Skip to content
SOLUTIONS · SOC TIER 1-2

Tier-1 closes the ticket like a senior would.

The verdict, the evidence trail and a recommended action land inside the SIEM alert. The same call cuts false positives, catches zero-day infrastructure and feeds SOAR. No new console, no agent, no migration.

One verdict · every console
  • Splunk SOAR
  • Sentinel
  • Tines
  • Elastic
  • Chronicle
  • QRadar
  • XSOAR
  • Splunk
The same enriched verdict lands in the SIEM and SOAR you already run: no new console, no migration.
01 · WHAT TIER-1 LIVES WITH

Twelve minutes per IOC, half of it bookkeeping.

The SIEM fires. The analyst opens VirusTotal, WHOIS, Shodan and a CTI tab. Fifteen minutes later the verdict is still ambiguous and the queue grew.

Reputation feeds say 2/73 vendors flagged a domain. The analyst cannot defend that to a tier-2 lead, let alone an audit. The choice collapses to escalate-by-default or close-by-fatigue. Both hurt: escalations clog tier-2, fatigue lets real threats through.

Most of the twelve minutes is not analysis. It is stitching: copy IOC, paste in VirusTotal, copy WHOIS dates, eyeball the SSL, hunt for co-tenancy. The signal exists. The bookkeeping buries it.

VirusTotal says 3 out of 73. What am I supposed to do with that?
02 · WHAT LANDS IN THE ALERT

Pre-hoc verdict in the payload. No tab-hopping.

Every alert payload calls POST /enrich. The verdict, the recommended_action and the signal trail enrich the alert before the analyst reads the first line.

Before · 4 tabs, ~12 min
  • VirusTotal: 3/73, inconclusive
  • WHOIS / RDAP: copy the dates
  • Shodan: eyeball the SSL
  • CTI tab: hunt co-tenancy

Minutes later, the verdict is still ambiguous.

After · 1 call
  • verdict + risk_score
  • recommended_action
  • signal trail + one-line evidence

Defensible in seconds. The ticket closes.

03 · THE VERDICT IN ACTION

One verdict. The whole tier-1 decision.

If tier-2 review is needed, the signal hierarchy (Group, Subgroup, signal and evidence) is already in the payload. No re-pivot. The audit trail is born with the verdict.

What /enrich returns
secure-•••[.]helpCritical
risk_score
96
recommended_action
block_domain
evidence_saturation
4 / 5
What the verdict tells you to do
  • block_domain · allowtier-1 closes the ticket
  • alert · monitortier-1 actions per runbook
  • escalatehand to tier-2
04 · TWO JOBS TIER-1 LIVES IN

False positives and zero-day. Both close in the same call.

SOC use cases lead with FP/FN reduction and zero-day detection. Both run on POST /enrich with the same verdict shape. The policy lives in your SIEM, not in our API.

JOB 01 · FP/FN REDUCTION

Cut alert noise. Catch the missed threats.

Verify SIEM verdicts at the moment they fire. Surface what is benign and what was missed.

Tier-1 spends 12 to 15 minutes per IOC stitching WHOIS, VirusTotal and Shodan. The decision is still ambiguous. False positives clog tier-2; false negatives sit in the SIEM unchecked.

Every alert payload calls /enrich. The verdict, the recommended action and the signal trail land in the alert before the analyst opens it. False positives drop without loosening detection. False negatives surface from the same call.

Triage time collapses to seconds. Analyst-A and analyst-B land on the same answer. Alert fatigue drops.

JOB 02 · ZERO-DAY DETECTION

Catch infrastructure before reputation feeds publish.

Behavioral signals fire on cold-start domains. Reputation feed match is not required.

Reputation feeds need a domain to misbehave first, publish, then propagate. The window is 24 to 72 hours. The campaign rotates inside that window. Your SIEM never sees the IOC marked as bad.

VerdictIQ models adversarial infrastructure behavior: dormant-then-activated lifecycles, co-tenancy with known malicious neighbors, fast-flux DNS rotation, short-lived SSL. Signals fire whether or not the IOC is in any feed.

Cold-start campaigns get scored at first sight. The reputation gap closes. Tier-1 reads the same verdict shape as for a known-bad IOC.

05 · SAME CALL, EVERY ANALYST

Decisions stop depending on the analyst, start depending on the system.

Determinism is not a slogan. It is the property that lets a tier-1 analyst defend a verdict the same way a tier-2 lead would, and lets a shift audit replay the call a week later.

Deterministic scoring

Same input, same verdict. Vendor updates do not silently shift the score. Analyst-A and analyst-B reach the same answer because the engine reaches the same answer.

Audit trail in the payload

Every verdict opens to Signal Group, Subgroup, signal and evidence. Compliance review reads the same trail across shifts and tenants.

Evidence saturation, not a blind score

Every verdict carries an evidence_saturation level. High saturation means many corroborating signals back the call, read it with confidence. Thin saturation flags the genuinely ambiguous IOCs to escalate, instead of escalating everything.

Supported IOC typesDomain · IP · ASN · CIDR · SHA256These five are what /enrich answers on. Pull the domain, IP or hash out of a URL or email alert and score that.
06 · HOW IT LANDS IN YOUR SIEM AND SOAR

An enrichment step. Not a console.

VerdictIQ is API-first. A SIEM enrichment pipeline or SOAR playbook calls POST /enrich on the IOC; the verdict and recommended_action enrich the alert or feed the decision node. No agent on the endpoint. No appliance in the rack. No migration of your existing detection content.

SIEM

Every modern SIEM exposes an enrichment hook (custom command, action, webhook). VerdictIQ slots into it; the verdict and recommended_action land on the alert. Your detection content stays put.

  • Splunk
  • QRadar
  • Sentinel
  • Elastic
  • Chronicle
SOAR

SOAR consumes the same verdict. The playbook condition node reads recommended_action or a specific signal. VerdictIQ feeds the decision, never executes it.

  • XSOAR
  • Splunk SOAR
  • Tines

Wire one alert. Read the verdict.

Get an API key. Pick an alert your SIEM already fires. Call /enrich on the IOC. Read the verdict in the payload. Move the second alert when you have proof on the first.

GDPR alignedLLM-free by defaultOwn infrastructureAudit-ready signal trail
See trust posture