Turn an indicator into a better investigation.
Start with a suspicious link, an IP from an alert, or an email from a report. Inspect the available records, follow the useful leads, and keep your team’s assessment together.
Investigate the infrastructure
Look up a reported domain, then inspect DNS, HTTP, certificates, registration, and available archives. Pivot to an IP for network context.
Check the other identifiers
Search an email or username from a report. Review returned public profiles and selected breach sources without treating a match as proof.
Make it repeatable
Send supported identifiers through the Search API, follow progress, and receive signed completion webhooks in your own workflow.
Follow the indicator, not a hunch.
Three different starting points. Open only the records that answer the question, then keep the source details with your assessment.
A reported login link needs triage.
Search the domain from the alert. Compare its DNS records, HTTP redirect, and certificate hostnames before deciding whether the link needs escalation.
Example domain; no live result is implied.
Reported domain
login.example.com
DNS
Addresses & records
HTTPS
Response & redirect
Certificate
Issuer & hostnames
Link triage
Sources & analyst notes
The inherited domains need a first pass.
After an acquisition, start with the domains you were given. Request subdomain, certificate, DNS, and passive service sections to map what is visible from outside. Keep the snapshot so the next review has a point of comparison.
An observed port or associated CVE is a lead for authorized verification, not a finding of current exposure.
Acquired domain list
Supplied by the security team
DNS & subdomains
Which hosts resolve?
Certificates
Which hostnames are covered?
Passive services
What was observed before?
Saved snapshots
What changed at the next review?
Request only the sections needed for this pass.
Give every indicator a first pass.
Your alert feed brings in a domain, an IP, and a sender address. Start a separate Search API request for each. Follow their progress and receive a signed webhook as each search finishes.
For a focused infrastructure check, choose the sections you need with Domain or IP Intelligence.
Talk to sales03 independent searches
Domain
login.example.com
IP address
192.0.2.17
contact@example.com
Osintly Search API
One request per indicator
Completion webhooks
One signed event per search
Keep the reasoning with the alert.
Save the reported URL, the source sections you checked, and what still needs verification in one organization project. The next analyst can reopen the searches and follow your reasoning.
Set up an organizationReported login link
- Input
- login.example.com
- Sources opened
- DNS · HTTP · certificate
Analyst note
Compare the redirect destination with the certificate hostnames. Confirm the current behavior before escalating.
Resources for your next investigation.
Questions from
security teams.
Put the right context
in your team’s hands.
Tell us which indicators you check, your daily volume, and where your analysts need the results.