Project · 2026
IOC Enricher
An AI-powered threat-intelligence dashboard that enriches IPs, domains, and file hashes with synthesized investigation context. The goal is to make early triage faster and more actionable.
Role
Security Tool Developer
Status
live
Stack
TypeScript, Python, Groq AI, VirusTotal API, AbuseIPDB API, MalwareBazaar API
Overview
IOC Enricher is a threat intelligence dashboard for investigating an IP address, domain, URL, or file hash from a single interface. It queries multiple threat intelligence platforms simultaneously, then uses Groq AI to synthesize the results into a plain-language investigation summary an analyst can act on immediately.
The Problem
Enriching a single IOC during a triage session typically means opening VirusTotal in one tab, AbuseIPDB in another, checking MalwareBazaar for hash lookups separately, and then assembling a picture across all three mentally. Under alert volume, that process introduces errors and delays. More importantly, the raw API responses require interpretation — a high detection count means something different for a newly registered domain than for an infrastructure IP.
Approach
IOC Enricher routes each submitted indicator to the appropriate sources in parallel:
VirusTotal — Vendor detection rates, reputation scores, related samples, and historical scan data. The tool surfaces the detection ratio prominently since it is the first thing an analyst needs to know.
AbuseIPDB — Abuse confidence scores, report history, originating country and ISP data, and category breakdowns for what the IP has been reported for (scanning, brute force, DDoS participation, etc.).
MalwareBazaar — Hash lookup for known malware samples, family attribution, and first-seen/last-seen timestamps for file indicators.
Groq AI synthesis — After the API results are assembled, Groq generates a short plain-language summary: what this indicator is, why it is or is not suspicious, what the threat intel sources agree on, and what the analyst should check next. This is not a generic description — it is generated from the actual structured API responses for that specific IOC.
Technical Decisions
The backend coordination layer is Python, running parallel API calls to VirusTotal, AbuseIPDB, and MalwareBazaar to minimize total latency. Results are normalized into a consistent schema before being passed to the Groq synthesis step, so the model receives structured context rather than raw JSON blobs of varying shape.
The frontend is TypeScript. Indicator type detection (IP vs. domain vs. URL vs. hash) is handled automatically so the analyst can paste anything and get the right enrichment path without selecting a category manually.
Outcomes
- Live at ioc-enricher-abd.vercel.app
- Actively used for real triage work as part of the SOC analyst workflow
- Part of the public security portfolio at m-abdullah-06/soc-analyst-portfolio
Related work
Phishing Analyzer
LiveAn email-forensics tool for inspecting raw .eml files, validating authentication, detecting spoofing, enriching IOCs, and preparing incident reports. It gives analysts a cleaner path from suspicious email to useful next steps.
SOC Analyst Portfolio
LiveA security-focused portfolio that documents alert triage, detections, investigations, and the tools built to support analysts. It presents the work in a way that is easy to scan and easy to trust.