FORENSIA

INTEL_GRAPH

Relationship graph

Neighborhood view for indicator-centric investigations — expand nodes in the canvas or narrow server filters via the query string.

Graph

Pass indicator_id= to center. Client filters below further narrow the payload. Search context (sq/prov/rk) is preserved in the URL for analyst continuity.

indicator_id=182419← Indicatorspermalink

Why the graph?

Neighborhood view links sightings, related indicators, and promotion paths for this IOC

The graph centers indicator #182419 so you can validate blast radius, compare pivots, and jump back to structured detail without losing your search thread.

React Flow mini map

Graph controls

{
  "node_count": 8,
  "edge_count": 7,
  "relation_types": {
    "mentions": 1,
    "ingested_via": 1,
    "linked_to": 1,
    "sightings_summary": 1,
    "enriched_by": 3
  },
  "node_types": {
    "enrichment": 3,
    "indicator": 1,
    "sighting_aggregate": 2,
    "connector": 1,
    "alert": 1
  },
  "compressed": true,
  "pre_compression": {
    "node_count": 12,
    "edge_count": 11
  }
}
{
  "edges": []
}