Built for operational cyber intelligence

CTILookUp®Cyber Intelligence Productivity Platform

Investigate. Correlate. Decide.

Turn IP addresses, domains, URLs and emails into actionable cyber intelligence through a unified investigation workflow.

Start with an observableIP addressDomainURLEmail
app.ctilookup.io
CTILookUp Insights workspace on desktop
CTILookUp Insights workspace on mobile
One investigation workspace, designed for desktop and mobile.

The problem isn’t more data.
It’s making sense of it.

Analysts move across tools to validate sources, reputation, DNS, infrastructure, web evidence and temporal signals. The work is not collecting another result. It is separating evidence from noise and establishing context.

CTILookUp brings that workflow into one place.

One observable.Multiple signals.One place to decide.

From observable to action.

A disciplined workflow for turning technical evidence into decision-ready context.

ObservableInvestigateCorrelateDecideAction
01

Investigate

Gather the evidence.

Enrich an observable with technical data, intelligence sources, security signals and relevant evidence.

02

Correlate

Connect the signals.

Identify relationships, anomalies, temporal context and meaningful patterns across multiple findings.

03

Decide

Understand what matters.

Transform correlated evidence into context that supports the analyst’s next operational decision.

One workspace.
From observable to context.

Investigate observables, correlate technical and intelligence signals, understand key findings and prioritize relevant risk without losing the investigation thread.

Intelligence that supports judgment — not replaces it.

CTILookUp does not automatically turn an isolated signal into a threat conclusion. It gathers evidence, correlates findings, provides technical and temporal context, and helps analysts understand what matters.

The analyst makes the decision.CTILookUp makes the decision better informed.

Built for the people behind the decision.

For practitioners responsible for validating evidence and choosing the next operational action.

SOC AnalystsThreat HuntersIncident RespondersCTI AnalystsDigital Forensics ProfessionalsCybercrime Investigators

Relevant context, organized around the investigation.

Observable Intelligence

  • IP address
  • Domain
  • URL
  • Email

Context & Correlation

  • Technical enrichment
  • Infrastructure context
  • Security observations
  • Temporal context
  • Key Findings

Operational Intelligence

  • Risk assessment
  • Risk drivers
  • Threat context
  • Geolocation
  • Historical analysis

Outputs

  • STIX 2.1
  • Structured findings
  • Analyst-ready context

Choose the depth of your workflow.

Plans and limits are shared with the CTILookUp application as the single product source.

Explore

User

$0/ month

Explore cyber threat intelligence analysis before moving into a professional workflow.

10 analysis credits
  • Cyber threat intelligence analysis
  • Up to 2 analyses / minute
  • 1 concurrent session
  • 1 concurrent analysis
  • 5-day retention
Start Investigating
Investigate

Starter

$7.90/ month

For occasional professional investigations and lookups.

100 analysis credits
  • Cyber threat intelligence analysis
  • Up to 5 analyses / minute
  • 1 concurrent session
  • 3 concurrent analyses
  • 30-day retention
Start Investigating
Operate

Specialist

$59.90/ month

For specialists conducting continuous high-volume investigations.

10,000 analysis credits
  • Cyber threat intelligence analysis
  • Up to 30 analyses / minute
  • 3 concurrent sessions
  • 9 concurrent analyses
  • 180-day retention
Start Investigating

Built by cybersecurity professionals,for cybersecurity professionals.

Investigate. Correlate. Decide.

From observable to context. From context to decision.

Start Investigating