Threat verdicts
you can prove.
Hunt threats and defend faster than ever. AI built into your workflow weighs the evidence and delivers a verdict you can trust.
One evidence-first engine. Three ways to use it.
The same reproducible scoring runs underneath all of it — whether you're running a SOC, checking a single indicator, or building on the score itself.
Platform
Defensible verdicts your team can hand to an examiner.
The operational layer priced on volume and instances — not seats. Connect your stack, work every indicator to a decision you can defend, with audit, isolation, and calibration built in.
Explore PlatformLookup
One indicator in. A verdict you can defend out.
Paste an IP, domain, URL, hash, CVE, or malware family and get a reproducible verdict — with the evidence, the source agreement, and a full dossier. No integration, no setup.
Explore LookupScoring
A score that reasons like an analyst.
The transparent, reproducible scoring that powers every verdict. It weighs sources by credibility, stays honest about uncertainty, and gets sharper as it learns what indicators truly became.
Explore ScoringFrom Sighting to the Whole Picture.
The same AI runs every step. It pulls your sources, scores the indicator, and links the verdict to everything it touches, so one lookup becomes the whole picture instead of a dead end. The call stays yours.
Every Feed. One Evidence Stream.
Commercial, OSINT, ISAC, and internal telemetry land as typed evidence with source, confidence, and observation time. The AI pulls and organizes it the moment it arrives, so there are no flat IOC lists to sort by hand and every claim is auditable from the start.
Learn MoreEvery Score, Explained.
Open any indicator and see exactly which evidence drove the verdict, weighted by source confidence and recency. Transitive claims are bridged at a reduced weight to prevent false-attribution propagation. Low completeness is labeled, not buried.
- Internal observation is the strongest single relevance signal. Volume is shown but never weighted.
- Mass scanners are explicitly identified and suppressed unless seen on your network.
- Ranking is per-analyst, tuned by active intelligence requirements.
Research at the speed of thought.
An investigation shouldn't be a scavenger hunt across ten tabs. One keystroke takes you anywhere, the agent runs the pivots while you keep your hands on the keyboard, and the evidence comes back the moment you ask. Fast enough to stay in flow — and every move still leaves a trail you can defend.
- Command paletteHit ⌘K from anywhere and go straight to any indicator, past lookup, or view — no menus, no mouse.
- Slash the pivotType /associations, /cve, or /compare and the agent runs the next move for you, then hands back the evidence.
- Paste anythingDrop a defanged IOC or a messy log dump; the values extract and refang themselves, ready to score.
- Copy as anythingLift a full verdict as Markdown, CSV, or STIX 2.1 in one click — report-ready, share-ready.
- See what changedReopen an indicator and the delta is right there — how severity, score, and sources moved since your last look.
Same evidence in. Same verdict out.
A verdict isn't a guess that drifts between runs. The same evidence always produces the same result, and a decision made last quarter can be re-derived today, exactly. That's the difference between a score and something you can stand behind.
Reproducible
Run it twice and get the same answer. A verdict from last quarter re-derives today, down to the evidence that drove it. A score you can reproduce is a score you can defend.
Explainable
Every verdict opens to the evidence behind it — which sources reported the indicator, how far each was trusted, and where they agreed. No black box, no shrug.
Yours to act on
We surface the decision with its confidence and the evidence attached. We never auto-enforce. The block, the isolate, the takedown stays your team's call.
Compose your own surfaces on the same primitives.
Subscribe to typed verdict and disposition events and wire them into the tools you already run — EDR, NGFW, SIEM — or build new analyst surfaces in days, not quarters. Every action is tenant-scoped, justification-tagged, and audit-logged, and enforcement stays a decision your team makes.
- Remote MCP for Claude
- Sign in — no token to copy
- Typed events + webhooks
- Push to EDR / NGFW / email
Connect Lookup as a remote MCP server and Claude triages indicators with everything you'd get in the app — the same evidence, the same reproducible score, and the written assessment behind it. Sign in once; no token to copy, and your plan and limits still apply.
Stop shipping verdicts no one can defend.
See how an evidence-first model changes what your team does on a Monday morning. A 30-minute walkthrough on your data, your requirements, your controls.