Research with public information.
OSINT means open-source intelligence: collecting and analyzing information that is legally available to the public. Start with a question, document your sources, and never treat a single result as absolute proof.
Use these tools responsibly
Only investigate information you are legally allowed to access. Never upload confidential files, harass people, bypass access controls, or assume a database result proves wrongdoing.
CISA Known Exploited Vulnerabilities
See which software weaknesses attackers are actively using.
Best first stop for patch priorities.MITRE ATT&CK
Understand how known attacker groups operate.
Best for learning tactics and techniques.VirusTotal
Check a suspicious file, link, domain, or IP address.
Never upload private or confidential files.URLhaus
Research web addresses connected to malware.
Useful for malicious-link investigations.Shodan
Find internet-connected devices and exposed services.
Use only for lawful research.Have I Been Pwned
Check whether an email appeared in a known breach.
Change reused passwords and enable MFA.AbuseIPDB
Review reports about suspicious or abusive IP addresses.
One signal, not proof by itself.National Vulnerability Database
Look up vulnerability details and severity scores.
Pair scores with actual exposure and exploitation.