Skip to content
CISO Marketplace Services

IOC Desk · passive lookups

One verdict on anything you paste or forward.

Malicious, Suspicious, Benign or Unknown, with the evidence behind the call and a next step you can hand to whoever sent it. We look up third-party intelligence. We don't scan, click, or execute.

No active scanHash only, never executeNo click-throughEvidence on every call

Paste the headers or the whole message, or upload the .eml. We read the sender, authentication, links and attachments. Links are looked up, never clicked.

RDAP · DNS · URLhaus · OTX · VirusTotal · urlscan · MalwareBazaar

Four doors

Same verdict shape, whichever way it comes in.

Door 01

Email

Paste the headers or the whole message, or upload the .eml. We read the sender, authentication, links and attachments. Links are looked up, never clicked.

RDAP · DNS · URLhaus · OTX · VirusTotal · urlscan · MalwareBazaar

Door 02

File or document

Drop the file and we hash it, or paste a hash. Only the hash is kept: the file is never stored, opened, or run.

VirusTotal · Hybrid Analysis (hash only) · MalwareBazaar · OTX

Door 03

IP address

Reputation from third parties, including Project Honey Pot http:BL. Shodan shows what it has already seen: we don't scan the address.

AbuseIPDB · GreyNoise · Project Honey Pot · OTX · Shodan (lookup)

Door 04

Domain or URL

Registration age, certificates, DNS, known malware URLs and scan history. We never visit the link.

RDAP · crt.sh · DNS · URLhaus · OTX · VirusTotal · urlscan · Shodan DNS · IntelX · GrayHat Warfare

What comes back

A finding, not a wall of raw data.

  1. 01

    In

    Paste it, drop the file, or upload the message. We parse what you gave us; we don't visit the link or run the file.

  2. 02

    Look up

    Third-party intelligence on that indicator, cheapest and most deterministic sources first.

  3. 03

    Verdict

    Malicious, Suspicious, Benign or Unknown, with a score. Every claim cites the source that returned it.

  4. 04

    Next step

    One action: quarantine, allow, or escalate. Thin data says so; it is never passed off as safe.

Pricing

Credits per lookup.

Every lookup hits paid intelligence services, so each one costs credits from your wallet. Members spend the credits that come with their card each month; anyone signed in can top up. Findings stay on your IOC Desk in the portal.

Still human

Testing and takedowns stay with practitioners.

The desk tells you what's known about an indicator. Scanning, penetration testing, incident response and takedowns are engagements, run under rules of engagement by a person.

Do you scan or test anything?

No. IOC Desk only looks up what third-party intelligence services already know. It never scans an IP, visits a URL, or opens a file. If you need something tested or taken down, that's an engagement with a practitioner.

What happens to a file I upload?

We compute its hash and keep only that: the file itself is never stored, opened, executed, or sent to a sandbox that would run it. An uploaded email is read for its headers and links, then deleted as soon as the lookup finishes. The finding (the verdict, the evidence and the hash) is what stays.

How is it priced?

Each lookup costs credits from your CISO Marketplace wallet; the price is on the button. A forwarded email costs the same as a paste. Members spend their monthly credits. If no intelligence source answers, the credit is refunded automatically.

Who can see my findings?

You, in your portal under IOC Desk. On a Practice license, the seats in your practice share one desk.

Is the verdict a guarantee?

No. Automated verdicts are informational. Unknown means the data was thin, not that the indicator is safe.

Your AI agents can run the same lookups through the IOC Desk MCP server, ioc-mcp.cisomarketplace.com/mcp, billed to the same wallet.

For AI agents
Talk to an advisor
Advisor