Loading...
Loading...
Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities and connect findings on different entity levels through a shared runtime entity. Covers identity-to-Smartscape mapping (incl. container-image digest/ID to workload), cross-level topology (K8s pod detection vs. node CVE via pod-to-node), per-entity risk summarization, and coverage match recipes shared by dt-sec-insights. Trigger: "map these findings to workloads/hosts", "which workload does this container image run as", "do these findings relate through the same runtime entity", "enrich this IoC match with entity context", "which threat report mentions this IoC". Queries security.events ONLY for THREAT_REPORT IoC enrichment (matched IoC to attributing reports); Do NOT use for broad security.events posture/overview (use dt-sec-insights), general DQL (use dt-dql-essentials), IoC hunting in logs/spans (use dt-sec-ioc-hunting), or K8s observability outside the security cross-level context (use dt-obs-kubernetes).
npx skill4agent add dynatrace/dynatrace-for-ai dt-sec-contextualizationK8S_PODKUBERNETES_NODEdt.smartscape_source.idcontainer_image.digestcontainer_image.idhost.ipdt.entity.*k8s.*GENAI_SERVICEcontainer_image.digestsmartscapeNodes CONTAINERis_part_of.*runs_on.hostdt.smartscape_source.idK8S_PODK8S_NODEk8s.node.nameTHREAT_REPORT| Intent / trigger | Reference |
|---|---|
| Map findings / IoC matches to workloads, hosts, or cloud entities | |
| Which Smartscape entity does this container image / digest run as? | |
| Do this detection and this CVE relate via a shared entity? | |
| Pod X fired - does it run on a vulnerable node? | |
| Per-entity risk summary (Critical/High/Medium/Low) | |
| Coverage match recipe - which workloads are covered by product Y? | |
| Which entity-identity fields are relevant to a finding type? | |
| Enrich a matched IoC (IP/domain/hash/CVE/...) with threat-report adversary context | |
| Scope findings to AI/GenAI workloads; which processes belong to an AI service; resolve a process to its AI service | |
THREAT_REPORTdt-dql-essentialsdt.smartscape_source.typedt.smartscape_source.idK8S_DEPLOYMENTK8S_DAEMONSETK8S_STATEFULSETK8S_CRONJOBK8S_JOBK8S_REPLICASETappendappenddt-obs-kubernetesdt-obs-kubernetes/references/pod-node-placement.mdcorrelation-and-coverage.mddt.system.bucketsecurity.eventsioc-enrichment.mddt-sec-insightsthreat-intelligence.md| Skill | Role |
|---|---|
| Load first. Core DQL syntax, functions, Smartscape patterns. |
| Consumer of mapping primitive; owns finding-schema queries and coverage counting logic. Owns forward threat-intel (report → environment correlation, overviews, IOC rollups) in |
| Routes cross-evidence correlation and entity enrichment to this skill. |
| Pod→node topology; K8s entity placement patterns. |
| Host inventory; process-level context for HOST/PROCESS_GROUP findings. |
| Cloud Smartscape topology for cloud-entity enrichment. |