Resources

Publicly available security research tools

Below is a list of publicly available resources I have experience with. This list is certainly not exhaustive. Also note that IOCs can be malicious in the absence of hits/reports at these sources. However, they can help you build context while researching or performing analysis.

General IOC validation

Resources will be presented in Chrome’s saved search format, where the search term is replaced with %s.

ResourceFile hashDomainIP addressURLNotesSearch FormatAPI Documentation
AbuseIPDBhttps://www.abuseipdb.com/check/%shttps://docs.abuseipdb.com/
VirusTotalhttps://www.virustotal.com/gui/search/%shttps://docs.virustotal.com/reference/overview
Spur Context APICan identify residential/anonymizing proxy and VPN use. Free tier does not include API keys, but can be used to search in the browser.https://app.spur.us/context?q=%shttps://docs.spur.us/context-api
URLScanSearches can show full HTTP request chains, redirects, and other behaviors related to a URL.https://urlscan.io/search/#%shttps://urlscan.io/docs/api/

Network exposure

The following tools can be used to assess network exposure, such as ports or services open to the internet.

ResourceSearch FormatAPI Documentation
Shodanhttps://www.shodan.io/host/%shttps://developer.shodan.io/
Censyshttps://search.censys.io/hosts/%shttps://search.censys.io/api

Other network tools

Hurricane Electric BGP Toolkit