TLP:CLEAR
SOCDESK
EDITION
TRACKED OBJECTS 0
LAST INGEST · NEXT PULL
The analyst's first stop — open-source threat intelligence
Try

Disclosure Pivot links send that indicator to the third-party service you click (urlscan publishes public scans). Use public indicators only. Everything you paste, mark or save stays in this browser — there is no backend, no account and no analytics.

Live wire
Work queue · 5 automated collectors · most relevant first

Threat feed

Every item scored 0–100 from KEV, EPSS, severity and recency — the queue surfaces what matters, chronology is one toggle away.
Work queue · all
KEV × CVSS × EPSS

Vulnerability triage

Actively exploited and most-likely-exploited first. A KEV chip means CISA has confirmed exploitation in the wild.
CVESeverity CVSSEPSS KEVProduct / vendor Published
MITRE ATT&CK · tracked profiles

Actors & malware

Every profile resolves in the verdict console — techniques, aliases and associated software, traced to ATT&CK.
Independently degradable

Collection health

One failing source degrades to a warning — never a broken page. Last-known-good data is retained.
0 collectors · 0 reference

Source registry

Collector-backed feeds are published here; reference sources are reached by pivot link, never mirrored.
SourceTypeOperational coverageAccess
Runs entirely in your browser

Analyst toolbelt

Paste artifacts straight from an alert. Nothing you type here leaves the page.
Defang / refang
IOC extract
Base64 decode · UTF-16LE aware
PowerShell command parser
LOLBin lookup
In-context lookup

Bookmarklet

On any page — a SIEM result, a ticket, an email header — select an indicator and click the bookmark. The console opens with the verdict already resolved. Select several at once and you get a bulk lookup.

The indicator travels in the URL fragment, which browsers never send to a server, so nothing you look up is transmitted to this site's host. No extension, no install, no permissions.

SOCDesk lookup ← drag to your bookmarks bar
AI-generated · local inference

Daily brief

Written on local hardware from the last 24 hours of collected intelligence. Generated .
Daily news and research
Vulnerability records
Actor and malware profiles
Analyst utilities
SOCDesk — a personal project by Carlos Sanchez (Sanchez on Security). Not affiliated with or endorsed by any employer; not an official tool of any organization. KEV (CISA, CC0) · NVD (NIST, public domain) · EPSS (FIRST) · ATT&CK © THE MITRE CORPORATION · NO WARRANTY — VERIFY BEFORE ACTING