Cyber Security Threat Intelligence Lookup

A list of Cyber Security threat intelligence tools that can be used to lookup domains, IP’s and file hash to gather additional detail around a potential threat.

URL/Domain Analysis


Intelligence Lookup ToolDescription
AlienVault OTXLearn about the latest online threats. Share and collaborate in developing threat intelligence. Protect yourself and the community against today’s latest threats.
Cisco TalosSearch by IP, domain, or network owner for real-time threat data.
IBM XForce ExchangeSearch or submit a file to scan. Check for IOCs, keywords, malware intelligence, or even Collections that other users have contributed.
WhoIsInvestigate the WhoIs records of a domain to identify the owners as well discovery when the domain was first registered and when it was last updated.
OPSWAT MetaDefender CloudSubmit and analyse files, URL’S, IP’s, Domains, Hash and CVE’s
Palo Alto URL CategoriesTest a site to identify the Palo Alto categorisation.
PhishTanksPhishTank is a collaborative database for data and information about phishing on the Internet.
URL VoidWebsite reputation checker.
VirusTotalAnalyze suspicious files and URLs to detect types of malware, automatically share them with the security community.
MX ToolboxThis tool can be used to investigate the MX Records of any domain.
URLScan.ioAn extremely useful tool to investigate a domain/URL which provides a screenshot, similar websites and much more.
Hybrid AnalysisA free online sandbox (Falcon Sandbox) to investigate URL’s & Files.
Cyber GordonInvestigate Domains/IP’s with a tool that collates information from many sources, similar to VirusTotal.
Redirect DetectiveA tool which can be used to investigate where URL’s redirect to.
DNS DumpsterA free domain research tool that can discover hosts related to a domain.

IP Analysis


Intelligence Lookup ToolDescription
AlienVault OTXLearn about the latest online threats. Share and collaborate in developing threat intelligence. Protect yourself and the community against today’s latest threats.
Cisco TalosSearch by IP, domain, or network owner for real-time threat data.
IBM XForce ExchangeSearch or submit a file to scan. Check for IOCs, keywords, malware intelligence, or even Collections that other users have contributed.
IP VoidVast range of IP address tools to discover details about IP addresses.
IP blacklist check, whois lookup, dns lookup, ping, and more!
OPSWAT MetaDefender CloudSubmit and analyse files, URL’S, IP’s, Domains, Hash and CVE’s
TOR CheckerCheck if an IP was used in the TOR network on particular dates.
AbuseIPDBCheck an IP, Domain or Subnets reputation.
ShodanA search engine which crawls the internet. This can be used to discover information on IP’s and domains.
VirusTotalAnalyze suspicious files and URLs to detect types of malware, automatically share them with the security community.
GreyNoiseInvestigate an IP’s reputation in the GreyNoise database.
Feodo TrackerInvestigate an IP in a database which tracks active Botnet and C2C channels.

File Analysis


Intelligence Lookup ToolDescription
AlienVault OTXLearn about the latest online threats. Share and collaborate in developing threat
VirusTotalAnalyze suspicious files and URLs to detect types of malware, automatically share them with the security community.
IBM XForce ExchangeSearch or submit a file to scan. Check for IOCs, keywords, malware intelligence, or even Collections that other users have contributed.
MalwareBazaarInvestigate a file hash for known malicious files.
OPSWAT MetaDefender CloudSubmit and analyse files, URL’S, IP’s, Domains, Hash and CVE’s

Email Analysis


Intelligence Lookup ToolDescription
Hunter.io This tool lets you find email addresses for domains which have been published online. This is particularly helpful to add additional protection mechanisms and identify areas of heightened risk.
DNSTwist DNSTwister Enumerate a list of potential domains similar to the one entered which can be used to either setup detection rules or to actively block or even buy.
DehashedQuery a database of assets compromised in attacks.
HaveIbeenpwned Easy tool to check as well as monitor if your email or phone has been breached. Note notifications can be setup for your personal email address/addresses as well as company corporate domai
MX Toolbox This tool can be used to investigate the MX Records of any domain.
For a list of Cyber Security threat intelligence sources check out here.