Cortex
· #181 most-usedRun every security analyzer. Fire every responder. From one agent.
Cortex is a security analytics engine built for SOCs, CSIRTs, and threat hunters — it lets you submit any observable (IP, domain, URL, file hash) to dozens of analyzers simultaneously and respond to confirmed threats with a single API call. Connect Cortex to Actionist and your agents can execute analyzers against live IoCs, retrieve structured verdict reports, fire responders to block IPs or quarantine endpoints, and chain the results into TheHive cases, Slack alerts, and SIEM enrichment — all without an analyst touching a browser.
Eliminates manual work. Cortex automation eliminates the manual copy-paste cycle of submitting observables to individual tools, waiting for results, and transcribing verdicts into incident tickets.
What your Cortex agent runs on autopilot
A week of scheduled jobs your Actionist agent will execute on your behalf.
Cortex × every other app you use
End-to-end automations that span multiple apps — each one a real business outcome.
Phishing alert triage, start to block
When a suspicious email lands in the security inbox, your agent pulls the embedded URLs and sender domain into Cortex, fires Execute Analyzer against VirusTotal and URLScan, reads the verdict reports, then posts a ranked risk summary to the #soc Slack channel and blocks the top-scoring domains—mean-time-to-containment under three minutes, zero analyst clicks.
Time saved for your team — every week, on autopilot
Savings
What your team gets back — two angles: what you stop doing manually, and what that's worth.
What you do manually today
What your agent runs for you
- Sales18 min / weekVendor domain reputation check
Sales engineers manually look up prospect domains in VirusTotal before demos, spending 15–20 minutes per account.
Sales Agent0 minAgent pre-screens every new prospectThe agent submits the domain to Cortex on deal creation and logs the verdict in the CRM before the first call is scheduled.
- Marketing13 min / weekLookalike domain scan before campaign
Marketing manually searches brand-lookalike domains before major campaign launches to check for typosquatting.
Marketing Agent0 minAgent monitors lookalikes at launchThe agent submits campaign domains to Cortex analyzers on HubSpot campaign activation and flags any hijack risk instantly.
- Customer Support18 min / weekPhishing link triage in support inbox
Support agents manually submit suspicious URLs from customer emails to VirusTotal one by one before responding.
Customer Support Agent0 minAgent triages and blocks in minutesThe agent extracts URLs from flagged emails, runs Cortex analyzers, and posts a verdict to the ticket before the support rep opens it.
- Human Resources7 min / weekNew contractor background domain check
HR manually verifies contractor company domains and email infrastructure before provisioning system access.
Human Resources Agent0 minAgent clears contractors on onboardingThe agent runs Cortex reputation checks on contractor domains as part of the automated onboarding workflow before access is granted.
- Finance13 min / weekPayee domain check before wire transfer
Finance teams manually verify high-value payee domains against threat databases to catch BEC fraud before approving wires.
Finance Agent0 minAgent screens every large paymentThe agent submits the payee domain to Cortex fraud analyzers automatically on payment approval requests above threshold.
- Operations25 min / weekNew vendor security vetting
Operations spends two days manually running vendor domains through multiple security tools during supplier onboarding.
Operations Agent0 minAgent vets vendors in ten minutesThe agent submits vendor domains to Cortex on procurement-sheet entry, retrieves the risk verdict, and logs it to the vendor register.
- Legal6 min / weekThird-party compliance domain audit
Legal manually checks partner domains for certificate anomalies and known malware infrastructure during due diligence.
Legal Agent0 minAgent runs due-diligence scans automaticallyThe agent submits partner domains to Cortex on contract initiation and attaches the verdict report to the legal review task.
Calculate what your team saves
Based on Cortex's typical team usage — the visible tasks plus a few other automations the agent runs: ~2.5 hrs / person / week of admin work automated.
How to plug Cortex into Actionist
Pick the connection method that suits your environment.
The fastest path to Cortex — install the gbrigandi MCP server and your agent gains direct access to every analyzer and responder through a permissioned API handshake. No token rotation, no URL configuration; the MCP layer handles auth and surfaces all available actions automatically.
Find Cortex in the Apps library and click Connect. MCP is selected by default — the gbrigandi/mcp-server-cortex integration connects to your self-hosted Cortex instance.
Provide the base URL of your Cortex deployment (e.g. https://cortex.yourdomain.com). The MCP server uses this to route all API calls to the correct instance.
Actionist runs a read-only call — listing available analyzers — to verify the handshake. A green checkmark confirms the agent can reach your Cortex instance and is ready to run analyses.
15 actions your agent can call
Read and write operations available to your Actionist agent.
7 events your agent can react to
Events your agent watches for, and the actions it kicks off in response.
Skills that pair with Cortex
Reusable agent skills that work well alongside this app.
MCP servers that work with Cortex
Connect Actionist to MCP servers built for or around this app.
A local-first persistent knowledge MCP server with OWL-RL reasoning that exposes 22 tools for structured knowledge graph management.
Provides 12 deterministic calendar and scheduling tools for temporal context, availability queries, and booking operations.
Neuroscience-grounded persistent memory for Claude Code — thermodynamic decay, hippocampal consolidation, predictive-coding write gate, and 33 MCP tools backed by PostgreSQL and pgvector.