An overall verdict, with its reasons
The same inputs always give the same answer, and every verdict shows why.
Security · The defenders / Cribl App
From indicator → evidence → detection, inside Cribl.
“Do we know this indicator, did we actually see it, when and where, and what's the proof?”
How it works
Paste an IP, domain or file hash, choose the sources to check and the time window, and press Run Investigation. Each source reports on its own, so one slow or failing source never blocks the others.
Why it matters
Without Threat Recon
With Threat Recon
Jumping between lookup tables, Cribl Search and VirusTotal in separate tabs
One screen, one click, every selected source checked in parallel
Writing a search query by hand for every indicator and every dataset
Queries generated from the indicator type and your field names
Threat feeds alone can't tell you what actually happened in your network
Internal intel, external reputation and real telemetry evidence, side by side
Opaque scores and AI summaries that are hard to defend
A deterministic, rule-based verdict with the exact reasons listed
Findings stay in a chat or a ticket
Saved investigations, and evidence turned into a detection candidate or a Cribl saved search
What you get
The same inputs always give the same answer, and every verdict shows why.
Events, hosts, users and datasets, first and last seen, top hosts and event types, and the raw evidence table.
When the activity happened. Click any spike to open the exact event.
Which hosts, users, datasets and destinations were connected to the indicator.
A short, plain-English summary written only from the results, with no speculation.
A Cribl Search query narrowed to the fields and datasets that matched: copy it, save it, or save it as a Cribl saved search.
Deliberately not an AI investigator: it complements Cribl's AI features with a precise, repeatable, evidence-first workflow for a single indicator.
Trust and safety
It never changes pipelines, routes, sources, destinations, workers, datasets or lookups. The only thing it can create is a saved search, after you confirm it by name.
VirusTotal adds queried indicators to its dataset, so it's never queried automatically: the analyst ticks an explicit notice every time.
The VirusTotal key lives in encrypted app storage and is injected by the Cribl proxy. Indicator values are masked in diagnostics.
It only sees what your Cribl role allows. A source you can't access shows “Permission denied”; everything else still works.
No evidence is reported as “no matching telemetry in the selected time range”, never as “safe”.
Your Cribl Lake / Search datasets and Stream lookup files. No new infrastructure. Requires Cribl.Cloud with Cribl Search.
Built by Arno Arzumanyan and Moïse Aubert (ARMO) for the Cribl App Hackathon. Community-built, open source under the Apache 2.0 licence. A demo mode with clearly labelled demo data lets anyone try it.