Collection

Breach, Exposure, and Attack Surface Research Toolkit

Editorial 8 tools 3 curated picks

A practical stack for confirming breach chatter and expanding it into external exposure context.

Stack snapshot

8 tool profiles in this workflow, including 3 curated picks.

Best for

Security teams, journalists, and investigators triaging breach signals, suspicious indicators, or external exposure around a company or identity.

Methodology

The stack starts with conservative confirmation and adds depth only when the lead justifies it, reducing overreaction to noisy exposure chatter.

Editorial note

Placement reflects corroboration value and workflow fit, not vendor prestige or product pricing.

Curated picks

Top pick

VirusTotal

Budget pick

Have I Been Pwned

Open-source pick

SpiderFoot

Tools in this collection

Tools in this workflow

Security teams, journalists, and investigators triaging breach signals, suspicious indicators, or external exposure around a company or identity.

Primary job: Breach and credential-exposure research

Have I Been Pwned

Role: Confirm known account exposure

Begin with conservative breach-name and date context for an authorized account check without implying current compromise or password validity.

Tested

Primary job: Breach and credential-exposure research

Hudson Rock Exposure Intelligence

Role: Assess infostealer exposure context

Use specialized exposure signals for defensive triage, limiting personal detail and routing material findings to the responsible security owner.

Affiliate
URLhaus official-page screenshot

Official-page screenshot

abuse.ch

Verified 2026-05-07

Malware-URL intelligence reference

Verification: Editorial review Workflow: Verification Pricing: Free

Best for: Use it when a URL or domain needs malware-distribution context and conservative threat corroboration.

Editorial

Primary job: Threat indicator reputation and enrichment

URLhaus

Role: Check malicious URL history

Look for known malware-distribution reports tied to a URL or host, then verify timing and indicator scope before acting on the match.

Editorial

Editorial proof card

OpenDNS / Cisco

Verified 2026-05-07

Community phishing URL verification

Verification: Editorial review Workflow: Verification Pricing: Free

Best for: Use it when a suspicious URL needs phishing-report context before broader URL or infrastructure triage.

Editorial

Primary job: Threat indicator reputation and enrichment

PhishTank

Role: Corroborate phishing reports

Check community-reviewed phishing submissions for a suspicious URL while recognizing that absence and stale reports are not clearance.

Editorial

Primary job: Threat indicator reputation and enrichment

Cisco Talos Intelligence

Role: Add reputation and threat context

Review domain, IP, and sender reputation observations as one evidence layer, confirming dates and source scope before escalation.

Editorial

Primary job: Threat indicator reputation and enrichment

AlienVault OTX

Role: Pivot through shared indicators

Use community pulses and related indicators to widen a defensive lead, distinguishing contributed context from independently verified facts.

Editorial
VirusTotal official-page screenshot

Official-page screenshot

Google Cloud

Verified 2026-05-27

Multi-source reputation context for indicators

Verification: Editorial review Workflow: Verification Pricing: Freemium

Best for: Quick reputation triage for suspicious URLs, domains, IPs, file hashes, and already-public malware or phishing indicators.

Editorial

Primary job: Threat indicator reputation and enrichment

VirusTotal

Role: Correlate multi-source observations

Compare engine results, relationships, and historical observations without equating a detection count with a final maliciousness verdict.

Editorial

Primary job: Passive reconnaissance automation

SpiderFoot

Role: Expand a scoped exposure lead

Automate passive collection around an authorized target only after a concrete indicator exists, then validate every consequential relationship manually.

Tested

Workflow notes

This collection is built for operators who need to move from a breach rumor, exposed credential clue, or suspicious external signal into a more defensible picture of risk.

Use this stack when

The case needs conservative breach confirmation, infostealer exposure context, suspicious-indicator review, internet-noise triage, or external attack-surface clues.

Recommended sequence

  • Start with Have I Been Pwned for a conservative breach confirmation step.
  • Use Hudson Rock when infostealer-style exposure or employee-device context matters.
  • Bring in Intelligence X for older, broader, or harder-to-find leak-adjacent traces.
  • Use VirusTotal when the lead is a suspicious URL, domain, IP, or hash that needs reputation context.
  • Use GreyNoise to separate noisy internet scanning from more interesting infrastructure signals.
  • Use Shodan to map exposed hosts and services tied to the organization.
  • Use urlscan.io when suspicious pages, landing pages, or web infrastructure need a preserved snapshot.

Escalate by question, not by tool count

  • Use FullHunt when a scoped organization needs another passive attack-surface view before you validate ownership and current exposure.
  • Use theHarvester or Recon-ng when a technical investigation needs repeatable passive collection around domains, hosts, contacts, or infrastructure leads.
  • Use Nmap only for assets you are authorized to assess. It is an active network-discovery step, not passive OSINT and not evidence of compromise by itself.

Editorial guardrail

This is not incident response in a box. Exposure signals can involve victims and sensitive data, so publish only conservative claims that survive source and authorization review.