OSINT · SOC · CSIRT

OSINT for SOC, CSIRT and blue teams

OSINT for SOC and CSIRT teams: fast IOC triage (IP, domain, email), phishing investigation and documented chain of custody. Built for SOCs, CSIRTs, MSSPs and threat intelligence teams.

What OSINT solves in a security operations room

Three tasks an analyst repeats several times a day that take too many minutes per ticket with manual tools.

Fast IOC triage

A suspicious IP, domain or email analyzed against 30+ sources in seconds. Reputation, hosting, RPKI, co-hosting and aggregated threat intel.

🎣

Phishing investigation

Follow a suspicious domain’s thread to its full infrastructure: WHOIS, SSL certificates, passive DNS, sibling domains and associated campaigns.

📑

Custody for tickets

Every analysis is delivered as a PDF with a SHA-256 hash and an RFC 3161 timestamp. Attachable to a SIRT ticket or the incident report.

Who uses it

Defensive teams who need to resolve IOCs in minutes without waiting for a complex integration.

🛡️

Internal SOCs

Operations teams in companies and government.

🏢

MSSPs

Managed security services and outsourced NOC/SOC.

🚨

CSIRT / CERT

Incident response teams and sector coordination.

🔬

Threat intelligence

Intelligence analysts, blue team and red/purple team defenders.

The three tools a SOC uses most

The typical entry points for triage. The rest of the catalog is there for lateral investigation.

⭐ Essential

IP analysis

To quickly enrich a suspicious IP before blocking, escalating or closing the ticket.

  • ASN, geolocation, hosting/cloud, RPKI
  • Aggregated reputation from 30+ threat-intel sources
  • Co-hosting (domains and other assets on the IP)
  • Historical passive DNS
See tool →
⭐ Essential

Domain analysis

To follow the thread of a phishing domain and map a campaign’s full infrastructure.

  • Historical WHOIS / RDAP
  • SSL certificates and CT logs
  • Sibling domains and typosquatting
  • Current hosting + passive DNS
See tool →
⭐ Essential

Email analysis

To validate a suspicious mailbox or a phishing campaign’s sender before sending the alert.

  • Technical validity, MX, SPF, DKIM, DMARC
  • Domain reputation and disposable detection
  • Presence in leaks and breaches
  • Linked accounts across platforms
See tool →

Complementary for lateral investigation: phone, social media and image.

Three typical cases in a SOC room

How the tools combine on a normal day of operations.

CASE 1

SIEM alert triage

An alert comes in with a suspicious destination IP. You analyze it in seconds: reputation, ASN, co-hosting, threat intel. You decide whether to dismiss, block or escalate to a deeper investigation.

CASE 2

Phishing investigation

A domain enters the anti-phishing campaign. You trace it through WHOIS, SSL certificate, passive DNS, sibling domains. You reconstruct the campaign’s infrastructure in minutes.

CASE 3

Reporting to the CISO

Closing the incident: you attach each analysis’s PDF, with RFC 3161 chain of custody, to the ticket. Documentation ready for audit or a CISO presentation with no extra effort.

🔜 On the roadmap · Q4 2026

REST API for native SIEM/SOAR integration

Authenticated HTTPS endpoints for automated IOC enrichment from your pipeline. Native connectors for Splunk, Microsoft Sentinel, Elastic, TheHive and MISP.

Still in development. Today, analysis runs via the web interface with CSV/JSON export. Sign up if you want early access and to help us prioritize connectors.

No spam. We’ll only write when the REST API is available for testing and we want early feedback.
We heard you! We’re actively building the SOC REST API. We’ll write to you as soon as it’s available for testing — and in the meantime we’ve sent you an email confirming your signup.
That email doesn’t look valid. Please check it and try again.

Frequently asked questions

What SOCs and response teams ask most before trying it.

Does IntelMind integrate with my SIEM or SOAR today?
Today, analysis runs via the web interface. We support exporting results as PDF, CSV or JSON to attach manually to your ticket or pipeline. The native REST API for automated integration with Splunk, Sentinel, Elastic, TheHive or MISP is in development, expected Q4 2026. Sign up for early access.
Do you support STIX/TAXII or MISP feeds?
Not yet. STIX, TAXII and MISP will be evaluated while building the REST API based on waitlist feedback. For now, everything extracted can be exported as CSV or JSON.
How does it fit into a threat intelligence team?
As a fast OSINT enrichment layer on specific IOCs during an investigation. It doesn’t replace commercial TI feeds (Recorded Future, Anomali, etc.) — it complements them when you need to chase a specific asset in detail (co-hosting, historical passive DNS, certificates, staff exposure).
How long does an analysis take?
Email and phone: 5–15 seconds. IP and domain: 30–60 seconds with all sources (RPKI, passive DNS, aggregated threat intel). Forensic image analysis: 1–5 minutes depending on depth.
Is an IntelMind report defensible in an audit or before a regulator?
Every report is delivered as a PDF with a SHA-256 hash, an RFC 3161 timestamp issued by FreeTSA, and a public verification URL. It’s defensible electronic evidence, attachable to SIRT tickets, CISO reports or regulator requests.
Is there a dedicated plan for high-volume SOC teams?
The Firma (700 credits/mo) and Corporativo (2,000 credits/mo) plans are built for teams with a recurring caseload of IOCs. One-off top-up packs and contractable volume are available for larger SOCs. See plans and credits.

Triage your next IP in under a minute

Free 14-day demo. Try it with a real IP or domain from your ticket queue before committing budget.

OSINT for SOC and CSIRT — correlated threat intel with 4D scoring
Regulatory framework and official resources

About OSINT for SOC and CSIRT

These are the legal frameworks, institutions and authority references behind the professional use of OSINT for SOC and CSIRT with IntelMind: