Skip to main content
DFIRLab
ResearchUse CasesCompare
Intel BriefingsThreat Actors
IOC CheckFile AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
Log → SplunkLog → Sentinel
WikiAbout
PlatformNew
DFIRLab

Security research, threat intelligence, and free DFIR tools.

Tools

Phishing CheckerExposure ScannerDomain LookupFile AnalyzerPrivacy CheckLog → SplunkLog → SentinelAPI Playground

Use Cases

SOC Phishing TriageIR IOC EnrichmentMSSP Exposure Monitoringn8n AutomationSee all use cases →

Compare

vs VirusTotalvs Shodanvs TheHiveSee all 8 →

Resources

DFIR WikiIntel BriefingsAboutPlatformAPI Docs

Legal

Privacy PolicyRSS FeedSitemap

© 2026 DFIR Lab. All rights reserved.

← All Tags
TAG

soc

10 posts
phishingemail-securityemail-headers+8

How to Analyze Phishing Email Headers: A Complete Guide for SOC Analysts

Apr 11, 202610 min read
TheHiveIOC EnrichmentCortex+3

DFIR Platform + TheHive: Automated IOC Enrichment for Case Management

Integrate DFIR Platform's multi-source IOC enrichment API with TheHive as a Cortex analyzer. Python code examples, architecture walkthrough, and step-by-step setup for SOC teams.

Apr 12, 202611 min read
WazuhThreat IntelligenceAlert Enrichment+4

DFIR Platform + Wazuh: Real-Time Alert Enrichment

Integrate DFIR Platform's IOC enrichment API with Wazuh for real-time alert enrichment. Includes integratord configuration, active response scripts, and example alert workflows for SOC teams.

Apr 13, 202610 min read
SplunkIOC EnrichmentCustom Search Command+3

DFIR Platform + Splunk: IOC Enrichment via Custom Search Commands

Build a Splunk custom search command that enriches IOCs via DFIR Platform API. Includes Python code, commands.conf configuration, packaging as a Splunk app, and example SPL queries.

Apr 14, 202611 min read
oc-enrichmentThreat Intelligencevirustotal+4

VirusTotal API Alternative: Cheaper Multi-Source IOC Enrichment for Security Teams

Apr 15, 20269 min read
phishingemail-headerssoc+3

How to Analyze Phishing Email Headers: A Complete Guide for SOC Analysts

Learn how to analyze phishing emails like a SOC analyst: trace delivery paths, verify SPF/DKIM/DMARC, detect spoofing, and automate header analysis.

Apr 3, 202611 min read
IOC EnrichmentThreat Intelligenceapi+1

VirusTotal API Alternative: Cheaper Multi-Source IOC Enrichment for Security Teams

VirusTotal is the industry standard for IOC enrichment, but its rate limits and enterprise pricing leave small and mid-size teams behind. Here's how DFIR Platform compares as a VirusTotal API alternative for SOC analysts and MSSPs.

Apr 8, 20269 min read
Threat IntelligenceiocIOC Enrichment+3

IOC Enrichment Explained: Why Multi-Source Threat Intelligence Matters

Apr 22, 202610 min read
phishingemail-securitysoc+2

Phishing Email Analysis Tools Compared (2026)

May 16, 202611 min read
IOC EnrichmentThreat Intelligenceapi+2

IOC Enrichment APIs: Free vs Paid Options for SOC Teams

May 23, 202611 min read