
Add and enrich entities. See shared infrastructure and identities as you work.
Query threat intelligence, infrastructure, identity, breach, blockchain, and company data from the graph.


Connect internal and proprietary data sources through private enrichments.

Define your own entity types when the defaults don't fit your case.

Link images and files to entities so evidence stays with your analysis.
Shared data points are connected automatically, revealing related infrastructure and identities.

Run up to 1,000 enrichments at once, then move or retype entities in bulk to keep large investigations manageable.

Work in the same case at the same time, with organization roles and case-level access controls.

Keep graphs, files, and analysis organized in cases that stay synchronized across your team.

Work on the same graph with other analysts and see their changes in real time.

Use roles and case-level permissions to control who can view or modify investigations.
Bring data from your preferred intelligence providers into the graph, run enrichments in bulk, and connect internal sources through private enrichments.

Plans for individual analysts, teams, and self-hosted deployments.

