🥷 Threat Intel toolbox
I endorse nothing you’ll do with these tools, use them at your own risks.
Combining multiple sources while investigating is highly recommended. Remember, these tools are only there to help your investigation, the conclusion is up to you. This list is updated often, check the date above for the latest update.
Domain and IP Threat Intel
Search by IP, domain, or network owner for real-time threat data
Website reputation checker
Quick way to find an IP reputation from threat feeds
Search by Domain, IP, Email or Organization
Shodan and others
Discover mutiple connected machines and interfaces
Another one:
Also:
And… another one:
Commdand line tool using Shodan to display vulnerabilities of an IP
The Chinese shodan 🇨🇳
IP cameras
Shodan, Zoomeye and others can discover IP cameras, but for a more in depth solution:
Phishing specific
Gives an image of the site. Useful to investigate phishing without visiting, public and private scans options.
Squatting
Files, hashes and URLs
On a side note for security researchers: Don’t upload your crafted payloads to see if they’re detected, rather use an up-to-date AV on a local machine. There’s less risk the signature will be shared among all AV vendors.
Analyze suspicious files and URLs to detect types of malware, automatically share them with the security community (good for daily file/url analysis)
Joe Sandbox detects and analyzes potential malicious files.
Mobile threat intelligence platform (APK, hash…)
and
Mobile Verification Toolkit for forensics on a smartphone
Open potential malicious PDF and convert them back to safe documents
You received a link containing tracking elements ? Test where it redirects
Browser emulation on an online VM
Browser emulation + fraud/spam analysis
Threat Intel and trackers
Malware threat intelligence
Public trackers of phishing urls, malwares
For lastest infos on compromised hosts or files
- Twitter, Reddit…
Find public documents:
Ransomware groups
Useful for active monitoring, updated continuously:
Global CTI source
Photo Forensic
Maybe the best online tool, useful for CTF and others
AI tool for upscaling low res images
VIDEO FORENSIC
Translate any social media video post