SOC alert enrichment and triage

Enrich indicators so analysts can triage alerts in seconds, not minutes.

Start with 500 free credits
$curl https://encrata.com/api/agent/lookup -H "Authorization: Bearer YOUR_API_KEY" -d '{"e": "satya@microsoft.com"}'

Use-case advisor

Advisor ready

Ask how soc alert enrichment and triage should work for your exact product, data and team.

What this use case means

SOC triage uses IP, domain and breach intelligence to add context to raw alerts - geolocation, ASN, reputation, C2 detection and passive DNS - so an analyst can decide fast.

When to use it

  • Use it inside your SIEM/SOAR when analysts are drowning in low-context alerts.
  • Manual review is slow because the useful signals live across IP, Domain, Dark web and related sources.
  • Your team needs structured JSON that can feed a CRM, risk queue, SOC case, support tool, warehouse or AI agent.

How Encrata powers it

01

Capture the identifier

Extract the indicators (IPs, domains) from the alert.

02

Run the lookup stack

Enrich each with reputation, routing and threat-feed data.

03

Score the result

Pivot across shared infrastructure to map the attacker.

04

Send it downstream

Escalate confirmed threats; auto-close benign noise.

Implementation shape

Example payloadPOST /api/agent/ip
{
"use_case": "soc-alert-triage",
"input": {
"ip": "example_ip",
"domain": "example_domain",
"darkweb": "example_darkweb"
},
"fields_to_watch": [
"ip reputation",
"vpn/proxy",
"geolocation",
"domain age",
"ssl status",
"dns records"
],
"action": "escalate or close"
}

Related use cases