There are a total of 8 types of search engines for the cybersecurity analyst given below. These are very well-known tools for the security analyst.
Server-based
- Netlas.io – A platform to discover, research, and monitor any assets available online
- Onyphe.io – A Cyber Defense Search Engine that provides open-source and cyber threat intelligence data
- Censys Search – A search engine for every server on the Internet, aimed at reducing exposure and improving security
- Shodan – An Internet of Everything search engine
- FOFA – A cyberspace mapping tool
- GreyNoise – A valuable resource for understanding internet noise
- ZoomEye – A global cyberspace mapping tool
- Natlas – A network scanning tool designed for scalability
Exploit search engine
- Exploit-DB – Comprehensive database of exploits
- Vulmon – Search engine for vulnerabilities and exploits
- Rapid7 – Vulnerability & Exploit Database
- Sploitus – Platform for identifying the latest exploits
- packetstormsecurity.com – Provider of Information Security Services, News, Files, Tools, Advisories, and Whitepapers
- XSS Payloads – Collection of unexpected JavaScript usages and more
- 0day.today – Extensive database of exploits and vulnerabilities
- GTFOBins – Curated list of Unix binaries for bypassing local security restrictions
- LOLBAS – Repository of Living Off The Land Binaries, Scripts, and Libraries
- Payloads All The Things – Compilation of useful payloads and bypasses for Web Application Security
- exploitalert.com – Repository of Exploits
Web history search engine
- UK Web Archive – Preserving millions of websites annually for future generations
- stored.website – Platform to view cached web pages and websites
- Archive.ph – Creating permanent copies of web pages for uninterrupted access
- CommonCrawl – Open repository of web crawl data for public use
- Web Archive – Access a vast collection of over 702 billion saved web pages
- CachedPages – Retrieving cached versions of any URL
Search engine for Devices
- MAC Vendor Lookup – Identify the vendor associated with a specific MAC Address
- macvendors.com – Instant MAC Address Vendors lookup service
- macaddress.io – Lookup MAC address vendors and associated details
- maclookup.app – Discover the vendor name of a device using OUI or MAC address
Phone book for information gathering
- PhoneBook: Lists all domains, email addresses, or URLs for the given input domain.
- IntelligenceX: A search engine and data archive.
- URLScan: A sandbox for the web.
- HackerTarget: Collects information about IP Addresses, Networks, Web Pages, and DNS records.
- MOZ Link Explorer: The world’s best backlink checker with over 40 trillion links.
- shorteners.grayhatwarfare.com: Search URLs exposed by Shortener services.
- CommonCrawl Index: An open repository of web crawl data
Information gathering tools for threat hunting
- VirusTotal – Analyze suspicious files, domains, IPs and URLs to detect malware and other breaches
- CyberCampaigns – Threat Actor information and Write-Ups
- bazaar.abuse.ch – Malware sample database
- ThreatCrowd – A Search Engine for Threats
- Rescure – Curated cyber threat intelligence for everyone
- PulseDive – Threat intelligence made easy
- otx.alienvault – The World’s First Truly Open Threat Intelligence Community
- urlquery.net – Service for detecting and analyzing web-based malware
- PassiveTotal – Security intelligence that scales security operations and response
- leakix.net – Search engine indexing public information and an open reporting platform linked to the results
- malapi.io – Windows APIs used for malicious purposes
- ThreatMiner – Data Mining for Threat Intelligence
- VirusShare – System currently contains 48 million malware samples
- Polyswarm – Launchpad for new technologies and innovative threat detection methods
- urlhaus.abuse.ch – Propose new malware URLs
- sslbl.abuse.ch – All malicious SSL certificates
- socradar.io – Extension to your SOC team
- WikiLeaks – News leaks and classified media provided by anonymous sources
- Cisco Talos – The threat intelligence organization at the center of the Cisco Security portfolio
- MITRE ATT&CK – Globally-accessible knowledge base of adversary tactics and techniques
- vx-underground.org – Malware library
- scamsearch.io – Find your scammer online & report them
- feodotracker.abuse.ch – List of botnet Command&Control servers
- tria.ge – Fully automated solution for high-volume malware analysis using advanced sandboxing technology
- yaraify.abuse.ch – Scan suspicious files such as malware samples or process dumps against a large repository of YARA rules
- threatfox.abuse.ch – Indicator Of Compromise (IOC) database
Dns Info tools
- Chaos – Enhance research and analyze changes around DNS for better insights
- DNSDumpster – DNS recon & research, find & lookup DNS records
- RapidDNS – DNS query tool which makes querying subdomains or sites of the same IP easy
- passivedns.mnemonic.no – Web interface for querying passive DNS data collected in our malware lab
- DNSTwister – The anti-phishing domain name search engine and DNS monitoring service
- ptrarchive.com – Over 230 billion reverse DNS entries from 2008 to the present
- HackerTarget – Collect information about IP Addresses, Networks, Web Pages, and DNS records
- DNSviz – Tool for visualizing the status of a DNS zone
- DNSTwister – The anti-phishing domain name search engine and DNS monitoring service
- DNSdb – Passive DNS historical database
- dnshistory.org – Domain Name System Historical Record Archive
- wannabe1337.xyz – Online Tools
- Omnisint – Reverse DNS lookup
- C99.nl – Over 57 quality APIs and growing
- PassiveTotal – Security intelligence that scales security operations and response
Search engine for Mail Addresses
- IntelligenceX – Search engine and data archive
- PhoneBook – Lists all domains, email addresses, or URLs for the given input domain
- Hunter.io – Find professional email addresses in seconds
- Reacher.email – Open-Source Email Verification
- EmailHippo – Email address verification technology
- Email-format.com – Find the email address formats in use at thousands of companies
- Melissa – Emailcheck – Check email addresses and verify they are live
- verify-email.org – Checks whether the mailbox exists or not
- RocketReach – Your first-degree connection to any professional
- ThatsThem – Reverse email lookup
- SynapsInt – The unified OSINT research tool
- VoilaNorbert – I can find anyone’s email address
- skymem.info – Find email addresses of companies and people
- findemails.com – Find Anyone’s Email Address in Seconds