Skip to content
Tools/Indicator Lookup
runs in your browser
Triage Tool

Indicator Lookup

Paste an indicator and get it straight to the services that can answer questions about it — no retyping, no hunting for the right search box. The type is detected automatically and defanged input is understood.

Before you click

Querying a third party is itself a disclosure. Looking up an attacker-controlled domain or uploading a sample tells that service — and in some cases the wider world — that someone is investigating. Adversaries do monitor public sandbox submissions and certificate logs for their own infrastructure. During a live incident, a careless lookup can tip off the intruder and trigger destruction of evidence.

Treat file hashes as safe to look up and URLs and domains as a judgement call. If in doubt, use passive sources first — certificate transparency, WHOIS history, passive DNS — and leave the active scanners until containment is complete. Never paste customer data, credentials or internal hostnames into a public service.

This page runs entirely in your browser. The indicator you type is never sent to Threat Sentinel, is not logged and is not stored — it only leaves your machine when you deliberately click one of the links, and then it goes to that service alone.

© 2026 Threat Sentinel · All linked services belong to their respective operators · Data sources
Public OSINT dashboard · no account, no tracking loaded Privacy press / to search