Modules | Intel471 Skip to content

Modules

Homepage Hero
Module
Description
Status
Link to module website
LOGO sfp totalhash

TotalHash.com

Check if a host/domain or IP is malicious according to TotalHash.com.

Free
LOGO sfp malwaredomainlist

malwaredomainlist.com

Check if a host/domain, IP or netblock is malicious according to malwaredomainlist.com.

Free
Logo Phish Stats

PhishStats

Determine if an IP Address is malicious

Free
LOGO sfp s3bucket

Amazon S3 Bucket Finder

Search for potential Amazon S3 buckets associated with the target and attempt to list their contents.

Free
LOGO sfp github

Github

Identify associated public code repositories on Github.

Free
LOGO sfp alienvaultipre

AlienVault IP Reputation

Check if an IP or netblock is malicious according to the AlienVault IP Reputation database.

Free
LOGO sfp abusech

abuse.ch

Check if a host/domain, IP or netblock is malicious according to abuse.ch.

Free
LOGO sfp urlscan

URLScan.io

Search URLScan.io cache for domain information.

Free
Logo default

Emerging Threats

Check if a netblock or IP is malicious according to emergingthreats.net.

Free
LOGO sfp opendns

OpenDNS

Check if a host would be blocked by OpenDNS DNS

Free
LOGO sfp open passive dns database

Open Passive DNS Database

Obtain passive DNS information from pdns.daloo.de Open passive DNS database.

Free
LOGO sfp builtwith

BuiltWith

Query BuiltWith.com's Domain API for information about your target's web technology stack, e-mail addresses and more.

Tiered
LOGO sfp phishtank

PhishTank

Check if a host/domain is malicious according to PhishTank.

Free
LOGO sfp venmo

Venmo

Gather user information from Venmo API.

Free
LOGO sfp cleantalk

CleanTalk Spam List

Check if a netblock or IP address is on CleanTalk.org's spam IP list.

Free
Logo name API

NameAPI

Check whether an email is disposable

Tiered
Logo jsonwhois

JsonWHOIS.com

Search JsonWHOIS.com for WHOIS records associated with a domain.

Tiered
Logo shodan

SHODAN

Obtain information from SHODAN about identified IP addresses.

Tiered
LOGO sfp blocklistde

blocklist.de

Check if a netblock or IP is malicious according to blocklist.de.

Free
LOGO sfp h1nobbdde

HackerOne

Check external vulnerability scanning/reporting service h1.nobbd.de to see if the target is listed.

Free
LOGO sfp bambenek

Bambenek C&C List

Check if a host/domain or IP appears on Bambenek Consulting's C&C tracker lists.

Free
LOGO sfp pulsedive

Pulsedive

Obtain information from Pulsedive's API.

Tiered
Logo hybridanalysis

Hybrid Analysis

Search Hybrid Analysis for domains and URLs related to the target.

Free
LOGO sfp duckduckgo

DuckDuckGo

Query DuckDuckGo's API for descriptive information about your target.

Free
LOGO sfp haveibeenpwned

HaveIBeenPwned

Check HaveIBeenPwned.com for hacked e-mail addresses identified in breaches.

Commercial
Logo ipqualityscore

IPQualityScore

Determine if target is malicious using IPQualityScore API

Tiered
Logo zetalytics

Zetalytics

Query the Zetalytics database for hosts on your target domain(s).

Tiered
LOGO sfp coinblocker

CoinBlocker Lists

Check if a host/domain or IP appears on CoinBlocker lists.

Free
LOGO sfp azureblobstorage

Azure Blob Finder

Search for potential Azure blobs associated with the target and attempt to list their contents.

Free
LOGO sfp callername

CallerName

Lookup US phone number location and reputation information.

Free
LOGO sfp arin

ARIN

Queries ARIN registry for contact information.

Free
LOGO sfp emailre

EmailRep

Search EmailRep.io for email address reputation.

Tiered
LOGO sfp googleobjectstorage

Google Object Storage Finder

Search for potential Google Object Storage buckets associated with the target and attempt to list their contents.

Free
Logo spur

spur.us

Obtain information about any malicious activities involving IP addresses found

Commercial
LOGO sfp yandexdns

Yandex DNS

Check if a host would be blocked by Yandex DNS

Free
LOGO sfp intelx

IntelligenceX

Obtain information from IntelligenceX about identified IP addresses, domains, e-mail addresses and phone numbers.

Tiered
LOGO sfp ipstack

ipstack

Identifies the physical location of IP addresses identified using ipstack.com.

Tiered
Logo bitcoinabuse

BitcoinAbuse

Check Bitcoin addresses against the bitcoinabuse.com database of suspect/malicious addresses.

Free
LOGO sfp numverif

numverify

Lookup phone number location and carrier information from numverify.com.

Tiered
Logo trumail

Trumail

Check whether an email is disposable

Free
LOGO sfp censys

Censys

Obtain information from Censys.io

Tiered
Logo Security Trails

SecurityTrails

Obtain Passive DNS and other information from SecurityTrails

Tiered
LOGO sfp wikileaks

Wikileaks

Search Wikileaks for mentions of domain names and e-mail addresses.

Free
LOGO sfp voipbl

VoIPBL OpenPBX IPs

Check if an IP or netblock is an open PBX according to VoIPBL OpenPBX IPs.

Free
Logo default

Onion.link

Search Tor 'Onion City' search engine for mentions of the target domain.

Free
LOGO sfp grep a

grep.app

Search grep.app API for links and emails related to the specified domain.

Free
LOGO sfp viewdns

ViewDNS.info

Reverse Whois lookups using ViewDNS.info.

Tiered
Logo default

Scylla

Gather breach data from Scylla API.

Free
LOGO sfp spamco

SpamCop

Query various spamcop databases for open relays, open proxies, vulnerable servers, etc.

Free
LOGO sfp quad9

Quad9

Check if a host would be blocked by Quad9

Free
LOGO sfp xforce

XForce Exchange

Obtain IP reputation and passive DNS information from IBM X-Force Exchange

Tiered
LOGO sfp multiprox

multiproxy.org Open Proxies

Check if an IP is an open proxy according to multiproxy.org' open proxy list.

Free
LOGO sfp apilit

Apility

Search Apility API for IP address and domain reputation.

Tiered
LOGO sfp whoisolog

Whoisology

Reverse Whois lookups using Whoisology.com.

Commercial
Logo projectdiscovery

Project Discovery Chaos

Search for hosts/subdomains using chaos.projectdiscovery.io

Commercial
LOGO sfp bingsearch

Bing

Obtain information from bing to identify sub-domains and links.

Tiered
LOGO sfp dnsgre

DNSGrep

Obtain Passive DNS information from Rapid7 Sonar Project using DNSGrep API.

Free
LOGO sfp badipscom

badips.com

Check if an IP address is malicious according to BadIPs.com.

Free
LOGO sfp metadefender

MetaDefender

Search MetaDefender API for IP address and domain IP reputation.

Tiered
LOGO sfp honeypot

Honeypot Checker

Query the projecthoneypot.org database for entries.

Free
LOGO sfp psbdm

Psbdmp

Check psbdmp.cc (PasteBin Dump) for potentially hacked e-mails and domains.

Free
LOGO sfp flickr

Flickr

Search Flickr for domains, URLs and emails related to the specified domain.

Free
LOGO sfp clearbit

Clearbit

Check for names, addresses, domains and more based on lookups of e-mail addresses on clearbit.com.

Tiered
LOGO sfp talosintel

Talos Intelligence

Check if a netblock or IP is malicious according to talosintelligence.com.

Free
LOGO sfp botscout

BotScout

Searches botscout.com's database of spam-bot IPs and e-mail addresses.

Tiered
LOGO sfp hunter

Hunter.io

Check for e-mail addresses and names on hunter.io.

Tiered
LOGO sfp zoneh

Zone-H Defacement Check

Check if a hostname/domain appears on the zone-h.org 'special defacements' RSS feed.

Free
Logo debounce

Debounce

Check whether an email is disposable

Free
LOGO sfp digitaloceanspace

Digital Ocean Space Finder

Search for potential Digital Ocean Spaces associated with the target and attempt to list their contents.

Free
LOGO sfp vxvault

VXVault.net

Check if a domain or IP is malicious according to VXVault.net.

Free
LOGO sfp comodo

Comodo

Check if a host would be blocked by Comodo DNS

Free
Logo developers google com safebrowser

Google SafeBrowsing

Check if the URL is included on any of the Safe Browsing lists.

Free
LOGO sfp adblock

AdBlock Check

Check if linked pages would be blocked by AdBlock Plus.

Tiered
LOGO sfp citadel

Leak-Lookup

Searches Leak-Lookup.com's database of breaches.

Free
LOGO sfp skymem

Skymem

Look up e-mail addresses on Skymem.

Free
LOGO sfp fringeproject

Fringe Project

Obtain network information from Fringe Project API.

Free
LOGO sfp abuseipdb

AbuseIPDB

Check if an IP address is malicious according to AbuseIPDB.com blacklist.

Tiered
LOGO sfp binaryedge

BinaryEdge

Obtain information from BinaryEdge.io Internet scanning systems, including breaches, vulnerabilities, torrents and passive DNS.

Tiered
Logo host io

Host.io

Obtain information about domain names from host.io.

Tiered
LOGO sfp fraudguard

Fraudguard

Obtain threat information from Fraudguard.io

Tiered
LOGO sfp crt

Certificate Transparency

Gather hostnames from historical certificates in crt.sh.

Free
LOGO sfp malwarepatrol

MalwarePatrol

Searches malwarepatrol.net's database of malicious URLs/IPs.

Tiered
Logo api c99 nl

C99

Queries the C99 API which offers various data (geo location, proxy detection, phone lookup, etc).

Commercial
Logo default

Greensnow

Check if a netblock or IP address is malicious according to greensnow.co.

Free
LOGO sfp cloudflaredns

CloudFlare Malware DNS

Check if a host would be blocked by CloudFlare Malware-blocking DNS

Free
Logo emailcrawl

EmailCrawlr

Search EmailCrawlr for email addresses and phone numbers associated with a domain.

Tiered
LOGO sfp alienvault

AlienVault OTX

Obtain information from AlienVault Open Threat Exchange (OTX)

Tiered
LOGO sfp riskiq

RiskIQ

Obtain information from RiskIQ's (formerly PassiveTotal) Passive DNS and Passive SSL databases.

Tiered
LOGO sfp fortinet

Fortiguard.com

Check if an IP is malicious according to Fortiguard.com.

Free
LOGO sfp neutrinoapi

NeutrinoAPI

Search NeutrinoAPI for IP address info and check IP reputation.

Tiered
LOGO sfp malwaredomains

malwaredomains.com

Check if a host/domain is malicious according to malwaredomains.com.

Free
LOGO sfp darksearch

Darksearch

Search the Darksearch.io Tor search engine for mentions of the target domain.

Free
LOGO sfp ahmia

Ahmia

Search Tor 'Ahmia' search engine for mentions of the target domain.

Free
Logo default

ipregistry

Query the ipregistry.co database for reputation and geo-location.

Tiered
LOGO sfp myspace

MySpace

Gather username and location from MySpace.com profiles.

Free
Logo koodous

Doodous

Search Koodous for mobile apps.

Free
LOGO sfp emailformat

EmailFormat

Look up e-mail addresses on email-format.com.

Free
LOGO sfp commoncrawl

CommonCrawl

Searches for URLs found through CommonCrawl.org.

Free
LOGO sfp spyonweb

SpyOnWeb

Search SpyOnWeb for hosts sharing the same IP address, Google Analytics code, or Google Adsense code.

Tiered
LOGO sfp instagram

Instagram

Gather information from Instagram profiles.

Free
LOGO sfp hackertarget

HackerTarget

Search HackerTarget.com for hosts sharing the same IP.

Free
Logo onyphe

Onyphe

Check Onyphe data (threat list, geo-location, pastries, vulnerabilities) about a given IP.

Tiered
LOGO sfp blockchain

Blockchain

Queries blockchain.info to find the balance of identified bitcoin wallet addresses.

Free
Logo leak IX

LeakIX

Search LeakIX for host data leaks, open ports, software and geoip.

Free
LOGO sfp slideshare

SlideShare

Gather name and location from SlideShare profiles.

Free
LOGO sfp googlemaps

Google Maps

Identifies potential physical addresses and latitude/longitude coordinates.

Tiered
Logo textmagic

TextMagic

Obtain phone number type from TextMagic API

Tiered
LOGO sfp watchguard

Watchguard

Check if an IP is malicious according to Watchguard's reputationauthority.org.

Free
LOGO sfp spamhaus

Spamhaus

Query the Spamhaus databases for open relays, open proxies, vulnerable servers, etc.

Free
LOGO sfp wikipediaedits

Wikipedia Edits

Identify edits to Wikipedia articles made from a given IP address or username.

Free
Logo default

Twilio

Obtain information from Twilio about phone numbers. Ensure you have the Caller Name add-on installed in Twilio.

Tiered
LOGO sfp ripe

RIPE

Queries the RIPE registry (includes ARIN data) to identify netblocks and other info.

Free
LOGO sfp cybercrimetracker

cybercrime-tracker.net

Check if a host/domain or IP is malicious according to cybercrime-tracker.net.

Free
LOGO sfp whox

Whoxy

Reverse Whois lookups using Whoxy.com

Commercial
LOGO sfp openstreetma

OpenStreetMap

Retrieves latitude/longitude coordinates for physical addresses from OpenStreetMap API.

Free
LOGO sfp spyse

Spyse

SpiderFoot plug-in to search Spyse API for IP address and domain information.

Tiered
Logo gstatic

Social Media Profile Finder

Tries to discover the social media profiles for human names identified.

Tiered
LOGO sfp bgpview

BGPView

Obtain network information from BGPView API.

Free
LOGO sfp bingsharedi

Bing (Shared IPs)

Search Bing for hosts sharing the same IP.

Tiered
Logo bitcoinwhoswho

Bitcoin Who's Who

Check for Bitcoin addresses against the Bitcoin Who's Who database of suspect/malicious addresses.

Tiered
LOGO sfp fullcontact

FullContact

Gather domain and e-mail information from FullContact.com API.

Tiered
LOGO sfp isc

Internet Storm Center

Check if an IP is malicious according to SANS ISC.

Free
LOGO sfp googlesearch

Google

Obtain information from the Google Custom Search API to identify sub-domains and links.

Tiered
LOGO sfp cleanbrowsing

CleanBrowsing.org

Check if a host would be blocked by CleanBrowsing.org DNS

Free
LOGO sfp openphish

OpenPhish

Check if a host/domain is malicious according to OpenPhish.com.

Free
LOGO sfp mnemonic

Mnemonic PassiveDNS

Obtain Passive DNS information from PassiveDNS.mnemonic.no.

Free
LOGO sfp openbugbount

Open Bug Bounty

Check external vulnerability scanning/reporting service openbugbounty.org to see if the target is listed.

Free
LOGO sfp pastebin

PasteBin

PasteBin search (via Google Search API) to identify related content.

Tiered
LOGO sfp virustotal

VirusTotal

Obtain information from VirusTotal about identified IP addresses.

Tiered
LOGO sfp whatcms

WhatCMS.org

Check web technology using WhatCMS.org API.

Tiered
LOGO sfp opencorporates

OpenCorporates

Look up company information from OpenCorporates.

Tiered
Logo default

Greynoise

Obtain information from Greynoise.io's Enterprise API.

Tiered
LOGO sfp onionsearchengine

Onionsearchengine.com

Search Tor onionsearchengine.com for mentions of the target domain.

Free
LOGO sfp threatcrowd

ThreatCrowd

Obtain information from ThreatCrowd about identified IP addresses, domains and e-mail addresses.

Free
LOGO sfp ipinfo

IPInfo.io

Identifies the physical location of IP addresses identified using ipinfo.io.

Tiered
LOGO sfp uceprotect

UCEPROTECT

Query the UCEPROTECT databases for open relays, open proxies, vulnerable servers, etc.

Free
Logo default

Snov

Gather available email IDs from identified domains

Tiered
LOGO sfp twitter

Twitter

Gather name and location from Twitter profiles.

Free
LOGO sfp dronebl

DroneBL

Query the DroneBL database for open relays, open proxies, vulnerable servers, etc.

Free
LOGO sfp networksdb

NetworksDB

Search NetworksDB.io API for IP address and domain information.

Tiered
Logo keybase io

Keybase

Obtain additional information about target username

Free
LOGO sfp circllu

CIRCL.LU

Obtain information from CIRCL.LU's Passive DNS and Passive SSL databases.

Free
LOGO sfp wigle

WiGLE

Query WiGLE to identify nearby WiFi access points.

Free
LOGO sfp fsecure riddler

F-Secure Riddler.io

Obtain network information from F-Secure Riddler.io API.

Commercial
LOGO sfp iknowwhatyoudownload

iknowwhatyoudownload.com

Check iknowwhatyoudownload.com for IP addresses that have been using BitTorrent.

Tiered
LOGO sfp gravatar

Gravatar

Retrieve user information from Gravatar API.

Free
Logo default

Maltiverse

Obtain information about any malicious activities involving IP addresses

Free
LOGO sfp archiveorg

Archive.org

Identifies historic versions of interesting files/pages from the Wayback Machine.

Free
Logo farsightsecurity

DNSDB

Query FarSight's DNSDB for historical and passive DNS data.

Tiered
LOGO sfp robtex

Robtex

Search Robtex.com for hosts sharing the same IP.

Free
LOGO sfp threatminer

ThreatMiner

Obtain information from ThreatMiner's database for passive DNS and threat intelligence.

Free
LOGO sfp sorbs

SORBS

Query the SORBS database for open relays, open proxies, vulnerable servers, etc.

Free
LOGO sociallinks

Social Links

Queries mtg-bi.com (Social Links) to gather intelligence from social media platforms and dark web.

Commercial
LOGO abstractapi

AbstractAPI

https://www.abstractapi.com/ip-geolocation-api

Commercial