← All Netgraph solutions
Threat Intelligence PlatformIntelligence & Operations

Intel that doesn't sit in a list. It matches, enriches, and deploys.

Netgraph's TIP ingests intelligence from any feed — including live OSINT feeds such as OTX — manages indicators with confidence and provenance, and puts them to work: continuously matched against inbound telemetry, enriching every alert, and pushed as blocks to every enforcement point you've enabled. And because enrichment runs on an embedded local GeoIP / ASN / WHOIS database, all of it works fully offline and air-gapped.

Feed-agnostic ingestLive OSINT feeds (OTX)Continuous Indicator-MatchOffline GeoIPASNWHOISIOC push with deploy receipts

What ships in the module

The full indicator lifecycle — ingest to enforcement.

01

Feed-agnostic ingest

Bring any intel source — live OSINT feeds like OTX, commercial feeds, community sharing — into one indicator store. No feed-format lock-in on what you're allowed to know.

02

Confidence & provenance

Every indicator carries confidence and provenance — where it came from, when, and how much to trust it — so downstream matching and blocking decisions rest on graded evidence, not a flat blocklist.

03

Indicator-Match

Confirmed indicators — drawn from closed cases and declared incidents — are continuously matched against inbound telemetry. Your own incident history becomes a live detection surface.

04

Embedded offline enrichment

A local GeoIP / ASN / WHOIS database — content-updatable CSV packs, wired straight into the enrichment pipeline — works fully offline and air-gapped. No external lookups required, ever.

05

Detection orchestration

Confirmed IOCs push to EDR, cloud, firewalls, AD, zero-trust, IPS and proxies via your enabled integrations — with deploy receipts recording exactly which indicator went to which control, when.

06

Dark-web fusion

Findings from dark-web monitoring publish directly into the TIP — leaked credentials and exposure signals join the same indicator lifecycle as feed intel.

07

Enrichment everywhere

Intel enriches every alert through the enrich Take-Action, and powers agent skills like IOC reputation — the same indicator store serves analysts and agents alike.

08

Indicators on the graph

Indicators land on the security knowledge graph as typed nodes linked to the incidents that produced or confirmed them — intel with lineage, traversable from any alert.

09

Per-tenant vaulted credentials

Integration credentials for feeds and enforcement points are vaulted per tenant — strict isolation between tenants' intel plumbing.

Close the loop

A closed case shouldn't just close. It should immunise the estate.

When a case closes or an incident is declared, its confirmed indicators don't retire to a spreadsheet. Indicator-Match keeps them live against inbound telemetry, and detection orchestration pushes them to every enforcement plane you've enabled — with a receipt for each deployment, so "did we actually block it everywhere?" has a documented answer.

  • Confirmed indicators sourced from closed cases and declared incidents.
  • Push targets: EDR, cloud, firewalls, AD, zero-trust, IPS, proxies — via enabled integrations.
  • Deploy receipts record exactly what went where, per integration.
  • Typed indicator nodes on the graph, linked to their originating incidents.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
Intel ingestFeed-agnostic ingest including live OSINT feeds (e.g. OTX)SOC ▸ Enrich ▸ TIP
Indicator managementIndicator store with confidence and provenance on every entrySOC ▸ Enrich ▸ TIP
Indicator-MatchConfirmed indicators from closed cases / declared incidents matched continuously against inbound telemetrySOC ▸ Enrich ▸ Indicator Match
Local enrichment DBEmbedded GeoIP / ASN / WHOIS — content-updatable CSV packs, fully offline / air-gappedEnrichment pipeline
Detection orchestrationPush confirmed IOCs to EDR, cloud, firewalls, AD, zero-trust, IPS, proxies — deploy receipts per integrationSOC ▸ Enrich ▸ TIP
Alert enrichmentIntel context on every alert via the enrich Take-Action; powers IOC-reputation agent skillsSOC ▸ Detect ▸ Alerts ▸ Take-Action
Graph fusionTyped indicator nodes linked to incidents; dark-web findings publish into TIPSecurity knowledge graph

See it live

Close a case. Watch its indicators deploy everywhere.