Skip to main content
DFIRLab
ResearchUse CasesCompare
Intel BriefingsThreat Actors
IOC CheckFile AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
Log → SplunkLog → Sentinel
WikiAbout
PlatformNew
DFIRLab

Security research, threat intelligence, and free DFIR tools.

Tools

Phishing CheckerExposure ScannerDomain LookupFile AnalyzerPrivacy CheckLog → SplunkLog → SentinelAPI Playground

Use Cases

SOC Phishing TriageIR IOC EnrichmentMSSP Exposure Monitoringn8n AutomationSee all use cases →

Compare

vs VirusTotalvs Shodanvs TheHiveSee all 8 →

Resources

DFIR WikiIntel BriefingsAboutPlatformAPI Docs

Legal

Privacy PolicyRSS FeedSitemap

© 2026 DFIR Lab. All rights reserved.

USE CASES
12
PERSONAS
7
CAPABILITIES
50
UPDATED
April 2026
USE CASE CATALOG

Case files by persona — pick the page that matches your team.

These are not marketing pages. Each entry lists the exact endpoints, real code, and verifiable credit math for one specific persona × capability combination.

Compare against other toolsJump to catalog
Personas
  • SOC
  • IR & Forensics
  • MSSP
  • Compliance
  • Education
  • Integrations
  • Freelance
01·CATALOG
01
SOC ANALYST

Automated Phishing Triage for SOC Teams

Tier 1 SOC analysts drown in user-reported phishing. DFIR Platform turns a 10-minute manual review into a 30-second API call — header parsing, SPF/DKIM/DMARC verdict, AI explanation, and multi-source enrichment of every extracted IOC, all in one workflow.
ENDPOINTS
4
TIER
Starter
FAQ
6
ENDPOINTS4TIERStarterFAQ6
02
IR CONSULTANT

IOC Enrichment for Incident Response

Hour one of an incident is IOC triage. You have a CSV from the client's EDR, a list of suspicious IPs from firewall logs, and a handful of hashes from a suspect host — and every minute spent pasting into VirusTotal tabs is a minute the attacker keeps the initial access. DFIR Platform collapses that hour into a single batch API call.
ENDPOINTS
4
TIER
Starter
FAQ
6
ENDPOINTS4TIERStarterFAQ6
03
MSSP OPERATOR

Continuous Exposure Monitoring for MSSPs

MSSPs get paid to surface what their clients missed — but running weekly attack-surface scans across 50, 100, 200 client orgs does not scale on per-seat enterprise VM pricing. DFIR Platform exposes one API that takes a domain and returns normalized exposure data, so the only thing your runbook has to do is loop over the client list.
ENDPOINTS
4
TIER
Professional
FAQ
6
ENDPOINTS4TIERProfessionalFAQ6
04
DETECTION ENGINEER

Threat Intelligence API for Security Teams

In-house TI aggregation is glue code — N rate-limiters, N auth schemes, N response schemas, and a Slack channel full of 'the VT API changed again'. DFIR Platform exposes one endpoint, one Bearer token, one normalized response schema, and one rate-limit bucket across every source a detection engineer actually uses.
ENDPOINTS
4
TIER
Professional
FAQ
6
ENDPOINTS4TIERProfessionalFAQ6
05
EMAIL SECURITY ENGINEER

Email Security Automation via API

You own the email pipeline — the gateway, the reporting button, the forward-to-IT mailbox, the BEC response playbook. Vendor auto-triage is opaque, brittle, and priced per seat. DFIR Platform gives you deterministic JSON per email and per inbox, so your rules stay your rules.
ENDPOINTS
6
TIER
Professional
FAQ
6
ENDPOINTS6TIERProfessionalFAQ6
06
AUTOMATION ENGINEER

Security Automation with n8n + DFIR Platform

n8n is the fastest way to stitch together a SOAR-style automation without paying enterprise licensing. DFIR Platform plugs into n8n through its built-in HTTP Request node — one Bearer-auth credential covers phishing triage, multi-source IOC enrichment, and exposure scanning across every workflow you build.
ENDPOINTS
4
TIER
Starter
FAQ
6
ENDPOINTS4TIERStarterFAQ6
07
SPLUNK / DETECTION ENGINEER

IOC Enrichment for Splunk

Splunk is where most SOC teams live, but SPL stops at the data you ingest — nothing in Splunk natively tells you whether an IP in your logs is a botnet node or a benign CDN. DFIR Platform plugs that gap with a custom search command that calls a single enrichment API from inside the search pipeline.
ENDPOINTS
3
TIER
Professional
FAQ
4
ENDPOINTS3TIERProfessionalFAQ4
08
THEHIVE / SOC ENGINEER

DFIR Platform as a TheHive Cortex Analyzer

TheHive is a leading open-source case manager, and Cortex is its companion analyzer framework. Most teams wire up a dozen Cortex analyzers — one per TI source — each with its own API key and quota. DFIR Platform collapses that into one analyzer that queries all of them in parallel.
ENDPOINTS
3
TIER
Professional
FAQ
4
ENDPOINTS3TIERProfessionalFAQ4
09
WAZUH / SOC ENGINEER

Alert Enrichment for Wazuh

Wazuh agents generate high alert volume — firewall hits, suspicious processes, FIM changes. The raw observable is there, but the reputation context isn't. DFIR Platform plugs into Wazuh's `integratord` daemon so alerts arrive at the analyst with risk score and TI verdict already attached.
ENDPOINTS
3
TIER
Professional
FAQ
4
ENDPOINTS3TIERProfessionalFAQ4
10
COMPLIANCE OFFICER / CISO

Attack Surface Management for NIS2 / DORA Compliance

NIS2 and DORA require regulated entities to maintain documented oversight of their external attack surface and to review it on a periodic basis. Enterprise VM suites are priced per-asset and gated behind sales calls. DFIR Platform gives you a scriptable exposure scanner, multi-source IOC context, and an AI-written board summary — priced per credit, no seat minimums.
ENDPOINTS
4
TIER
Professional
FAQ
6
ENDPOINTS4TIERProfessionalFAQ6
11
EDUCATOR / STUDENT

DFIR Training Tools for Students and Educators

Teaching digital forensics requires real indicators, real enrichment, and real sandbox output — but commercial TI feeds ban educational use and enterprise licensing locks classrooms out. DFIR Platform ships an explicit Academic tier at $9/month with 500 credits, 2 API keys, and full access to the phishing, IOC, and file-analysis endpoints.
ENDPOINTS
5
TIER
Academic
FAQ
6
ENDPOINTS5TIERAcademicFAQ6
12
FREELANCE CONSULTANT

DFIR Toolkit for Freelance Consultants

Independent DFIR and IR consultants need enterprise-grade tooling on an independent-consultant budget. DFIR Platform packages multi-source IOC enrichment, file triage, exposure scanning, and AI-assisted report writing behind one self-serve API key — from $29/month, no annual contract, commercial use permitted.
ENDPOINTS
6
TIER
Starter
FAQ
6
ENDPOINTS6TIERStarterFAQ6