Skip to content
POST /verdict/bulk

Verify every decision your stack already made.

Grab the batch your SOC just acted on, an incident's IOC list or yesterday's block log, and send it as one POST /verdict/bulk call. Minutes later the disagreements are back: over-blocks to lift, coverage gaps to close, each carrying the full signal set that produced it. Nothing to deploy, nothing to schedule.

Same deterministic verdictsAudit-ready signal trailNo setup, no pipeline
Representative product screen
Bulk Replaybatch_a4f9 · 12,480 IOCs · 3:12
Agreed11,995Your action and the verdict agree
Coverage gap73Allowed; the verdict says block
Over-block412Blocked; the verdict says allow
Enter your IOCs, open the report

Numbers are illustrative. Every row opens with its signal trail in the portal.

USE CASES

Three jobs, one endpoint.

POST /verdict/bulk accepts the same indicators as the single-IOC verdict call: domains today, with IP, CIDR, ASN and file hash coming soon, in any mix. Three different teams reach for it for three different reasons; verification is the loudest, the other two are just as bulk-native.

Verify the decisions you just made

Replay the actions your SIEM and SOAR just took. Get the agree / coverage gap / over-block breakdown back, audit-defensible while the response window is still open.

See full use case

Score 10,000 IOCs in one call

One bulk call instead of 10,000 single /verdict requests. A full shift's verdicts finish in minutes, not hours. Same deterministic scoring, batch-shape latency.

See full use case

One ticket, every IOC in it

A single incident often carries five to fifty indicators. Send the domains all at once and read the whole ticket's verdict in one response; IP, CIDR, ASN and file hash are coming soon.

See full use case
REPLAY OR WATCH THE STREAM

Replay on demand. Blind Spot watches the stream.

Two verification surfaces share the same verdict engine; they differ in when they run.

This page

Bulk Replay: one batch, minutes later

On demand and deliberately easy: paste a list or send one bulk call, read the three buckets while the response window is still open. Built for the moment you are holding a specific batch, an incident's IOCs, an audit sample, yesterday's block log.

Continuous sibling

Blind Spot Analysis: your live traffic, continuously

Blind Spot Analysis scores the actions you report on the queries your stack is already making, continuously, in the portal. A standing coverage view of live traffic instead of a one-off answer.

See Blind Spot Analysis
CLOSED LOOP

Enrichment scores the IOC.
Verification checks if your action was right.

Most threat intelligence gives you the score and stops there. /verdict/bulk runs the second pass: it takes the action your stack already took, compares it to today's verdict, and surfaces every IOC where the two disagree.

Others

A classic TI feed gives you data: WHOIS, passive DNS, vendor flags. The decision still hangs on the analyst.

VerdictIQ

Bulk Replay reads the decisions you already made and closes the feedback loop. Same deterministic verdict, same signal trail, applied to a batch instead of a single call. The audit gets a defensible answer; the SOC gets a queue of fixes.

SCALE

Score ten thousand IOCs without breaking your loop.

Throughput is the bulk endpoint's second life. Push 1,000-10,000 IOCs in a single request and the response carries the same deterministic verdict and signal trail per item, batch-shape latency. SIEM enrichers, SOAR pipelines and MSSP multi-tenant batch jobs use this path when scale matters more than verification.

POST /verdict/bulk10,000 IOCs~ minutes, not hours

SIEM enricher · SOAR pipeline · MSSP batch

TICKET SCOPE

One ticket, every IOC in it.

A typical SOC ticket carries dozens of domains: the suspicious URLs the user clicked, the lookalikes behind the callbacks, the hosts the alert chained through. Send the whole set in one /verdict/bulk call and read every verdict in one response. IP, CIDR, ASN and file hash are coming soon.

No tab switching

Open the ticket, fire one call, read every verdict in the same pane. No copy-paste between SIEM, WHOIS lookup and reputation tabs.

One audit trail per ticket

Each ticket's full IOC verdict + signal chain archived together. The auditor sees what your analyst saw, in one place.

SOC tier 1 · IR analyst · ticket triage

Coming soon:IP · CIDR · ASN · SHA256

WHY REPLAY

Forensics asks what we missed. Verification asks what to fix today.

Quarterly forensics surface past mistakes weeks late. Bulk decision verification surfaces them while the incident response window is still open.

THE FORENSIC QUESTION
What did we miss last quarter?
Forensic analysis plus threat hunt, weeks later, hard to action while the window is still open.
THE VERIFICATION QUESTION
Which of the blocks we just made were wrong, and what did we miss?
Replayable in minutes, every delta cited, ready to defend at the next audit review.

Bulk decision verification is not post-incident forensics. If you need payload analysis or campaign mapping, pair it with payload-analysis or threat-hunting tooling. We surface what disagreed; we don't reproduce the kill chain.

Replay your live queue in minutes.

Start with one batch your SOC just acted on. Get the deltas back, ready to defend at the next audit review.

GDPR alignedLLM-free by defaultOwn infrastructureAudit-ready signal trail
See our security posture