A tool every SOC should have
- Gives latest threat reports regarding an artifact (IP, domain or hash).
- Browser extension provides a real-time information about an artifact.
- Accurate in identifying malicious domains and IPs.
Cons
- For the Browser extension, since the main purpose is to present information with regards to the IP, I think it's best to give us an idea of where the IP originated/some additional information about the organization it belongs to.
- Web page display of the IP/domain reputation
- Queries for pwned domains of our clients
- Recorded Future crashes my web browser in cases I have to open a web page containing hundreds of IPs. A quick disable feature for a particular tab would be beneficial for someone like me.