Skip to main content
DFIRLab
ResearchUse CasesCompare
Intel BriefingsThreat Actors
IOC CheckFile AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
WikiAbout
PlatformNew
DFIRLab

Security research, threat intelligence, and free DFIR tools.

Tools

Phishing CheckerExposure ScannerDomain LookupFile AnalyzerPrivacy Check

Use Cases

SOC Phishing TriageIR IOC EnrichmentMSSP Exposure Monitoringn8n AutomationSee all use cases →

Compare

vs VirusTotalvs Shodanvs TheHiveSee all 8 →

Resources

DFIR WikiIntel BriefingsAboutPlatformAPI Docs

Legal

Privacy PolicyRSS FeedSitemap

© 2026 DFIR Lab. All rights reserved.

USE CASES
12
PERSONAS
7
CAPABILITIES
50
UPDATED
April 2026
USE CASE CATALOG

Case files by persona — pick the page that matches your team.

These are not marketing pages. Each entry lists the exact endpoints, real code, and verifiable credit math for one specific persona × capability combination.

Compare against other toolsJump to catalog
Personas
  • SOC
  • IR & Forensics
  • MSSP
  • Compliance
  • Education
  • Integrations
  • Freelance
01·CATALOG
01
SOC ANALYST

Automated Phishing Triage for SOC Teams

Tier 1 SOC analysts drown in user-reported phishing. DFIR Platform turns a 10-minute manual review into a 30-second API call — header parsing, SPF/DKIM/DMARC verdict, AI explanation, and multi-source enrichment of every extracted IOC, all in one workflow.
ENDPOINTS
4
TIER
Starter
FAQ
6
ENDPOINTS4TIERStarterFAQ6
02
IR CONSULTANT

IOC Enrichment for Incident Response

Hour one of an incident is IOC triage. You have a CSV from the client's EDR, a list of suspicious IPs from firewall logs, and a handful of hashes from a suspect host — and every minute spent pasting into VirusTotal tabs is a minute the attacker keeps the initial access. DFIR Platform collapses that hour into a single batch API call.
ENDPOINTS
4
TIER
Starter
FAQ
6
ENDPOINTS4TIERStarterFAQ6
03
MSSP OPERATOR

Continuous Exposure Monitoring for MSSPs

MSSPs get paid to surface what their clients missed — but running weekly attack-surface scans across 50, 100, 200 client orgs does not scale on per-seat enterprise VM pricing. DFIR Platform exposes one API that takes a domain and returns normalized exposure data, so the only thing your runbook has to do is loop over the client list.
ENDPOINTS
4
TIER
Professional
FAQ
6
ENDPOINTS4TIERProfessionalFAQ6
04
DETECTION ENGINEER

Threat Intelligence API for Security Teams

In-house TI aggregation is glue code — N rate-limiters, N auth schemes, N response schemas, and a Slack channel full of 'the VT API changed again'. DFIR Platform exposes one endpoint, one Bearer token, one normalized response schema, and one rate-limit bucket across every source a detection engineer actually uses.
ENDPOINTS
4
TIER
Professional
FAQ
6
ENDPOINTS4TIERProfessionalFAQ6
05
EMAIL SECURITY ENGINEER

Email Security Automation via API

You own the email pipeline — the gateway, the reporting button, the forward-to-IT mailbox, the BEC response playbook. Vendor auto-triage is opaque, brittle, and priced per seat. DFIR Platform gives you deterministic JSON per email and per inbox, so your rules stay your rules.
ENDPOINTS
6
TIER
Professional
FAQ
6
ENDPOINTS6TIERProfessionalFAQ6
06
AUTOMATION ENGINEER

Security Automation with n8n + DFIR Platform

n8n is the fastest way to stitch together a SOAR-style automation without paying enterprise licensing. DFIR Platform plugs into n8n through its built-in HTTP Request node — one Bearer-auth credential covers phishing triage, multi-source IOC enrichment, and exposure scanning across every workflow you build.
ENDPOINTS
4
TIER
Starter
FAQ
6
ENDPOINTS4TIERStarterFAQ6
07
SPLUNK / DETECTION ENGINEER

IOC Enrichment for Splunk

Splunk is where most SOC teams live, but SPL stops at the data you ingest — nothing in Splunk natively tells you whether an IP in your logs is a botnet node or a benign CDN. DFIR Platform plugs that gap with a custom search command that calls a single enrichment API from inside the search pipeline.
ENDPOINTS
3
TIER
Professional
FAQ
4
ENDPOINTS3TIERProfessionalFAQ4
08
THEHIVE / SOC ENGINEER

DFIR Platform as a TheHive Cortex Analyzer

TheHive is a leading open-source case manager, and Cortex is its companion analyzer framework. Most teams wire up a dozen Cortex analyzers — one per TI source — each with its own API key and quota. DFIR Platform collapses that into one analyzer that queries all of them in parallel.
ENDPOINTS
3
TIER
Professional
FAQ
4
ENDPOINTS3TIERProfessionalFAQ4
09
WAZUH / SOC ENGINEER

Alert Enrichment for Wazuh

Wazuh agents generate high alert volume — firewall hits, suspicious processes, FIM changes. The raw observable is there, but the reputation context isn't. DFIR Platform plugs into Wazuh's `integratord` daemon so alerts arrive at the analyst with risk score and TI verdict already attached.
ENDPOINTS
3
TIER
Professional
FAQ
4
ENDPOINTS3TIERProfessionalFAQ4
10
COMPLIANCE OFFICER / CISO

Attack Surface Management for NIS2 / DORA Compliance

NIS2 and DORA require regulated entities to maintain documented oversight of their external attack surface and to review it on a periodic basis. Enterprise VM suites are priced per-asset and gated behind sales calls. DFIR Platform gives you a scriptable exposure scanner, multi-source IOC context, and an AI-written board summary — priced per credit, no seat minimums.
ENDPOINTS
4
TIER
Professional
FAQ
6
ENDPOINTS4TIERProfessionalFAQ6
11
EDUCATOR / STUDENT

DFIR Training Tools for Students and Educators

Teaching digital forensics requires real indicators, real enrichment, and real sandbox output — but commercial TI feeds ban educational use and enterprise licensing locks classrooms out. DFIR Platform ships an explicit Academic tier at $9/month with 500 credits, 2 API keys, and full access to the phishing, IOC, and file-analysis endpoints.
ENDPOINTS
5
TIER
Academic
FAQ
6
ENDPOINTS5TIERAcademicFAQ6
12
FREELANCE CONSULTANT

DFIR Toolkit for Freelance Consultants

Independent DFIR and IR consultants need enterprise-grade tooling on an independent-consultant budget. DFIR Platform packages multi-source IOC enrichment, file triage, exposure scanning, and AI-assisted report writing behind one self-serve API key — from $29/month, no annual contract, commercial use permitted.
ENDPOINTS
6
TIER
Starter
FAQ
6
ENDPOINTS6TIERStarterFAQ6