OSINT Research Assistant
Overview
Query IPs, domains, emails and file hashes across 9 free threat intelligence services. Page scanner included. No API keys required.
OSINT Research Assistant is a free, lightweight browser extension designed for cybersecurity analysts, threat hunters, incident responders, and security researchers. It accelerates threat investigation workflows by enabling fast, in-browser lookups of indicators of compromise (IOCs) without requiring any API keys or account registration. HOW IT WORKS Select any IP address, domain name, email address, URL, or file hash (MD5, SHA-1, SHA-256) on a web page, right-click, and choose "OSINT Lookup". A floating results panel opens directly on the page and queries up to 9 free threat intelligence services simultaneously. You can also right-click anywhere and choose "OSINT: Scan page for threats" to automatically highlight all IOCs found on the current page. SERVICES QUERIED IP-API: Geolocation, ISP, proxy and VPN detection Shodan InternetDB: Open ports and known CVEs for an IP address GreyNoise Community: IP threat classification (malicious, benign, or unknown scanner) Whois / RDAP: Domain registration dates, registrar, name servers, and IP block information crt.sh: SSL/TLS certificate history and subdomain enumeration via Certificate Transparency logs Google DNS: DNS record lookup (A, AAAA, MX, TXT, NS, CNAME) CIRCL HASHLOOKUP: File hash identification and malicious file detection via the NSRL database mailcheck.ai: Email address reputation, disposable address detection, and spam classification URLScan.io: Domain and URL scan history with malicious/suspicious verdicts SUPPORTED IOC TYPES IPv4 and IPv6 addresses Domain names URLs Email addresses MD5, SHA-1, and SHA-256 file hashes KEY FEATURES No API keys, no registration, no configuration required — install and use immediately All services used are free and publicly available Results are displayed in a draggable, resizable panel on the current page Page scanner mode: highlights all IOCs on any page with one click, navigate between them with prev/next buttons Color-coded threat verdicts: clean, suspicious, or malicious English and Turkish language support with instant switching Runs entirely in the browser — no backend server, no data stored or transmitted beyond the selected IOC WHO IS IT FOR This extension is intended for cybersecurity professionals performing authorized security research, penetration testers, SOC analysts triaging alerts, CTF participants, and anyone who needs quick threat context on an indicator of compromise. PRIVACY The extension does not collect, store, or transmit any personal data. The only data sent externally is the text the user selects and explicitly submits for lookup (an IP address, domain, email, or hash). This data is sent directly to the respective third-party threat intelligence APIs listed above. No browsing history, page content, or identifying information is ever accessed or transmitted.
0 out of 5No ratings
Details
- Version1.3.0
- UpdatedJuly 1, 2026
- Offered byShemmus Tools
- Size25.3KiB
- LanguagesEnglish (United States)
- Developer
Email
asg.cetr23@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes