5 items
Page triage, pivot graph and STIX export. 16 free threat intel sources, optional keys. Nothing leaves your device. OSINT Research Assistant grades indicators of compromise in the page you are already reading. No account, no API key, no backend — everything runs on your machine. Built for SOC analysts, threat hunters, incident responders and security researchers. WHAT MAKES IT DIFFERENT Most lookup tools handle one indicator at a time. This one triages a whole page. Open any threat report, press Ctrl+Shift+U, and every IP, domain, email and file hash on the page is graded at once and ranked worst-first. A 200-indicator report costs the same as a single lookup — zero API requests — because matching happens against a threat index held locally on your device. HOW IT WORKS Select an indicator and press Ctrl+Shift+O, or right-click and choose "OSINT Lookup". You can also type one straight into the toolbar popup. Results open in a floating panel: the Summary tab answers the question, the other tabs show the detail. Defanged input is understood. 185.220.101[.]45, hxxps://evil[.]com and user[at]mail[.]com all work, because threat intelligence is never shared in clickable form. PIVOT GRAPH Walk the infrastructure instead of reading isolated results. An IP expands to the AS that announces it, that AS's other prefixes, and its peer networks. A domain expands to its resolving addresses, name servers and subdomains from certificate transparency logs. Nodes already listed in a threat feed are red, so a bad neighbourhood is visible rather than inferred. CASE FILE AND EXPORT Collect findings across pages into a case, then export as STIX 2.1 bundle, MISP event, CSV or Markdown — formats a detection pipeline can ingest, not just a human. SOURCES (14 built in, no key required) Threat Feeds — ThreatFox, URLhaus, Feodo Tracker and OpenPhish, matched locally, with malware family names AlienVault OTX — community threat reports: campaign names and MITRE ATT&CK techniques Team Cymru MHR — is this hash known malware, and what is the antivirus detection rate CIRCL HASHLOOKUP — is this hash a known legitimate file (NSRL known-good database) Shodan InternetDB + CVE-Search — open ports and CVEs enriched with CVSS scores and CISA KEV status GreyNoise Community — internet-wide scanner classification Tor exit node list — is this address a Tor exit RIPEstat — which AS announces this address and how large that network is IP-API — geolocation, ISP, proxy and VPN detection Whois / RDAP — registration dates, registrar, name servers, IP block owner crt.sh — certificate transparency history and subdomain enumeration Google DNS — A, AAAA, MX, TXT, NS and CNAME records URLScan.io — scan history and malicious verdicts mailcheck.ai — disposable address, spam and MX checks Optional: add a VirusTotal or Shodan key in Settings for more depth. Nothing degrades without them — those tabs simply do not appear. SUPPORTED INDICATORS IPv4 and IPv6 addresses, domain names, URLs, email addresses, and MD5, SHA-1 and SHA-256 file hashes. OTHER FEATURES Draggable, resizable results panel that remembers where you put it Colour-coded verdicts, with the summary shown before the detail Per-source health tracking — success rate, latency and last error Individual services can be switched off English and Turkish, switchable instantly Light and dark themes HONEST LIMITS A tool that hides its blind spots is worse than one that names them: Absence is not innocence. The threat index holds a few thousand current indicators. A miss returns "unknown", never "clean", and the interface says so. Team Cymru MHR covers MD5 and SHA-1 only. SHA-256 hashes get no malware verdict from it, and the summary says that rather than implying safety. CIRCL HASHLOOKUP is a known-good database. It answers "is this a legitimate file", not "is this malware". Both are shown, labelled separately. NON-COMMERCIAL SOURCES Four sources — IP-API, OpenPhish, Team Cymru MHR and RIPEstat — restrict their free tier to non-commercial use under their own terms. Using them inside a company, including by a security team, is not covered. These four are labelled "non-commercial" in Settings and can be switched off individually. With them off the extension still works using the remaining sources. Please check each provider's terms before using this at work. PRIVACY No account, no server, no telemetry, no analytics. The only data sent externally is the indicator you explicitly submit, which goes directly to the third-party services listed above. Browsing history, page content and identifying information are never accessed or transmitted. Threat feeds are downloaded from their publishers and matched entirely on your device, so page triage sends nothing anywhere. Lookup history, your case file and any optional API keys are stored locally and never synced. For authorized security research only.
Aug 11, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.