Intelligence X Security Search
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
🔥TIP: How to Investigate an Email
Example: [email protected]
1️⃣ Intelligence Search (full email)
Result: 69 files found
• usenet: 30 (forum discussions)
• leaks.logs: 22 (victim browser history)
• leaks.private: 13 (data breaches)
• darknet.tor: 3 (exposed on .onion sites)
2️⃣ Domain Recon (domain: adobe.com)
Result: 100+ related emails discovered
• [email protected]
• [email protected]
• [email protected]
• [email protected]
• ...and more
3️⃣ Reverse Search (domain: adobe.com)
Result: 125 compromised accounts
One email led to:
• 69 breach files
• 100+ related emails
• 125 compromised accounts
WEB https://intelligencesecurity.io
BOT https://t.me/intelligencesecurityiobot
3 · 1.1K · Intelligence X Security Search
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
🔍 Intelligence Search: Email Investigation
Searching [email protected] reveals 500+ results:
📁 Data Breaches (194 files):
├─ Collection #2-#5 → 48 files
├─ TruecallerIndia → 20 files
├─ StarTribune → 12 files
└─ SMS Services leaks
📋 Pastes → 84 files
🌐 Darknet (Tor + I2P) → 48 files
🔍 WHOIS Records → 59 files
🏛 Public Government Docs → 51 files
⚠️ Important: Data leaks don't always mean YOU were hacked.
Your email can appear in breaches from:
├─ Third-party services you registered on
├─ Companies that stored your data insecurely
├─ Public records and government documents
├─ Marketing databases sold or leaked
└─ Contact lists from infected devices (not yours)
🎯 Intelligence Search shows your complete digital footprint across all indexed sources.
🔗WEB https://intelligencesecurity.io/features
🤖BOT https://t.me/intelligencesecurityiobot
4 · 1.2K · Intelligence X Security Search
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
🔍 Intelligence Search: Phone Number Investigation
Searching +447911123456 (UK) reveals 1,000+ results:
📁 Data Breaches (161 files):
├─ pureincubation.com → 25 files
├─ Magento e-commerce → 11 files
├─ TAPAir Portugal → 10 files
├─ LinkedIn 2023 35M → 3 files
└─ sevenrooms.com → 3 files
📋 Stealer Logs (197 files):
├─ Multi-country origins (US, ZA, AE, PK)
├─ Browser passwords & autofills
└─ Infected device extractions
🔍 WHOIS/DNS Records → 108 files
🌐 Darknet (Tor) → 2 files
⚠️ Important: Phone numbers leak differently than emails.
Your number can appear in breaches from:
├─ Apps that access your contacts (WhatsApp, Telegram)
├─ E-commerce platforms storing billing info
├─ Marketing databases and lead generation services
├─ Airline & travel booking systems
└─ Devices infected with info-stealers (not yours)
🎯 Intelligence Search reveals your phone's complete exposure across global data sources.
🔗WEB https://intelligencesecurity.io/features
🤖BOT https://t.me/intelligencesecurityiobot
9 · 1.3K · Intelligence X Security Search
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
🍪 Session Intelligence: Cookie Extraction
Cookies from affected systems can contain active sessions, auth tokens, and user preferences.
📌 EXAMPLE: trustwallet.com
→ 15 cookie files from 15 systems
→ Date range: last 7 days only
📂 What's inside exposed cookies?
├─ 🔑 Session tokens → Active login sessions
├─ 🔐 Auth cookies → Access without password
├─ ⚙️ Consent/preferences → User fingerprinting
├─ 📍 Tracking pixels → Cross-site identification
💡 Why cookies matter:
🎯 For Bug Bounty & Red Team:
- Session persistence testing
- 2FA bypass validation
- Auth flow security assessment
🛡 For Security Teams:
- Monitor corporate domain exposure
- Detect exposed employee sessions
- Incident response: identify active leaks
Session Intelligence extracts cookies by domain from stealer logs, grouped by source system, prioritizing recent sessions.
🔗 https://intelligencesecurity.io/features
🤖 https://t.me/intelligencesecurityiobot
9 · 1K · Intelligence X Security Search
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
🔎 Internal Search: Real-Time Line Extraction
Unlike standard breach searches that show file names, Internal Search reads INSIDE every indexed file and returns the exact line where your query appears.
📌 EXAMPLE: ftx.com
→ 5,218 results (January 2026 only)
→ Sources: darknet.tor, leaks.logs, web archives
📂 What the search revealed:
├─ 🛒 "FTX.COM - Kyc Verified Account/Drop (Fresh)" → Darknet markets
├─ 🌐 "URL: https://ftx.com/onboarding/signup" → Browser history from affected systems
├─ 📄 "A Crypto Derivatives Exchange, built by traders" → Archived site mentions
├─ 🔗 References across Russian financial forums
💡 Why line-level search matters:
Standard search: "Your email appears in 50 files"
Internal Search: "Login: [email protected]" — shows exact context
🎯 For Investigators & Red Team:
- See HOW data is stored (login fields, autofills, URLs)
- Identify patterns across stealer logs
- Track mentions in darknet forums
🛡 For Security Teams:
- Understand exposure context, not just existence
- Export 5,000+ lines to Excel for bulk analysis
- Filter by date range for recent activity only
Internal Search performs real-time extraction across billions of indexed records.
🔗 https://intelligencesecurity.io/features/
🤖 https://t.me/intelligencesecurityiobot
4 · 1.3K · Intelligence X Security Search
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
🔑 Credential Exposure: Monitor leaked credentials by domain
Search any domain to identify exposed username:password pairs from stealer log collections.
📌 EXAMPLE: example.com
→ 1,699 total entries found
→ 479 unique credentials
→ 1,220 duplicates filtered
📊 Why deduplication matters:
Leaked credential datasets contain massive redundancy:
├─ Same data repackaged across collections
├─ Repeated entries from multiple sources
├─ Duplicates inflate exposure metrics
Our system normalizes results automatically, showing only unique pairs.
📂 Data returned per credential:
├─ 🔗 URL → Login endpoint
├─ 👤 User → Account identifier
├─ 🔐 Password → Exposed value (masked in demo)
├─ 📅 Date → Collection timestamp
├─ 📦Source → Origin dataset
🛡 Security Operations Use Cases:
- Identify exposed employee credentials
- Prioritize forced password resets
- Measure corporate exposure over time
- Support incident response investigations
🎯 Research & Assessment:
- Validate exposure scope for clients
- Demonstrate risk in security assessments
- Track credential circulation patterns
📅
Built for security professionals to understand and remediate credential exposure.
🔗 https://intelligencesecurity.io
🤖 https://t.me/intelligencesecurityiobot
7 · 1.3K · Intelligence X Security Search
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
🔍 INVESTIGATION TIP: TreeView - Exploring Stealer Log Contents
Container files hide valuable intel. TreeView lets you explore inside before downloading.
📦 Real Example: [Nigeria]_[REDACTED]_steal273.rar
└─ 853 files inside
🌐 Browser Data (61 files)
├─ /History → 27 files
│ ├─ Chrome_Default.txt
│ ├─ Edge_Default.txt
│ ├─ Firefox_default-release.txt
│ └─ Opera_Stable_Default.txt
├─ /Cookies → 14 files
├─ /AutoFills → 8 files (saved form data)
├─ /Passwords → 5 files
├─ /Bookmarks → 5 files
└─ /GoogleAccounts → 2 files
📂 FileGrabber Data (782 files)
├─ /DDrive → 736 files
│ ├─ Video editing drafts → 629 projects
│ ├─ Development files → 74 source code files
│ └─ Media projects → 8 files
├─ /Documents → 42 files
└─ /Downloads → 4 files
🖥 System Info
├─ UserInformation.txt (IP, location, hardware)
├─ InstalledSoftware.txt
├─ ProcessList.txt
├─ Passwords.txt (extracted credentials)
├─ Environment.txt
└─ screenshot.jpg (desktop capture)
💡 What TreeView reveals:
From a single container file:
├─ Browser data across 4+ browsers
├─ Development project files
├─ Personal documents & media projects
└─ Full credential extraction
One RAR file = 853 files to analyze without downloading.
🛡 Why this matters for organizations:
- Incident Response → Understand exactly what data was exfiltrated from a compromised endpoint
- Employee Monitoring → Check if corporate credentials or internal documents appear in stealer logs
- Risk Assessment → Evaluate exposure depth per affected system
- Compliance & Reporting → Document scope of data exposure for regulatory reports
🎯 For Security Researchers:
- Analyze stealer log structure without downloading full containers
- Identify what types of data each malware family collects
- Study infection patterns across regions and browsers
TreeView: Browse container contents directly in your browser. No downloads. No risk.
Search → Find container → TreeView → Explore contents
🔗 DEMO https://intelligencesecurity.io/search/demo/i
7 · 1K · Intelligence X Security Search
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
🔍 CASE STUDY: The 000webhost Breach (2015)
In March 2015, http://000webhost.com (free web hosting) was breached.
Result: 13.5 million accounts exposed with PLAINTEXT passwords.
📊 Searching http://000webhost.com on Intelligence Security:
Result: 299 files found
📂 Where This Data Appears Today:
Major Compilations:
├─ Collection #1 → 23 files
├─ Collection #2-#5 & Antipublic → 50 files
├─ CompilationOfManyBreaches → 7 files
├─ onliner_spambot.rar → 7 dedicated files
└─ http://darknetleaks.ru → 4 files
Leak Logs (33 files):
├─ Users reusing 000webhost passwords
├─ Browser autofill with old credentials
└─ Credential testing results
Other Sources:
├─ Pastes → 38 files
├─ Usenet archives → 31 files
├─ DNS/WHOIS → 40 files
└─ DoxBin archives → 7 files
⚠️ Why This Breach Still Matters (10 Years Later):
1️⃣ Password Reuse
├─ Users registered with same email/password on other sites
├─ 000webhost password → Gmail, Facebook, PayPal access
└─ Credential stuffing still works today
2️⃣ Plaintext Storage
├─ Passwords were NOT hashed
├─ Direct access to real passwords
└─ No cracking needed = Instant access
3️⃣ Compilation Amplification
├─ Original: 13.5M records
├─ Merged into Collection #1-#5: 73+ files
└─ Still circulating in 2025
📋 What Was Exposed:
├─ Email addresses
├─ Passwords (plaintext)
├─ IP addresses
├─ Account creation dates
└─ Hosted website URLs
🔄 Real Impact Timeline:
2014 → User signs up for 000webhost
2015 → Breach happens
2019 → Data added to Collection #1
2024 → Credentials tested on Gmail
2025 → Account access possible 10 years later
🛡 How to Check Your Exposure:
Search your email on Intelligence Security.
If you had a 000webhost account:
├─ Change passwords on ALL sites
├─ Enable 2FA everywhere
├─ Check for unauthorized access
└─ Use unique passwords per site
One breach from 2015 = Still a risk in 2026.
SEARCH - http://intelligencesecurity.io/search
5 · 975 · Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
🌐 Domain Recon: Mapping a Company's Digital Footprint
What can you discover from a single domain name?
We ran uber.com through Domain Recon.
📊 Results:
├─ 🔗 Subdomains: 778 discovered
├─ 📧 Emails: 18,170 found
└─ 🌍 URLs: 20,740 indexed
Total: 39,688 data points
🔗 Subdomains reveal infrastructure:
├─ 🏢 Authentication
│ ├─ auth.uber.com
│ └─ accounts.uber.com
│
├─ 💻 Development
│ ├─ api.uber.com
│ ├─ developers.uber.com
│ ├─ ci.uber.com (CI/CD pipeline)
│ └─ devbuilds.uber.com
│
├─ 🏢 Internal Systems
│ ├─ corp.uber.com
│ ├─ dashboards.uber.com
│ └─ engineering.uber.com
│
└─ 🌍 Regional
├─ cn.uber.com (China)
├─ de.uber.com (Germany)
└─ fr.uber.com (France)
📧 Emails reveal organizational structure:
├─ 🎧 Support Teams
│ ├─ [email protected]
│ ├─ [email protected]
│ └─ [email protected]
│
├─ 📋 Departments
│ ├─ [email protected]
│ ├─ [email protected]
│ └─ [email protected]
│
└─ 🔒 Security
└─ [email protected]
💡 Why Domain Recon matters:
🛡 For Security Teams:
├─ Discover forgotten subdomains
├─ Find exposed internal systems
└─ Map your external footprint
🔍 For OSINT Researchers:
├─ Map organizational structure
├─ Understand regional operations
└─ Identify department patterns
🎯 For Authorized Assessments:
├─ Enumerate targets systematically
├─ Discover dev/staging environments
└─ Find authentication endpoints
📋 What we found in 39K+ results:
├─ Internal CI/CD and dev infrastructure
├─ Email patterns by department
├─ Regional operations across 50+ countries
└─ Naming conventions and structure
Run Domain Recon on your own domain.
You might be surprised what's publicly visible.
🔗 DEMO https://intelligencesecurity.io/search/demo/domainrecon
🤖 https://t.me/intelligencesecurityiobot
11 · 1.2K · Intelligence X Security Search
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
📊B2B Data Brokers - The Industry Trading Your Information
Did you know companies exist solely to collect and sell professional data?
We searched apollo.io on Intelligence Security:
→ 6,940 results found
📂 What's exposed:
├─ 🔑 Passwords: 403 files
├─ 🍪 Cookies: 537 files
├─ ⌨️ Autofills: 114 files
├─ 📁 Browser data: 990 files
├─ 📋 Combo lists: 2,164 files
└─ 📄 Other: 2,696 files
🏢 B2B platforms commonly found in leaks:
├─ Apollo.io → 200M+ professional contacts
├─ Clearbit → Business data enrichment
├─ Exactis → 340M records leaked (2018)
└─ People Data Labs → 1.2B records exposed
📋 What these databases contain:
├─ Corporate & personal emails
├─ Direct phone numbers
├─ Job titles & departments
├─ Employment history
├─ Linked social profiles
├─ Company revenue estimates
└─ Technology stack information
⚠️ The risk:
When data brokers get breached, professional intel becomes accessible beyond sales teams:
├─ Detailed org charts exposed
├─ Executive contact info circulating
├─ Corporate structures mapped
└─ Years of enriched data in one place
🛡 How to protect your organization:
├─ Search your corporate domain regularly
├─ Request data removal from brokers (GDPR/CCPA)
├─ Monitor executive exposure
├─ Train employees on data sharing risks
└─ Implement email obfuscation policies
Your professional data is a product. Know where it's circulating.
🔗 https://intelligencesecurity.io/search
🤖 https://t.me/intelligencesecurityiobot
9 · 1.6K · Intelligence X Security Search
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
🔍 DOMAIN RECON: http://onlyfans.com — 208 subdomains mapped with a single query
OnlyFans processes billions in creator payments annually.
We ran Domain Recon through our platform and verified each subdomain.
📊 Results:
├─ 📡 208 subdomains discovered
├─ 🌐 18 resolving to live IPs
└─ ☁️ Infrastructure across 3 cloud providers
🔎 Key findings by category:
🔐 Authentication & Identity:
├─ http://oauth.onlyfans.com → Auth endpoints
├─ http://id.onlyfans.com → KYC system (Azure)
└─ http://autodiscover.onlyfans.com → Exchange services
⚙️ Internal Tools:
├─ http://bug2.onlyfans.com → Error tracking (Sentry)
├─ http://webhook-beta.onlyfans.com → Beta webhooks
└─ Multiple staging/test environments detected
📺 Streaming Infrastructure:
├─ 12+ live streaming servers identified
├─ Multiple stream processors and converters
├─ Geo-distributed nodes (US, UK, DE, SG, CA)
└─ Release canary pipeline detected
🛒 Third-Party Integrations:
├─ http://store.onlyfans.com → Shopify
├─ http://status.onlyfans.com → StatusPage
└─ KYC provider integration visible
💡 What this reveals for security teams:
├─ Full tech stack identification
├─ Cloud provider distribution mapped
├─ Development/staging environments discoverable
├─ Third-party dependencies exposed
└─ Geographic infrastructure layout visible
One query. No scanning. Just public intelligence.
🔗 https://intelligencesecurity.io/en/search
🤖 https://t.me/intelligencesecurityiobot
12 · 2.8K ·