Item logo image for SOC Lens

SOC Lens

ExtensionTools2 users
Item media 5 (screenshot) for SOC Lens
Item media 1 (screenshot) for SOC Lens
Item media 2 (screenshot) for SOC Lens
Item media 3 (screenshot) for SOC Lens
Item media 4 (screenshot) for SOC Lens
Item media 5 (screenshot) for SOC Lens
Item media 1 (screenshot) for SOC Lens
Item media 1 (screenshot) for SOC Lens
Item media 2 (screenshot) for SOC Lens
Item media 3 (screenshot) for SOC Lens
Item media 4 (screenshot) for SOC Lens
Item media 5 (screenshot) for SOC Lens

Overview

Instant multi-source Threat Intel at your fingertips. Right-click any IOC to query 25 TI platforms simultaneously — no tab-switching

SOC Lens is a threat intelligence side panel built for analysts who need answers fast. Right-click any indicator on any page — or paste it directly — and SOC Lens queries up to 25 intelligence sources in parallel and streams results back as they arrive. Built for SOC analysts, CTI teams, CERT responders, and DFIR investigators. ──────────────────────────── INSTANT IOC TRIAGE ──────────────────────────── Highlight any indicator on any web page, right-click, and choose "Auto-detect & Lookup All". SOC Lens identifies the IOC type automatically — IPv4, IPv6, CIDR, domain, URL, MD5/SHA-1/SHA-256, email address, or CVE — and queries every relevant source simultaneously. Results stream in as each source responds, not all at once. A pinned consensus card summarises the aggregate verdict at the top so you get the conclusion before you've read a single card. Supports Ctrl+Shift+L to trigger a lookup on selected text without touching the mouse. ──────────────────────────── 25 INTELLIGENCE SOURCES ──────────────────────────── Many sources require no API key at all. The rest support free-tier keys — no paid subscription needed to get started. ──────────────────────────── BUILT FOR THE REAL WORKFLOW ──────────────────────────── Auto-refang — defanged indicators like 8[.]8[.]8[.]8 or hxxps://evil[.]com are automatically cleaned before lookup. No manual editing. QR phishing (quishing) — decode QR code images without leaving the browser. Right-click a QR image in webmail, or paste/drag a screenshot from Outlook or Teams. The decoded URL pivots straight into a full TI lookup. Bulk triage — paste a list of IOCs from an alert, screen them all in seconds, and export the results as CSV. CyberChef-style decode panel — Base64, Hex, URL encoding, entropy, hashing, timestamp conversion, and more, inline. Pivot any decoded value directly to a lookup or open in full CyberChef for complex recipes. Session reports — select history entries and export as CSV, PDF, or styled HTML ready to paste into Jira, Confluence, or a SIEM ticket. Reports include analyst name, incident reference, and per-source verdicts. ──────────────────────────── PRIVACY-FIRST ──────────────────────────── Your API keys and lookup history never leave your machine. SOC Lens calls the threat intel APIs directly from your browser — there is no SOC Lens backend, no telemetry, and no cloud sync. Everything is stored locally in Chrome's extension storage. ──────────────────────────── FREE TO USE ──────────────────────────── SOC Lens is free. Configure as many or as few API keys as you have — all free-tier sources work immediately with no sign-up required.

Details

  • Version
    1.0.0
  • Updated
    August 12, 2026
  • Offered by
    Soc Lens
  • Size
    168KiB
  • Languages
    English (United Kingdom)
  • Developer
    Email
    soclens@outlook.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes
Google apps