Security analysts spend hours manually pivoting across threat intelligence sources — querying VirusTotal for a file hash, checking AbuseIPDB for an IP, cross-referencing MITRE ATT&CK, then synthesizing it all into a report. This cookbook shows how to build a Haijun-powered agent that automates that entire workflow.
The agent takes raw Indicators of Compromise (IOCs) — IP addresses, file hashes, or domains — and uses Haijun's tool-use capabilities to decide which intelligence sources to query, correlate findings across sources, and produce structured, analyst-ready threat reports. The tools in this example are simulated, but the architecture is designed so you can swap in real APIs (VirusTotal, AbuseIPDB, Shodan, etc.) without changing the orchestration logic.
How to design tool schemas that give Haijun enough context to choose the right intelligence source
How to build an agentic loop that lets Haijun chain tool calls based on what it discovers
How to prompt for multi-source correlation and MITRE ATT&CK mapping
How to convert free-text analysis into structured JSON reports for downstream systems
Prerequisites
pacity-0 group-hover:opacity-100 group-focus-within:opacity-100 right-2 top-2">
%pip install juglow python-dotenv --quiet
Note: you may need to restart the kernel to use updated packages. import json import juglow from dotenv import load_dotenv load_dotenv() client = juglow.Juglow() MODEL_NAME = "haijun-sonnet-4-6" Step 2: Define threat intelligence tools We define four tools that represent common threat intelligence data sources. Each tool has a clear description that helps Haijun understand when and why to use it — this is critical for effective agentic behavior. In production, these would wrap real API calls; the schemas stay the same.
g-left:12ch;text-indent:-12ch"> "properties": {
"domain": {
"type": "string",
"description": "The domain name to investigate (e.g., example.com).",
}
},
"required": ["domain"],
},
},
{
"name": "get_mitre_techniques",
"description": "Map observed behaviors, malware families, or attack patterns to the MITRE ATT&CK framework. Returns matching technique IDs, tactic categories, associated threat groups, and detection recommendations.",
"input_schema": {
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "Description of the behavior, malware family, or attack pattern to map (e.g., 'command and control beaconing', 'credential theft', 'lateral movement').",
}
},
"required": ["query"],
},
},
]
print(f"Defined {len(tools)} threat intelligence tools:")
for tool in tools:
print(f" - {tool['name']}: {tool['description'][:80]}...")
Defined 4 threat intelligence tools: - lookup_ip_reputation: Query IP reputation database to get geolocation, ISP information, abuse history,... - lookup_file_hash: Query file reputation service with a cryptographic hash. Returns detection ratio... - lookup_domain: Investigate a domain's reputation including registration details, DNS records, S... - get_mitre_techniques: Map observed behaviors, malware families, or attack patterns to the MITRE ATT&CK... Step 3: Build simulated threat intel backends These functions simulate real threat intelligence APIs. Each returns realistic data structures that mirror what you'd get from services like VirusTotal, AbuseIPDB, or a MITRE ATT&CK lookup. To go to production, replace the body of each function with an API call — the interface stays the same.
adding-left:12ch;text-indent:-12ch"> "registrant_country": "Panama",
"hosting_provider": "BulletProof Hosting Ltd",
"hosting_country": "Moldova",
"ip_addresses": ["192.0.2.55", "192.0.2.56"],
"mx_records": [],
"ssl_issuer": "Let's Encrypt",
"ssl_valid_from": "2026-02-28T00:00:00Z",
"targeted_brand": "Bank of America",
"similar_domains_found": 12,
"urlhaus_reference": "https://urlhaus.abuse.ch/url/2345678/",
"tags": ["phishing-kit", "credential-harvest", "typosquat"],
"associated_ips_with_other_malicious_domains": True,
"dns_records": {
"A": ["192.0.2.55"],
"NS": ["ns1.bulletproof-dns.cc", "ns2.bulletproof-dns.cc"],
"TXT": [],
},
},
"update-service-cdn.ru": {
"domain": "update-service-cdn.ru",
"reputation_score": 91,
"category": "malware",
"subcategory": "c2_server",
"active": True,
"registrar": "REG.RU LLC",
"registration_date": "2025-07-14T00:00:00Z",
"registrant_country": "Russia",
"hosting_provider": "MnogoByte LLC",
"hosting_country": "Russia",
"ip_addresses": ["203.0.113.42"],
"ssl_issuer": "Self-signed",
"tags": ["emotet-c2", "malware-distribution", "fast-flux"],
"associated_malware": ["Emotet", "Trickbot"],
"dns_records": {
"A": ["203.0.113.42", "203.0.113.88"],
"NS": ["ns1.reg.ru", "ns2.reg.ru"],
"TXT": [],
},
},
}
return domain_database.get(
domain,
{
"domain": domain,
"reputation_score": 0,
"category": "unknown",
"active": None,
"note": "No records found for this domain",
},
)
def get_mitre_techniques(query: str) -> dict:
"""Map behaviors to MITRE ATT&CK. In production: query ATT&CK STIX/TAXII feed or local DB."""
mitre_mappings = {
"command and control": {
"techniques": [
{
"id": "T1071.001",
"name": "Web Protocols",
"tactic": "Command and Control",
"description": "Adversaries communicate using application layer protocols associated with web traffic to avoid detection",
},
{
"id": "T1573.002",
"name": "Asymmetric Cryptography",
"tactic": "Command and Control",
"description": "Use asymmetric encryption for C2 communications",
},
{
"id": "T1008",
"name": "Fallback Channels",
"tactic": "Command and Control",
"description": "Use alternate communication channels if primary C2 is disrupted",
},
],
"associated_groups": ["APT28", "APT29", "Lazarus Group", "Wizard Spider"],
"detection_suggestions": [
"Monitor for unusual outbound HTTPS to non-standard ports",
"Inspect TLS certificates for self-signed or recently issued certs",
"Track beaconing patterns in network flow data",
],
},
"credential theft": {
"techniques": [
{
"id": "T1056.001",
"name": "Keylogging",
"tactic": "Collection",
"description": "Log keystrokes to intercept credentials as they are typed",
},
{
"id": "T1555.003",
"name": "Credentials from Web Browsers",
"tactic": "Credential Access",
"description": "Acquire credentials from web browser credential stores",
},
{
"id": "T1003.001",
"name": "LSASS Memory",
"tactic": "Credential Access",
"description": "Access credential material stored in LSASS process memory",
},
],
"associated_groups": ["Trickbot operators", "Emotet operators", "FIN7"],
"detection_suggestions": [
"Monitor for LSASS access by unusual processes",
"Alert on credential store file access",
"Deploy credential guard on endpoints",
],
},
"phishing": {
"techniques": [
{
"id": "T1566.001",
"name": "Spearphishing Attachment",
"tactic": "Initial Access",
"description": "Send emails with a malicious attachment to gain access",
},
{
"id": "T1566.002",
"name": "Spearphishing Link",
"tactic": "Initial Access",
"description": "Send emails with malicious links to credential-harvesting sites",
},
{
"id": "T1598.003",
"name": "Spearphishing Link (for Information)",
"tactic": "Reconnaissance",
"description": "Send spearphishing links to gather information for targeting",
},
],
"associated_groups": ["APT28", "Lazarus Group", "Kimsuky", "TA505"],
"detection_suggestions": [
"Implement DMARC/DKIM/SPF for email authentication",
"Deploy URL rewriting and sandboxing for links",
"Monitor for newly registered look-alike domains",
],
},
"lateral movement": {
"techniques": [
{
"id": "T1210",
"name": "Exploitation of Remote Services",
"tactic": "Lateral Movement",
"description": "Exploit remote services to move laterally within the environment",
},
{
"id": "T1021.002",
"name": "SMB/Windows Admin Shares",
"tactic": "Lateral Movement",
"description": "Use valid accounts to interact with remote network shares using SMB",
},
],
"associated_groups": ["Wizard Spider", "FIN6", "Sandworm Team"],
"detection_suggestions": [
"Monitor for anomalous SMB traffic patterns",
"Alert on use of PsExec or similar tools",
"Track authentication events across endpoints",
],
},
}
query_lower = query.lower()
for key, mapping in mitre_mappings.items():
if key in query_lower:
return mapping
Fuzzy fallback: check if any keyword appears
for key, mapping in mitre_mappings.items():
for word in key.split():
if word in query_lower:
return mapping
return {
"techniques": [],
"associated_groups": [],
"note": "No direct MITRE ATT&CK mapping found for this query. Try broader terms like 'command and control', 'credential theft', 'phishing', or 'lateral movement'.",
}
print(
"Simulated threat intel backends ready. In production, replace function bodies with real API calls."
)
Simulated threat intel backends ready. In production, replace function bodies with real API calls. Step 4: Create the agent loop This is the core orchestration. We give Haijun a system prompt that positions it as a senior threat intelligence analyst, then let it decide which tools to call and in what order. The while loop continues as long as Haijun wants to call tools — it may call one tool, inspect the results, then decide to call another based on what it found. This multi-turn reasoning is what makes this an agent rather than a simple API wrapper.
print(json.dumps(report, indent=2))
print()
====================================================================== STRUCTURED THREAT INTELLIGENCE REPORTS ====================================================================== --- 203.0.113.42 --- { "ioc": "203.0.113.42", "ioc_type": "ip_address", "severity": "critical", "confidence": 87, "threat_classification": "botnet_c2", "summary": "IP 203.0.113.42 is a confirmed malicious infrastructure node hosted in Saint Petersburg, Russia via MnogoByte LLC (AS48666), with an abuse confidence score of 87/100 and 1,243 community abuse reports. It is actively associated with Emotet and TrickBot botnet C2 operations, malware distribution, brute-force attacks, and banking trojan activity \u2014 a combination strongly attributed to the Wizard Spider threat group and historically used as a precursor to Ryuk/Conti ransomware deployment. The infrastructure is currently active as of March 10, 2026, and any observed connections from an organization's environment should be treated as a high-priority security incident requiring immediate response.", "related_malware": [ "Emotet", "TrickBot", "Ryuk", "Conti" ], "related_threat_groups": [ "Wizard Spider", "TA542", "FIN6", "Sandworm Team", "APT28" ], "mitre_techniques": [ { "technique_id": "T1566.001", "technique_name": "Spearphishing Attachment", "tactic": "Initial Access" }, { "technique_id": "T1566.002", "technique_name": "Spearphishing Link", "tactic": "Initial Access" }, { "technique_id": "T1071.001", "technique_name": "Web Protocols", "tactic": "Command and Control" }, { "technique_id": "T1573.002", "technique_name": "Asymmetric Cryptography", "tactic": "Command and Control" }, { "technique_id": "T1008", "technique_name": "Fallback Channels", "tactic": "Command and Control" }, { "technique_id": "T1056.001", "technique_name": "Keylogging", "tactic": "Credential Access" }, { "technique_id": "T1555.003", "technique_name": "Credentials from Web Browsers", "tactic": "Credential Access" }, { "technique_id": "T1003.001", "technique_name": "LSASS Memory", "tactic": "Credential Access" }, { "technique_id": "T1110", "technique_name": "Brute Force", "tactic": "Credential Access" }, { "technique_id": "T1021.002", "technique_name": "SMB/Windows Admin Shares", "tactic": "Lateral Movement" }, { "technique_id": "T1210", "technique_name": "Exploitation of Remote Services", "tactic": "Lateral Movement" } ], "recommended_actions": [ "Block 203.0.113.42 at perimeter firewall, NGFW, and all security layers immediately for both inbound and outbound traffic", "Query SIEM and EDR for all historical connections to or from this IP across the entire environment for at least the last 90 days", "Isolate any hosts that have established connections to this IP and treat them as potentially compromised", "Alert the Security Operations Center and initiate Incident Response protocol if connections are found", "Threat hunt for Emotet and TrickBot indicators including suspicious Office document executions and cmd.exe spawned from winword.exe", "Search for lateral movement indicators such as anomalous SMB traffic, PsExec usage, and new admin share connections", "Audit Active Directory for new accounts, privilege escalation, or group policy changes that may indicate TrickBot post-exploitation activity", "Review email logs for malspam received from or relayed through this IP", "Inspect DNS logs for any domain resolutions associated with this IP", "Deploy or validate Credential Guard on all Windows endpoints to mitigate LSASS credential dumping", "Disable SMBv1 and restrict Admin Shares to mitigate TrickBot lateral movement techniques", "Subscribe to Emotet and TrickBot IOC feeds and automate blocking of emerging C2 infrastructure", "Implement DMARC, DKIM, and SPF if not already in place to reduce Emotet malspam effectiveness", "Conduct a tabletop exercise simulating the Emotet to TrickBot to ransomware kill chain" ], "related_iocs": [] } --- d131dd02c5e6eec4693d9a0698aff95c --- { "ioc": "d131dd02c5e6eec4693d9a0698aff95c", "ioc_type": "file_hash", "severity": "critical", "confidence": 85, "threat_classification": "banking_trojan_dropper", "summary": "The investigated MD5 hash corresponds to update_service.dll, identified as Emotet Epoch 5, a banking trojan and dropper operated by Wizard Spider/TA542, detected by 80.6% of 72 AV engines. The sample communicates with confirmed C2 infrastructure hosted in Russia and exhibits credential harvesting, persistence, and lateral movement behaviors consistent with a multi-stage attack chain. The co-presence of TrickBot infrastructure indicates a high risk of downstream ransomware deployment via Ryuk, Conti, or BlackBasta.", "related_malware": [ "Emotet", "TrickBot", "Ryuk", "Conti", "BlackBasta" ], "related_threat_groups": [ "Wizard Spider", "TA542", "FIN7" ], "mitre_techniques": [ { "technique_id": "T1218.010", "technique_name": "Regsvr32", "tactic": "Execution" }, { "technique_id": "T1053.005", "technique_name": "Scheduled Task/Job", "tactic": "Persistence" }, { "technique_id": "T1071.001", "technique_name": "Web Protocols (HTTPS)", "tactic": "Command and Control" }, { "technique_id": "T1573.002", "technique_name": "Asymmetric Cryptography", "tactic": "Command and Control" }, { "technique_id": "T1008", "technique_name": "Fallback Channels", "tactic": "Command and Control" }, { "technique_id": "T1056.001", "technique_name": "Keylogging", "tactic": "Collection" }, { "technique_id": "T1555.003", "technique_name": "Credentials from Web Browsers", "tactic": "Credential Access" }, { "technique_id": "T1003.001", "technique_name": "LSASS Memory", "tactic": "Credential Access" }, { "technique_id": "T1021.002", "technique_name": "SMB/Windows Admin Shares", "tactic": "Lateral Movement" }, { "technique_id": "T1210", "technique_name": "Exploitation of Remote Services", "tactic": "Lateral Movement" } ], "recommended_actions": [ "Isolate any host where update_service.dll or MD5 d131dd02c5e6eec4693d9a0698aff95c has been detected and assume full compromise", "Block IPs 203.0.113.42, 203.0.113.88, and 192.0.2.101 at all perimeter controls including firewall, proxy, DNS, and EDR", "Block domains update-service-cdn.ru and cdn-api-gateway.cc across all perimeter controls", "Block outbound traffic on non-standard ports 8080 and 4444", "Hunt across all endpoints for SHA256 a1b2c3d4...abcdef01 and filename update_service.dll", "Reset credentials for any accounts active on affected hosts due to confirmed keylogging capability", "Audit scheduled tasks across the environment for unauthorized or recently created entries", "Review regsvr32 execution logs in EDR/SIEM for suspicious DLL invocations", "Inspect LSASS access logs for non-system processes accessing lsass.exe", "Analyze network flow data for beaconing patterns on non-standard ports", "Check for TrickBot IOCs given shared infrastructure confirming likely co-infection", "Engage email security team to audit gateways and warn users as Emotet spreads via malicious email", "Deploy Credential Guard on Windows endpoints to protect LSASS", "Restrict regsvr32 via AppLocker or WDAC policy to prevent LOLBin abuse", "Enable MFA on VPN, email, and all privileged accounts", "Implement SMB signing and network segmentation to limit lateral movement", "Conduct full threat hunt using Emotet Epoch 5 IOC feeds from CISA, Abuse.ch, and MalwareBazaar", "Preserve forensic images of affected hosts and consider notifying CISA and FBI IC3", "Escalate to executive leadership and engage an incident response retainer given imminent ransomware risk" ], "related_iocs": [ "203.0.113.42", "203.0.113.88", "192.0.2.101", "update-service-cdn.ru", "cdn-api-gateway.cc", "a1b2c3d4...abcdef01", "update_service.dll" ] } --- secure-bankofamerica-login.com --- { "ioc": "secure-bankofamerica-login.com", "ioc_type": "domain", "severity": "critical", "confidence": 92, "threat_classification": "phishing", "summary": "secure-bankofamerica-login.com is a confirmed, actively operating phishing domain impersonating Bank of America, registered via a privacy-shielding registrar in Panama and hosted on bulletproof infrastructure in Moldova. The domain employs credential harvesting tactics including TLS certificate spoofing and deceptive keyword-stuffed naming, and has been corroborated as malicious by URLhaus. Immediate blocking and incident response actions are required, as this domain is part of an organized phishing campaign cluster with 12 identified related domains.", "related_malware": [ "phishing-kit" ], "related_threat_groups": [ "TA505", "FIN7", "Wizard Spider" ], "mitre_techniques": [ { "technique_id": "T1598.003", "technique_name": "Spearphishing Link for Information", "tactic": "Reconnaissance" }, { "technique_id": "T1566.002", "technique_name": "Phishing: Spearphishing Link", "tactic": "Initial Access" }, { "technique_id": "T1056.001", "technique_name": "Input Capture: Keylogging / Web Form", "tactic": "Credential Access" }, { "technique_id": "T1555.003", "technique_name": "Credentials from Web Browsers", "tactic": "Credential Access" }, { "technique_id": "T1071.001", "technique_name": "Application Layer Protocol: Web", "tactic": "Command and Control" }, { "technique_id": "T1573.002", "technique_name": "Encrypted Channel: Asymmetric Cryptography", "tactic": "Command and Control" }, { "technique_id": "T1008", "technique_name": "Fallback Channels", "tactic": "Command and Control" } ], "recommended_actions": [ "Block secure-bankofamerica-login.com at all DNS resolvers, proxies, firewalls, and email security gateways immediately", "Block hosting IPs 192.0.2.55 and 192.0.2.56 at perimeter firewall and proxy", "Block nameservers ns1.bulletproof-dns.cc and ns2.bulletproof-dns.cc to prevent resolution of related domains", "Search email gateway logs for inbound messages containing this URL or the string 'bankofamerica-login' and quarantine matches", "Search DNS and web proxy logs for internal hosts that have already resolved or accessed this domain and treat as potentially compromised", "Investigate and block the 12 similar domains identified during the investigation", "Submit abuse reports to NameSilo, URLhaus, PhishTank, APWG, and Google Safe Browsing", "Notify Bank of America brand protection team at abuse@bankofamerica.com for expedited takedown", "Deploy SIEM and EDR detection rules for the domain pattern bankofamericalogin*", "Conduct threat hunting using MITRE techniques T1566.002 and T1056.001 across the environment", "Implement or validate DMARC, DKIM, and SPF policies to reduce spoofed email delivery risk", "Implement FIDO2 or hardware MFA for banking and critical accounts to render harvested credentials non-replayable", "Report infrastructure to CERT-MD and notify FS-ISAC regarding this campaign cluster", "Integrate lookalike domain monitoring tooling for ongoing early detection of new phishing infrastructure" ], "related_iocs": [ "192.0.2.55", "192.0.2.56", "ns1.bulletproof-dns.cc", "ns2.bulletproof-dns.cc" ] } Summary and next steps This cookbook demonstrated how to build a threat intelligence enrichment agent that autonomously investigates IOCs by querying multiple data sources, cross-referencing findings, and producing structured reports. The key patterns you can take away: