All your threat intel, in the browser.
SOC teams invest millions in SIEM, SOAR, and TI platforms — but none of it helps the analyst directly. Deep Detect gives every analyst one view for all threat intelligence, right in their browser. No tab switching. No tool hopping. Just answers.
No credit card for the trial · Works in Chrome 114+ · Data stays on your device
IOC
185.220.101.42
IPv4 · refanged from 185[.]220[.]101[.]42
Verdict
HIGH
- VirusTotal14 / 89 engines
- AbuseIPDB98% confidence
- GreyNoiseClassified: malicious
- Shodan3 open ports
See a pivot in 30 seconds
Right-click an IOC, read the verdict, open the deep investigation — without leaving your SIEM tab.
Demo video coming soon
A 30-second walkthrough of a full pivot
How it works
From selection to verdict in one click
Right-click any IOC
Highlight an IP, domain, URL, hash, email, or CVE anywhere in your browser and pick Deep Detect. Defanged IOCs like evil[.]com are refanged automatically.
Get an instant verdict
The Triage popup fans out to all five Tier 1 sources in parallel and returns one verdict — HIGH, MEDIUM, LOW, or UNKNOWN — using worst-verdict-wins. One strong malicious hit is enough.
Investigate deeper
Need more? Open a Deep Investigation tab for full source detail, analyst notes, and Tier 2 verification links — opened only when you deliberately click through.
Features
Built for the analyst, not the platform
Everything an analyst needs to triage an IOC — and nothing that gets in the way.
Automatic IOC detection
Detects IPs, domains, URLs, file hashes, emails, and CVEs from any selected text. Defanged IOCs are refanged first; ambiguous types prompt instead of guessing.
5 Tier 1 sources, queried in parallel
VirusTotal, AbuseIPDB, Shodan, GreyNoise, and ipinfo — all fetched at once and rendered inline. No tab-hopping between consoles.
Worst-verdict-wins scoring
Verdicts are never averaged. A single malicious, high-confidence hit makes the verdict HIGH — and clicking it shows exactly which source triggered it.
Triage, then Deep Investigation
The popup gives a fast verdict without leaving your SIEM tab. The full results tab adds source detail, notes, and Tier 2 verification links when you need them.
All data stays local
Everything is stored in chrome.storage.local — nothing is synced, nothing leaves the device. A clean fit for Saudi PDPL and GDPR requirements.
Bring your own API keys
Use your own source API keys, stored locally. host_permissions cover all five domains directly — no proxy, no middleman, no rate-limit games.
Pricing
Simple pricing, per analyst
Start with a 30-day full-feature trial. No credit card required.
Individual
For the solo analyst.
- 1 seat / 1 license key
- All 5 Tier 1 sources
- Triage + Deep Investigation
- Bring your own API keys
- 90-day local history
Team
For a SOC shift.
- 2–10 seats, one key per seat
- Admin distributes keys
- Everything in Individual
- Regenerate keys per seat
- Priority email support
Enterprise
For the whole SOC.
- 10+ seats
- Annual PO / invoice billing
- Manual license provisioning
- PDPL & procurement support
- GCC-friendly onboarding
FAQ
Frequently asked questions
Five Tier 1 sources are queried inline and in parallel: VirusTotal, AbuseIPDB, Shodan, GreyNoise, and ipinfo. IP-only sources (Shodan, GreyNoise, AbuseIPDB, ipinfo) are skipped for non-IP IOCs. Additional Tier 2 sources open in a single tab only when you deliberately click "Verify on [platform]".
Stop tab-hopping. Start pivoting.
Add Deep Detect to Chrome and get a verdict on your next IOC in seconds. Free for 30 days.