A fully local, passive threat analysis engine built for SOC analysts who need depth without risk. No detonation. No interaction. No compromise.
Every time an analyst visits a URL, runs a file, or resolves a domain manually — they expose themselves and their organisation to attacker-controlled infrastructure.
Clicking URLs confirms victim activity to the attacker. Visiting phishing pages can trigger tracking pixels, deliver payloads, or fingerprint the analyst's machine and IP address.
Detonation environments add minutes of latency to each investigation. They produce verbose logs, often miss evasive malware, and can't correlate email authentication context with artifact behaviour.
SPF/DKIM/DMARC verdicts are shown as raw pass/fail without explaining why. ARC chains, gateway overrides, and relay hops are invisible — leaving analysts unable to determine the true origin and authentication path.
iRECON reconstructs the full threat picture using only API-based intelligence and passive static analysis — never touching attacker infrastructure directly.
Runs entirely on your machine. No cloud processing, no telemetry, no external data transmission beyond your own API keys.
Extracts IOCs from emails and files through static analysis only. URLs are decoded and scored — never visited.
Correlates threat intelligence, infrastructure signals, entropy, impersonation patterns, and email authentication into a single risk score with full factor breakdown.
A complete investigation stack covering every phase of phishing and infrastructure analysis — from initial triage to deep enrichment.
Three-layer SOC model: Transport Flow, Authentication Timeline, and Trust Decisions. ARC chain trust mapping, gateway-level auth clarity, SPF/DKIM/DMARC per evaluator.
Passive extraction from email bodies: URLs, domains, IPs, QR codes, ICS calendar links, and attachment hashes. No interaction — all static analysis.
Full chain unwrapping of security gateway wrappers. SafeLinks, Proofpoint URLDefense (v2/v3), Mimecast Protect, Barracuda — peeled to the true destination.
Controlled redirect chain reconstruction via VirusTotal and URLScan.io intelligence. Each hop scored independently — no direct HTTP to attacker infrastructure.
Multi-signal additive scoring across 30+ factors: TI APIs, TLD risk, ASN reputation, entropy, brand impersonation, TLS age, infrastructure classification.
Unicode homoglyph detection, brand token analysis, domain entropy scoring, and lure keyword identification. Catches visually deceptive lookalike domains.
Extract embedded URLs from PDF annotations and body text, DOCX hyperlink relationships, HTML attachments, and QR codes embedded in images and documents.
Fast triage mode for mixed IOC lists — IPs, domains, URLs, and hashes in a single batch. Parallel enrichment with consolidated risk scoring.
Standalone file scanning for PDFs, DOCX, XLSX, PPTX, and images. Same Safe Processing Mode — no execution, no network calls, all in-memory static analysis.
Every IOC is scored across a tiered signal hierarchy — threat intelligence anchors the verdict, structural signals corroborate it.
Malicious/suspicious engine count, detection age, URL reputation, file hash lookup. Tiered scoring from contextual to confirmed malicious.
Checks if a domain or IP appears in community threat reports. Assigns a confidence level: Strong = actively used in malware, Suspicious = flagged but not confirmed, Contextual = mentioned in threat data. Old established domains get reduced scores to avoid false alarms.
Abuse confidence score and report volume for IP addresses. Corroborates VT findings with community-sourced abuse reporting.
Checks the network provider behind the IP — some are repeatedly abused for phishing. Detects domains registered and deployed overnight (a strong phishing signal). Distinguishes legitimate CDN use from phishing infrastructure hiding behind it. Scores the domain's TLD against a known abuse ranking.
Homoglyph analysis, brand token extraction, Levenshtein similarity scoring, lure keyword detection, and multi-signal impersonation correlation.
The only tool that reconstructs the full email transport path, maps ARC sealing entities to their actual server FQDNs, and explains exactly who evaluated and trusted what — at every hop.
Per-evaluator authentication records. Each gateway's SPF/DKIM/DMARC verdict is isolated — never merged. Proofpoint's AR-Original preserves the upstream truth before M365 re-evaluates against relay IPs.
ARC chain with actual sealing server FQDNs mapped from transport hops. Sender identity mismatch detection. Final verdict with provenance — AR-Original wins over downstream re-evaluation.
Amazon SES, SendGrid, Mailgun and 15+ ESPs are detected. smtp.mailfrom ≠ From is classified as informational, not anomalous — no false positives on legitimate bulk mail.
A lightweight FastAPI backend with a pure static frontend. No database. No persistent storage. Stateless by design.
iRECON's security model is not a feature — it is the architecture. Every design decision enforces analyst safety at the code level.
No HTTP requests, no DNS lookups, no socket connections to extracted IOCs at any point in the analysis pipeline. Threat intelligence is fetched only from trusted TI APIs using the IOC as a query string.
Attachments are parsed in-memory using pure Python string operations. PDFs, Office documents, and images are never executed, rendered through external engines, or written to disk. SHA-256 hashing uses stdlib only.
iRECON never stores, transmits, or logs your API keys beyond the local profile. Keys are used only to call TI APIs on your behalf. No telemetry, no phone-home, no analytics.
All analysis runs on your machine. Email content, extracted IOCs, and investigation context never leave your environment. Safe for use with sensitive incident data and protected communications.
From daily phishing triage to deep incident response — iRECON fits every stage of the SOC workflow.
Process reported phishing emails in seconds. Full header analysis, artifact extraction, and risk scoring in a single pass — without touching a single attacker URL.
Reconstruct the complete attack chain: mail flow, authentication path, URL redirection chain, payload delivery infrastructure, and brand impersonation signals.
Safe-mode artifact analysis of suspicious files and emails during active incidents. Identify IOCs without risk of further compromise or attacker notification.
Bulk IOC enrichment for hunting operations. Mix IPs, domains, URLs, and hashes in a single batch. Correlate infrastructure signals across large IOC sets rapidly.