OSINT Research Assistant
1 rating
)Overview
Page triage, pivot graph and STIX export. 14 free threat intel sources, optional keys. Nothing leaves your device.
OSINT Research Assistant grades indicators of compromise in the page you are already reading. No account, no API key, no backend — everything runs on your machine. Built for SOC analysts, threat hunters, incident responders and security researchers. WHAT MAKES IT DIFFERENT Most lookup tools handle one indicator at a time. This one triages a whole page. Open any threat report, press Ctrl+Shift+U, and every IP, domain, email and file hash on the page is graded at once and ranked worst-first. A 200-indicator report costs the same as a single lookup — zero API requests — because matching happens against a threat index held locally on your device. HOW IT WORKS Select an indicator and press Ctrl+Shift+O, or right-click and choose "OSINT Lookup". You can also type one straight into the toolbar popup. Results open in a floating panel: the Summary tab answers the question, the other tabs show the detail. Defanged input is understood. 185.220.101[.]45, hxxps://evil[.]com and user[at]mail[.]com all work, because threat intelligence is never shared in clickable form. PIVOT GRAPH Walk the infrastructure instead of reading isolated results. An IP expands to the AS that announces it, that AS's other prefixes, and its peer networks. A domain expands to its resolving addresses, name servers and subdomains from certificate transparency logs. Nodes already listed in a threat feed are red, so a bad neighbourhood is visible rather than inferred. CASE FILE AND EXPORT Collect findings across pages into a case, then export as STIX 2.1 bundle, MISP event, CSV or Markdown — formats a detection pipeline can ingest, not just a human. SOURCES (14 built in, no key required) Threat Feeds — ThreatFox, URLhaus, Feodo Tracker and OpenPhish, matched locally, with malware family names AlienVault OTX — community threat reports: campaign names and MITRE ATT&CK techniques Team Cymru MHR — is this hash known malware, and what is the antivirus detection rate CIRCL HASHLOOKUP — is this hash a known legitimate file (NSRL known-good database) Shodan InternetDB + CVE-Search — open ports and CVEs enriched with CVSS scores and CISA KEV status GreyNoise Community — internet-wide scanner classification Tor exit node list — is this address a Tor exit RIPEstat — which AS announces this address and how large that network is IP-API — geolocation, ISP, proxy and VPN detection Whois / RDAP — registration dates, registrar, name servers, IP block owner crt.sh — certificate transparency history and subdomain enumeration Google DNS — A, AAAA, MX, TXT, NS and CNAME records URLScan.io — scan history and malicious verdicts mailcheck.ai — disposable address, spam and MX checks Optional: add a VirusTotal or Shodan key in Settings for more depth. Nothing degrades without them — those tabs simply do not appear. SUPPORTED INDICATORS IPv4 and IPv6 addresses, domain names, URLs, email addresses, and MD5, SHA-1 and SHA-256 file hashes. OTHER FEATURES Draggable, resizable results panel that remembers where you put it Colour-coded verdicts, with the summary shown before the detail Per-source health tracking — success rate, latency and last error Individual services can be switched off English and Turkish, switchable instantly Light and dark themes HONEST LIMITS A tool that hides its blind spots is worse than one that names them: Absence is not innocence. The threat index holds a few thousand current indicators. A miss returns "unknown", never "clean", and the interface says so. Team Cymru MHR covers MD5 and SHA-1 only. SHA-256 hashes get no malware verdict from it, and the summary says that rather than implying safety. CIRCL HASHLOOKUP is a known-good database. It answers "is this a legitimate file", not "is this malware". Both are shown, labelled separately. NON-COMMERCIAL SOURCES Four sources — IP-API, OpenPhish, Team Cymru MHR and RIPEstat — restrict their free tier to non-commercial use under their own terms. Using them inside a company, including by a security team, is not covered. These four are labelled "non-commercial" in Settings and can be switched off individually. With them off the extension still works using the remaining sources. Please check each provider's terms before using this at work. PRIVACY No account, no server, no telemetry, no analytics. The only data sent externally is the indicator you explicitly submit, which goes directly to the third-party services listed above. Browsing history, page content and identifying information are never accessed or transmitted. Threat feeds are downloaded from their publishers and matched entirely on your device, so page triage sends nothing anywhere. Lookup history, your case file and any optional API keys are stored locally and never synced. For authorized security research only.
5 out of 51 rating
Details
- Version2.3.3
- UpdatedAugust 17, 2026
- Offered byShemmus Tools
- Size74.72KiB
- LanguagesEnglish (United States)
- Developer
Email
asg.cetr23@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes