Verify the decisions you just made
Replay the actions your SIEM and SOAR just took. Get the agree / coverage gap / over-block breakdown back, audit-defensible while the response window is still open.
See full use caseGrab the batch your SOC just acted on, an incident's IOC list or yesterday's block log, and send it as one POST /verdict/bulk call. Minutes later the disagreements are back: over-blocks to lift, coverage gaps to close, each carrying the full signal set that produced it. Nothing to deploy, nothing to schedule.
Numbers are illustrative. Every row opens with its signal trail in the portal.
POST /verdict/bulk accepts the same indicators as the single-IOC verdict call: domains today, with IP, CIDR, ASN and file hash coming soon, in any mix. Three different teams reach for it for three different reasons; verification is the loudest, the other two are just as bulk-native.
Replay the actions your SIEM and SOAR just took. Get the agree / coverage gap / over-block breakdown back, audit-defensible while the response window is still open.
See full use caseOne bulk call instead of 10,000 single /verdict requests. A full shift's verdicts finish in minutes, not hours. Same deterministic scoring, batch-shape latency.
See full use caseA single incident often carries five to fifty indicators. Send the domains all at once and read the whole ticket's verdict in one response; IP, CIDR, ASN and file hash are coming soon.
See full use caseTwo verification surfaces share the same verdict engine; they differ in when they run.
On demand and deliberately easy: paste a list or send one bulk call, read the three buckets while the response window is still open. Built for the moment you are holding a specific batch, an incident's IOCs, an audit sample, yesterday's block log.
Blind Spot Analysis scores the actions you report on the queries your stack is already making, continuously, in the portal. A standing coverage view of live traffic instead of a one-off answer.
See Blind Spot Analysis →Most threat intelligence gives you the score and stops there. /verdict/bulk runs the second pass: it takes the action your stack already took, compares it to today's verdict, and surfaces every IOC where the two disagree.
A classic TI feed gives you data: WHOIS, passive DNS, vendor flags. The decision still hangs on the analyst.
Bulk Replay reads the decisions you already made and closes the feedback loop. Same deterministic verdict, same signal trail, applied to a batch instead of a single call. The audit gets a defensible answer; the SOC gets a queue of fixes.
Throughput is the bulk endpoint's second life. Push 1,000-10,000 IOCs in a single request and the response carries the same deterministic verdict and signal trail per item, batch-shape latency. SIEM enrichers, SOAR pipelines and MSSP multi-tenant batch jobs use this path when scale matters more than verification.
SIEM enricher · SOAR pipeline · MSSP batch
A typical SOC ticket carries dozens of domains: the suspicious URLs the user clicked, the lookalikes behind the callbacks, the hosts the alert chained through. Send the whole set in one /verdict/bulk call and read every verdict in one response. IP, CIDR, ASN and file hash are coming soon.
Open the ticket, fire one call, read every verdict in the same pane. No copy-paste between SIEM, WHOIS lookup and reputation tabs.
Each ticket's full IOC verdict + signal chain archived together. The auditor sees what your analyst saw, in one place.
SOC tier 1 · IR analyst · ticket triage
Coming soon:IP · CIDR · ASN · SHA256
Quarterly forensics surface past mistakes weeks late. Bulk decision verification surfaces them while the incident response window is still open.
“What did we miss last quarter?”
“Which of the blocks we just made were wrong, and what did we miss?”
Bulk decision verification is not post-incident forensics. If you need payload analysis or campaign mapping, pair it with payload-analysis or threat-hunting tooling. We surface what disagreed; we don't reproduce the kill chain.
Start with one batch your SOC just acted on. Get the deltas back, ready to defend at the next audit review.