Digital Network Intelligence [DNINT]

A collection of online resources and tools to assist with domain, IP address and general DNINT investigations, as well as website enumeration, exploits, CCTV, webcams and more.

WHOIS

  • WhoisFreaksarrow-up-right An API which allows you to search for WHOIS records by company name, owner name or keyword. Currently has over 430 million records dating as far back as 1986. Requires registration.

  • Whoisologyarrow-up-right Search for WHOIS records and other data via domain name, email address or keyword. For enhanced results, a paid subscription is required.

  • DomainBigDataarrow-up-right Find the registrant and other domains owned by the same person with their reverse WHOIS. Find domain history, domains on same IP, network owner and more.

  • Marcariaarrow-up-right Search WHOIS information in over 2,000 extensions including international ccTLDs and gTLDs.

  • IQ WHOISarrow-up-right A great WHOIS search tool that offers downloadable databases, historical WHOIS records and more.

  • WhoisDSarrow-up-right Access over 30 days worth of newly registered domains with this database. Database is updated daily.

Internet Protocol Addresses [IP]

  • IKnowWhatYouDownloadarrow-up-right Search an IPv4 or IPv6 address and view the most recent torrents that have been downloaded or that the user is currently seeding.

  • AbuseIPDBarrow-up-right A database of abuse reports. Search an IP address and see if it has been included in any abuse reports, malicious activity reports, and spam campaigns.

  • Hurricane Electric BGP Toolkitarrow-up-right Contains loads of great networking tools.

  • BGPViewarrow-up-right A BGP toolkit and ASN routing lookup tool that allows you to debug and investigate information about IP addresses, ASN, IXs, BGP, ISPs, prefixes and domain names.

  • InfoSniperarrow-up-right Provides detailed IP geo-location information.

  • IP Hubarrow-up-right An IP lookup tool featuring proxy and VPN detection. A free API is also available. Requires a paid subscription for best results.

  • IP Quality Scorearrow-up-right A collection of fraud detection tools including proxy and VPN detection, bot detection, email validation, and lots of other tools. Offers many free tools. Requires a paid subscription to be able to use everything.

  • IP Teoharrow-up-right Simple tool that provides basic information about an IP address. Geo-location, ISP, and proxy/VPN/TOR node detection.

  • CentralOpsarrow-up-right A great collection of various networking tools. Ping, traceroute, WHOIS, nslookup, domain dossier and so on.

  • IP-Neighborsarrow-up-right Find neighboring websites, hostnames, and domains. Get an idea who runs a host, the hosting density, and neighboring hosts.

  • NetworksDBarrow-up-right Contains information about the public IPv4 and IPv6 addresses, networks and domains owned by companies and organizations across the world along with city-level IP geolocation data and autonomous system information. Also offers a free API.

  • PeeringDBarrow-up-right A user-maintained database of networks. Provides a wealth of interconnection data.

  • Robtexarrow-up-right Gathers public information about IP numbers, domain names, host names, autonomous systems, routes, etc. It then indexes the data in a big database and provides free access to the data.

  • IntelX IP Address Searcharrow-up-right A great IP address search tool offered by IntelX.

  • CriminalIParrow-up-right Search for information about IP addresses, domains, malicious links, phishing sites and more.

  • IPinfoarrow-up-right Provides information about IP addresses, also offers a great CLI tool. Requires a paid subscription.

  • GreenSnow IP Blacklistarrow-up-right A IP blacklist of known spammer and malicious IP addresses that is constantly being updated.

  • InfoByIParrow-up-right Domain and IP bulk lookup tool allows you to lookup domains, locations, ISPs and ASNs for multiple hosts at once.

  • Spur.usarrow-up-right A great tool that provides tools and data to detect VPNs, residential IPs, proxies, and bots. Simply input an IP address in the URL, like so: spur.us/context/ENTER-IP-ADDRESS-HERE.

Domain Name System [DNS] Records

  • PTArchivearrow-up-right Search for historical reverse DNS records. Currently has over 230 billion records retrieved from 2008 to now.

  • PassiveDNSarrow-up-right Search for DNS records via domain name.

  • IntoDNSarrow-up-right Checks the health and configuration of DNS and mail servers.

  • ViewDNS Infoarrow-up-right Allows users to gather a large amount of data about a given website or IP address.

  • DNSlyticsarrow-up-right Offers loads of great tools such as DNS, MX, WHOIS and SPF lookups along with multiple reverse search tools.

  • dnstwisterarrow-up-right The anti-phishing domain name search engine and DNS monitoring service, Search a domain name and this tool will show you related domain names that could potentially be used for phishing campaigns.

  • DMNSarrow-up-right Domains App makes it easy to see domains availability across extensions and notifies you about any WHOIS or DNS changes.

  • DomainCodexarrow-up-right Research domain information and all associated data, including records, IP addresses, page metadata, location and much more. Has over 315 million indexed domains.

  • IntelX Domain Searcharrow-up-right A great domain search engine offered by IntelX.

  • DNS Institutearrow-up-right Enables domain owners and DNS professionals to monitor and check conformance and vulnerabilities of their DNS infrastructure, through scheduled protocol tests, vulnerability tests, alerts, news, and statistics with complete reporting. They also offer many interesting reports.

  • Host.ioarrow-up-right A great API for domain name data, uncover new domains and the relationships between them. Requires a paid subscription.

  • RapidDNSarrow-up-right DNS search tool. Find subdomains, shared IPs and more. Claims to have over 3 billion records.

  • CompleteDNSarrow-up-right Research domain history and other DNS details. Currently has over 20 years worth of data. Requires a paid subscription.

  • DNSDumpsterarrow-up-right A free domain research tool that can discover hosts related to a domain. Finding visible hosts from the attackers perspective is an important part of the security assessment process.

Website Analysis

Certificate Transparency [CT]

  • crt.sharrow-up-right A great site where you could find all the SSL and/or TLS certificates of a target domain. crt.sh is pronounced "Search", by the way.

  • SSLMatearrow-up-right Instantly search Certificate Transparency logs for any domains SSL certificates using this convenient API.

  • Entrustarrow-up-right Entrust records all SSL/TLS certificates that we issue to the CT logs. This practice promotes transparency and provides an open way for domain owners to audit and monitor certificates that have been issued in their name.

  • SSL Toolsarrow-up-right Offers some useful tools when investigating SSL certificates.

Wireless Fidelity [WiFi]

  • WiGLEarrow-up-right The Wireless Geographic Logging Engine is a website for collecting crowd-sourced wardriving information about the different wireless networks and cell towers around the world. Users can register on the website and upload hotspot data like GPS coordinates, SSID, MAC address and the encryption type used on the hotspots discovered. Great way to get an address from a Wi-Fi SSID.

  • Mylnikov APIarrow-up-right A free API that allows you to get latitude and longitude by Wi-Fi BSSID or MAC address.

  • OpenWiFiarrow-up-right API and database. The project seems idle since 2018 but the service is still online.

  • 3WiFiarrow-up-right Similar to Wigle, this is a interactive, crowd-sourced map of wireless access points.

  • RadioCellsarrow-up-right A community project to collect information on cell tower and Wi-Fi base stations and plot them on a map. The project itself was founded in 2009.

  • OpenWiFiMaparrow-up-right Database and map for free network Wi-Fi access points from all over the world.

  • WiManarrow-up-right Helps find all the free Wi-Fi hotspots available per destination and elsewhere in the world.

  • WiFiSpacearrow-up-right Find open free and public Wi-Fi hotspots practically anywhere in the world.

  • WiFi Maparrow-up-right Another site that shows you publicly open Wi-Fi networks by location. They also offer a mobile app.

  • BT WiFiarrow-up-right The UK's biggest Wi-Fi hotspot network. Over 5 million available hotspots nation wide.

  • OpenWiFiSpotsarrow-up-right Search for free open wireless networks worldwide.

  • Airport WiFiarrow-up-right Provides WiFi passwords from airports and lounges around the world.

Media Access Control [MAC]

User Agents

  • Device Discovery

    • Shodanarrow-up-right A search engine that lets the user find specific types of computers and IoT devices connected to the internet using a variety of filters.

    • Censysarrow-up-right The search engine for finding internet devices, like computers, servers, and other smart devices.

    • ZoomEyearrow-up-right Another search engine which is used mostly to see open devices that are vulnerable and most often used by pentesters to test or exploit their vulnerabilities over the internet. Zoomeye lets user find specific connected network devices.

    • Thingfularrow-up-right A search engine for the internet of things (IoT), providing a unique geographical index of connected objects around the world, including energy, radiation, weather, and air quality devices as well as seismographs, iBeacons, ships, aircraft and even animal trackers.

    • GreyNoisearrow-up-right Collects, analyzes, and labels mass internet scan and attack activity into a feed of Anti-Threat Intelligence (ATI).

    • Natlasarrow-up-right This is described as a "collection of nmaps". Catalogs things like open ports and software versions.

    • ONYPHEarrow-up-right A cyber defense search engine for open-source and cyber threat intelligence data. Collected by crawling various sources available on the Internet and active internet scanning.

    • FOFAarrow-up-right FOFA is a cyberspace search engine. It help customers find IP assets quickly. Essentially a clone of Shodan.

    • LeakIXarrow-up-right Search engine indexing open ports on the internet. It focuses on listing the databases and table names and keeps an history of every successful connection.

    • BinaryEdgearrow-up-right Focuses on acquiring, analyzing and classifying internet wide data by combining efforts in the areas of cybersecurity, data science and machine learning. Requires registration.

    • FullHunt.ioarrow-up-right Attack surface database of the entire Internet. Search info by domain, IP, technology, host, tag, port, city and more.

CCTV and Webcams

Application Programming Interfaces [API]

  • BeVigil OSINT APIarrow-up-right A powerful tool that provides access to millions of asset footprint data points including domain intel, cloud services, API information, and third party assets extracted from millions of mobile apps being continuously uploaded and scanned. Requires registration.

Attack Maps

Public Buckets

Exploits and Proof of Concept [PoC]

  • ExploitDBarrow-up-right An archive of exploits, vulnerabilities, shellcode, 0days, security articles, whitepapers and more. Ran by Offensive Security.

  • GHDBarrow-up-right

    The Google Hacking Data Base is an index of search queries (we call them dorks) used to find publicly available information, intended for pentesters and security researchers.

  • MITRE CVEarrow-up-right The mission of the CVE program is to identify, define, and catalog publicly disclosed cyber-security vulnerabilities.

  • NIST NVDarrow-up-right The U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). Enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.

  • CVE Detailsarrow-up-right You can browse for vendors, products and versions and view CVE entries, vulnerabilities, related to them. You can view statistics about vendors, products and versions of products. Vulnerability data is updated daily using NVD feeds.

  • VulDBarrow-up-right A vulnerability database documenting and explaining security vulnerabilities, threats, and exploits since 1970.

  • CVE Trendsarrow-up-right Crowdsourced CVE intelligence and trends.

  • 0day.todayarrow-up-right A database and marketplace for both public and 0day exploits.

  • RouterPwnarrow-up-right An outdated database of router exploits.

  • Vulnersarrow-up-right Claims to be the largest correlated database of vulnerabilities and exploits.

Advanced Persistent Threats [APTs]

Malware and Malware Analysis

  • vx-undergroundarrow-up-right The best source for malware samples available on the internet. They also have large archives of various whitepapers, zines and other interesting things.

  • Malware Traffic Analysisarrow-up-right A source if pcap files and malware samples. Since the summer of 2013, this site has published over 2,000 blog entries about malicious network traffic. Almost every post on this site includes pcap files and/or malware samples.

  • DarkFeedarrow-up-right A live feed of malicious indicators of compromise (IOCs). Including domains, URLs, hashes, and IP addresses.

  • Malpediaarrow-up-right The primary goal of Malpedia is to provide a resource for rapid identification and actionable context when investigating malware.

  • Abuse.charrow-up-right A research project at the Bern University of Applied Sciences (BFH). Home of some great projects such as MalwareBazzar, botnet C&C trackers, SSL blacklists and more.

  • URLHausarrow-up-right A project from abuse.ch with the goal of sharing malicious URLs that are being used for malware distribution.

  • FireHOL IP Listsarrow-up-right This site analyses all available security IP Feeds, mainly related to on-line attacks, on-line service abuse, malwares, botnets, command and control servers and other cybercrime activities.

  • Ransom-DBarrow-up-right Provides ransomware tracking in real-time, tracking ransomware groups and their victims.

  • RansomWatcharrow-up-right A constantly updated database that tracks ransomware operators.

  • Threat Intelligence Platformarrow-up-right Combines several threat intelligence sources to provide in-depth insights on threat hosts and attack infrastructure. Requires a paid subscription.

Personal Connection Profiling

Browser Extension Resources

Other Tools

An organized and importable .html bookmark file that includes everything listed on this page.
A PDF copy that contains everything on this page for offline use. Updated - 24/9/2022.

Last updated