BlockchainChainalysis
Wallet exposure & transaction intelligence
Bring licensed counterparty context, transfer alerts, and risk categories into the same case as the underlying onchain activity.
IN THE INVESTIGATIONInvestigate a suspicious funding route with attributed exposure context.
BlockchainTRM Labs
Address screening & attribution
Add wallet-screening results and attributed entity context to help an analyst prioritize a lead and document the basis for review.
IN THE INVESTIGATIONReview an address alongside its provider-supplied attribution and exposure.
BlockchainElliptic
Wallet & transaction screening
Attach wallet and transaction analyses to a case, with rescreening context when the provider’s assessment changes.
IN THE INVESTIGATIONRevisit a previously reviewed counterparty when its screening context changes.
Threat intelligenceFlashpoint
Deep & dark web intelligence
Connect licensed reporting on illicit communities, threat actors, fraud, and exposed credentials to the wider investigation.
IN THE INVESTIGATIONCorrelate a reported campaign with relevant infrastructure and onchain leads.
Threat intelligenceRecorded Future
Threat actors, indicators & relationships
Enrich indicators with threat context, actor intelligence, and entity relationships while preserving provider attribution.
IN THE INVESTIGATIONUnderstand whether a domain or IP connects to a wider observed campaign.
InfrastructureVirusTotal
Files, URLs, domains & IPs
Pull existing reputation and relationship reports for artifacts associated with an investigation. Keep offchain evidence beside the wallet trail.
IN THE INVESTIGATIONReview infrastructure linked to a suspected wallet-drainer site.
InfrastructureGreyNoise
IP activity & internet scanning context
Add IP classification and observed activity to help distinguish broad internet scanning from infrastructure that deserves closer attention.
IN THE INVESTIGATIONGive an infrastructure lead context before escalating it to the response team.
Team workflowsMISP
Community & internal intelligence exchange
Controlled import and export of events, indicators, and context from the intelligence communities your team trusts.
IN THE INVESTIGATIONUse your own MISP intelligence as attributed context in a case.
Team workflowsOpenCTI
Structured knowledge & relationships
Connect investigations with your existing threat knowledge graph and preserve relationships across actors, campaigns, and infrastructure.
IN THE INVESTIGATIONHand a reviewed finding back to the organization’s intelligence knowledge base.
Team workflowsSplunk
Security operations handoff
Event delivery through HTTP Event Collector, with reviewed case references and observations for your security workflows.
IN THE INVESTIGATIONSend an analyst-reviewed finding into the team’s existing monitoring process.
Team workflowsMicrosoft Sentinel
Threat intelligence exchange
Standards-based indicator handoffs, with source references and analyst context for the team operating in Sentinel.
IN THE INVESTIGATIONShare vetted indicators through a scoped STIX/TAXII exchange.