PROJECT

CTI-AI

CTI Workbench

LIVE OPERATIONS
SOCRadarLABS
100% Free Threat Intelligence Tools

Empowering Security Teams with SOCRadar Labs

Search Indicators of Compromise, check dark web leak exposures, audit attack surfaces, grade email security, and track active cyber extortion campaigns.

Quick Samples:
AI-POWEREDFREE
Threat Intelligence

IOC Radar

Instant risk scoring & geo-enrichment for IP, domain, hash, and CVE.

Risk Score (0-100)
Threat Actor Linkage
ASN & Geo-location
Sigma YAML Generation
LIVEFREE
Threat Intelligence

Vulnerability & CVE Intel

EPSS exploitation odds, CISA KEV status, CVSS v3.1/v4.0 & PoC availability.

CISA KEV Verification
EPSS Percentile Probability
Public PoC Scanner
Vendor Patch & Mitigations
LIVEFREE
Threat Intelligence

Ransomware & Extortion Feed

Dark web leak site victims, ransomware cartels & extortion claims.

Victim Leak Feeds
Cartel Profiles
Target Sector Breakdown
Exfiltrated Data Previews
LIVEFREE
Threat Intelligence

Active Cyber Campaigns

Analyst breakdowns of live ransomware waves, APT ops & malware blitzes.

Targeted Sectors
MITRE ATT&CK Mapping
Malware Clusters
Detection Playbooks
FREEFREE
Dark Web & Exposure

Dark Web Report

Scan dark web forums, infostealer logs, and credential dumps for your domain.

Stealer Log Dumps
Compromised Credentials
Underground Forum Mentions
Executive Exposure Risks
FREEFREE
Dark Web & Exposure

Account Breach Checker

Check if corporate or personal email credentials appear in breach dumps.

Breach Source & Date
Exposed Data Classifications
Password Type (Plain/Hashed)
Remediation Checklist
LIVEFREE
Dark Web & Exposure

Dark Mirror (Chatter Stream)

Live dark web chatter stream, Initial Access Broker listings & zero-day auctions.

Initial Access Brokers
Marketplace Pricing ($/XMR)
Threat Actor Aliases
Exfiltration Claims
FREEFREE
Attack Surface & Perimeter

External Attack Surface

Discover internet-facing digital assets, subdomains, and shadow IT.

Subdomain Enumeration
Open Ports & Services
SSL/TLS Health
Shadow IT Discovery
FREEFREE
Attack Surface & Perimeter

VPN & Proxy Radar

Identifies exposed SSL-VPN gateways, TOR nodes, and proxy endpoints.

SSL-VPN Gateway Detection
VPN Vendor & Version Fingerprint
TOR Exit Node Status
Anonymizer Risk Grade
FREEFREE
Attack Surface & Perimeter

DoS Resilience Checker

Tests DNS, NTP, SNMP & LDAP amplification risk and Slowloris resilience.

Open DNS Resolver Check
NTP Amplification Risk
SNMP / LDAP Reflection
Slowloris Connection Shield
FREEFREE
SOC Incident Toolkit

Email Security Grader

SPF, DKIM, DMARC, BIMI & MTA-STS compliance and spoofing audit.

DMARC Policy Enforcement
SPF Alignment & Syntax
DKIM Selector Inspection
BIMI & MTA-STS Verification
AI-POWEREDFREE
SOC Incident Toolkit

Email Threat Header Analyzer

Paste raw RFC 822 email headers to detect spoofing, hop path & malware links.

Hop Path Trace
Originating IP Geolocation
Auth Flag Parser (SPF/DKIM)
Phishing Probability Score
FREEFREE
SOC Incident Toolkit

Phishing & Lookalike Radar

Typosquatting permutation scan & brand impersonation detector.

Homoglyph Mutations
Live DNS Resolution
MX Record Check
Takedown Recommended Flags
AI-POWEREDFREE
Global Threat Landscapes

Country Threat Landscape

Geopolitical threat intelligence, nation-state APTs & regional cyber trends.

Top Threat Actor Groups
Target Sector Heatmap
Ransomware Distribution
Geopolitical Cyber Brief
AI-POWEREDFREE
Global Threat Landscapes

Industry Threat Landscape

Sector-specific threat research: Financial, Healthcare, Energy, Gov & Defense.

Sector Risk Level
Top TTPs (MITRE ATT&CK)
Dominant Malware Strains
Regulatory Defense Standards
LIVE OSINT FEED
[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.