OSINT Research Assistant
1 rating
)Overview
Page triage, pivot graph and STIX export. 15 free threat intel sources, optional keys. Nothing leaves your device.
OSINT Research Assistant grades indicators of compromise in the page you are already reading. No account, no API key, no backend — everything runs on your machine. Built for SOC analysts, threat hunters, incident responders and security researchers. WHAT MAKES IT DIFFERENT Most lookup tools handle one indicator at a time. This one triages a whole page — or a whole email. Open any threat report, press Ctrl+Shift+U, and every IP, domain, email and file hash on the page is graded at once and ranked worst-first. A 200-indicator report costs the same as a single lookup — zero API requests — because matching happens against a threat index held locally on your device. Got a report that isn't on a page — an email body, a Slack message, text copied out of a PDF? Paste it in and triage it the same way, at no cost per indicator. HOW IT WORKS Select an indicator and press Ctrl+Shift+O, or right-click and choose "OSINT Lookup". You can also type one straight into the toolbar popup. Results open in a floating panel: the Summary tab answers the question, the other tabs show the detail. Defanged input is understood. 185.220.101[.]45, hxxps://evil[.]com and user[at]mail[.]com all work, because threat intelligence is never shared in clickable form. EMAIL HEADER ANALYSIS Paste a raw email header block and get the two things every phishing or BEC triage starts with: did SPF, DKIM and DMARC pass, and where did this actually come from. The tool walks the Received chain past internal relays to find the true originating IP, geolocates it, checks the sender domain's age and registrar, and flags a From:/Return-Path mismatch — while correctly ignoring legitimate bounce subdomains (mail routed through bounces.yourprovider.com is not spoofing). PIVOT GRAPH Walk the infrastructure instead of reading isolated results. An IP expands to the AS that announces it, that AS's other prefixes, and its peer networks. A domain expands to its resolving addresses, name servers and subdomains from certificate transparency logs. Nodes already listed in a threat feed are red, so a bad neighbourhood is visible rather than inferred. CASE FILE AND EXPORT Collect findings across pages into a case, then export as STIX 2.1 bundle, MISP event, CSV or Markdown — formats a detection pipeline can ingest, not just a human. SOURCES (15 built in, no key required) Fifteen keyless sources cover the ground a triage needs: current threat feeds matched locally against a downloaded index, community-reported campaign intelligence, malware and known-good hash databases, internet-wide scan and exposure data, DNS and certificate transparency history, network registration lookups, and a CVE database with CVSS scoring and known-exploited status. Every source is listed individually in Settings, with what it answers and a toggle to turn it off. Optional: add a VirusTotal or Shodan key in Settings for more depth. Nothing degrades without them — those tabs simply do not appear. SUPPORTED INDICATORS IPv4 and IPv6 addresses, domain names, URLs, email addresses, MD5/SHA-1/SHA-256 file hashes, and CVE identifiers. OTHER FEATURES Draggable, resizable results panel that remembers where you put it Colour-coded verdicts, with the summary shown before the detail Per-source health tracking — success rate, latency and last error Individual services can be switched off English and Turkish, set once in Settings Light and dark themes HONEST LIMITS A tool that hides its blind spots is worse than one that names them: Absence is not innocence. The threat index holds a few thousand current indicators. A miss returns "unknown", never "clean", and the interface says so. Team Cymru MHR covers MD5 and SHA-1 only. SHA-256 hashes get no malware verdict from it, and the summary says that rather than implying safety. CIRCL HASHLOOKUP is a known-good database. It answers "is this a legitimate file", not "is this malware". Both are shown, labelled separately. NON-COMMERCIAL SOURCES Four sources — IP-API, OpenPhish, Team Cymru MHR and RIPEstat — restrict their free tier to non-commercial use under their own terms. Using them inside a company, including by a security team, is not covered. These four are labelled "non-commercial" in Settings and can be switched off individually. With them off the extension still works using the remaining sources. Please check each provider's terms before using this at work. PRIVACY No account, no server, no telemetry, no analytics. The only data sent externally is the indicator you explicitly submit, which goes directly to the relevant third-party source. Browsing history, page content and identifying information are never accessed or transmitted. Threat feeds are downloaded from their publishers and matched entirely on your device, so page triage sends nothing anywhere. Lookup history, your case file and any optional API keys are stored locally and never synced. Open source (MIT licensed) — the code behind every claim on this page is public: github.com/shemmus/osint-research-assistant For authorized security research only.
5 out of 51 rating
Details
- Version2.5.2
- UpdatedSeptember 1, 2026
- Offered byShemmus Tools
- Size80.82KiB
- LanguagesEnglish (United States)
- Developer
Email
asg.cetr23@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes