目录导航
在渗透测试、漏洞评估、红/蓝团队工作、漏洞赏金等过程中有用的精选搜索引擎列表
中文翻译
通用搜索引擎

服务器

- Shodan – 万物互联的搜索引擎
- Censys 搜索– 互联网上每台服务器的搜索引擎,以减少暴露并提高安全性。
- Onyphe.io – 用于开源和网络威胁情报数据的网络防御搜索引擎
- ZoomEye – 全球网络空间测绘
- GreyNoise – 了解互联网噪音的来源
- Natlas – 缩放网络扫描
- Netlas.io – 发现、研究和监控任何可用的在线资产
- FOFA – 网络空间映射

漏洞
- NIST NVD – 国家漏洞数据库
- MITRE CVE – 识别、定义和分类公开披露的网络安全漏洞
- GitHub Advisory Database – 安全漏洞数据库,包括 CVE 和 GitHub 起源的安全建议
- cloudvulndb.org – 开放云漏洞和安全问题数据库
- osv.dev – 开源漏洞
- Vulners.com – 您的安全情报搜索引擎
- opencve.io – 跟踪 CVE 更新和收到新漏洞警报的最简单方法

- security.snyk.io – 开源漏洞数据库
- Mend Vulnerability Database – 最大的开源漏洞数据库
- Rapid7 – DB – 漏洞和利用数据库
- CVEDetails – 终极安全漏洞数据源
- VulnIQ – 漏洞情报和管理解决方案
- SynapsInt – 统一的 OSINT 研究工具
- Aqua Vulnerability Database – 开源应用程序和云原生基础架构中的漏洞和弱点
- Vulmon – 漏洞利用搜索引擎
- VulDB – 排名第一的漏洞数据库
- ScanFactory – 实时安全监控
- Trend Micro Zero Day Initiative – 零日计划研究人员发现的公开披露的漏洞
- 谷歌零项目– 包括零日在内的漏洞
漏洞利用

- Exploit-DB – 漏洞利用数据库
- Sploitus – 用于识别最新漏洞利用的便利中心位置
- Rapid7 – DB – 漏洞和利用数据库
- Vulmon – 漏洞利用搜索引擎
- packetstormsecurity.com – 信息安全服务、新闻、文件、工具、漏洞利用、咨询和白皮书
- 0day.today – 漏洞利用和漏洞的终极数据库
- LOLBAS – Living Off The Land 二进制文件、脚本和库
- GTFOBins – 精选的 Unix 二进制文件列表,可用于绕过错误配置系统中的本地安全限制
- Payloads All The Things – Web 应用程序安全的有用有效载荷和绕过列表
- XSS Payloads – JavaScript 意外仙境用法的等等
- exploitalert.com – 漏洞数据库
攻击面

- FullHunt.io – 整个互联网的攻击面数据库
- BynaryEdge – 我们扫描网络并为您收集数据
- Censys ASM – 攻击面管理解决方案
- RedHunt Labs – 持续发现您的攻击面
- SecurityTrails – 互联网总清单
- overcast-security.com – 我们可以轻松跟踪您的外部攻击面
代码搜索引擎
- GitHub 代码搜索– 在整个 GitHub 中进行全局搜索,或将搜索范围限定在特定存储库或组织
- grep.app – 搜索 50 万个 git仓库

- publicwww.com – 在网页 HTML、JS 和 CSS 代码中查找任何字母数字片段、签名或关键字
- SearchCode – 从 4000 万个项目中搜索 750 亿行代码
- NerdyData – 根据网站的技术堆栈或代码查找公司
- RepoSearch – 源代码搜索引擎,可帮助您查找实现细节、示例用法或仅分析代码
- SourceGraph – 了解和搜索整个代码库
- HotExamples – 从超过 100 万个项目中搜索代码示例
- WP Directory – 在 WordPress 插件和主题目录中快速正则表达式搜索代码
邮件地址

- Hunter.io – 在几秒钟内找到专业的电子邮件地址
- PhoneBook – 列出给定输入域的所有域、电子邮件地址或 URL
- IntelligenceX – 搜索引擎和数据存档
- Reacher.email – 开源电子邮件验证
- RocketReach – 您与任何专业人士的一级联系
- email-format.com – 查找数千家公司使用的电子邮件地址格式
- EmailHippo – 电子邮件地址验证技术
- ThatsThem – 反向电子邮件查找
- verify-email.org – 检查邮箱是否存在
- Melissa – Emailcheck – 检查电子邮件地址并验证它们是否有效
- VoilaNorbert – 我可以找到任何人的电子邮件地址
- SynapsInt – 统一的 OSINT 研究工具
- skymem.info – 查找公司和个人的电子邮件地址
- findemails.com – 在几秒钟内找到任何人的电子邮件地址
域名

- PhoneBook – 列出给定输入域的所有域、电子邮件地址或 URL
- IntelligenceX – 搜索引擎和数据存档
- Omnisint – 子域枚举
- Riddler – 允许您在高质量数据集中进行搜索
- RobTex – IP 号、域名等的各种研究
- CentralOps – DomainDossier – 调查域和 IP 地址
- DomainIQ – 全面的域智能
- whois.domaintools.com – 业界最快的域发现引擎和最广泛、最准确的数据
- grayhatwarfare.com – 域– 如何搜索缩短服务公开的 URL
- whoisology.com – 域名与其所有者之间的深层联系
- who.is – WHOIS 搜索、域名、网站和 IP 工具
- pentest-tools.com – 发现子域并确定组织的攻击面
- BuiltWith – 找出网站是用什么建造的
- MoonSearch – 反向链接检查器和 SEO 报告
- sitereport.netcraft.com – 找出任何站点使用的基础设施和技术
- SynapsInt – 统一的 OSINT 研究工具
- spyonweb.com – 查找相关网站
- statscrop.com – 正在使用 StatsCrop 分析网络上数百万个令人惊叹的网站
- securityheaders.com – 立即扫描您的网站
- visualsitemapper.com – 创建您网站的视觉地图
- similarweb.com – 了解网上真实情况的最简单、最快速的工具
- buckets.grayhatwarfare.com – 公共的存储桶
- C99.nl – 超过 57 个优质 API,并且还在不断增加!
- PassiveTotal – 可扩展安全操作和响应的安全情报
- wannabe1337.xyz – 在线工具
- subdomainfinder.c99.nl – 扫描整个域以找到尽可能多的子域的扫描程序
网址
- PhoneBook – 列出给定输入域的所有域、电子邮件地址或 URL
- IntelligenceX – 搜索引擎和数据存档
- URLScan – 网络沙箱
- HackerTarget – 收集有关 IP 地址、网络、网页和 DNS 记录的信息
- MOZ Link Explorer – 世界上最好的反向链接检查器,拥有超过 40 万亿个链接
- shorteners.grayhatwarfare.com – 由 Shortener 服务公开的搜索 URL
- CommonCrawl Index – 网络抓取数据的开放存储库
域名系统

- DNSDumpster – dns 侦察和研究,查找和查找 dns 记录
- Chaos – 加强研究并分析 DNS 周围的变化以获得更好的见解
- RapidDNS – dns 查询工具,可以轻松查询同一 ip 的子域或站点
- DNSdb – 被动 DNS 历史数据库
- Omnisint – 反向 DNS 查找
- HackerTarget – 收集有关 IP 地址、网络、网页和 DNS 记录的信息
- passivedns.mnemonic.no – 用于查询在我们的恶意软件实验室中收集的被动 DNS 数据的 Web 界面
- ptrararchive.com – 从 2008 年到现在超过 2300 亿个反向 DNS 条目
- dnshistory.org – 域名系统历史记录存档
- DNSTwister – 反钓鱼域名搜索引擎和 DNS 监控服务
- DNSviz – 可视化 DNS 区域状态的工具
- C99.nl – 超过 57 个优质 API 并且还在不断增加
- PassiveTotal – 可扩展安全操作和响应的安全情报
- wannabe1337.xyz – 在线工具
证书

- Crt.sh – 证书搜索
- CTSearch – 证书透明度搜索工具
- tls.bufferover.run – 快速查找 IPv4 空间中的证书
- CertSpotter – 监控您的域是否有过期的、未经授权的和无效的 SSL 证书
- SynapsInt – 统一的 OSINT 研究工具
- Censys 搜索 – 证书– 证书搜索
- PassiveTotal – 可扩展安全操作和响应的安全情报
- ciphersuite.info – TLS 密码套件搜索。使用 IANA、OpenSSL 或 GnuTLS 名称格式搜索特定密码套件
无线网络

- Wigle.net – 带有统计数据的 802.11 无线网络地图和数据库
- wifimap.io – 使用 WiFi 地图应用程序连接到世界各地的所有免费 WiFi 热点!
- wificafespots.com – 免费 WiFi 咖啡馆点
- wifispc.com – 随时随地查看 Wi-Fi 密码的免费地图!
- openwifimap.net – 带有 OpenWiFiMap 数据的 HTML5 地图
- mylnikov.org – Wi-Fi 地理位置数据库的公共 API 实现
设备信息

- MAC 供应商查找– 查找特定 MAC 地址的供应商
- macvendors.com – 查找 MAC 地址供应商。现在。
- macaddress.io – MAC 地址供应商查找
- maclookup.app – 通过输入 OUI 或 MAC 地址查找设备的供应商名称
证书

- Have I Been Pwned – 检查您的电子邮件或电话是否存在数据泄露
- Dehashed – 免费的深层网络扫描和防止凭证泄漏
- Leak-Lookup – 搜索数以千计的数据泄露
- Snusbase – 掌握最新的数据库漏洞
- LeakCheck.io – 确保您的凭据没有被泄露
- crackstation.net – 用于破解密码哈希的大量预计算查找表
- breachdirectory.org – 检查您的信息是否在数据泄露中暴露
- BreachForums – 违规、数据泄露、数据库等
- Siph0n Breach DB (onionsite) – 漏洞、数据泄露、漏洞利用
- HashKiller – 预先破解的哈希,易于搜索
隐藏服务

- AHMIA – 搜索 Tor 网络上的隐藏服务
- thehiddenwiki.org – 暗网指南
- tor.link – 免费的匿名深度网络/暗网搜索引擎

- deepweblinks.net – 洋葱链接
- onionengine.com – Tor 网络上可访问服务的搜索引擎
- OnionLand – 发现隐藏的服务并访问 Tor 的洋葱站点
社交网络
这些对于 osint 和社会工程很有用。
- YouTube
- Tumblr
- Flickr
- SnapChat
- Quora
- TikTok
- Vimeo
- Medium
- VK
- Tinder
电话号码
- NumLookup – 免费反向电话查询
- SpyDialer – 免费反向查找搜索
- WhitePages – 查找人员、联系信息和背景调查
- National Cellular Directory – 立即开始全面的人员搜索
- Phone Validator – 是手机还是固定电话还是假电话?
- 免费运营商查询– 输入电话号码,我们将返回运营商名称
- RocketReach – 您与任何专业人士的一级联系
- sync.me – 找出谁打来的
- EmobileTracker – 跟踪移动所有者姓名、位置和移动服务提供商
- 反向电话查询– 找出电话号码的所有者
- ThatsThem – 反向电话查询
- thisnumber.com – 国际电话目录
- usphonebook.com – 免费反向电话号码查询
- truepeoplesearch.com – 获取当前地址、手机号码、电子邮件地址、亲戚、朋友等等
- Tellows – 谁在打电话?电话号码反向搜索
- SynapsInt – 统一的 OSINT 研究工具
- C99.nl – 超过 57 个优质 API 并且还在不断增加
威胁情报

- MITRE ATT&CK – 全球可访问的对手战术和技术知识库
- PulseDive – 威胁情报变得简单
- ThreatCrowd – 威胁搜索引擎
- ThreatMiner – 威胁情报的数据挖掘
- VirusTotal – 分析可疑文件、域、IP 和 URL 以检测恶意软件和其他违规行为
- vx-underground.org – 恶意软件库
- bazaar.abuse.ch – 恶意软件样本数据库

- feodotracker.abuse.ch – 僵尸网络命令和控制服务器列表
- sslbl.abuse.ch – 所有恶意 SSL 证书
- urlhaus.abuse.ch – 提出新的恶意软件 url
- threatfox.abuse.ch – 侵害指标 (IOC) 数据库
- yaraify.abuse.ch – 针对大型 YARA 规则存储库扫描可疑文件,例如恶意软件样本或进程转储
- Rescure – 为所有人精心策划的网络威胁情报
- otx.alienvault – 世界上第一个真正开放的威胁情报社区
- urlquery.net – 用于检测和分析基于 Web 的恶意软件的服务
- socradar.io – 扩展到您的 SOC 团队
- VirusShare – 系统目前包含 4800 万个恶意软件样本
- 维基解密– 匿名消息来源提供的新闻泄露和分类媒体
- PassiveTotal – 可扩展安全操作和响应的安全情报
- malapi.io – 用于恶意目的的 Windows API
- filesec.io – 攻击者使用的最新文件扩展名

- leakix.net – 搜索引擎索引公共信息和链接到结果的开放报告平台
- tria.ge – 使用高级沙盒技术进行大容量恶意软件分析的全自动解决方案
- Polyswarm – 新技术和创新威胁检测方法的发射台
- Cisco Talos – 位于思科安全产品组合中心的威胁情报组织
- scamsearch.io – 在线查找骗子并举报他们
- CyberCampaigns – 威胁参与者信息和评论
网络历史
- Web Archive – 探索随时间推移保存的超过 7020 亿个网页

- Archive.ph – 创建一个网页的副本,即使原始链接已关闭,该网页也会始终打开
- CachedPages – 获取任何 URL 的缓存页面
- stored.website – 查看缓存的网页/网站
- CommonCrawl – 开放的网络抓取数据存储库
- UK Web Archive – 每年收集数百万个网站,为子孙后代保存它们
未分类
- NetoGraph – 捕获和索引网站行为的详细、低级快照
- DorkSearch – 加速你的 Dorking
- usersearch.org – 在社交网络、约会网站、论坛、加密论坛、聊天网站和博客上通过用户名或电子邮件查找某人

不工作/暂停
英文原版
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
General Search Engines
Servers
- Shodan – Search Engine for the Internet of Everything
- Censys Search – Search Engine for every server on the Internet to reduce exposure and improve security.
- Onyphe.io – Cyber Defense Search Engine for open-source and cyber threat intelligence data
- ZoomEye – Global cyberspace mapping
- GreyNoise – The source for understanding internet noise
- Natlas – Scaling Network Scanning
- Netlas.io – Discover, Research and Monitor any Assets Available Online
- FOFA – Cyberspace mapping
Vulnerabilities
- NIST NVD – National Vulnerability Database
- MITRE CVE – Identify, define, and catalog publicly disclosed cybersecurity vulnerabilities
- GitHub Advisory Database – Security vulnerability database inclusive of CVEs and GitHub originated security advisories
- cloudvulndb.org – The Open Cloud Vulnerability & Security Issue Database
- osv.dev – Open Source Vulnerabilities
- Vulners.com – Your Search Engine for Security Intelligence
- opencve.io – Easiest way to track CVE updates and be alerted about new vulnerabilities
- security.snyk.io – Open Source Vulnerability Database
- Mend Vulnerability Database – The largest open source vulnerability DB
- Rapid7 – DB – Vulnerability & Exploit Database
- CVEDetails – The ultimate security vulnerability datasource
- VulnIQ – Vulnerability intelligence and management solution
- SynapsInt – The unified OSINT research tool
- Aqua Vulnerability Database – Vulnerabilities and weaknesses in open source applications and cloud native infrastructure
- Vulmon – Vulnerability and exploit search engine
- VulDB – Number one vulnerability database
- ScanFactory – Realtime Security Monitoring
- Trend Micro Zero Day Initiative – Publicly disclosed vulnerabilities discovered by Zero Day Initiative researchers
- Google Project Zero – Vulnerabilities including Zero Days
Exploits
- Exploit-DB – Exploit Database
- Sploitus – Convenient central place for identifying the newest exploits
- Rapid7 – DB – Vulnerability & Exploit Database
- Vulmon – Vulnerability and exploit search engine
- packetstormsecurity.com – Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
- 0day.today – Ultimate database of exploits and vulnerabilities
- LOLBAS – Living Off The Land Binaries, Scripts and Libraries
- GTFOBins – Curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems
- Payloads All The Things – A list of useful payloads and bypasses for Web Application Security
- XSS Payloads – The wonderland of JavaScript unexpected usages, and more
- exploitalert.com – Database of Exploits
Attack Surface
- FullHunt.io – Attack surface database of the entire Internet
- BynaryEdge – We scan the web and gather data for you
- Censys ASM – Attack Surface Management Solutions
- RedHunt Labs – Discover your Attack Surface, Continuously
- SecurityTrails – The Total Internet Inventory
- overcast-security.com – We make tracking your external attack surface easy
Code Search Engines
- GitHub Code Search – Search globally across all of GitHub, or scope your search to a particular repository or organization
- grep.app – Search across a half million git repos
- publicwww.com – Find any alphanumeric snippet, signature or keyword in the web pages HTML, JS and CSS code
- SearchCode – Search 75 billion lines of code from 40 million projects
- NerdyData – Find companies based on their website’s tech stack or code
- RepoSearch – Source code search engine that helps you find implementation details, example usages or just analyze code
- SourceGraph – Understand and search across your entire codebase
- HotExamples – Search code examples from over 1 million projects
- WP Directory – Lightning fast regex searching of code in the WordPress Plugin and Theme Directories
Mail Addresses
- Hunter.io – Find professional email addresses in seconds
- PhoneBook – Lists all domains, email addresses, or URLs for the given input domain
- IntelligenceX – Search engine and data archive
- Reacher.email – Open-Source Email Verification
- RocketReach – Your first-degree connection to any professional
- email-format.com – Find the email address formats in use at thousands of companies
- EmailHippo – Email address verification technology
- ThatsThem – Reverse email lookup
- verify-email.org – Checks whether the mailbox exists or not
- Melissa – Emailcheck – Check email addresses and verify they are live
- VoilaNorbert – I can find anyone’s email address
- SynapsInt – The unified OSINT research tool
- skymem.info – Find email addresses of companies and people
- findemails.com – Find Anyone’s Email Address in Seconds
Domains
- PhoneBook – Lists all domains, email addresses, or URLs for the given input domain
- IntelligenceX – Search engine and data archive
- Omnisint – Subdomain enumeration
- Riddler – Allows you to search in a high quality dataset
- RobTex – Various kinds of research of IP numbers, Domain names, etc
- CentralOps – DomainDossier – Investigate domains and IP addresses
- DomainIQ – Comprehensive Domain Intelligence
- whois.domaintools.com – Industry’s fastest domain discovery engine and broadest, most accurate data
- grayhatwarfare.com – domains – How to search URLs exposed by Shortener services
- whoisology.com – Deep Connections Between Domain Names & Their Owners
- who.is – WHOIS Search, Domain Name, Website, and IP Tools
- pentest-tools.com – Discover subdomains and determine the attack surface of an organization
- BuiltWith – Find out what websites are Built With
- MoonSearch – Backlinks checker & SEO Report
- sitereport.netcraft.com – Find out the infrastructure and technologies used by any site
- SynapsInt – The unified OSINT research tool
- spyonweb.com – Find out related websites
- statscrop.com – Millions of amazing websites across the web are being analyzed with StatsCrop
- securityheaders.com – Scan your site now
- visualsitemapper.com – Create a visual map of your site
- similarweb.com – The easiest and fastest tool to find out what’s really going on online
- buckets.grayhatwarfare.com – Public buckets
- C99.nl – Over 57 quality API’s and growing!
- PassiveTotal – Security intelligence that scales security operations and response
- wannabe1337.xyz – Online Tools
- subdomainfinder.c99.nl – Scanner that scans an entire domain to find as many subdomains as possible
URLs
- PhoneBook – Lists all domains, email addresses, or URLs for the given input domain
- IntelligenceX – Search engine and data archive
- URLScan – A sandbox for the web
- HackerTarget – Collect information about IP Addresses, Networks, Web Pages and DNS records
- MOZ Link Explorer – The world’s best backlink checker with over 40 trillion links
- shorteners.grayhatwarfare.com – Search URLs exposed by Shortener services
- CommonCrawl Index – Open repository of web crawl data
DNS
- DNSDumpster – dns recon & research, find & lookup dns records
- Chaos – Enhance research and analyse changes around DNS for better insights
- RapidDNS – dns query tool which make querying subdomains or sites of a same ip easy
- DNSdb – Passive DNS historical database
- Omnisint – Reverse DNS lookup
- HackerTarget – Collect information about IP Addresses, Networks, Web Pages and DNS records
- passivedns.mnemonic.no – Web interface for querying passive DNS data collected in our malware lab
- ptrarchive.com – Over 230 billion reverse DNS entries from 2008 to the present
- dnshistory.org – Domain Name System Historical Record Archive
- DNSTwister – The anti-phishing domain name search engine and DNS monitoring service
- DNSviz – Tool for visualizing the status of a DNS zone
- C99.nl – Over 57 quality API’s and growing
- PassiveTotal – Security intelligence that scales security operations and response
- wannabe1337.xyz – Online Tools
Certificates
- Crt.sh – Certificate Search
- CTSearch – Certificate Transparency Search Tool
- tls.bufferover.run – Quickly find certificates in IPv4 space
- CertSpotter – Monitors your domains for expiring, unauthorized, and invalid SSL certificates
- SynapsInt – The unified OSINT research tool
- Censys Search – Certificates – Certificates Search
- PassiveTotal – Security intelligence that scales security operations and response
- ciphersuite.info – TLS Ciphersuite Search. Search for a particular cipher suite by using IANA, OpenSSL or GnuTLS name format
WiFi Networks
- Wigle.net – Maps and database of 802.11 wireless networks with statistics
- wifimap.io – Connect to all Free WiFi Hotspots using WiFi Map App all over the World!
- wificafespots.com – Free WiFi Cafe Spots
- wifispc.com – Free map of Wi-Fi passwords anywhere you go!
- openwifimap.net – HTML5 map with OpenWiFiMap data
- mylnikov.org – Public API implementation of Wi-Fi Geo-Location database
Device Information
- MAC Vendor Lookup – Look up the vendor for a specific MAC Address
- macvendors.com – Find MAC Address Vendors. Now.
- macaddress.io – MAC address vendor lookup
- maclookup.app – Find the vendor name of a device by entering an OUI or a MAC address
Credentials
- Have I Been Pwned – Check if your email or phone is in a data breach
- Dehashed – Free deep-web scans and protection against credential leaks
- Leak-Lookup – Search across thousands of data breaches
- Snusbase – Stay on top of the latest database breaches
- LeakCheck.io – Make sure your credentials haven’t been compromised
- crackstation.net -Massive pre-computed lookup tables to crack password hashes
- breachdirectory.org – Check if your information was exposed in a data breach
- BreachForums – Breaches, Data leaks, databases and more
- Siph0n Breach DB (onionsite) – Breaches, Data leaks, Exploits
- HashKiller – Pre-cracked Hashes, easily searchable
Hidden Services
- AHMIA – Search hidden services on the Tor network
- thehiddenwiki.org – The darknet guide
- tor.link – Free anonymous deepweb / Darknet search engine
- deepweblinks.net – Onion Links
- onionengine.com – A search engine for services accessible on the Tor network
- OnionLand – Discover Hidden Services and access to Tor’s onion sites
Social Networks
These can be useful for osint and social engineering.
- YouTube
- Tumblr
- Flickr
- SnapChat
- Quora
- TikTok
- Vimeo
- Medium
- VK
- Tinder
Phone Numbers
- NumLookup – Free reverse phone lookup
- SpyDialer – Free Reverse Lookup Search
- WhitePages – Find people, contact info & background checks
- National Cellular Directory – Begin your comprehensive people search now
- Phone Validator – Is it a cell phone or is it a landline or is it a fake?
- Free Carrier Lookup – Enter a phone number and we’ll return the carrier name
- RocketReach – Your first-degree connection to any professional
- sync.me – Find out who called
- EmobileTracker – Track Mobile Owner Name, Location and Mobile Service Provider
- Reverse Phone Lookup – Find Out The Owner Of A Phone Number
- ThatsThem – Reverse phone lookup
- thisnumber.com – International Phone Directories
- usphonebook.com – Free Reverse Phone Number Lookup
- truepeoplesearch.com – Get current address, cell phone number, email address, relatives, friends and a lot more
- Tellows – Who is calling? The phone number reverse search
- SynapsInt – The unified OSINT research tool
- C99.nl – Over 57 quality API’s and growing
Threat Intelligence
- MITRE ATT&CK – Globally-accessible knowledge base of adversary tactics and techniques
- PulseDive – Threat intelligence made easy
- ThreatCrowd – A Search Engine for Threats
- ThreatMiner – Data Mining for Threat Intelligence
- VirusTotal – Analyze suspicious files, domains, IPs and URLs to detect malware and other breaches
- vx-underground.org – Malware library
- bazaar.abuse.ch – Malware sample database
- feodotracker.abuse.ch – List of botnet Command&Control servers
- sslbl.abuse.ch – All malicious SSL certificates
- urlhaus.abuse.ch – Propose new malware urls
- threatfox.abuse.ch – Indicator Of Compromise (IOC) database
- yaraify.abuse.ch – Scan suspicious files such as malware samples or process dumps against a large repository of YARA rules
- Rescure – Curated cyber threat intelligence for everyone
- otx.alienvault – The World’s First Truly Open Threat Intelligence Community
- urlquery.net – Service for detecting and analyzing web-based malware
- socradar.io – Extension to your SOC team
- VirusShare – System currently contains 48 million malware samples
- WikiLeaks – News leaks and classified media provided by anonymous sources
- PassiveTotal – Security intelligence that scales security operations and response
- malapi.io – Windows APIs used for malicious purposes
- filesec.io – Latest file extensions being used by attackers
- leakix.net – Search engine indexing public information and an open reporting platform linked to the results
- tria.ge – Fully automated solution for high-volume malware analysis using advanced sandboxing technology
- Polyswarm – Launchpad for new technologies and innovative threat detection methods
- Cisco Talos – The threat intelligence organization at the center of the Cisco Security portfolio
- scamsearch.io – Find your scammer online & report them
- CyberCampaigns – Threat Actor information and Write-Ups
Web History
- Web Archive – Explore more than 702 billion web pages saved over time
- Archive.ph – Create a copy of a webpage that will always be up even if the original link is down
- CachedPages – Get the cached page of any URL
- stored.website – View cached web pages/website
- CommonCrawl – Open repository of web crawl data
- UK Web Archive – Collects millions of websites each year, preserving them for future generations
Unclassified
- NetoGraph – Captures and indexes detailed, low-level snapshots of website behaviour
- DorkSearch – Speed up your Dorking
- usersearch.org – Find someone by username or email on Social Networks, Dating Sites, Forums, Crypto Forums, Chat Sites and Blogs
Not working / Paused
转载请注明出处及链接