Skip to content
Abdullah

Project · 2026

IOC Enricher

An AI-powered threat-intelligence dashboard that enriches IPs, domains, and file hashes with synthesized investigation context. The goal is to make early triage faster and more actionable.

Role

Security Tool Developer

Status

live

Stack

TypeScript, Python, Groq AI, VirusTotal API, AbuseIPDB API, MalwareBazaar API

Overview

IOC Enricher is a threat intelligence dashboard for investigating an IP address, domain, URL, or file hash from a single interface. It queries multiple threat intelligence platforms simultaneously, then uses Groq AI to synthesize the results into a plain-language investigation summary an analyst can act on immediately.

The Problem

Enriching a single IOC during a triage session typically means opening VirusTotal in one tab, AbuseIPDB in another, checking MalwareBazaar for hash lookups separately, and then assembling a picture across all three mentally. Under alert volume, that process introduces errors and delays. More importantly, the raw API responses require interpretation — a high detection count means something different for a newly registered domain than for an infrastructure IP.

Approach

IOC Enricher routes each submitted indicator to the appropriate sources in parallel:

VirusTotal — Vendor detection rates, reputation scores, related samples, and historical scan data. The tool surfaces the detection ratio prominently since it is the first thing an analyst needs to know.

AbuseIPDB — Abuse confidence scores, report history, originating country and ISP data, and category breakdowns for what the IP has been reported for (scanning, brute force, DDoS participation, etc.).

MalwareBazaar — Hash lookup for known malware samples, family attribution, and first-seen/last-seen timestamps for file indicators.

Groq AI synthesis — After the API results are assembled, Groq generates a short plain-language summary: what this indicator is, why it is or is not suspicious, what the threat intel sources agree on, and what the analyst should check next. This is not a generic description — it is generated from the actual structured API responses for that specific IOC.

Technical Decisions

The backend coordination layer is Python, running parallel API calls to VirusTotal, AbuseIPDB, and MalwareBazaar to minimize total latency. Results are normalized into a consistent schema before being passed to the Groq synthesis step, so the model receives structured context rather than raw JSON blobs of varying shape.

The frontend is TypeScript. Indicator type detection (IP vs. domain vs. URL vs. hash) is handled automatically so the analyst can paste anything and get the right enrichment path without selecting a category manually.

Outcomes

  • Live at ioc-enricher-abd.vercel.app
  • Actively used for real triage work as part of the SOC analyst workflow
  • Part of the public security portfolio at m-abdullah-06/soc-analyst-portfolio