Free web tools

Browser-based OSINT and threat-intel sources.

This English page mirrors the Turkish free-tools shelf. It lists sources that can be opened from the browser and used as first signals, not as final proof.

20

tools

17

beginner-friendly

passive

default use

Define the input

Domain, IP, URL, hash, CVE, archive, or public claim.

Open the right source

Use the source family that fits the question.

Record context

Write the date, source, and what the result actually shows.

Verify again

Compare with at least one second source before reporting.

Choose first

What are you checking?

Free or public accessLow risk

Threat maps

Check Point Live Cyber Threat Map

What it helps with

Threat maps

Show details

What not to assume

Treat vendor telemetry as situational awareness, not attribution proof.

threat-maptelemetrysituational-awareness
Open source
Free or public accessLow risk

Threat maps

Kaspersky Cyberthreat Map

What it helps with

Threat maps

Show details

What not to assume

Treat vendor telemetry as situational awareness, not attribution proof.

threat-mapstatisticstelemetry
Open source
Free or public accessLow risk

Threat maps

FortiGuard Threat Map

What it helps with

Threat maps

Show details

What not to assume

Treat vendor telemetry as situational awareness, not attribution proof.

fortiguardthreat-mapmalware
Open source
Free or public accessLow risk

Threat maps

Radware Live Threat Map

What it helps with

Threat maps

Show details

What not to assume

Treat vendor telemetry as situational awareness, not attribution proof.

ddosthreat-maptelemetry
Open source
Free or public accessLow risk

Threat maps

Zscaler ThreatLabz Threat Map

What it helps with

Threat maps

Show details

What not to assume

Use this as an initial signal. Check date, source context, and a second source before reporting.

cloudthreat-mapzscaler
Open source
Free account may be requiredLow risk

IOC and threat intelligence

AlienVault OTX / LevelBlue OTX

What it helps with

IOC and threat intelligence

Show details

What not to assume

Use this as an initial signal. Check date, source context, and a second source before reporting.

iocotxthreat-intelligence
Open source
Free or public accessLow risk

OSINT directories

OSINT Framework

What it helps with

OSINT directories

Show details

What not to assume

Use this as an initial signal. Check date, source context, and a second source before reporting.

directoryosintlearning
Open source
Free or public accessLow risk

Threat context

SANS Internet Storm Center

What it helps with

Threat context

Show details

What not to assume

Use this as an initial signal. Check date, source context, and a second source before reporting.

sansdiarythreat-context
Open source
Free or public accessMedium risk

Malware URL feeds

Abuse.ch URLhaus

What it helps with

Malware URL feeds

Show details

What not to assume

Use this as an initial signal. Check date, source context, and a second source before reporting.

abusechmalware-urlurl
Open source
Free or public accessMedium risk

Malware intelligence

Abuse.ch MalwareBazaar

What it helps with

Malware intelligence

Show details

What not to assume

Use this as an initial signal. Check date, source context, and a second source before reporting.

malwarehashabusech
Open source
Free or public accessMedium risk

Botnet feeds

Abuse.ch Feodo Tracker

What it helps with

Botnet feeds

Show details

What not to assume

Use this as an initial signal. Check date, source context, and a second source before reporting.

botnetc2abusech
Open source
Free or public accessLow risk

Vulnerability tracking

CISA Known Exploited Vulnerabilities Catalog

What it helps with

Vulnerability tracking

Show details

What not to assume

Use this as an initial signal. Check date, source context, and a second source before reporting.

cisakevcve
Open source
Free or public accessLow risk

Vulnerability tracking

NVD

What it helps with

Vulnerability tracking

Show details

What not to assume

Compare CVE records with vendor advisories before prioritizing.

nvdcvecvss
Open source
Free or public accessLow risk

Vulnerability tracking

MITRE CVE

What it helps with

Vulnerability tracking

Show details

What not to assume

Compare CVE records with vendor advisories before prioritizing.

mitrecveidentifier
Open source
Free or public accessMedium risk

URL, hash, domain, and IP checks

VirusTotal

What it helps with

URL, hash, domain, and IP checks

Show details

What not to assume

Do not upload private or sensitive files to public scanning services.

reputationhashurldomain
Open source
Free account may be requiredMedium risk

Passive internet visibility

Shodan

What it helps with

Passive internet visibility

Show details

What not to assume

Use only as a passive visibility source for owned or authorized assets.

internet-exposureservicespassive
Open source
Free or public accessLow risk

IP context

GreyNoise Visualizer

What it helps with

IP context

Show details

What not to assume

Use this as an initial signal. Check date, source context, and a second source before reporting.

ipnoisescanner
Open source
Free account may be requiredLow risk

Domain and DNS history

SecurityTrails

What it helps with

Domain and DNS history

Show details

What not to assume

Use this as an initial signal. Check date, source context, and a second source before reporting.

dnsdomain-historysubdomains
Open source
Free or public accessLow risk

Certificate transparency

crt.sh

What it helps with

Certificate transparency

Show details

What not to assume

Certificate records can show historical or inactive assets.

certificate-transparencysubdomaindomain
Open source
Free or public accessLow risk

Web archives

Wayback Machine

What it helps with

Web archives

Show details

What not to assume

Archive time is not always the original publication time.

archiveverificationweb-history
Open source

Careful-use note

Free tools change terms, limits, and data quality over time. Use them as starting points. Do not upload sensitive material to public scanning services.

Move checked notes into a report