SOCRadar XTI
Overview
Enrich IPs, domains, URLs & hashes with SOCRadar threat intel as JSON or STIX 2.1, add to Company Pocket, plus malware analysis.
SOCRadar XTI brings SOCRadar threat intelligence right into your browser, so you can enrich indicators without breaking your investigation flow. Select or right-click any IP, domain, URL, or file hash on a page and instantly get a verdict, risk score, and the context behind it — pulled from your own SOCRadar account. You choose the format: enrich as JSON, or as an official STIX 2.1 bundle ready for your TIP or SIEM. A side panel collects every indicator on the page for fast bulk triage, and an optional Malware Analysis module lets you submit URLs and files or look up hashes and read the results without leaving the tab. WHAT YOU CAN DO • Enrich IPs, domains, URLs, and file hashes in context — via right-click, a selection chip, or by clicking an auto-highlighted indicator on the page. • Choose your format at query time: "Enrich JSON" for the full enrichment response, or "Enrich STIX" for the official SOCRadar STIX 2.1 bundle. Each is a single API call — you decide which one to spend it on. • See verdict, risk score, and supporting details (country, ASN, first/last seen, threat actors, tags, categories) at a glance — then copy or download the JSON, or copy or download the STIX bundle. • Collect every indicator on a page into a side panel, tick exactly the ones you want with checkboxes, and act in bulk: Copy selected, Export selected (CSV), Enrich selected, Pocket selected, Analyze selected. • Company Pocket: add indicators to your SOCRadar company pocket from the page, the side panel, the result card, or the right-click menu — without spending enrichment credits. • Optional Malware Analysis: Analyze URL, Analyzed Files Lookup (search your previously analyzed files by hash), or Analyze file — including .eml and .msg with nested attachment verdicts, plus structural and dynamic results and screenshots. • Works on any http(s) page you investigate — SIEM consoles, ticketing systems, reports, threat feeds, and webmail. HOW IT WORKS SOCRadar XTI uses YOUR OWN SOCRadar API access. Add your SOCRadar IoC Enrichment API key (and, if you use them, your Malware Analysis key and Company Pocket key) in the extension's Options. Entering a key enables its module automatically, and each module can be turned on or off independently. No third-party servers are involved — the extension talks only to SOCRadar's API on your behalf. REQUIREMENTS • A SOCRadar account with API access (IoC Enrichment, and optionally Malware Analysis and/or the Standard API for Company Pocket). • Existing customers: SOCRadar platform → API & Integrations → API Options / Keys. Not a customer yet, including freemium? Open a ticket at help.socradar.io or email support@socradar.io. PRIVACY The extension only sends the indicators you choose — and, for the malware module, the URLs/files/hashes you submit — to SOCRadar's API using your key. Your API keys are stored locally in your browser and are never exposed to the pages you visit. There is no SOCRadar XTI backend, no analytics, no remote code, and no ads. Privacy policy: https://socradar.io/privacy-policy/ SOCRadar, the SOCRadar logo, and "XTI" are trademarks of SOCRadar.
0 out of 5No ratings
Details
- Version1.6.2
- UpdatedJuly 17, 2026
- Offered bySOCRadar Cyber Intelligence Inc.
- Size87.98KiB
- LanguagesEnglish
- Developer
Email
integration@socradar.io - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
SOCRadar XTI has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
SOCRadar XTI handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site