BinaryEdge tool
An internet-wide scanning platform and search engine similar in purpose to Shodan/Censys — exposed services, vulnerabilities and threat intelligence indexed from continuous global scans.
Everything the team reaches for — CTF, red team, blue team, OSINT, forensics, wireless and living-off-the-land, plus the one-liners we retype every engagement. Search, filter by tag, and click any code block to copy it.
An internet-wide scanning platform and search engine similar in purpose to Shodan/Censys — exposed services, vulnerabilities and threat intelligence indexed from continuous global scans.
Free breach-data search engine with hash-based password lookups alongside email and username exposure checks.
Search-results clustering engine that groups a large result set into labelled topic clusters, useful for making sense of a broad OSINT search dump.
An internet-wide device and certificate search engine built from continuous internet scanning — heavily used for attack-surface discovery and certificate-based host enumeration.
Internet-wide scan search engine for hosts, services and certificates, built from continuous scanning of the public IPv4 space plus a hosted certificate-transparency index.
Open, petabyte-scale repository of web crawl data, usable to find historical pages, linking patterns or exposed content at a scale no single scraper could reach.
Threat-intel-flavoured internet asset search engine combining Shodan-like banner search with IP risk scoring, phishing/malicious-URL lookups and domain intel.
Comprehensive bibliography database of computer-science publications, the standard way to trace an author's full publication history or a paper's exact venue and year.
Internet asset search engine (Huawei/Baimaohui-affiliated) with its own query syntax for finding hosts by banner, title, certificate or icon hash.
Attack-surface search engine and monitoring platform that continuously tracks a company's exposed hosts, subdomains and services.
General academic search engine widely used to trace citations of a security paper and find who has since built on or broken a given technique.
Internet-asset search engine with a particular focus on IoT/ICS device fingerprinting, alongside general host/service banner search.
Free people- and username-search engine that aggregates social profiles, images and public records for a name or handle into one results page.
Full-text search across the Internet Archive's millions of archived books, documents and software — distinct from the Wayback Machine's URL-based page snapshots.
Breach-data search engine checking whether an email, username or password has surfaced in a known leak, with a public API for programmatic checks.
Search engine that lets you strip out the top N most popular results, surfacing the obscure long tail a normal search buries — handy in dorking when the top results are all noise.
Internet-scanning search engine covering hosts, domains, certificates and WHOIS, positioned as a cheaper alternative to Shodan/Censys with a similar dork syntax.
Cross-border investigative search engine over leaked documents, corporate registries and sanctions data, built by the Organized Crime and Corruption Reporting Project.
Scrapes multiple dark-web search engines at once for a search term and consolidates the .onion results into one list.
onionsearch --search "keyword" --output results.txt
Cyber defense search engine that collects internet-wide scan, passive DNS and threat data and exposes it via a query language and API for attack-surface discovery.
Source-code search engine that lets you grep the indexed web for a snippet — a tracking ID, a JS library string or a signature left by a specific web shell/skimmer.
Free threat-intelligence search engine that correlates indicators pulled from a wide range of open-source feeds into a single scored lookup.
Self-hostable, privacy-respecting metasearch engine that aggregates results from many search backends without tracking the querier — useful for dorking without one engine seeing every query.
AI-assisted academic search engine with citation graphs and influence scoring, an alternative lens on the same literature Google Scholar indexes.
The original internet-wide device search engine — indexes banners from scanning the whole IPv4 space, so you can search for exposed services, devices and misconfigurations by product, port or CVE.
shodan search "apache" country:DK
Code search and navigation engine across many repositories at once, self-hostable or hosted — useful for tracing where a leaked secret or vulnerable pattern is actually used.
Privacy-focused search engine that proxies Google's index without forwarding the searcher's identity to Google, useful for dorking without linking queries to an account.
One of the oldest reverse image search engines, strong at tracing where an image first appeared online and how it has been reused since.
Vulnerability intelligence search engine tracking newly disclosed CVEs, linked exploits and vendor patches, with free email alerts by product.
Chinese-run internet device/service search engine indexing banners, ports and web components, comparable in scope to Shodan/Censys with different vantage points.