Skip to content
USE CASES

One solution, wired into your entire security stack.

VerdictIQ is a single decision motor that drops into every layer you already run: SIEM, SOAR, EDR, SWG, DNS firewall and the CTI workbench. One response shape, one signal hierarchy. Wire it once; more than ten jobs across SOC, security engineering, MSSP and CTI read the same verdict.

01 · WHY THIS PAGE EXISTS

Use cases are not abstract.
They are the queues your team lives in.

SIEM alert queue. SOAR playbook branch. EDR feed loader. CTI pivot panel. Every team has its own door into the verdict, and a different policy that hangs off it.

You did not arrive with a feature checklist. You arrived from a queue: an alert that needs a verdict before it escalates, a playbook branch stalled on one missing field, a feed of IOCs with no score attached. The jobs below are written from inside those queues, not from a datasheet. Find the door your team came through, and the use case that sits behind it.

02 · THE USE CASES

Pick the one your queue lands on first.

More than ten canonical jobs across the same response shape. Each row carries the persona who lives the pain, the answer VerdictIQ returns, and the endpoint behind it.

SOC + SEC ENG

Decide before the IOC fires, not after the incident report.

Operational verdict at alert time, not forensic reconstruction after the incident.

Most enrichment lands after the action. Tier-1 blocks first and explains later; CTI writes the report after impact. The verdict arrives too late to change the outcome.

POST /enrich returns a verdict, a recommended action and a signal trail at the moment the alert fires. The decision is operational, not archaeological. Same response shape across every queue.

  • Pre-hoc decision
  • POST /enrich

Actions land while they still change the outcome. The incident report reads what the system decided, not what an analyst guessed.

SOC TIER 1-2

Cut alert noise. Catch the missed threats.

Verify SIEM verdicts at the moment they fire. Surface what is benign and what was missed.

Tier-1 spends 12-15 minutes per IOC stitching WHOIS, VirusTotal and Shodan. The decision is still ambiguous. Most of that time is bookkeeping, not analysis.

Every alert payload calls /enrich. The verdict, the recommended action and the signal trail land in the alert before the analyst opens it. False positives drop without loosening detection. False negatives surface from the same call.

  • FP/FN reduction
  • POST /enrich
  • audit-ready

Triage time collapses to seconds; analyst-A and analyst-B land on the same answer. Alert fatigue drops.

SECURITY ENGINEERING

Drive playbook decisions from signals, not just scores.

Trigger hard, soft or observational branches per signal presence, score threshold or specific signal name.

Generic risk score is too coarse for policy. Some playbook branches need to fire on a specific signal regardless of score; others key off score thresholds. SIEM and TIP feeds do not expose either.

POST /enrich returns the full Group, Subgroup and signal hierarchy. Your playbook condition node branches on score (above N), recommended_action (block_domain), or specific signal (visited_by_a_malicious_domain). Hard, soft or observational routes per your policy.

  • SOAR decision engine
  • POST /enrich

Policy-aware automation without analyst-in-the-loop on every alert. Playbook conditions read deterministic fields, no NLP, no opaque scoring.

SOC + CTI

Catch infrastructure before reputation feeds publish.

Behavioral signals fire on cold-start domains; reputation feed match is not required.

Reputation feeds need a domain to misbehave first, then publish, then propagate. Window: 24 to 72 hours. The campaign rotates inside that window.

VerdictIQ models adversarial infrastructure behavior: dormant-then-activated lifecycles, co-tenancy with known malicious neighbors, fast-flux DNS rotation, hosting reuse patterns. Signals fire whether or not the IOC is in any feed. The verdict carries the reasoning.

  • Zero-day detection
  • POST /enrich
  • behavioral

Cold-start campaigns get scored at first sight. Reputation gap closes.

For payload analysis or full campaign forensics, pair VerdictIQ with payload-analysis or threat-hunting tooling. We trigger the action; we don't reproduce the payload.

CTI ANALYST

Score domains, IPs, ASNs and CIDRs deterministically.

Move from per-domain pivot to ASN-level and hosting-provider trust verdicts.

Single-domain analysis misses infrastructure abuse patterns. The same ASN, same datacenter, same hosting provider is reused; the signal hides at single-domain scope.

POST /enrich accepts Domain, IP, CIDR or ASN with the same response shape. Hosting trust, ASN reputation, datacenter scoring and infrastructure clustering surface as signals. Cluster-level investigation pivots from one IOC to its neighborhood via POST /pivot.

  • Infrastructure trust scoring
  • POST /enrich
  • cluster-level

Targeted policy on hosting reputation, not blanket country blocks. Legitimate traffic flows; malicious neighbors stop together.

SECURITY ENGINEERING + MSSP

Replay shipped SIEM decisions at scale.

Bulk-feed a day of SIEM verdicts, surface the false positives and the false negatives buried in them.

Single-call enrichment is fine for live triage. The verdicts your stack already shipped (block, allow, alert) sit in the SIEM unchecked. False positives kept legitimate traffic out; false negatives let real threats through. No feedback loop closes.

POST /enrich_bulk takes a day of decisions in a single call. VerdictIQ scores each, flags FP, FN, decision inconsistencies and IOCs whose risk profile shifted since the original decision. Same signal hierarchy. Same audit trail. Built for log-pipeline batch jobs and weekly review.

  • Decision verification
  • POST /enrich_bulk
  • FP/FN feedback loop
  • audit replay

Continuous decision quality measurement. Operations team gets a closed-loop signal on what the SIEM kept and what it missed.

SECURITY ENGINEERING

Score 10,000 IOCs in one call. Wire the pipeline once.

SIEM enricher and SOAR pipeline integration without per-IOC HTTP overhead.

Per-IOC enrichment buries the network on bulk paths: log enricher loops, threat feed evaluation, EDR allowlist scrub. Rate limits make linear loops infeasible.

POST /enrich_bulk accepts up to 10,000 IOCs per call. Same response shape per item. Built for log-pipeline batch, scheduled threat-feed evaluation and EDR/SWG list hygiene jobs.

  • Bulk throughput
  • POST /enrich_bulk
  • 10K/call

Bulk paths scale to feed volume. The SIEM enricher and the SOAR pipeline read one contract.

INCIDENT RESPONSE ANALYST

One ticket, every IOC, one call.

A single incident with 12 domains and 4 IPs gets one verdict bundle, not 16 round-trips.

Incident tickets carry mixed-type IOC lists. Analysts paste each into a separate tab, copy the result back, lose the trail of which IOC scored what.

POST /enrich_bulk takes the full ticket payload: domains, IPs, hashes in a single request. The response keeps per-IOC verdict, signals and evidence indexed to the input order. The ticket gets a single attachment.

  • Ticket scope enrichment
  • POST /enrich_bulk

Ticket triage runs at incident granularity, not IOC granularity. Audit trail attaches to the case, not the analyst's clipboard.

SOC TIER 1 + MSSP

Read the verdict like a senior analyst wrote it.

Optional narrative layer turns the signal trail into a closure-ready summary in plain language.

Tier-1 has the verdict, the signals and the evidence, but still escalates because writing the closure note takes longer than reading it. MSSP teams need consistent voice across tenants.

Opt-in VerdictIQ AI layer composes a senior-analyst narrative on top of the deterministic verdict. The score and signals stay deterministic; the narrative summarizes them for the closure note. Toggle per query or per tenant.

  • AI narrative
  • POST /enrich
  • narrative-read

Tier-1 closes more tickets without escalation. MSSP voice stays consistent across analysts and shifts.

REGULATED + GRC

Defend every blocked legitimate domain at audit.

Every verdict opens to signal, evidence and analyst Q&A: the same trail compliance review reads.

Finance, telco and healthcare blocks have to survive customer complaints, regulator review and internal audit. Opaque vendor scores don't defend; analyst notes drift.

Every VerdictIQ verdict carries a deterministic signal trail and a stable evidence shape. Compliance reads the same view your analyst saw. Per-API-key partitioning keeps the audit boundary clean.

  • Audit defensibility
  • POST /enrich
  • POST /enrich_bulk

Audit and customer complaints get answered from the verdict, not the analyst's memory.

DETECTION ENGINEERING

Turn behavioral signals into SIEM rules.

Every named signal is queryable, exportable and ready for Sigma, KQL or SPL conversion.

Detection engineering needs portable signal definitions, not vendor-locked scores. Writing detections against opaque risk scores produces fragile, drift-prone rules.

Signal names and evidence shapes are stable and documented. Export a verdict, inspect the signals behind it, codify the pattern in Sigma, KQL or SPL. The signal library is your rule catalog.

  • Detection engineering
  • POST /enrich

Detection rules track named signals, not opaque vendors. Drift becomes visible at the signal layer.

03 · NEAR THIS

Three endpoints behind every job.

Use cases hit one of three product surfaces. The job is the lens; the endpoint is the contract.

Enrichment

Real-time verdict on a single IOC. Drives FP/FN, SOAR, infra trust, zero-day.

POST /enrich
  • Domain · IP · CIDR · ASN · SHA256 input
  • same response shape
  • explainable
Open Enrichment
Bulk IOC Enrichment

Replay shipped SIEM decisions at scale. Drives Decision Verification.

POST /enrich_bulk
  • batch input
  • per-IOC verdict + delta vs prior
  • audit-friendly export
Open Decision Verification

Pick a job. Try the verdict.

Get an API key. Send your first IOC. Wire the response into the use case that hits your queue first. Move to the next when you have proof.

GDPR alignedLLM-free by defaultOwn infrastructureAudit-ready signal trail
See our security posture