Skip to main content
Orion is the threat intelligence and reconnaissance specialist. When you need to know whether something is dangerous — an indicator of compromise, a domain, an IP address, an email — Orion investigates it and tells you what it found and how concerned you should be.

What Orion Investigates

Indicators of compromise

Analyze and correlate IOCs — hashes, IPs, domains, URLs — to determine whether they’re tied to known threats.

Domain & IP reputation

Check the reputation and registration details of domains and IP addresses, and map the infrastructure behind them.

Threat investigations

Investigate suspected threats and attribute activity to known campaigns or actors where the evidence supports it.

Exposure checks

Check whether an email address or domain appears in known breaches, and review domain-security posture.

How to Use Orion

Ask Orion in plain language, and @-mention it to send an investigation straight its way:
  • “@Orion investigate the domain example-malicious.com and tell me if it’s linked to known campaigns.”
  • “Is this IP address associated with malicious activity?”
  • “Check whether this email address has been exposed in a breach.”

In the SOC Flow

When you investigate an alert, Centurion’s SOC variant can call on Orion to enrich the detection — turning raw indicators into context you can act on. This is often the first step of an investigation: understand what you’re looking at before you respond.

From Intelligence to Action

Orion tells you what’s dangerous; the rest of the team acts on it. Once Orion confirms a threat, Hydra can block it on your firewalls, Perseus can respond on an affected host, and Scribe can document the whole investigation.
Orion focuses on threat-specific intelligence. For general web research and external context, that’s Iris.