Threat Data
Is this bad?
Use this page for indicator reputation, enrichment, passive DNS, certificate history, blockchain analysis, and quick lookup tools. Detection engineering, YARA, sandboxes, reverse engineering, active recon, and exploit research live in their own sections.
How to Use This Page
Reputation checks are starting points, not verdicts. An indicator can still be malicious even if it does not appear on any blacklist, and a shared service, CDN, or compromised host can create false positives. Use multiple sources, document what each source said, and keep the surrounding context: ASN, registrar, creation date, passive DNS history, related certificates, associated malware families, and analyst comments.
Threat Maps
Threat maps can help with situational awareness, but they should not be treated as precise telemetry for a specific incident.
Threat Actor Information
DarkFeed RansomWiki - Ransomware group tracking and links.
CrowdStrike Adversary Universe - Threat actor profiles and e-crime tracking.
Malpedia - Malware family and actor context. Malware analysis details are maintained in DFIR.
Blacklist Checks and Reputation Data
Multi-Source Lookups
Hurricane Electric BGP Toolkit - IP, domain, ASN, subnet, WHOIS, BGP, DNS, and related metadata.
VirusTotal - File, hash, IP, URL, and domain reputation with community comments and relationship pivots.
Cisco Talos Intelligence - IP, domain, network owner, email volume, and reputation data.
MXToolbox Blacklist Check - Domain and IP blacklist checks.
MultiRBL - DNSBL and FCrDNS lookup.
InfoByIP Bulk IP Lookup - Bulk IP/domain lookup.
IP Reputation
IPVoid - IP blacklist, reverse DNS, ASN, and geolocation summary.
DNSBL.info - Mail server DNSBL checks.
Team Cymru IP Reputation - IP reputation lookup.
blocklist.de - Abuse-oriented IP and netblock lookup.
Project Honey Pot - Distributed honeypot IP activity.
Focsec - API-only VPN, proxy, Tor, and bot risk checks.
IPQualityScore IP Reputation - IP fraud, spam, proxy, and VPN risk checks.
URL and Domain Reputation
urlscan.io - URL scanning, screenshot, HTTP transaction, IP, domain tree, and technology data.
URLVoid - URL/domain reputation, WHOIS, reverse DNS, and ASN data.
Zscaler Zulu - URL risk analysis.
PhishTank - Community phishing URL database.
Google Safe Browsing - Google phishing and malware status.
Quttera - Website malware scanning.
Sucuri SiteCheck - Website malware and security checks.
AdGuard Reports - AdGuard block list lookup.
LOTS Project - Legitimate domains commonly abused for phishing, C2, exfiltration, and malware delivery.
File Hash Reputation
Cisco Talos File Reputation - SHA-256 file reputation.
MalwareBazaar - Malware samples and hash lookup from abuse.ch.
Team Cymru Malware Hash Registry - MD5, SHA-1, and SHA-256 hash lookup.
CIRCL Hashlookup - Hash lookup API from CIRCL.
Xcitium Valkyrie - File verdicts and dynamic analysis metadata.
For full sandboxing and malware behavior analysis, use DFIR sandboxing.
SandboxingEmail and Spam Data
EmailRep - Email reputation, domain reputation, social presence, and policy context.
MXToolbox MX Lookup and SuperTool - MX, DMARC, DNS, and blacklist pivots.
HaveIBeenEmotet - Historical Emotet malspam involvement lookup.
Indicator Enrichment
These platforms add context to indicators through scanner telemetry, historical data, abuse reports, and related infrastructure.
GreyNoise - Separates internet background noise from targeted activity and provides scanner tags.
BrightCloud URL/IP Lookup - URL/IP category and reputation.
AbuseIPDB - IP abuse reporting and confidence scores.
SANS DShield - Honeypot, SSH, port, header, and reputation context.
ThreatFox - IoC library from abuse.ch.
Spamhaus - IP and domain blacklist status.
ThreatIntelligencePlatform.com - Domain/IP/hash enrichment.
OPSWAT MetaDefender - File, URL, IP, domain, hash, and CVE lookup.
Microsoft Defender Threat Intelligence - Microsoft threat intelligence platform, formerly RiskIQ/PassiveTotal.
Pulsedive - Indicator, threat, and feed enrichment.
ThreatShare - Malware URL and family context.
PhishStats - Phishing URL metadata.
Abusix Lookup - IP, domain, and email blocklist lookup.
CleanTalk - Spam and blocklist checks.
Threat intelligence platforms and feed management tools live in Intel Feeds and Sources.
Intel Feeds and SourcesPassive DNS and Historical Data
SecurityTrails - Historical DNS, WHOIS, subdomains, and IP history.
Microsoft Defender Threat Intelligence - Passive DNS, WHOIS, SSL certificates, trackers, and related infrastructure.
Farsight DNSDB - Passive DNS database.
DNSHistory.org - Historical DNS lookup.
WhoisXMLAPI - Historical WHOIS and DNS records.
ViewDNS.info - DNS and network lookup tools.
DNSTrails - Historical DNS and passive DNS database.
Domain-focused passive investigation workflows live in Domain OSINT.
DomainCertificate Transparency and SSL/TLS Analysis
crt.sh - Certificate transparency log search.
Censys Certificates - Certificate search with filtering.
SSL Labs Server Test - SSL/TLS configuration analysis.
SSLShopper SSL Checker - Certificate verification and chain analysis.
Certificate Search - Multi-source certificate transparency search.
Google Certificate Transparency Report - Google CT search interface.
Browser Extensions and Quick Lookup Tools
CrowdSec CTI Extension - Quick IP and URL lookups.
Sputnik - Configurable OSINT and threat intelligence lookup extension.
Gotanda - OSINT browser extension for extracting and searching indicators.
ThreatConnect Extension - ThreatConnect lookups from selected text.
URL Unshortener - Shows destinations of shortened URLs.
VirusTotal Checker - Browser context-menu VirusTotal lookups.
Cryptocurrency and Blockchain Analysis
Blockchain.com Explorer - Bitcoin explorer.
Etherscan - Ethereum explorer.
BlockCypher - Multi-blockchain explorer.
BTC.com - Bitcoin explorer and mining pool statistics.
Chainalysis - Commercial blockchain analysis platform.
Elliptic - Commercial cryptocurrency compliance and investigation tooling.
Crystal Blockchain - Cryptocurrency intelligence platform.
Bitcoin Abuse Database - Community reports of scam and ransomware Bitcoin addresses.
Investigation Tools
Some tools require more complex URL structures than simple parameter appending. Additional functionality may be needed for full automation.
Local helper copy: EasyOSINT.html
The following mind map illustrates commonly used tools for indicator analysis and their relationships:

The interactive version can be found here:
Related Sections
Internet-wide search engines such as Shodan, Censys, FOFA, ZoomEye, BinaryEdge, Onyphe, and FullHunt live in Cyber Search.
YARA rules and malware signature hunting live in DFIR.
Sigma rules, MITRE CAR, detection content, and detection engineering live in Event Detection.
LOLBAS, GTFOBins, LOLDrivers, LOLAPPS, and WADComs are useful for detection and adversary tradecraft context. Keep them with detection engineering or technique-specific pages rather than reputation lookup.
Vulnerability databases, CISA KEV, EPSS, SSVC, and CVSS live in Asset and Vulnerability Management.
Exploit archives and offensive exploit research live in Red Offensive.
Best Practices for Indicator Analysis
Validate across multiple sources.
Preserve context such as ASN, registrar, domain age, passive DNS, certificates, and comments.
Document sources consulted and the time of lookup.
Use passive analysis first when you do not want to alert adversaries.
Treat blocklist absence as unknown, not benign.
Verify indicators before blocking or alerting on them.
Deprecated and Legacy Tools
ThreatCrowd - Deprecated. Data migrated to AlienVault OTX; original service is no longer maintained.
Digital Attack Map - Discontinued by Arbor Networks/NETSCOUT.
Malware Domain List (MDL) - No longer actively maintained.
Ransomwhere - Bitcoin ransomware tracker that appears inactive.
CybOX - Legacy observable specification largely superseded by STIX 2.x observables.
Sigmac - Deprecated Sigma converter; pySigma and sigma-cli replaced it.
YARA-Rules/rules - Archived community YARA rules repository.
Tool Accuracy Notes
Blacklist source counts change frequently, so this page avoids hard-coding source counts.
Free APIs often have rate limits or require registration.
Browser extension links can change; search by extension name if a store link breaks.
Passive DNS retention varies by provider.
Advanced malware may detect sandbox environments and alter behavior.
Last updated