Threat Intelligence Explore →

Open-Source Threat Intelligence

Research domains, IP addresses, infrastructure and abuse reports from one search platform. UserSearch gives security teams source-attributed findings they can verify, organise into Cases and report on.

One Platform for Security Research

Threat Intelligence & Open-Source Research

Security research usually means moving between a dozen tools. UserSearch brings specialist Search types and 100+ third-party data sources into one workflow, so an analyst can go from a domain or an IP address to the registrations, hosting and abuse reports around it.

Alongside your existing security tools, UserSearch helps you research threats on demand: lookalike domains, phishing infrastructure, internet-facing services and reputation data. Every finding shows its source, so your team can verify it before acting.

How UserSearch Helps

Three Ways Security Teams Use It

Infrastructure Research

Look up domains, IP addresses and internet-facing services through Domain Intelligence, IP Intelligence and Cyber Intelligence. See registrations, DNS records, hosting and the services a host presents to the public internet.

Phishing & Lookalike Domains

Find typosquatted and lookalike domains, the sites hosted on them and the infrastructure behind them. Run the search whenever you need to, and use the source-attributed findings to support a takedown request.

Case-Based Analysis

Bring findings from different data sources into one Case, with the source shown on every result. Your team reviews, verifies and prioritises what matters, then generates a Report from the Case bookmarks.

Threat Intelligence, On Demand

UserSearch brings specialist Search types and integrated data sources into one workflow. Each search runs when an analyst asks for it, and its Credit cost is shown before it runs.

Results arrive with their source attached, so they can be corroborated and cited in your reporting.

Brand Abuse Research

Research how a brand is being imitated: lookalike domains, imitation websites and copied brand assets. Findings are attributed to their source, ready to support takedown requests to registrars, hosts and marketplaces.

A result is saved to a Case only when you choose to save it, so your team keeps a clean record of what was found, where and when.

From Results to Reports

OneScan runs one input across the data sources you select, and SargeBot, the integrated AI assistant, helps you review what comes back.

Bookmark what matters into a Case and generate a Report from it, with the source shown against every finding.

Where It Fits

Key Use Cases & Applications

Six common research tasks for security and threat intelligence teams.

Phishing Infrastructure

Map the infrastructure behind a phishing campaign:

  • Identify typosquatting and lookalike domains
  • Find sites that imitate a brand
  • Review registration, DNS and hosting records
  • Link related domains through shared infrastructure

Domain Intelligence

Understand a domain and what sits behind it:

  • Registration and expiry records
  • DNS records and DNS history
  • Hosting provider and network ownership
  • Related domains and subdomains

Brand Abuse Research

Find where a brand is being imitated:

  • Search marketplaces for counterfeit listings
  • Find unauthorised use of logos and brand assets
  • Identify imitation apps and storefronts
  • Collect source-attributed findings for takedown requests

Threat Indicator Research

Check an indicator against reputation and abuse data:

  • Look up IP address and domain reputation
  • Review blocklist and abuse reports
  • Compare what independent sources say
  • Keep findings together in one Case

Attack Surface Research

See how internet-facing infrastructure looks from the outside:

  • Discover internet-facing assets and shadow IT
  • Check for outdated third-party components
  • Search public mentions of infrastructure
  • Identify misconfigured cloud services

Third-Party Due Diligence

Research suppliers and partners before you connect to them:

  • Corporate records and registrations
  • Domain and infrastructure review
  • Sanctions and watchlist screening
  • A Report your team can file

Common Questions

Answers to common questions from security and threat intelligence teams.

How does UserSearch support a security team?

Pick the Search type and Module that fit the question — a domain, an IP address or another supported identifier — and UserSearch brings together what the selected data sources hold. Coverage and refresh rates vary by source, so corroborate what you find before acting on it.

What kind of data can a security analyst expect to see?

Registration, DNS and hosting records for domains, the services an IP address presents to the public internet, corporate records, and reputation and abuse data. It is drawn from third-party and public sources and is best treated as leads to verify.

What's your platform's approach to data retention?

We keep only what's genuinely needed to run the platform. Results are saved only if you choose to save them, and our Privacy Policy sets out exactly what is recorded.

Does your platform comply with data protection laws?

We'd rather confirm than claim — email [email protected] and we'll verify any certification or compliance status you need before you rely on it.

Ready to try it on a real research task?

Create an account, or ask us for a walkthrough of the Search types security teams use most.