SOC Lens
Overview
Instant multi-source Threat Intel at your fingertips. Right-click any IOC to query 25 TI platforms simultaneously — no tab-switching
SOC Lens is a threat intelligence side panel built for analysts who need answers fast. Right-click any indicator on any page — or paste it directly — and SOC Lens queries up to 25 intelligence sources in parallel and streams results back as they arrive. Built for SOC analysts, CTI teams, CERT responders, and DFIR investigators. ──────────────────────────── INSTANT IOC TRIAGE ──────────────────────────── Highlight any indicator on any web page, right-click, and choose "Auto-detect & Lookup All". SOC Lens identifies the IOC type automatically — IPv4, IPv6, CIDR, domain, URL, MD5/SHA-1/SHA-256, email address, or CVE — and queries every relevant source simultaneously. Results stream in as each source responds, not all at once. A pinned consensus card summarises the aggregate verdict at the top so you get the conclusion before you've read a single card. Supports Ctrl+Shift+L to trigger a lookup on selected text without touching the mouse. ──────────────────────────── 25 INTELLIGENCE SOURCES ──────────────────────────── Many sources require no API key at all. The rest support free-tier keys — no paid subscription needed to get started. ──────────────────────────── BUILT FOR THE REAL WORKFLOW ──────────────────────────── Auto-refang — defanged indicators like 8[.]8[.]8[.]8 or hxxps://evil[.]com are automatically cleaned before lookup. No manual editing. QR phishing (quishing) — decode QR code images without leaving the browser. Right-click a QR image in webmail, or paste/drag a screenshot from Outlook or Teams. The decoded URL pivots straight into a full TI lookup. Bulk triage — paste a list of IOCs from an alert, screen them all in seconds, and export the results as CSV. CyberChef-style decode panel — Base64, Hex, URL encoding, entropy, hashing, timestamp conversion, and more, inline. Pivot any decoded value directly to a lookup or open in full CyberChef for complex recipes. Session reports — select history entries and export as CSV, PDF, or styled HTML ready to paste into Jira, Confluence, or a SIEM ticket. Reports include analyst name, incident reference, and per-source verdicts. ──────────────────────────── PRIVACY-FIRST ──────────────────────────── Your API keys and lookup history never leave your machine. SOC Lens calls the threat intel APIs directly from your browser — there is no SOC Lens backend, no telemetry, and no cloud sync. Everything is stored locally in Chrome's extension storage. ──────────────────────────── FREE TO USE ──────────────────────────── SOC Lens is free. Configure as many or as few API keys as you have — all free-tier sources work immediately with no sign-up required.
0 out of 5No ratings
Details
- Version1.0.0
- UpdatedAugust 12, 2026
- Offered bySoc Lens
- Size168KiB
- LanguagesEnglish (United Kingdom)
- Developer
Email
soclens@outlook.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes