OSINT Investigation Suite
Four free OSINT tools for analysts and IT teams: map a company domain's public footprint, check whether infostealer malware took its logins, then turn your notes into a dated timeline and a MITRE ATT&CK map.
Only the domain is used. An email is cut down to the part after the @.
The four tools, in the order an investigation runs
Exposure Graph
Subdomains from certificate logs and passive DNS, which of them are live, dangling CNAMEs, hosting, mail posture (SPF, DMARC, MTA-STS), DNSSEC and registration dates.
Sources: dns.google, crt.sh, Cert Spotter, HackerTarget, ipwho.is, RDAP
Stealer Exposure Check
Infected staff and customer machines that held logins for a domain, which login pages were hit, stealer families and a cleanup playbook. Compare two domains side by side.
Source: Hudson Rock Cavalier, counts only, through a pwnsy proxy
Breach Timeline Builder
Dated notes become a sorted timeline with severity, observables shared between events, the largest gap and CSV or JSON export.
Parses: 2026-08-13, 13 Aug 2026, Aug 13, 2026, 13/08/2026 and more
ATT&CK Evidence Mapper
Incident notes and log lines become MITRE ATT&CK techniques with the matched phrases shown, a tactic heatmap, extracted indicators and a Navigator layer.
Rules: local phrase rules on MITRE ATT&CK Enterprise IDs
How the OSINT suite works
Start with a domain. The launcher above trims a URL or email down to the domain name and opens the tool you pick with the domain already in the address, so the result can be shared as a link.
- Exposure Graph queries DNS over HTTPS, certificate transparency logs, passive DNS, RDAP and an IP owner lookup from your browser, then resolves up to 150 of the names it finds.
- Stealer Exposure Check asks pwnsy for Hudson Rock's aggregate counts for the domain. pwnsy caches each answer for six hours and shows counts and login URLs only.
- Breach Timeline Builder and ATT&CK Evidence Mapper read text you paste and run in the page. Nothing you paste is sent anywhere.
How to read the results
Each tool opens with a headline card in green, amber or red, then the numbers behind it. Red items are the ones to check first: a dangling CNAME, a staff machine in infostealer logs, a high severity event or a high confidence technique. Each item shows the evidence that produced it (the host, the login URL, the matched phrase or the dated line) so you can confirm it before you report it.
OSINT suite FAQ
Do these OSINT tools need an account or API key?
No. All four tools are free and need no sign-in. The two domain tools call public sources from your browser, and the stealer check goes through a pwnsy proxy that caches each answer for six hours.
Which tools send data off my device?
The Exposure Graph sends the domain you enter to public DNS, certificate transparency, passive DNS, RDAP and IP lookup services. The Stealer Exposure Check sends the domain to pwnsy, which asks Hudson Rock. The ATT&CK Evidence Mapper and the Breach Timeline Builder run in the page and send nothing.
Can I check an email address?
The launcher accepts an email address but only keeps the domain part, so the lookup is about the company. Email lookups are not offered because they return data about one person.
Does a result prove a breach or name an attacker?
No. Each tool structures public evidence so an analyst can check it. Risk labels, confidence levels and severity scores are triage prompts that need confirmation against your own logs.
Nothing here proves attribution. Each tool structures evidence for an analyst to validate.