Guide
How to Use Vera5
Vera5 brings indicator detection, threat-intelligence enrichment, investigation tools, and analyst-ready exports directly into your browser.
This guide walks you through installing Vera5, configuring your intelligence sources, completing your first enrichment, and using Vera5 during real SOC, CTI, DFIR, email-security, phishing, and MDR workflows.
On this page
Getting Started
Before you begin
Vera5 is built for analysts who work with indicators inside browser-based tools and reports.
Typical users include:
- SOC analysts
- CTI analysts
- DFIR analysts
- threat hunters
- email-security analysts
- phishing analysts
- MDR analysts
- malware researchers
- incident responders
You can use Vera5 on alert pages, tickets, security blogs, webmail, dashboard exports, intelligence reports, case queues, sandbox reports, and other pages containing supported indicators.
What you need
You need:
- a supported Chromium-based browser or Firefox;
- the Vera5 extension;
- at least one API key from a supported intelligence provider for live enrichment; and
- a webpage containing supported indicators.
You do not need:
- a Vera5 account;
- a Vera5 cloud login;
- a paid Vera5 subscription;
- Vera5-hosted API credentials; or
- a Vera5-operated enrichment server.
Vera5 uses a bring-your-own-key model. You choose the intelligence providers, obtain your own credentials, and control which providers are enabled.
Supported indicator types
Vera5 can detect supported security artifacts including:
- IPv4 addresses
- domains
- URLs
- MD5 hashes
- SHA-1 hashes
- SHA-256 hashes
- CVE identifiers
- email addresses
- autonomous system numbers
- CIDR ranges
- onion domains
- conservatively detected file paths
- defanged forms such as
hxxpand[.]
Provider support varies by indicator type. A source that enriches an IP address may not support a file hash, email address, or CVE.
Install Vera5
Chromium-based browsers
Until the official browser-store listing is available, install Vera5 using the current release or unpacked-extension instructions provided in the Vera5 GitHub repository.
The general process is:
- Download or build the current Vera5 extension package.
- Open your browser’s extension-management page.
- Enable developer mode when required.
- Select Load unpacked.
- Choose the Vera5 extension build directory.
- Pin Vera5 to the browser toolbar.
Use the exact installation path documented in the current Vera5 release and README. Do not load the source directory unless the documentation specifically identifies it as the correct unpacked build.
Firefox
Vera5 also supports a Firefox Manifest V3 build.
For local or development use, Firefox may require the extension to be loaded as a temporary add-on. Temporary add-ons may need to be loaded again after a full Firefox restart.
Review the current browser-support documentation for the exact Firefox build and temporary-installation procedure.
Confirm the installation
After installation:
- Select the Vera5 icon in the browser toolbar.
- Confirm that the popup opens without an error.
- Open Settings.
- Verify that the options page loads.
- Return to a normal webpage before attempting a scan.
Browser-internal pages, extension stores, and certain protected browser pages may prevent extensions from running.
Complete first-run setup
Vera5 includes onboarding and settings designed to keep external requests under your control.
Add an intelligence-provider API key
Start with at least one supported provider.
Common starting sources include:
- AbuseIPDB
- AlienVault OTX
- URLScan.io
- GreyNoise
Additional supported sources may include:
- VirusTotal
- Shodan
- Censys
To configure a source:
- Open the Vera5 popup.
- Select Settings.
- Find the provider under the enrichment-source settings.
- Enter your API key or credential.
- Save the credential.
- Enable the provider.
API keys are masked after saving. Vera5 should never display a saved credential in full.
Entering a key and enabling a source are separate actions. A stored key does not necessarily mean the provider is active. For the full source list and per-provider notes, see the API integrations documentation.
Review safe operating defaults
Before using live enrichment, review:
- extension enabled or disabled;
- indicator highlighting;
- automatic scanning;
- manual-only enrichment;
- pre-query notices;
- domain allowlist and denylist;
- private IPv4 handling;
- enabled indicator types;
- cache duration;
- enabled providers; and
- analyst-mode preset.
For the most deliberate workflow
- keep automatic scanning disabled until you are comfortable with the behavior;
- use manual enrichment;
- keep pre-query notices enabled;
- enable only providers you intend to query; and
- review sensitive-domain rules before using Vera5 in webmail or internal tools.
Analyst presets
Vera5 may provide presets for workflows such as:
- SOC
- CTI
- DFIR
A preset can apply sensible defaults for source behavior, pivots, export templates, and workflow emphasis.
Presets are optional. You can configure each setting manually.
Core Workflows
Run your first enrichment
This walkthrough covers the core Vera5 workflow.
Step 1: Open a page containing indicators
Open:
- a security alert;
- a CTI report;
- a phishing ticket;
- a malware-analysis article;
- a supported dashboard export; or
- one of the sample pages included with Vera5.
Practice safely
For a first test, use a controlled sample page rather than a sensitive production system.
Step 2: Scan the page
Open the Vera5 popup and select Scan Page.
You can also use the configured scan-page keyboard shortcut:
Ctrl+Shift+Yon Windows or LinuxCmd+Shift+Yon macOS
Vera5 examines permitted visible page content locally and identifies supported indicators.
Step 3: Review the scan result
After the scan, Vera5 may:
- highlight detected indicators on the page;
- display the number of detected indicators;
- populate the popup indicator tray;
- group indicators by type; and
- begin or update the active investigation session.
Detection alone does not necessarily send an indicator to an external provider.
Step 4: Open an indicator
Select a highlighted indicator on the page.
Vera5 opens its on-page analysis overlay near the selected value.
The overlay may show:
- indicator value;
- indicator type;
- detection explanation;
- defanged and refanged forms;
- source rows;
- current enrichment state;
- copy actions;
- pivot actions;
- risk information;
- analyst notes; and
- save or export actions.
Step 5: Start enrichment
Use the manual enrichment control in the overlay.
When pre-query notices are enabled, Vera5 shows which indicator and providers are about to be queried.
Review the notice, then approve the request.
Only providers that are:
- enabled;
- configured;
- compatible with the indicator type; and
- permitted by the current trust policy
should receive a request.
Step 6: Read the results
Vera5 displays provider results inside the overlay.
A result may be labeled:
- Live: returned through a new provider request;
- Cached: returned from Vera5’s local cache;
- Error: the provider request failed;
- Skipped: the provider was disabled, unsupported, blocked, or unavailable.
Each result remains associated with its source.
Step 7: Continue the investigation
From the overlay, you may:
- copy the indicator;
- copy a defanged or refanged version;
- open an attributed provider pivot;
- inspect normalized provider information;
- inspect available raw response details;
- add an analyst note;
- save the indicator to a collection;
- pin or label the indicator;
- export the result; or
- move to another detected indicator.
Use Esc or the overlay close control to dismiss the current card.
Understand the results
Vera5 combines information from multiple sources without hiding where the information came from.
Source attribution
Every enrichment result should remain associated with the provider that produced it.
Examples include:
- AbuseIPDB
- AlienVault OTX
- URLScan.io
- GreyNoise
- VirusTotal
- Shodan
- Censys
Providers may disagree. Vera5 keeps that disagreement visible rather than silently turning conflicting results into a single unexplained verdict.
Composite risk score
Vera5 may show an explainable composite label such as:
- Unknown
- Low
- Suspicious
- High
- Critical
The score is an analyst aid, not a final verdict.
Review:
- the contributing sources;
- the age of the information;
- conflicting provider results;
- provider-specific context;
- the indicator’s role in your environment; and
- internal evidence.
A high score does not prove malicious activity. A low or unknown score does not prove that an indicator is safe.
Explain-this-IOC reasoning
Vera5 may display a deterministic explanation of why a score or label was produced.
This explanation is based on normalized source results and documented scoring rules. It is separate from optional AI-generated summaries.
Live and cached data
Vera5 caches enrichment results locally to reduce repeat calls and protect vendor quotas.
A cached result should display:
- that it is cached;
- the last update time; and
- the relevant source.
Use manual refresh when you need current provider data. Refreshing may consume provider quota.
Raw response inspection
Where supported, Vera5 can provide an expandable raw-response view.
Use it when:
- the normalized result does not contain enough detail;
- you need to verify field mapping;
- sources disagree; or
- you need the original provider context.
Credentials and secrets should be redacted.
Use the indicator tray
The popup indicator tray provides an alert-wide view of the current page.
It can help you avoid opening indicators one at a time.
The tray may provide:
- total indicator count;
- count by indicator type;
- type filters;
- copy-all;
- copy-filtered;
- selected-indicator export;
- enrichment-status hints;
- jump-to-highlight;
- multi-select;
- bulk enrichment; and
- save-to-collection actions.
Jump to an indicator
Select an indicator row in the tray.
Vera5 attempts to:
- scroll to the matching highlight;
- focus the detected value; and
- open the corresponding overlay.
If the page changed after the scan, the stored highlight may be stale. Rescan the page to rebuild the indicator map.
Filter the tray
Use type filters when a page contains many artifacts.
For example, you can narrow the tray to:
- domains;
- IP addresses;
- URLs;
- hashes; or
- CVEs.
Filtered selections can then be copied or exported.
Enrich selected text
You do not always need to scan an entire page.
For a single visible indicator:
- Select the text with your mouse.
- Right-click the selection.
- Choose Enrich selection with Vera5 or the current Vera5 selection command.
- Confirm the detected indicator.
- Approve the provider request when required.
You can also use the popup or command palette to enrich a current selection.
Selection-based enrichment is useful for:
- dense dashboards;
- long reports;
- webmail;
- ticket comments;
- chat transcripts;
- tables; and
- pages where full-page scanning is unnecessary.
Trust controls and domain policy still apply.
Investigations
Work with investigation sessions
An investigation session is a named, local workspace for one investigation.
Examples include:
- Phishing Investigation
- Suspicious Login Review
- Malware Campaign Analysis
- Customer Alert Triage
- Threat Hunt Follow-Up
A session may be created on the first scan or through an explicit New Session action.
Session contents
A session may contain:
- title;
- source page;
- creation and update times;
- detected indicators;
- per-type indicator counts;
- enrichment history;
- export events;
- analyst notes;
- labels;
- pinned indicators; and
- source-attributed findings.
Manage sessions
From the Vera5 interface, you may be able to:
- rename a session;
- reopen a recent session;
- archive a session;
- delete a session;
- add notes;
- review indicator counts; and
- export the complete session.
Sessions are stored locally. They are not shared through a Vera5 cloud account.
Session labels
An indicator may be labeled as:
- benign;
- internal;
- suppressed false positive; or
- case-important.
Labels help organize the investigation but do not replace provider evidence or analyst judgment.
Save indicators to collections
Collections are persistent local groupings of indicators.
A session represents an individual investigation workflow. A collection represents a reusable group of indicators that may span multiple sessions.
Examples include:
- APT29 Research
- Qakbot Infrastructure
- Phishing Campaign
- Internal Scanner Addresses
- Known Customer Domains
Add an indicator to a collection
You may add indicators from:
- the on-page overlay;
- the popup tray;
- the active session; or
- a filtered tray selection.
Choose Save to collection, select an existing collection, or create a new one.
Vera5 deduplicates matching normalized indicators within the same collection.
Promote a session
Where available, promote the indicators from an investigation session into a new collection.
This is useful when a single case becomes part of a longer-running hunt or campaign.
Manage collections
You may be able to:
- rename a collection;
- edit its description;
- view members;
- remove members;
- delete the collection;
- export the collection; and
- navigate to a matching indicator on the active page.
Collections remain local unless you explicitly export them.
Export your findings
Vera5 can create analyst-ready artifacts from normalized enrichment data.
Available export formats
Depending on the selected workflow, Vera5 may support:
- Markdown
- JSON
- CSV
- Jira comment
- TheHive case note
- Obsidian note
- plain-text analyst update
- Markdown report
Export an individual indicator
An indicator export may include:
- indicator value and type;
- composite score;
- disagreement notice;
- source-attributed findings;
- cache status;
- timestamps;
- analyst notes;
- pivot suggestions; and
- export schema version.
Export a tray selection
Use the indicator tray to export:
- all detected indicators;
- indicators matching a type filter; or
- manually selected indicators.
Export a session
Session exports may include:
- session summary;
- page information;
- indicator counts;
- complete indicator table;
- enrichment snippets;
- source attribution;
- analyst notes; and
- activity history.
Supported session formats may include Markdown, JSON, and CSV.
Export a collection
Collection exports may include:
- collection metadata;
- member indicators;
- indicator types;
- cached enrichment where available; and
- source attribution.
Important
API keys and provider secrets must not be included in exports.
Use exports responsibly
Before pasting an export into a ticket, wiki, or chat:
- verify the destination is authorized;
- review sensitive indicators;
- remove unnecessary internal context;
- confirm source timestamps;
- verify the score explanation; and
- make sure no restricted information is included.
Use command and bulk workflows
These capabilities are useful after you understand the basic scan-and-enrich workflow.
Command palette
Open the Vera5 command palette using:
Ctrl+Shift+Kon Windows or LinuxCmd+Shift+Kon macOS
Available commands may include:
- scan page;
- enrich selection;
- copy Markdown;
- export tray selection;
- clear highlights;
- open settings; and
- open supported operator surfaces.
Command availability may depend on the active page and current Vera5 version.
Keyboard navigation
Vera5 supports keyboard-oriented investigation workflows.
Depending on the active surface, you may be able to:
- move between detected indicators;
- open an indicator;
- close the overlay;
- scan the page;
- open the command palette; and
- trigger copy or export actions.
Bulk enrichment
The tray can support selecting multiple indicators for a controlled enrichment queue.
Before starting the queue, Vera5 should show a warning concerning:
- provider quota;
- request count;
- rate limits; and
- enabled sources.
Bulk enrichment is sequential and capped. It is not intended to silently enrich every indicator on a page.
You can cancel an active queue.
Domain restrictions, pre-query controls, missing credentials, provider rate limits, and other trust policies still apply.
Source operations
Vera5 can expose operational information such as:
- recent source status;
- previous provider errors;
- HTTP 429 cooldown;
- cache entry count; and
- last cache-clear time.
Use these details when a source appears unavailable or stops returning live results.
Advanced Features
Use the optional local backend
Optional
The local backend is disabled by default and is not required for standard extension operation.
Vera5 can operate without a backend.
The optional local backend is intended for users who want a locally operated enrichment service, centralized local caching, or local rate-limit handling.
It runs on a localhost address such as:
http://127.0.0.1:<port>
When to use it
The local backend may be useful when you want:
- centralized cache behavior;
- backend-managed provider configuration;
- consistent rate-limit handling;
- a local integration point; or
- separation between the browser extension and certain provider credentials.
Important characteristics
The local backend is:
- optional;
- disabled by default;
- user-operated;
- designed for localhost or self-hosted use;
- not a Vera5 cloud service; and
- not required for standard extension operation.
Follow the current local-mode documentation for installation, environment configuration, startup, and extension settings.
Keep the service bound to localhost unless you deliberately secure and operate it for another approved environment.
Use optional local AI summaries
Optional
Local AI is optional and disabled by default.
Vera5 can connect to a user-operated local AI endpoint, including compatible llama.cpp services.
What the model receives
A typical summary request may include:
- selected indicator;
- normalized enrichment results;
- source attribution;
- score explanation;
- analyst-selected notes; and
- requested output format.
The intended input is normalized investigation context, not the complete webpage.
What the model should not receive
Vera5 should not intentionally send:
- API keys;
- browser cookies;
- passwords;
- authentication tokens;
- unrelated browsing history;
- unrelated complete page contents; or
- provider credentials.
Configure a local endpoint
Use the local AI settings to enter the compatible localhost endpoint.
The service may resemble:
http://127.0.0.1:8080
The exact endpoint, route, model, and request format depend on your local runtime. See the local AI summary documentation for details.
Generate a summary
After enrichment:
- Open the indicator overlay.
- Select Generate Summary or the current local-AI action.
- Wait for the local model response.
- Review the result against the source findings.
Local AI summaries should be visibly labeled:
AI summary — local, unverified
AI output is not a verdict
AI output can be wrong, incomplete, or overly confident. It does not replace the source-attributed score, original provider records, or analyst judgment.
Privacy & Security
Understand security and privacy
Vera5 is designed around local-first analysis and user-controlled enrichment.
What stays local
Vera5 is designed to keep the following on your device:
- page detection;
- extension settings;
- API keys;
- cached enrichment;
- sessions;
- collections;
- analyst notes;
- export preferences;
- local AI settings; and
- investigation history.
What may leave your device
When you approve or trigger enrichment, the enabled provider may receive:
- the selected indicator;
- your provider API credential;
- your IP address;
- request time;
- ordinary network metadata; and
- provider-specific request parameters.
The provider handles that information under its own terms and privacy policy.
No full-page upload
Vera5 is not designed to upload complete webpages to Vera5 infrastructure.
Detection occurs locally.
External intelligence providers receive the indicator required for the requested lookup, not the complete page.
Sensitive indicators
An indicator can reveal sensitive operational information.
Examples include:
- internal IP addresses;
- private domains;
- internal hostnames;
- customer assets;
- investigation targets;
- URLs containing authentication parameters;
- confidential campaign infrastructure;
- classified or controlled information.
Before enrichment, determine whether the indicator is authorized for submission to the selected provider.
Domain policy
Vera5 may block scanning or enrichment on sensitive domains based on its domain policy.
This may include webmail, internal systems, banking sites, health systems, or user-configured restricted domains.
If enrichment is blocked:
- verify that the page is appropriate for Vera5;
- review the domain policy;
- inspect the allowlist and denylist;
- confirm organizational authorization; and
- change the policy only when appropriate.
External pivots
Opening a provider pivot takes you to an external service.
The destination may receive:
- the indicator in the URL;
- your IP address;
- browser information;
- cookies already associated with that service; and
- ordinary request metadata.
Defanged URL handling may display a warning before Vera5 opens a live destination.
Shared machines
On a shared computer:
- remove provider credentials after use;
- clear local caches when necessary;
- review browser synchronization;
- export only approved investigation data;
- delete sessions or collections that should not remain; and
- secure the browser profile.
For the full security model, review Vera5’s Security & Privacy page, Privacy Policy, Third-Party Services Disclosure, and public security documentation.
Troubleshooting
Troubleshoot common problems
No indicators are highlighted
Possible causes:
- Vera5 is disabled;
- highlighting is disabled;
- the page has not been scanned;
- the relevant indicator type is disabled;
- no supported indicators appear in visible text;
- the page is restricted by domain policy;
- the browser prevents extension execution on that page.
Try:
- Confirm Vera5 is enabled.
- Confirm highlighting is enabled.
- Select Scan Page.
- Review enabled indicator types.
- Try a Vera5 sample page.
- Check domain policy.
- Reload the page and scan again.
The popup shows no detected indicators
The current tab may not have been scanned, or the page may have changed since the previous scan.
Select Scan Page and reopen the popup.
The overlay says an API key is missing
The provider is enabled but no valid credential is saved.
Open Settings, add the provider credential, save it, and retry.
A provider returns 401 or 403
The key may be:
- incorrect;
- expired;
- revoked;
- missing required permission;
- associated with the wrong account tier; or
- entered in the wrong field.
Verify the credential in the provider portal.
A provider returns HTTP 429
The provider rate limit or quota was reached.
Try:
- waiting for the displayed cooldown;
- using cached data;
- reducing bulk requests;
- enabling manual-only enrichment;
- disabling unnecessary providers; or
- reviewing your provider plan.
Do not repeatedly bypass or retry provider limits.
Enrichment is blocked on the current website
The page may match a domain denylist or sensitive-domain policy.
Review Settings → Trust and consent or the corresponding domain-policy area.
Only permit enrichment when doing so is authorized.
A provider says the indicator type is unsupported
Not every source supports every indicator type.
Enable another compatible provider or use the available static pivots.
The tray does not jump to the indicator
The page DOM may have changed after the scan.
Rescan the page and try again.
The overlay appears in the wrong place
The page layout may have moved, changed, or loaded additional content.
Close the overlay, rescan if necessary, and reopen the indicator.
Cached data appears instead of a live result
The local cache entry is still valid.
Use manual refresh to bypass the cache when current data is required. This may consume provider quota.
Bulk enrichment stops early
Possible causes:
- provider rate limit;
- trust policy;
- missing key;
- unsupported indicator type;
- user cancellation;
- network timeout;
- source cooldown.
Review the per-source status and queue message.
The local backend cannot be reached
Verify:
- the backend is running;
- the host and port match Vera5 settings;
- the service is listening on localhost;
- local firewall rules permit the request;
- CORS and extension-origin settings are correct; and
- the backend health endpoint responds.
Vera5 may fall back to direct extension connectors when configured to do so.
The local AI summary fails
Verify:
- the local model server is running;
- the endpoint is correct;
- the selected model is loaded;
- the API format is compatible;
- local AI is enabled;
- the request did not time out; and
- the service accepts requests from the extension.
The Firefox extension disappeared
A temporarily loaded Firefox add-on may be removed after a full browser restart.
Load the Firefox extension again using the current temporary add-on instructions.
Settings appear missing after an update
Check:
- the active browser profile;
- whether you switched between Chrome and Firefox;
- whether browser storage was cleared;
- whether a different extension build was installed; and
- whether the extension identifier changed.
Do not import an old settings file unless you trust the source and have reviewed its contents.
You found a bug
Report reproducible bugs through the official Vera5 GitHub repository.
Include:
- Vera5 version;
- browser and version;
- operating system;
- exact steps;
- expected behavior;
- observed behavior; and
- sanitized screenshots or logs.
Never include API keys, passwords, customer data, restricted indicators, or confidential investigation records in a public issue.
Current limitations
Vera5 remains under active development.
Current limitations may include:
- official browser-store listings may not yet be available;
- some installations may require loading an unpacked extension;
- Firefox installation may use a temporary add-on workflow;
- provider availability depends on your credentials and provider plan;
- not every provider supports every IOC type;
- third-party APIs may change without notice;
- local AI requires a separately installed and configured model server;
- the optional backend requires local setup;
- provider results may be incomplete, stale, or contradictory;
- some protected browser pages do not permit extension execution;
- page changes can invalidate stored highlight positions; and
- Vera5 does not replace SIEM, SOAR, EDR, sandbox, case-management, or threat-intelligence platforms.
Vera5 assists investigations. It does not produce definitive malicious or benign verdicts.
Next Steps
Where to go next
After completing your first enrichment:
- review the Vera5 GitHub README;
- explore the analyst-workflow documentation;
- read the security model;
- review supported API integrations;
- configure additional providers;
- create an investigation session;
- save recurring indicators to a collection;
- test the local backend;
- test a local AI summary;
- report issues or contribute through GitHub.
Vera5 is open source. You can inspect how it detects indicators, stores settings, performs enrichment, calculates scores, and communicates with providers.
Quick-reference workflow
Open investigation page
↓
Scan page or select an indicator
↓
Open the Vera5 overlay
↓
Review the indicator and provider list
↓
Approve enrichment
↓
Compare source-attributed results
↓
Review score and disagreement
↓
Pivot, label, save, or export
↓
Continue the investigation