.md — generalized identity->Smartscape resolver (mapping primitive Paths 1/2/3/4), pre-flight identifier checks, level selection, and entity-identity field guidance.
- entity-enrichment.md — consumers of the mapping primitive: cloud (Path 1), K8s workload (3-way), host-by-IP, host-by-entity, natural-language fallback, problem->entities->findings chain. Per-entity risk-level breakdowns (Critical/High/Medium/Low).
- correlation-and-coverage.md — cross-level entity convergence, pod->node topology resolution, scoring contract, and 2-way/3-way coverage match recipes shared with dt-sec-insights.
- ioc-enrichment.md — reverse-lookup IoC
enrichment: attribute a matched IoC to ingested
THREAT_REPORTevents and surface adversary context (actor / malware / MITRE / targeting). Single and batch (per-IoC) templates; supported-IoC taxonomy.
Universal Best Practices
- Always load
dt-dql-essentialsfirst — DQL syntax and function names differ from SQL. Confirm all functions before generating queries. - Ground every query in a named template — do not improvise Smartscape joins. The 3-way match, digest→CONTAINER→workload, and pod→node traversal patterns are precise; deviating produces silent zero-row results.
- Run the pre-flight check before the full 3-way enrichment — external providers vary widely. Confirm at least one identifier path is populated before running the expensive append chain.
- Check
dt.smartscape_source.typebefore trusting Path 1 — a non-nulldt.smartscape_source.idis not proof of workload-level resolution; the field may point to a namespace, cluster, or cloud resource. Only K8s workload types (K8S_DEPLOYMENT,K8S_DAEMONSET,K8S_STATEFULSET,K8S_CRONJOB,K8S_JOB,K8S_REPLICASET) are eligible for workload enrichment via Path 1. - Dedup early and after
append— dedup before joins to collapse re-ingested duplicates; dedup again afterappendbecause the same finding can match multiple paths. - Tier 3 correlation is context only — same namespace/cluster shared by two findings does not raise the exposure score. Never treat a cluster-level shared attribute as proof of entity-level relatedness.
- Route topology queries to
dt-obs-kubernetes— pod→node placement and Smartscape edge traversal patterns live indt-obs-kubernetes/references/pod-node-placement.md. Do not re-author them here; reference them and apply the output incorrelation-and-coverage.md. - No
dt.system.bucketfilters — security event data may live in any bucket; filtering by bucket risks hiding findings. - THREAT_REPORT is the one
security.eventsquery allowed here — reverse lookup only.ioc-enrichment.mdattributes a matched IoC to reports (IoC → report). Broad THREAT_REPORT overviews, IOC rollups, and forward report → environment correlation stay indt-sec-insights(threat-intelligence.md). Never author finding/posture queries here.
Related Skills
| Skill | Role |
|---|---|
dt-dql-essentials |
Load first. Core DQL syntax, functions, Smartscape patterns. |
dt-sec-insights |
Consumer of mapping primitive; owns finding-schema queries and coverage counting logic. Owns forward threat-intel (report → environment correlation, overviews, IOC rollups) in threat-intelligence.md; this skill owns only the reverse IoC → report enrichment (ioc-enrichment.md). |
dt-sec-ioc-hunting |
Routes cross-evidence correlation and entity enrichment to this skill. |
dt-obs-kubernetes |
Pod→node topology; K8s entity placement patterns. |
dt-obs-hosts |
Host inventory; process-level context for HOST/PROCESS_GROUP findings. |
dt-obs-aws / dt-obs-azure / dt-obs-gcp |
Cloud Smartscape topology for cloud-entity enrichment. |
Loading...
Select a file to preview
Analyzing security...
Checking scan reports and verification data.
Bill of Materials
Everything this skill can do — files, network, commands, and more.
No demos yet. To add one, ask your AI agent: "Submit a demo for @dynatrace/dt-sec-contextualization" — or upload via the API.
To add a demo, ask your AI agent: "Submit a demo for @dynatrace/dt-sec-contextualization"
No eval data yet. Eval results are published via the SkillSafe API.