Cylist
A triage buddy at your fingertips.
Made for SOC analysts, by SOC analysts.
One search, four intelligence sources
Paste an IP address, domain, URL or file hash. Cylist queries every source that covers it in parallel and combines the results into a single threat score.
VirusTotal
IPs, domains, file hashesDetections from around 95 engines, community reputation, network ownership and WHOIS.
AbuseIPDB
IPsAbuse confidence score, report history, ISP, geolocation and TOR exit detection.
ThreatFox
IPs, domains, URLs, file hashesMalware family, threat type and confidence from abuse.ch's IOC database.
ipinfo.io
IPsWho operates an address and where it's registered: ASN, network operator and country.
How it works
- Step 1
Search an indicator
Enter an IP, domain, URL or hash. Cylist detects the type and queries the matching sources.
- Step 2
Read one verdict
Results are scored and combined into a threat level, with each source's findings a click away.
- Step 3
Report and share
Generate an AI case report, save indicators to collections, and work through cases with your team.
Common questions
What is Cylist?+
Cylist is a threat intelligence triage platform for SOC analysts. It checks an indicator of compromise against several threat intelligence sources at once, scores the result and can write an AI case report for it.
Which indicators can I look up?+
IPv4 and IPv6 addresses, domains, URLs, and MD5, SHA-1 and SHA-256 file hashes.
Is Cylist free?+
Yes. Cylist is free to use right now; paid plans for heavier use and teams are coming later.
Is my identity shared with the intelligence sources?+
No. Only the indicator you look up is sent to the threat intelligence sources, never your identity or account details.