What Orion Investigates
Indicators of compromise
Analyze and correlate IOCs — hashes, IPs, domains, URLs — to determine whether
they’re tied to known threats.
Domain & IP reputation
Check the reputation and registration details of domains and IP addresses, and
map the infrastructure behind them.
Threat investigations
Investigate suspected threats and attribute activity to known campaigns or
actors where the evidence supports it.
Exposure checks
Check whether an email address or domain appears in known breaches, and review
domain-security posture.
How to Use Orion
Ask Orion in plain language, and@-mention it to send an investigation straight its way:
- “@Orion investigate the domain example-malicious.com and tell me if it’s linked to known campaigns.”
- “Is this IP address associated with malicious activity?”
- “Check whether this email address has been exposed in a breach.”
In the SOC Flow
When you investigate an alert, Centurion’s SOC variant can call on Orion to enrich the detection — turning raw indicators into context you can act on. This is often the first step of an investigation: understand what you’re looking at before you respond.From Intelligence to Action
Orion tells you what’s dangerous; the rest of the team acts on it. Once Orion confirms a threat, Hydra can block it on your firewalls, Perseus can respond on an affected host, and Scribe can document the whole investigation.Orion focuses on threat-specific intelligence. For general web research and
external context, that’s Iris.