Custom Enrichment MCP
A practical way for SOC analysts to gather and review security context without adding paid API subscriptions to the client's stack.
- Client
- Security professional
- Constraint
- No budget for paid enrichment APIs
- Work
- Workflow design and a custom enrichment utility
The situation
The analysts were enriching investigations by moving between separate public sources and repeating the same checks by hand. The team wanted a faster, more consistent process, but the client did not want to take on paid API subscriptions.
How we approached it
We started with the analysts' actual investigation flow: what they looked up, when they needed context, and which decisions still required human judgment. From that, we built a Custom Enrichment MCP that brought selected no-cost sources into one repeatable workflow. It accepts the indicators an investigation starts with—such as an IP address, domain, URL, file hash, or email—and directs the right lookups without the analyst having to rebuild the process each time.
The service combines threat-intelligence context with security knowledge bases, including MITRE ATT&CK, Sigma, LOLBAS, and GTFOBins. It presents the returned context in a consistent, source-labelled format, allowing a professional to assess the evidence rather than treating automation as an autonomous verdict.
Evidence in. Context out.
One repeatable path from an investigation indicator to source-labelled context.
Security professional
Starts with an IP, domain, URL, file hash, or email.
Custom Enrichment MCP
Routes approved lookups and normalizes the returned context.
Threat intelligence
Public indicator context
MITRE ATT&CK
Adversary techniques
Sigma
Detection-rule context
LOLBAS · GTFOBins
Living-off-the-land context
Source-labelled context returns to the professional, who keeps the judgment.
What changed
The security professional had one clear place to begin enrichment instead of rebuilding the same sequence of lookups for every investigation. The workflow reduced context switching, made the process easier to repeat, and met the client's cost constraint without hiding where the underlying information came from.
Have a security workflow that does not fit an off-the-shelf tool?
Explore custom security projects