Security · The defenders / Cribl App

ArMo Threat Recon

From indicator → evidence → detection, inside Cribl.

“Do we know this indicator, did we actually see it, when and where, and what's the proof?”

  • Cribl App
  • Released · v0.1.3
  • Cribl App Hackathon
  • Open source · Apache-2.0

How it works

One indicator. One click. One clear answer.

Paste an IP, domain or file hash, choose the sources to check and the time window, and press Run Investigation. Each source reports on its own, so one slow or failing source never blocks the others.

  1. Enter an indicatorIPv4, IPv6, domain, MD5, SHA-1 or SHA-256, detected and validated in the browser.
  2. Select sourcesCribl Lookups, Cribl Lake / Search, and VirusTotal if you choose.
  3. Set the time rangeFrom 15 minutes to 30 days, or a custom window.
  4. Get the answerVerdict, evidence, timeline and a detection candidate.

Why it matters

“It's in a threat feed” isn't “it hit our network”.

Without Threat Recon

With Threat Recon

Jumping between lookup tables, Cribl Search and VirusTotal in separate tabs

One screen, one click, every selected source checked in parallel

Writing a search query by hand for every indicator and every dataset

Queries generated from the indicator type and your field names

Threat feeds alone can't tell you what actually happened in your network

Internal intel, external reputation and real telemetry evidence, side by side

Opaque scores and AI summaries that are hard to defend

A deterministic, rule-based verdict with the exact reasons listed

Findings stay in a chat or a ticket

Saved investigations, and evidence turned into a detection candidate or a Cribl saved search

What you get

Proof, not guesses.

  • Malicious
  • Suspicious
  • Internal Match
  • Observed
  • No Evidence
  • Inconclusive

An overall verdict, with its reasons

The same inputs always give the same answer, and every verdict shows why.

What was observed

Events, hosts, users and datasets, first and last seen, top hosts and event types, and the raw evidence table.

An event timeline

When the activity happened. Click any spike to open the exact event.

Evidence relationships

Which hosts, users, datasets and destinations were connected to the indicator.

An incident story

A short, plain-English summary written only from the results, with no speculation.

A detection candidate

A Cribl Search query narrowed to the fields and datasets that matched: copy it, save it, or save it as a Cribl saved search.

Deliberately not an AI investigator: it complements Cribl's AI features with a precise, repeatable, evidence-first workflow for a single indicator.

Trust and safety

Safe by design.

Read-only

It never changes pipelines, routes, sources, destinations, workers, datasets or lookups. The only thing it can create is a saved search, after you confirm it by name.

External lookups need consent

VirusTotal adds queried indicators to its dataset, so it's never queried automatically: the analyst ticks an explicit notice every time.

No secrets in the browser

The VirusTotal key lives in encrypted app storage and is injected by the Cribl proxy. Indicator values are masked in diagnostics.

Respects your permissions

It only sees what your Cribl role allows. A source you can't access shows “Permission denied”; everything else still works.

Honest results

No evidence is reported as “no matching telemetry in the selected time range”, never as “safe”.

Uses what you already have

Your Cribl Lake / Search datasets and Stream lookup files. No new infrastructure. Requires Cribl.Cloud with Cribl Search.

Built by Arno Arzumanyan and Moïse Aubert (ARMO) for the Cribl App Hackathon. Community-built, open source under the Apache 2.0 licence. A demo mode with clearly labelled demo data lets anyone try it.