Skip to content
POST /enrich_bulk

Verify every decision your stack already made.

Send the batch your SOC just acted on. POST /enrich_bulk returns the verdicts that disagree, each one carrying the full signal set that produced it, so you fix the false positives, catch the false negatives, and keep your blocks defensible while the response window is still open.

Same deterministic verdictsAudit-ready signal trailYour logs stay home
Sample · decision verification output
batch_a4f912,480 IOCs · 72ms
Domaincdn-xxx-service[.]netFalse negativeHigh Risk
IP185.xxx.108[.]42Risk driftSuspicious
Domainlogin.exa-xxx[.]comFalse positiveClean
CIDR45.xxx.205[.]0/24ConfirmedHigh Risk
ASNAS14xxxRisk driftSuspicious
Domainsupport-xxx-portal[.]coConfirmedLow Risk

Sample batch summary. Replay your own queue to see how each decision scores today.

Replay your own batch
01 · USE CASES

Three jobs, five indicator types, one endpoint.

POST /enrich_bulk accepts the same five indicators as single-IOC enrichment (domain, IP, CIDR, ASN, file hash) in any mix. Three different teams reach for it for three different reasons; verification is the loudest, the other two are just as bulk-native.

Verify the decisions you just made

Replay the actions your SIEM and SOAR just took. Get the FP/FN/drift list back, audit-defensible while the response window is still open.

SOC tier 2-3 · audit defense

See full use case

Score 10,000 IOCs in one call

One bulk call instead of 10,000 single /enrich requests. A full shift's enrichment finishes in minutes, not hours. Same deterministic scoring, batch-shape latency.

SIEM enricher · SOAR pipeline · MSSP batch

See full use case

One ticket, every IOC in it

A single incident often carries five to fifty mixed indicators: domains, IPs, ASN, CIDR, file hash. Send them all at once and read the whole ticket's verdict in one response.

SOC tier 1 · IR analyst

See full use case
02 · CLOSED LOOP

Enrichment scores the IOC.
Verification checks if your action was right.

Most threat intelligence gives you the score and stops there. /enrich_bulk runs the second pass: it takes the action your stack already took, compares it to today's verdict, and surfaces every IOC where the two disagree.

Others

A classic TI feed gives you data: WHOIS, passive DNS, vendor flags. The decision still hangs on the analyst.

VerdictIQ

Decision Verification reads the decisions you already made and closes the feedback loop. Same deterministic verdict, same signal trail, applied to a batch instead of a single call. The audit gets a defensible answer; the SOC gets a queue of fixes.

03 · SCALE

Score ten thousand IOCs without breaking your loop.

Throughput is the bulk endpoint's second life. Push 1,000-10,000 IOCs in a single request and the response carries the same deterministic verdict and signal trail per item, batch-shape latency. SIEM enrichers, SOAR pipelines and MSSP multi-tenant batch jobs use this path when scale matters more than verification.

POST /enrich_bulk10,000 IOCs~ minutes, not hours

SIEM enricher · SOAR pipeline · MSSP batch

04 · TICKET SCOPE

One ticket, every IOC in it.

A typical SOC ticket carries dozens of domains and IPs: the suspicious URLs the user clicked, the hosts they resolved to, the addresses behind the callbacks. CIDR, ASN and file hash show up when the ticket needs them. Send the whole set in one /enrich_bulk call and read every verdict in one response.

No tab switching

Open the ticket, fire one call, read every verdict in the same pane. No copy-paste between SIEM, WHOIS lookup and reputation tabs.

One audit trail per ticket

Each ticket's full IOC verdict + signal chain archived together. The auditor sees what your analyst saw, in one place.

SOC tier 1 · IR analyst · ticket triage

Also supported:CIDR · ASN · SHA256

05 · WHY REPLAY

Forensics asks what we missed. Verification asks what to fix today.

Quarterly forensics surface past mistakes weeks late. Bulk decision verification surfaces them while the incident response window is still open.

THE FORENSIC QUESTION
What did we miss last quarter?
Forensic analysis plus threat hunt, weeks later, hard to action while the window is still open.
THE VERIFICATION QUESTION
Which of the blocks we just made were wrong, and what did we miss?
Replayable in minutes, every delta cited, ready to defend at the next audit review.

Bulk decision verification is not post-incident forensics. If you need payload analysis or campaign mapping, pair it with payload-analysis or threat-hunting tooling. We surface what disagreed; we don't reproduce the kill chain.

06 · FOUR BUCKETS

One batch in. Four buckets out.

Every event you send lands in exactly one of four buckets. The verdict structure is identical to single-IOC enrichment; what changes is the audit lens we run it through.

Confirmed · 11,872

Your action matches our verdict. Block stays block, allow stays allow. Most of the batch lands here.

False positives · 412

You blocked something we would allow. Legitimate traffic cut by mistake. Each one ships with the signals that exonerate it, so you can roll the block back with evidence.

False negatives · 73

You allowed something we would block. Malicious traffic that slipped past your existing rules. Behavioral signals catch what reputation feeds missed.

Risk drift · 123

Same action, different score today. The IOC's signals have shifted since you decided. Not a delta yet, but worth watching in the next batch.

Replay your live queue in minutes.

Start with one batch your SOC just acted on. Get the deltas back, ready to defend at the next audit review.

GDPR alignedLLM-free by defaultOwn infrastructureAudit-ready signal trail
See our security posture