IOC Desk · passive lookups
One verdict on anything you paste or forward.
Malicious, Suspicious, Benign or Unknown, with the evidence behind the call and a next step you can hand to whoever sent it. We look up third-party intelligence. We don't scan, click, or execute.
Paste the headers or the whole message, or upload the .eml. We read the sender, authentication, links and attachments. Links are looked up, never clicked.
RDAP · DNS · URLhaus · OTX · VirusTotal · urlscan · MalwareBazaar
Four doors
Same verdict shape, whichever way it comes in.
Door 01
Paste the headers or the whole message, or upload the .eml. We read the sender, authentication, links and attachments. Links are looked up, never clicked.
RDAP · DNS · URLhaus · OTX · VirusTotal · urlscan · MalwareBazaar
Door 02
File or document
Drop the file and we hash it, or paste a hash. Only the hash is kept: the file is never stored, opened, or run.
VirusTotal · Hybrid Analysis (hash only) · MalwareBazaar · OTX
Door 03
IP address
Reputation from third parties, including Project Honey Pot http:BL. Shodan shows what it has already seen: we don't scan the address.
AbuseIPDB · GreyNoise · Project Honey Pot · OTX · Shodan (lookup)
Door 04
Domain or URL
Registration age, certificates, DNS, known malware URLs and scan history. We never visit the link.
RDAP · crt.sh · DNS · URLhaus · OTX · VirusTotal · urlscan · Shodan DNS · IntelX · GrayHat Warfare
What comes back
A finding, not a wall of raw data.
01
In
Paste it, drop the file, or upload the message. We parse what you gave us; we don't visit the link or run the file.
02
Look up
Third-party intelligence on that indicator, cheapest and most deterministic sources first.
03
Verdict
Malicious, Suspicious, Benign or Unknown, with a score. Every claim cites the source that returned it.
04
Next step
One action: quarantine, allow, or escalate. Thin data says so; it is never passed off as safe.
Pricing
Credits per lookup.
Every lookup hits paid intelligence services, so each one costs credits from your wallet. Members spend the credits that come with their card each month; anyone signed in can top up. Findings stay on your IOC Desk in the portal.
Still human
Testing and takedowns stay with practitioners.
The desk tells you what's known about an indicator. Scanning, penetration testing, incident response and takedowns are engagements, run under rules of engagement by a person.
Do you scan or test anything?
No. IOC Desk only looks up what third-party intelligence services already know. It never scans an IP, visits a URL, or opens a file. If you need something tested or taken down, that's an engagement with a practitioner.
What happens to a file I upload?
We compute its hash and keep only that: the file itself is never stored, opened, executed, or sent to a sandbox that would run it. An uploaded email is read for its headers and links, then deleted as soon as the lookup finishes. The finding (the verdict, the evidence and the hash) is what stays.
How is it priced?
Each lookup costs credits from your CISO Marketplace wallet; the price is on the button. A forwarded email costs the same as a paste. Members spend their monthly credits. If no intelligence source answers, the credit is refunded automatically.
Who can see my findings?
You, in your portal under IOC Desk. On a Practice license, the seats in your practice share one desk.
Is the verdict a guarantee?
No. Automated verdicts are informational. Unknown means the data was thin, not that the indicator is safe.
Your AI agents can run the same lookups through the IOC Desk MCP server, ioc-mcp.cisomarketplace.com/mcp, billed to the same wallet.