THE INTELLIGENCE STACK

Great intelligence.
Better, connected.

The best investigation follows the evidence wherever it leads. Explore the sources and workflows behind financial exposure, threat actors, malicious infrastructure, and a well-supported case. Build the intelligence stack around your team’s mandate.

11INTELLIGENCE & WORKFLOW TOOLS
ONE INVESTIGATION LAYER
11 INTEGRATIONSLICENSED SOURCES. PRESERVED ATTRIBUTION.
CAAPI & DATA
Blockchain

Chainalysis

Wallet exposure & transaction intelligence

Bring licensed counterparty context, transfer alerts, and risk categories into the same case as the underlying onchain activity.

IN THE INVESTIGATION

Investigate a suspicious funding route with attributed exposure context.

TRMAPI & DATA
Blockchain

TRM Labs

Address screening & attribution

Add wallet-screening results and attributed entity context to help an analyst prioritize a lead and document the basis for review.

IN THE INVESTIGATION

Review an address alongside its provider-supplied attribution and exposure.

ELAPI & DATA
Blockchain

Elliptic

Wallet & transaction screening

Attach wallet and transaction analyses to a case, with rescreening context when the provider’s assessment changes.

IN THE INVESTIGATION

Revisit a previously reviewed counterparty when its screening context changes.

FPAPI & DATA
Threat intelligence

Flashpoint

Deep & dark web intelligence

Connect licensed reporting on illicit communities, threat actors, fraud, and exposed credentials to the wider investigation.

IN THE INVESTIGATION

Correlate a reported campaign with relevant infrastructure and onchain leads.

RFAPI & DATA
Threat intelligence

Recorded Future

Threat actors, indicators & relationships

Enrich indicators with threat context, actor intelligence, and entity relationships while preserving provider attribution.

IN THE INVESTIGATION

Understand whether a domain or IP connects to a wider observed campaign.

VTAPI & DATA
Infrastructure

VirusTotal

Files, URLs, domains & IPs

Pull existing reputation and relationship reports for artifacts associated with an investigation. Keep offchain evidence beside the wallet trail.

IN THE INVESTIGATION

Review infrastructure linked to a suspected wallet-drainer site.

GNAPI & DATA
Infrastructure

GreyNoise

IP activity & internet scanning context

Add IP classification and observed activity to help distinguish broad internet scanning from infrastructure that deserves closer attention.

IN THE INVESTIGATION

Give an infrastructure lead context before escalating it to the response team.

MIAPI & DATA
Team workflows

MISP

Community & internal intelligence exchange

Controlled import and export of events, indicators, and context from the intelligence communities your team trusts.

IN THE INVESTIGATION

Use your own MISP intelligence as attributed context in a case.

OCAPI & DATA
Team workflows

OpenCTI

Structured knowledge & relationships

Connect investigations with your existing threat knowledge graph and preserve relationships across actors, campaigns, and infrastructure.

IN THE INVESTIGATION

Hand a reviewed finding back to the organization’s intelligence knowledge base.

SPAPI & DATA
Team workflows

Splunk

Security operations handoff

Event delivery through HTTP Event Collector, with reviewed case references and observations for your security workflows.

IN THE INVESTIGATION

Send an analyst-reviewed finding into the team’s existing monitoring process.

MSAPI & DATA
Team workflows

Microsoft Sentinel

Threat intelligence exchange

Standards-based indicator handoffs, with source references and analyst context for the team operating in Sentinel.

IN THE INVESTIGATION

Share vetted indicators through a scoped STIX/TAXII exchange.

Your access. Your sources.

Shape the scope around your team’s provider access, licenses, and data requirements. Commercial services require an eligible license or an agreed commercial arrangement; coverage and entitlements vary by provider. Each source links to its official reference for technical and licensing details.

FROM LEAD TO HANDOFF

From a wallet trail
to a wider threat.

Imagine a suspected drainer campaign: trace the funds, examine the associated site, enrich the indicators, and hand off a case with the evidence attached.

01

Follow the money

Chainalysis · TRM · Elliptic

02

Understand the campaign

Flashpoint · Recorded Future

03

Examine the infrastructure

VirusTotal · GreyNoise

04

Share the evidence

MISP · OpenCTI · SIEM

An investigative hypothesis connects sources; it does not establish attribution. The analyst reviews the evidence.

Define your intelligence stack
THE NEXT CONNECTION IS THE ONE THAT MATTERS.
MANY ECOSYSTEMS / ONE CONNECTED PICTURE

Connect the dots.
Own the investigation.

A wider view of the threat.
A clearer next move.

Register for the desktop trialEvaluate the workspace · No card required