SOC-GRADE INVESTIGATION TOOL
iRECN
Contextual Infrastructure Intelligence

A fully local, passive threat analysis engine built for SOC analysts who need depth without risk. No detonation. No interaction. No compromise.

NO URL Interaction NO DNS Resolution to IOCs NO Payload Execution Memory-Only Processing Intelligence-Driven
Explore Features ↓ GitHub ↗
9+ Analysis Modules
4 TI APIs Integrated
100% Local Processing
0 IOC Interactions
// THE PROBLEM

Traditional Investigation
Creates Risk

Every time an analyst visits a URL, runs a file, or resolves a domain manually — they expose themselves and their organisation to attacker-controlled infrastructure.

Direct Infrastructure Contact

Clicking URLs confirms victim activity to the attacker. Visiting phishing pages can trigger tracking pixels, deliver payloads, or fingerprint the analyst's machine and IP address.

🐢
Sandboxes Are Slow & Noisy

Detonation environments add minutes of latency to each investigation. They produce verbose logs, often miss evasive malware, and can't correlate email authentication context with artifact behaviour.

🔗
Missing Email Context

SPF/DKIM/DMARC verdicts are shown as raw pass/fail without explaining why. ARC chains, gateway overrides, and relay hops are invisible — leaving analysts unable to determine the true origin and authentication path.

Passive Intelligence.
Zero Risk.

iRECON reconstructs the full threat picture using only API-based intelligence and passive static analysis — never touching attacker infrastructure directly.

iRECON // SAFE PROCESSING MODE
analyze --target phish.site/login
Extracting artifacts...
URLs found: 3 · Domains: 2 · IPs: 1

VT malicious:8 suspicious:2
OTX tier:Suspicious pulses:4
TLD high-risk (.xyz)
ASN DigitalOcean (abused)
TLS 7 days old
Entropy high (3.82)

Risk Score: 67 ■ HIGH THREAT

No HTTP requests made to analyzed domains
No DNS resolution of attacker infrastructure
SAFE PROCESSING MODE — CORE PRINCIPLE

Analyst Safety Is
Non-Negotiable

Every iRECON analysis runs under a strict isolation model. The engine never reaches out to attacker-controlled infrastructure regardless of what is being investigated.

🌐
HTTP Requests
to extracted URLs
or domains
🔎
DNS Resolution
of IOC targets
or attacker infra
⚙️
File Execution
of attachments,
scripts, or macros
💾
Disk Writes
all processing
in-memory only
📡
Socket Connections
to extracted
infrastructure
// CAPABILITIES

Feature Overview

A complete investigation stack covering every phase of phishing and infrastructure analysis — from initial triage to deep enrichment.

01
📧
Email Header Analysis

Three-layer SOC model: Transport Flow, Authentication Timeline, and Trust Decisions. ARC chain trust mapping, gateway-level auth clarity, SPF/DKIM/DMARC per evaluator.

SPFDKIMDMARCARCGateway Detection
02
🔗
Artifact Extraction

Passive extraction from email bodies: URLs, domains, IPs, QR codes, ICS calendar links, and attachment hashes. No interaction — all static analysis.

URLsDomainsIPsQR CodesICS
03
🔓
URL Unwrapping

Full chain unwrapping of security gateway wrappers. SafeLinks, Proofpoint URLDefense (v2/v3), Mimecast Protect, Barracuda — peeled to the true destination.

SafeLinksURLDefenseMimecastBarracuda
04
Redirect Chain Analysis

Controlled redirect chain reconstruction via VirusTotal and URLScan.io intelligence. Each hop scored independently — no direct HTTP to attacker infrastructure.

VirusTotalURLScan.ioPer-hop Scoring
05
📊
Risk Scoring Engine

Multi-signal additive scoring across 30+ factors: TI APIs, TLD risk, ASN reputation, entropy, brand impersonation, TLS age, infrastructure classification.

30+ FactorsAdditiveExplainable
06
🔤
Homoglyph & Entropy Detection

Unicode homoglyph detection, brand token analysis, domain entropy scoring, and lure keyword identification. Catches visually deceptive lookalike domains.

HomoglyphsEntropyBrand TokensLure Keywords
07
📎
Attachment Intelligence

Extract embedded URLs from PDF annotations and body text, DOCX hyperlink relationships, HTML attachments, and QR codes embedded in images and documents.

PDF LinksDOCX HyperlinksQR ExtractionSHA-256
08
Bulk IOC Analysis

Fast triage mode for mixed IOC lists — IPs, domains, URLs, and hashes in a single batch. Parallel enrichment with consolidated risk scoring.

Mixed IOCsParallelFast Triage
09
📄
File Analysis

Standalone file scanning for PDFs, DOCX, XLSX, PPTX, and images. Same Safe Processing Mode — no execution, no network calls, all in-memory static analysis.

PDFDOCXImages10MB limit
// INTELLIGENCE ENGINE

Multi-Signal Risk Correlation

Every IOC is scored across a tiered signal hierarchy — threat intelligence anchors the verdict, structural signals corroborate it.

VirusTotal Detection
PRIMARY THREAT INTELLIGENCE
+20
OTX Pulse Intelligence
ALIENVAULT / OTXV2
+10
High-Risk TLD (.xyz, .to)
TLD RISK TAXONOMY
+15
Abused ASN Infrastructure
ASN REPUTATION / INFRA CLASS
+8
TLS Certificate Age
TLS FRESHNESS SIGNAL
+5
Multi-Signal Correlation
BEHAVIORAL PATTERN DETECTION
+10
FINAL RISK SCORE
68
HIGH THREAT
🌐
VirusTotal

Malicious/suspicious engine count, detection age, URL reputation, file hash lookup. Tiered scoring from contextual to confirmed malicious.

👁
OTX AlienVault

Checks if a domain or IP appears in community threat reports. Assigns a confidence level: Strong = actively used in malware, Suspicious = flagged but not confirmed, Contextual = mentioned in threat data. Old established domains get reduced scores to avoid false alarms.

🚨
AbuseIPDB

Abuse confidence score and report volume for IP addresses. Corroborates VT findings with community-sourced abuse reporting.

🏗
Infrastructure Classification

Checks the network provider behind the IP — some are repeatedly abused for phishing. Detects domains registered and deployed overnight (a strong phishing signal). Distinguishes legitimate CDN use from phishing infrastructure hiding behind it. Scores the domain's TLD against a known abuse ranking.

🔣
Brand & Impersonation Detection

Homoglyph analysis, brand token extraction, Levenshtein similarity scoring, lure keyword detection, and multi-signal impersonation correlation.

// HIGHLIGHT FEATURE

Visual Mail Flow &
ARC Chain Trust Map

The only tool that reconstructs the full email transport path, maps ARC sealing entities to their actual server FQDNs, and explains exactly who evaluated and trusted what — at every hop.

LAYER 1 — TRANSPORT FLOW · Reconstructed from Received headers · Oldest hop first
TRUE ORIGIN
ses-smtp-out.example-sender.com
[203.0.113.57]
GATEWAY
mail-gateway.pphosted.com
[198.51.100.216]
M365 EOP
abc1def2xyz3456.mail.protection.outlook.com
[IPv6]
MAILBOX
recipient@example-corp.com
internal relay
ARC CHAIN: i=1 · Microsoft 365 abc1def2xyz3456.mail.protection.outlook.com cv=none (first stamp) ✓ TRUSTED BY FINAL GATEWAY AR-Original: Proofpoint PASS
LAYER 2 — AUTH TIMELINE

Per-evaluator authentication records. Each gateway's SPF/DKIM/DMARC verdict is isolated — never merged. Proofpoint's AR-Original preserves the upstream truth before M365 re-evaluates against relay IPs.

LAYER 3 — TRUST DECISIONS

ARC chain with actual sealing server FQDNs mapped from transport hops. Sender identity mismatch detection. Final verdict with provenance — AR-Original wins over downstream re-evaluation.

ESP AWARENESS

Amazon SES, SendGrid, Mailgun and 15+ ESPs are detected. smtp.mailfrom ≠ From is classified as informational, not anomalous — no false positives on legitimate bulk mail.

Clean, Modular Design

A lightweight FastAPI backend with a pure static frontend. No database. No persistent storage. Stateless by design.

FRONTEND — Static UI
HTML / CSS / Vanilla JS
Single-page application
FastAPI static file serving
Offline-capable
No frontend framework deps
BACKEND — Python / FastAPI
async / await throughout
Concurrent TI API calls
Per-request session tracking
Rate limiting middleware
Profile-based API key mgmt
ANALYSIS MODULES (9+)
email_parser
email_artifacts
redirect_chain
risk_engine
infra_classifier
brand_similarity
domain_entropy
tls_checker
subdomain_enum
url_heuristics
otx · virustotal · abuseipdb · urlscan
// SECURITY MODEL

Built for Analysts.
Trusted by Design.

iRECON's security model is not a feature — it is the architecture. Every design decision enforces analyst safety at the code level.

🚫
Zero Attacker Infrastructure Contact

No HTTP requests, no DNS lookups, no socket connections to extracted IOCs at any point in the analysis pipeline. Threat intelligence is fetched only from trusted TI APIs using the IOC as a query string.

💊
No Payload Execution

Attachments are parsed in-memory using pure Python string operations. PDFs, Office documents, and images are never executed, rendered through external engines, or written to disk. SHA-256 hashing uses stdlib only.

🔑
BYOK — Bring Your Own API Keys

iRECON never stores, transmits, or logs your API keys beyond the local profile. Keys are used only to call TI APIs on your behalf. No telemetry, no phone-home, no analytics.

🏠
Fully Local Processing

All analysis runs on your machine. Email content, extracted IOCs, and investigation context never leave your environment. Safe for use with sensitive incident data and protected communications.

// USE CASES

Who Uses iRECON

From daily phishing triage to deep incident response — iRECON fits every stage of the SOC workflow.

01 📬
SOC Email Triage

Process reported phishing emails in seconds. Full header analysis, artifact extraction, and risk scoring in a single pass — without touching a single attacker URL.

02 🎣
Phishing Investigation

Reconstruct the complete attack chain: mail flow, authentication path, URL redirection chain, payload delivery infrastructure, and brand impersonation signals.

03 🔥
Incident Response

Safe-mode artifact analysis of suspicious files and emails during active incidents. Identify IOCs without risk of further compromise or attacker notification.

04 🔭
Threat Hunting

Bulk IOC enrichment for hunting operations. Mix IPs, domains, URLs, and hashes in a single batch. Correlate infrastructure signals across large IOC sets rapidly.