Cylist

Cylist

A triage buddy at your fingertips.

Made for SOC analysts, by SOC analysts.

Speed
Tired of searching through endless lists of indicators with multiple tabs open? We've got you covered.
Optimization
We have optimized the platform so you can minimize your time spent on triaging IOCs.
Simplification
We've stripped out all the clutter and complexity, so you can focus on what really matters.

One search, four intelligence sources

Paste an IP address, domain, URL or file hash. Cylist queries every source that covers it in parallel and combines the results into a single threat score.

VirusTotal

IPs, domains, file hashes

Detections from around 95 engines, community reputation, network ownership and WHOIS.

AbuseIPDB

IPs

Abuse confidence score, report history, ISP, geolocation and TOR exit detection.

ThreatFox

IPs, domains, URLs, file hashes

Malware family, threat type and confidence from abuse.ch's IOC database.

ipinfo.io

IPs

Who operates an address and where it's registered: ASN, network operator and country.

How it works

  1. Step 1

    Search an indicator

    Enter an IP, domain, URL or hash. Cylist detects the type and queries the matching sources.

  2. Step 2

    Read one verdict

    Results are scored and combined into a threat level, with each source's findings a click away.

  3. Step 3

    Report and share

    Generate an AI case report, save indicators to collections, and work through cases with your team.

Common questions

What is Cylist?+

Cylist is a threat intelligence triage platform for SOC analysts. It checks an indicator of compromise against several threat intelligence sources at once, scores the result and can write an AI case report for it.

Which indicators can I look up?+

IPv4 and IPv6 addresses, domains, URLs, and MD5, SHA-1 and SHA-256 file hashes.

Is Cylist free?+

Yes. Cylist is free to use right now; paid plans for heavier use and teams are coming later.

Is my identity shared with the intelligence sources?+

No. Only the indicator you look up is sent to the threat intelligence sources, never your identity or account details.