NewKnowledge base governance playbook is live
← Back to work
Internal tool case studyPublic-safe presentation

New Analyst Toolbox

Chrome extension · embedded learning · analyst workflow support

A floating browser tool for analyst guidance, threat-intelligence extraction, queue references, label confirmation, case tracking, pace support, and educational AI-assisted signals.

Official documentation and analyst judgment remained central. The toolbox reduced context switching and placed the right reference or helper closer to the work.

Chrome extensionKnowledge systemsWorkflow designAnalyst enablementAI-assisted support
Project proof strip

State the contribution and the authority boundary

The page separates my contribution from official guidance and analyst judgment.

My contribution

Product concept, workflow research, extension architecture, UI structure, implementation, signal logic, documentation, testing, iteration, and release maintenance

Existing context

Internal analyst workflow, official SOPs, queue definitions, escalation paths, and existing security guidance

Audience

New and developing analysts who needed faster access to guidance, context, and repeatable workflow support

Shipped state

A working browser extension with eight sections, more than 30 releases, persistent settings, and backup and restore

In brief

Keep the analyst workbench on the page

The floating surface combines pace tracking, investigation helpers, decision guidance, queue references, label confirmation, case notes, and educational signal review.

Reconstructed analyst toolbox
CounterIntelGuideTrackerAssist

Daily pace

35 / 50

Intel signals

Domains, URLs, authentication context, and preview paths.

Label support

Guided questions, definitions, tells, and examples.

Assist boundary

Educational signal support with visible evidence and analyst review.

Public-safe mockup based on the real tool structure. It shows the system pattern without exposing internal screenshots or private case details.

System boundary

Make the source of truth easier to reach

The toolbox links analysts to trusted resources inside the workflow. It does not replace them.

Boundary

No autonomous labeling

The tool can surface signals and educational suggestions, but it does not make the final security decision.

Boundary

Official guidance remains authoritative

Internal SOPs, queue rules, and escalation paths remain the source of truth.

Boundary

Evidence is visible

Assistive conclusions are paired with fired signals and context so analysts can inspect why a suggestion appeared.

Boundary

Public proof is reconstructed

This case study uses generalized UI and fictionalized data rather than exposing internal screenshots or sensitive case details.

Problem

Analysts needed guidance closer to the decision

Analysts already had documentation, but it lived outside the active workflow. I identified the references, helpers, and decision support that would be more useful on the page where analysts worked.

Constraint

Reduce context switching without taking control

The extension had to open quickly, stay lightweight, preserve analyst control, and update cleanly. Official SOPs remained authoritative; the toolbox made them easier to reach during live work.

Approach

Maintain the extension as a working product

I released updates as workflows, browser limits, and analyst needs changed. The changelog records bug fixes, edge cases, UI changes, safer handling, and new support features.

Outcome

The final surface combined tools, references, and training

The floating Chrome extension included eight sections for workflow support, threat-intelligence extraction, queue references, label confirmation, case tracking, progress, and educational AI-assisted signals.

Technical architecture

A browser-native support layer with human review at the end

  1. 01

    Page context

    The content script reads the visible page and identifies supported fields, links, indicators, and interface regions.

  2. 02

    Extraction and rules

    The toolbox parses page context into signals, lookup inputs, progress data, and decision support.

  3. 03

    Background services

    The service worker handles protected routing and requests blocked by page security rules.

  4. 04

    Local state

    The browser stores preferences, counters, layout settings, notes, and backups across shifts.

  5. 05

    Human review

    Analysts review the evidence, check official guidance, and make the final decision.

What the tool supported

Organize eight needs in one analyst surface

Each tab handles a specific task: tracking work, finding indicators, checking guidance, logging cases, reviewing queues, confirming labels, or reviewing edge cases.

Tool section

Counter

Tracks labeled messages per shift with daily and weekly goals, live pace calculations, countdown timing, alarms, and celebrations.

Tool section

Intel

Extracts threat indicators from the current page and supports one-click lookups, urlscan preview, domain profiles, and authentication context.

Tool section

Guide

Brings interactive labeling guidance into the workflow, including quick triage and deeper investigation walkthroughs.

Tool section

Tracker

Lets analysts log case URLs, labels, and notes during a shift, with exportable case-tracking output.

Tool section

Queues

Provides quick-reference cards for queue types, including SLA context, KPI expectations, labeling rules, and common gotchas.

Tool section

Labels

Guides analysts through confirmation flows for suspected labels with definitions, tells, examples, and result cards.

Tool section

Assist

Adds educational AI-assisted label suggestions using 40+ signals, domain age, queue context, field extraction, request patterns, lookalike logic, and spoof indicators.

Tool section

About

Houses guide links, feedback pathways, backup and restore controls, and context for maintaining the tool.

Product workflow

Use four steps to build inside the workflow

The tool needed a usable surface, clear structure, embedded support, and regular releases.

Stage 01

Surface

Place guidance in the browser so analysts do not have to search separate resources.

Stage 02

Structure

Organize repeated analyst needs into clear tabs: counter, intel, guide, tracker, queues, labels, assist, and about.

Stage 03

Support

Add guided flows, reference cards, indicator extraction, case notes, and visible evidence.

Stage 04

Refine

Release updates for safer links, in-place translation, UI changes, signal logic, and backup and restore.

Build details

Match the technical design to the job

A browser extension kept the tool inside the analyst’s existing workflow.

Format

Chrome extension

Surface

Floating workflow widget

Architecture

Content script + service worker

Storage

Browser-local persistence

Designed as a floating Chrome extension so analysts could use it inside the browser workflow.

Organized into eight sections so different support needs had clear homes.

Included embedded guidance to keep learning connected to the work.

Added threat-intelligence extraction, preview paths, domain profiles, authentication context, and quick lookup routes.

Handled practical workflow needs such as draggable placement, resizing, opacity, tab reordering, sticky settings, and backup and restore.

Framed AI assistance as educational signal support with analyst review at the center.

Released through more than 30 versions, showing ongoing iteration, maintenance, and refinement.

Iteration

Use the changelog as evidence of maintenance

The releases address safer links, CSP limits, UI changes, signal expansion, case evidence, and customization.

v2.98

New UI awareness

Updated Assist for new structured fields, relationship context, request patterns, lookalike domains, spoof headers, tab order, and backup and restore.

v2.97

Investigation playbook integration

Added investigation guidance for sender identity, mismatches, attachments, links, and escalation.

v2.92

Signal expansion

Expanded Assist to more than 40 signals across Attack, Spam, Gray, and Safe categories and showed the evidence for each signal.

v2.58

CSP-safe translation

Replaced blocked script injection with text-node translation through the background service worker.

v2.57

Safe document opening

Added protected document routing and a user-controlled header option.

v2.42

Intel extraction

Added an Intel tab for page indicators, one-click lookups, authentication context, and red flags.

Result

Use internal tools to deliver knowledge in context

The tool combines documentation, analyst judgment, embedded training, security workflow support, and ongoing maintenance.

Principle

Guidance belongs near the decision

The tool places references, label logic, and workflow helpers near the decision.

Principle

Assistive tools need clear authority lines

The AI-assisted layer shows evidence and supports learning. SOPs, escalation paths, and analyst review remain authoritative.

Principle

Iteration is part of the product

The changelog records bug fixes, workflow changes, safer handling, UI updates, and clearer evidence.

Useful internal tools make the right action easier to find during the work.