IoCHub // ioc graph
vt key:not set backend:offline

VirusTotal API key

The key is encrypted in your browser with your password and stored on the server only as ciphertext. The server can never read it. It is decrypted on login and requires logging in again after a page reload.

MISP

instance:
The key is encrypted in your browser with your password like the VT key. MISP queries run directly from your browser to the instance (MISP allows CORS). Common attributes (hashes) cross-check with VirusTotal; comments/tags become misp.*; galaxies & events spawn as sub-entities.

Backend

Used for the VT relay, CAPE (later) and optional server-side graph sync.

Sub-entity fields (which attributes auto-render as sub-entities)

Autopivot rules (graph auto-expansion; depth, per-type false-positive sensitivity, and attribute rules)

passes over the graph (newly-added nodes are pivoted next pass)
task log
graph storage
Two graph slots, encrypted with your password and stored on the server. Download to keep a permanent copy.
entities
report extractor
waiting…
click an entity → details & enrichers · right-click a sub-entity → collapse · drag to move · scroll to zoom