CyberHunter CyberHunter
// OSINT hub

OSINT Hub - IOC, DNS, HTTP/TLS & Reputation Analysis

Investigate IOCs quickly with DNS, PTR, and HTTP/TLS probes plus direct pivots to public threat intelligence services. Designed for SOC triage and practical OSINT workflows.

No API key requiredServer-side probesIP · domain · URL · hash

Run your OSINT investigation

osint://workspace DNS · PTR · HTTP/TLS · reputation
Detected typeUnknown

Open in other tools

Pivot the indicator to public reputation, WHOIS and infrastructure services.

Reputation & intel

  • VirusTotal
  • AbuseIPDB
  • AlienVault OTX
  • Cisco Talos Intelligence
  • GreyNoise
  • SANS ISC
  • IBM X-Force Exchange

WHOIS & DNS

  • WHOIS (who.is)

Exposure & scans

  • Shodan
  • Censys

Malware & phishing

  • URLhaus (abuse.ch)
  • Malware Bazaar
  • PhishTank
  • Hybrid Analysis

// built-in probes work without API keys · VirusTotal enrichment depends on server configuration

01 About this tool

Why an OSINT hub, and how to use it

Why use an OSINT hub?

During incident triage, analysts often jump between many tabs and services. A hub centralizes IOC handling so you pivot faster between DNS, HTTP/TLS checks, and reputation sources - reducing context switching during threat intelligence and security investigations.

Features of the OSINT hub

  • IOC handling for IPs, domains, URLs, and hashes
  • DNS and PTR lookups for infrastructure context
  • HTTP/TLS probe with headers, redirects, and cert fingerprints
  • Quick pivots to VirusTotal, AbuseIPDB, and WHOIS

How to use the OSINT hub

  1. 01

    Enter an IOC (IP, domain, URL, or hash) - the type is detected automatically.

  2. 02

    Run the built-in probes and inspect the technical output (DNS, PTR, HTTP/TLS).

  3. 03

    Pivot to external intelligence services for deeper context.

What you can analyze

  • Suspicious domains and URLs from alerts
  • IP indicators with reverse-DNS context
  • TLS fingerprints and redirect chains
  • Hashes and IOC pivots to reputation platforms
02 FAQ

Questions fréquentes

Do I need API keys for DNS, PTR, or HTTP/TLS probes?

No. Built-in DNS resolution, reverse DNS (PTR), and HTTP/TLS probing on this server work without you supplying keys. Optional VirusTotal enrichment only applies when the server is configured with VIRUSTOTAL_API_KEY.

What do the external links do?

They open public services such as VirusTotal, AbuseIPDB, or WHOIS in a new context so you can pivot quickly from the same IOC.

What data does the HTTP/TLS probe return?

It shows response headers, redirects, and TLS certificate fingerprints to help you reason about the endpoint without replacing a full scanner.

Is this legal for any target?

Only use these capabilities on systems and indicators you are authorized to investigate. Unauthorized probing may violate law or policy.

03 Keep going