Intel that doesn't sit in a list. It matches, enriches, and deploys.
Netgraph's TIP ingests intelligence from any feed — including live OSINT feeds such as OTX — manages indicators with confidence and provenance, and puts them to work: continuously matched against inbound telemetry, enriching every alert, and pushed as blocks to every enforcement point you've enabled. And because enrichment runs on an embedded local GeoIP / ASN / WHOIS database, all of it works fully offline and air-gapped.
What ships in the module
The full indicator lifecycle — ingest to enforcement.
Close the loop
A closed case shouldn't just close. It should immunise the estate.
When a case closes or an incident is declared, its confirmed indicators don't retire to a spreadsheet. Indicator-Match keeps them live against inbound telemetry, and detection orchestration pushes them to every enforcement plane you've enabled — with a receipt for each deployment, so "did we actually block it everywhere?" has a documented answer.
- Confirmed indicators sourced from closed cases and declared incidents.
- Push targets: EDR, cloud, firewalls, AD, zero-trust, IPS, proxies — via enabled integrations.
- Deploy receipts record exactly what went where, per integration.
- Typed indicator nodes on the graph, linked to their originating incidents.
Functionality map
Module functions at a glance
| Function | What it does | Where it lives |
|---|---|---|
| Intel ingest | Feed-agnostic ingest including live OSINT feeds (e.g. OTX) | SOC ▸ Enrich ▸ TIP |
| Indicator management | Indicator store with confidence and provenance on every entry | SOC ▸ Enrich ▸ TIP |
| Indicator-Match | Confirmed indicators from closed cases / declared incidents matched continuously against inbound telemetry | SOC ▸ Enrich ▸ Indicator Match |
| Local enrichment DB | Embedded GeoIP / ASN / WHOIS — content-updatable CSV packs, fully offline / air-gapped | Enrichment pipeline |
| Detection orchestration | Push confirmed IOCs to EDR, cloud, firewalls, AD, zero-trust, IPS, proxies — deploy receipts per integration | SOC ▸ Enrich ▸ TIP |
| Alert enrichment | Intel context on every alert via the enrich Take-Action; powers IOC-reputation agent skills | SOC ▸ Detect ▸ Alerts ▸ Take-Action |
| Graph fusion | Typed indicator nodes linked to incidents; dark-web findings publish into TIP | Security knowledge graph |
Works with everything on the graph
Agentic AI SOC
IOC-reputation and enrichment skills read the TIP directly — agents triage with the same intel analysts see.
Explore→NextGen SIEM
Intel enrichment joins geo, asset and identity context in the ingest pipeline — alerts arrive pre-enriched.
Explore→Cloud Security
Cloud is both a telemetry source for Indicator-Match and a push target for confirmed IOCs.
Explore→