Research path

Threat Intelligence

A focused view of OSINT4ALL tool profiles mapped to this investigation path.

26 mapped profiles No pay-to-rank ordering

How to use this path

  • Start broad here, then narrow in the directory filters.
  • Open profiles for limits, pricing, and verification notes.
  • Use collections when you need a workflow stack, not one tool.
Hunt.io official-page screenshot

Official-page screenshot

Hunt.io

Source checked 2026-09-19

Explore threat-related internet infrastructure observations

Verification: Pending Verification Workflow: Enrichment, Triage Pricing: Freemium

Best for: Defensive research into suspicious services, hosting patterns and reported command-and-control infrastructure.

Editorial

Tool profile

Hunt.io

Explore threat-related internet infrastructure observations

WorkflowEnrichment, Triage AccessFreemium
Editorial
Open profile
OpenCTI official-page screenshot

Official-page screenshot

OpenCTI

Source checked 2026-09-19

Manage structured cyber-threat knowledge and relationships

Verification: Pending Verification Workflow: Enrichment, Triage Pricing: Freemium

Best for: Teams organizing indicators, entities, reports and relationships across multiple intelligence sources.

Editorial

Tool profile

OpenCTI

Manage structured cyber-threat knowledge and relationships

WorkflowEnrichment, Triage AccessFreemium
Editorial
Open profile
IntelOwl official-page screenshot

Official-page screenshot

IntelOwl

Source checked 2026-09-19

Orchestrate indicator enrichment across analysis services

Verification: Pending Verification Workflow: Enrichment, Triage Pricing: Free

Best for: Running controlled enrichment of hashes, domains or other permitted indicators across multiple configured sources.

Editorial

Tool profile

IntelOwl

Orchestrate indicator enrichment across analysis services

WorkflowEnrichment, Triage AccessFree
Editorial
Open profile
ThreatFox official-page screenshot

Official-page screenshot

ThreatFox

Source checked 2026-09-19

Search community-shared malware indicators

Verification: Pending Verification Workflow: Enrichment, Triage Pricing: Free

Best for: Checking whether a scoped domain, IP or hash appears in reported malware-related indicator data.

Editorial

Tool profile

ThreatFox

Search community-shared malware indicators

WorkflowEnrichment, Triage AccessFree
Editorial
Open profile
MalwareBazaar official-page screenshot

Official-page screenshot

MalwareBazaar

Source checked 2026-09-19

Look up malware sample hashes and associated metadata

Verification: Pending Verification Workflow: Enrichment, Triage Pricing: Free

Best for: Defensive identification of a known file hash without opening or executing the file.

Editorial

Tool profile

MalwareBazaar

Look up malware sample hashes and associated metadata

WorkflowEnrichment, Triage AccessFree
Editorial
Open profile

Tool profile

Chainabuse

Public crypto scam and suspicious-address reporting database

WorkflowDiscovery, Triage AccessFree
Editorial
Open profile

Tool profile

Pulsedive

Community threat-intelligence search and indicator enrichment

WorkflowTriage, Verification AccessFreemium
Editorial
Open profile

Tool profile

Etherscan

Ethereum blockchain explorer for public wallet and transaction research

WorkflowDiscovery, Verification AccessFree
Editorial
Open profile

Tool profile

Hybrid Analysis

Malware-analysis report community

WorkflowVerification AccessFreemium
Editorial
Open profile

Tool profile

ANY.RUN

Interactive threat-analysis sandbox

WorkflowVerification AccessFreemium
Editorial
Open profile
Joe Sandbox official-page screenshot

Official-page screenshot

Joe Security

Source checked 2026-05-07

Automated threat-analysis sandbox

Verification: Verification status not listed Workflow: Verification Pricing: Freemium

Best for: Use it when a security team needs deeper sandbox reporting for an authorized suspicious sample.

Editorial

Tool profile

Joe Sandbox

Automated threat-analysis sandbox

WorkflowVerification AccessFreemium
Editorial
Open profile
URLhaus official-page screenshot

Official-page screenshot

abuse.ch

Source checked 2026-05-07

Malware-URL intelligence reference

Verification: Verification status not listed Workflow: Verification Pricing: Free

Best for: Use it when a URL or domain needs malware-distribution context and conservative threat corroboration.

Editorial

Tool profile

URLhaus

Malware-URL intelligence reference

WorkflowVerification AccessFree
Editorial
Open profile

Editorial proof card

OpenDNS / Cisco

Source checked 2026-05-07

Community phishing URL verification

Verification: Verification status not listed Workflow: Verification Pricing: Free

Best for: Use it when a suspicious URL needs phishing-report context before broader URL or infrastructure triage.

Editorial

Tool profile

PhishTank

Community phishing URL verification

WorkflowVerification AccessFree
Editorial
Open profile

Tool profile

Cisco Talos Intelligence

IP, domain, and email reputation intelligence

WorkflowEnrichment AccessFree
Editorial
Open profile

Tool profile

AlienVault OTX

Open threat-intelligence community pulses

WorkflowEnrichment AccessFree
Editorial
Open profile

Tool profile

MISP

Open-source threat-intelligence sharing platform

WorkflowReporting AccessFree
Editorial
Open profile

Tool profile

ONYPHE

Cyber defense search engine and attack-surface data

WorkflowEnrichment AccessFreemium
Editorial
Open profile

Tool profile

Babel Street

Enterprise intelligence platform for multilingual risk and threat workflows

WorkflowEnrichment, Monitoring AccessEnterprise
Editorial
Open profile