Cyber Threat Intelligence
76 toolsOSINT tools for threat analysis, threat hunting, detection engineering, SOC analysis, incident response, and digital forensics.
Pricing
Min Rating
Top-Rated Tools
Shodan
4.7/5Search engine for internet-connected devices — find exposed servers, industrial systems, and network infrastructure worldwide.
urlscan.io
4.6/5Free website scanner that captures full-page screenshots, network requests, and DOM snapshots for any URL
bbot
4.5/5One command seeds a recursive scan that automatically enumerates subdomains, port-scans live hosts, screenshots web interfaces, and detects exposed secrets — without manual pipeline steps between each phase.
Bitdefender
4.5/5Award-winning antivirus and endpoint security suite with advanced threat detection for individuals and teams
HackRF One
4.5/5The open-source SDR transceiver covering 1 MHz to 6 GHz — the standard platform for frequency scanning, signal analysis, and RF research.
MISP Warning Lists
4.5/5A structured false-positive filtering layer that helps analysts stop treating common benign infrastructure as malicious indicators.
More Tools
VirusTotal
Threat IntelligenceMulti-engine malware scanner and threat intelligence platform for files, URLs, IPs, and domains
capa
Threat IntelligenceA malware triage tool that quickly tells analysts what an executable is capable of doing and where those behaviors appear.
Cortex Analyzers
Threat IntelligenceA modular enrichment engine that lets TheHive analysts analyze observables in place instead of pivoting across dozens of external CTI tools.
Cortex
Threat IntelligenceAn enrichment and response engine that lets TheHive analysts analyze observables and trigger actions without leaving the case workflow.
destroylist
Threat IntelligenceA continuously updated phishing and scam domain feed that helps defenders block fraud infrastructure through DNS, hosts files, or API lookups.
Have I Been Pwned
Identity InvestigationThe fastest way to confirm whether an email address appears in known data breaches — free, accurate, and maintained by a single researcher who vets every dataset.
httpx
Network ReconA high-speed HTTP probing tool that turns raw host lists into triaged, fingerprinted web targets ready for investigation.
MISP Galaxy
Threat IntelligenceA structured cluster library that gives threat intelligence events actor, malware, and technique context instead of leaving them as unlabeled IOC collections.
MISP
Threat IntelligenceAn open source threat intelligence platform built for structured IOC management, community sharing, and fast operational distribution.
subfinder
Network ReconFast passive subdomain enumeration that gives pentesters a clean starting point for external recon.
Amass
Network ReconMap an organization's full external attack surface — ASNs, domains, subdomains, and infrastructure relationships — through 50+ integrated data sources and a persistent graph database.
Anthropic Cybersecurity Skills
Threat IntelligenceA structured open skill library that gives AI agents concrete cybersecurity workflows mapped to ATT&CK, D3FEND, ATLAS, and NIST frameworks.
C2 Tracker
Threat IntelligenceA live C2 infrastructure feed that helps defenders hunt, block, and correlate active command-and-control servers by framework type.
crt.sh
Network ReconPassive certificate transparency searches uncover subdomains and related infrastructure before you ever touch the target.
DorkSearch
Network Recon889,000+ pre-built Google dorks with an AI dork builder for instant recon
Awesome Lists (mthcht)
Threat IntelligenceA blue-team-first security directory that helps SOC and CTI teams find relevant feeds, rule sources, and detection references without wading through offensive tooling.
OpenCTI
Threat IntelligenceStore, correlate, and visualize structured threat intelligence using STIX2 as the native data model — with a 150+ connector ecosystem and graph-based investigation workflows designed for serious TI programs.
Web Check
Network ReconPaste a URL and get DNS records, SSL details, security headers, tech stack, WHOIS, and 100+ more domain intelligence checks in a single browser view — in under thirty seconds.
WorldMonitor
GeospatialCorrelated multi-domain intelligence across conflicts, maritime, aviation, infrastructure, finance, and climate on a single open source map surface.
BuiltWith
Network ReconTechnology intelligence — find what any website is built with and who else uses it
IntelOwl
Threat IntelligenceOrchestrate IOC enrichment across 100+ threat intelligence sources through a single API — with automated multi-hop correlation and direct output to MISP, OpenCTI, or DFIR-IRIS.
ProtonVPN
Identity InvestigationSwiss-based VPN with open-source client and strong jurisdiction for journalists and investigators
SpiderFoot
Network ReconMap a target's full digital footprint automatically — domains, IPs, emails, names, and ASNs across 500+ sources.
Sucuri
Network ReconWebsite security platform used by investigators to analyze site integrity, malware, and CDN infrastructure
Awesome Incident Response
Threat IntelligenceA categorized DFIR directory that helps responders discover forensic, malware, and case-management tools with added adoption signals from GitHub metadata.
Censys
Network ReconInternet-wide scanner with certificate transparency coverage no other tool matches.
cyberbro
Threat IntelligenceA paste-and-submit IOC triage tool that extracts indicators from messy text and checks their reputation across multiple CTI services.
FOFA
Network ReconA web-focused internet asset search engine that helps analysts pivot from one exposed fingerprint to broader infrastructure quickly.
GrayHatWarfare
Network ReconFind exposed cloud storage faster by searching indexed public S3 buckets and blob containers tied to real targets.
Hudson Rock
Threat IntelligenceInfostealer intelligence platform exposing compromised credentials from malware-infected machines worldwide
LeakIX
Network ReconInternet-wide scanner for exposed services and data leaks, with a focus on misconfigured databases and sensitive data exposure
nomore403
Network ReconA fast 403 bypass automation tool that turns forbidden content discovery results into systematically tested access-control edge cases.
NordVPN
Identity InvestigationEncrypted tunnel and threat protection for OSINT investigators working in hostile environments
openSquat
Threat IntelligenceAn open source monitoring tool that helps defenders catch brand lookalike domains before phishing campaigns go live.
Ransomware Tool Matrix
Threat IntelligenceA group-centric ransomware reference that helps defenders translate gang attribution into concrete tools, hunt leads, and detection priorities.
reconFTW
Network ReconA full-scope domain recon framework that chains proven CLI tools into one repeatable workflow for broad attack surface discovery.
Recorded Future
Threat IntelligenceThe leading threat intelligence platform for enterprise security teams
Surfshark
Identity InvestigationVPN with built-in identity monitoring and anonymous browsing identity tools
WiGLE
GeospatialCrowdsourced wireless network database mapping billions of Wi-Fi, Bluetooth, and cell networks globally
YARD Stick One
Network ReconSub-1 GHz wireless transceiver for 433/868 MHz IoT, key fob, and industrial protocol analysis — the dedicated tool for the RF bands that run smart devices.
Awesome Forensics
Threat IntelligenceA curated DFIR resource directory that helps investigators find relevant forensic tools quickly when unfamiliar evidence types appear.
cariddi
Network ReconA fast Go web crawler that plugs cleanly into recon pipelines to uncover endpoints, JavaScript URLs, and exposed secrets at scale.
DFIRTrack
Threat IntelligenceA focused incident response tracking app that helps teams manage systems, artifacts, tasks, and timelines without relying on spreadsheets.
discover
Network ReconA Kali-native bash automation wrapper that speeds up standard recon, scanning, and payload generation without forcing you into a heavyweight framework.
IVRE
Network ReconTurn your Nmap and Masscan output into a persistent, queryable network intelligence database with Shodan-style query capabilities against your own infrastructure.
mihari
Threat IntelligenceA rule-driven OSINT hunting engine that automates recurring infrastructure queries and alerts only on what is newly discovered.
NordPass
Identity InvestigationPassword manager with breach monitoring built for secure credential hygiene
Open Source Threat Intel Feeds
Threat IntelligenceA practical reference directory for finding, comparing, and operationalizing free IOC feeds across MISP, SIEM, and enrichment pipelines.
Pulsedive
Threat IntelligenceCommunity-driven threat intelligence platform with enriched IOC data and free analyst-grade lookups
SEMrush
Network ReconCompetitive intelligence and web footprint analysis for digital investigators
Sploitus
Threat IntelligenceA centralized exploit search engine that helps analysts check public exploit availability across multiple sources in one place.
Adalanche
Network ReconA single-binary Active Directory graph tool that helps operators find ACL-driven escalation paths without standing up a separate graph database.
Avilla Forensics
Threat IntelligenceA free Android forensic utility that simplifies ADB-based extraction and app analysis for investigators without a commercial mobile suite.
Hacking Tools (aw-junaid)
Network ReconA multi-language security tool collection that helps researchers study how offensive and analysis utilities are built across different ecosystems.
Criminal IP
Network ReconIP and domain scanner that scores addresses by malicious activity and maps CVEs to exposed service banners.
deepdarkCTI
Threat IntelligenceA structured reference of dark web and deep web CTI sources — ransomware tracking sites, IOC feeds, paste monitors, and threat actor Telegram channels — organized for feed coverage auditing.
Findomain
Network ReconA fast passive subdomain enumerator that adds built-in monitoring, history, and alerting for newly exposed assets.
Netlas
Network ReconInternet scanning platform with 8 billion+ indexed IP addresses for attack surface and infrastructure analysis
Norton Small Business
Threat IntelligenceEndpoint protection and threat detection for small OSINT teams and security firms
Recon-ng
Network ReconCLI-based web reconnaissance framework modeled after Metasploit
theHarvester
Network ReconPassively harvest emails, subdomains, and hostnames from public sources before you touch a single target system.
metabigor
Network ReconA zero-configuration ASN and network scope discovery tool that helps hunters map organizational IP space without API setup.
Mitaka
Threat IntelligenceA browser extension that turns highlighted indicators into instant OSINT and threat intelligence lookups without breaking analyst flow.
SecurityTrails
Network ReconHistorical DNS and domain intelligence database covering 10+ years of infrastructure changes
TorBot
Threat IntelligenceA Tor-routed OSINT crawler that helps analysts map .onion infrastructure, collect contact details, and preserve volatile dark web content.
GreyNoise
Network ReconInternet noise classifier that separates mass-scanning background traffic from targeted activity so you can stop chasing ghosts in your SIEM.
Onyphe
Threat IntelligenceCyber defense search engine indexing internet-wide scan data, threat intelligence feeds, and passive DNS
sitedorks
Network ReconRun the same dork across multiple search engines and target site collections without rebuilding every query by hand.
Maltego
Network ReconThe gold standard for visual link analysis and OSINT pivoting
ZoomEye
Network ReconChinese-operated internet search engine for cyberspace — maps exposed services and devices globally