OSINT
Using the hacked search engine Censys
Censys scans and indexes internet-facing assets with research-level accuracy. What it does: Discovers exposed infrastructure Analyzes SSL certificates Tracks asset changes over time Who should use it: Security architects, researchers, and cloud security teams....
AlienVault OTX a threat intelligence sharing platform
AlienVault OTX is a crowdsourced threat intelligence platform. What it does: Shares Indicators of Compromise (IOCs) Tracks real-world attack campaigns Enables threat enrichment Who should use it: SOC teams, MSSPs, and threat intelligence analysts....
Shodan is a search engine for internet-connected devices
Shodan is a search engine for internet-connected devices. What it does: Finds exposed servers, databases, and IoT devices Indexes banners and metadata Reveals misconfigurations Who should use it: Security researchers, red teams, and risk analysts....
CVE List — a database of information security vulnerabilities
MITRE’s CVE database catalogs publicly disclosed software vulnerabilities. What it does: Assigns unique vulnerability IDs Links exploits, vendors, and patches Supports risk assessment Who should use it: Security engineers, IT managers, and risk officers....
ARIN WHOIS IP Address Database Search
ARIN Whois provides authoritative IP ownership data for North America. What it does: Identifies IP owners Displays ASN and allocation history Supports attribution analysis Who should use it: Investigators, journalists, and compliance professionals....
Lookyloo: Open-Source Webpage Capture and Analysis
Lookyloo visually replays how websites load and connect to other resources. What it does: Creates interactive behavior trees Detects malicious redirects Reveals hidden third-party connections Who should use it: Threat hunters and malware investigators....
OSINT Framework
OSINT Framework is a structured directory of OSINT tools categorized by investigation type. What it does: Organizes hundreds of tools Teaches investigation methodology Reduces blind spots Who should use it: Beginners, journalists, educators, and researchers....
Checking the SSL configuration
SSL Labs analyzes SSL/TLS configurations of public web servers. What it does: Tests certificate strength Detects weak encryption and protocols Provides security grades Who should use it: Web administrators, auditors, and compliance teams....
MXToolbox focuses on email and domain infrastructure diagnostics
MXToolbox focuses on email and domain infrastructure diagnostics. What it does: Checks MX, SPF, DKIM, and DMARC records Detects phishing infrastructure Identifies blacklist issues Who should use it: Email administrators, fraud analysts, and security teams....
Online file virus scanning with Hybrid Analysis
Hybrid Analysis is an advanced malware sandbox powered by CrowdStrike. What it does: Executes files in a safe virtual environment Records system and network behavior Maps activity to MITRE ATT&CK techniques Who should use it: Advanced threat analysts and reverse engineers....
What is VirusTotal and how do I use it?
VirusTotal scans files, URLs, and hashes using dozens of antivirus engines simultaneously. What it does: Detects malware and suspicious files Correlates threat intelligence Shows historical detection trends Who should use it: Incident responders, malware analysts, and IT security teams....
Domain intelligence services by CentralOps
CentralOps offers classic internet reconnaissance tools in one simple interface. What it does: WHOIS lookups DNS and IP analysis Traceroute and email verification Who should use it: OSINT beginners, infrastructure analysts, and investigators....
The best services for checking links for viruses
urlscan.io safely analyzes websites without requiring you to visit them directly. What it does: Simulates real browser visits Captures redirects, scripts, and third-party connections Provides screenshots and behavior analysis Who should use it: Phishing investigators, journalists, fraud analysts,...
AbuseIPDB is a database of IP addresses associated with malicious activity
AbuseIPDB is a community-driven database of IP addresses associated with malicious activity. What it does: Scores IP reputation based on abuse reports Identifies brute-force attacks, spam, and malware Shows attack history and confidence levels Who should use it: System administrators, SOC analysts,...
Have I Been Pwned: Check if your email address has been
Have I Been Pwned (HIBP) is the world’s most well-known data breach search engine. It allows anyone to check whether an email address or phone number has appeared in known data leaks. What it does: Searches billions of breached credentials Uses cryptographic hashing to protect privacy Alerts users...