Open-Source Threat Intelligence
Research domains, IP addresses, infrastructure and abuse reports from one search platform. UserSearch gives security teams source-attributed findings they can verify, organise into Cases and report on.
Threat Intelligence & Open-Source Research
Security research usually means moving between a dozen tools. UserSearch brings specialist Search types and 100+ third-party data sources into one workflow, so an analyst can go from a domain or an IP address to the registrations, hosting and abuse reports around it.
Alongside your existing security tools, UserSearch helps you research threats on demand: lookalike domains, phishing infrastructure, internet-facing services and reputation data. Every finding shows its source, so your team can verify it before acting.
Three Ways Security Teams Use It
Infrastructure Research
Look up domains, IP addresses and internet-facing services through Domain Intelligence, IP Intelligence and Cyber Intelligence. See registrations, DNS records, hosting and the services a host presents to the public internet.
Phishing & Lookalike Domains
Find typosquatted and lookalike domains, the sites hosted on them and the infrastructure behind them. Run the search whenever you need to, and use the source-attributed findings to support a takedown request.
Case-Based Analysis
Bring findings from different data sources into one Case, with the source shown on every result. Your team reviews, verifies and prioritises what matters, then generates a Report from the Case bookmarks.
Threat Intelligence, On Demand
UserSearch brings specialist Search types and integrated data sources into one workflow. Each search runs when an analyst asks for it, and its Credit cost is shown before it runs.
Results arrive with their source attached, so they can be corroborated and cited in your reporting.
Brand Abuse Research
Research how a brand is being imitated: lookalike domains, imitation websites and copied brand assets. Findings are attributed to their source, ready to support takedown requests to registrars, hosts and marketplaces.
A result is saved to a Case only when you choose to save it, so your team keeps a clean record of what was found, where and when.
From Results to Reports
OneScan runs one input across the data sources you select, and SargeBot, the integrated AI assistant, helps you review what comes back.
Bookmark what matters into a Case and generate a Report from it, with the source shown against every finding.
Key Use Cases & Applications
Six common research tasks for security and threat intelligence teams.
Phishing Infrastructure
Map the infrastructure behind a phishing campaign:
- Identify typosquatting and lookalike domains
- Find sites that imitate a brand
- Review registration, DNS and hosting records
- Link related domains through shared infrastructure
Domain Intelligence
Understand a domain and what sits behind it:
- Registration and expiry records
- DNS records and DNS history
- Hosting provider and network ownership
- Related domains and subdomains
Brand Abuse Research
Find where a brand is being imitated:
- Search marketplaces for counterfeit listings
- Find unauthorised use of logos and brand assets
- Identify imitation apps and storefronts
- Collect source-attributed findings for takedown requests
Threat Indicator Research
Check an indicator against reputation and abuse data:
- Look up IP address and domain reputation
- Review blocklist and abuse reports
- Compare what independent sources say
- Keep findings together in one Case
Attack Surface Research
See how internet-facing infrastructure looks from the outside:
- Discover internet-facing assets and shadow IT
- Check for outdated third-party components
- Search public mentions of infrastructure
- Identify misconfigured cloud services
Third-Party Due Diligence
Research suppliers and partners before you connect to them:
- Corporate records and registrations
- Domain and infrastructure review
- Sanctions and watchlist screening
- A Report your team can file
Common Questions
Answers to common questions from security and threat intelligence teams.
How does UserSearch support a security team?
Pick the Search type and Module that fit the question — a domain, an IP address or another supported identifier — and UserSearch brings together what the selected data sources hold. Coverage and refresh rates vary by source, so corroborate what you find before acting on it.
What kind of data can a security analyst expect to see?
Registration, DNS and hosting records for domains, the services an IP address presents to the public internet, corporate records, and reputation and abuse data. It is drawn from third-party and public sources and is best treated as leads to verify.
What's your platform's approach to data retention?
We keep only what's genuinely needed to run the platform. Results are saved only if you choose to save them, and our Privacy Policy sets out exactly what is recorded.
Does your platform comply with data protection laws?
We'd rather confirm than claim — email [email protected] and we'll verify any certification or compliance status you need before you rely on it.
Ready to try it on a real research task?
Create an account, or ask us for a walkthrough of the Search types security teams use most.