DuckIntel / Security Tools
Pivot across 59+ OSINT sources for IPs, domains, emails, hashes, usernames, and phone numbers. Auto-detects input type and opens relevant intelligence tools.
The OSINT Pivot tool auto-detects your input as an IP address, domain name, email address, file hash, username, or phone number and opens the most relevant intelligence sources in new browser tabs. With 59+ integrated sources, it eliminates the manual work of bookmarking and navigating to each tool individually.
Open Source Intelligence (OSINT) pivoting is the process of taking one piece of information — a suspicious IP from a log, an email address from a phishing message, a file hash from malware — and rapidly expanding your knowledge of it using publicly available data sources. Effective OSINT pivoting can reveal the infrastructure behind an attack campaign, link seemingly unrelated incidents, and uncover attacker attribution clues.
Sources are organized by input type: IP addresses are sent to Shodan, Censys, GreyNoise, AbuseIPDB, and Spamhaus; domains go to VirusTotal, URLScan, and DomainTools; hashes go to MalwareBazaar, Any.run, and VirusTotal; usernames go to social media and forum search tools. The tool remembers your recent pivots using localStorage so you can pick up an investigation where you left off.
Related tools
IP / DNS LookupIOC Bulk ScannerLookalike Domain DetectorHash Analyzer
Part of DuckIntel.io — 59 free browser-based security tools for SOC analysts. No login. No tracking. 100% client-side.