Intelligence Vault · Free · No Account Required

Search threat intelligence.
Right now, for free.

Look up any indicator, CVE, domain, hash, or IP. Trace it to threat actors, campaigns, and source articles — no account needed.

Free · No sign-up required · IOCs, CVEs, domains, hashes, techniques

Threat Actor ProfilesSource MaterialIOC + CVE Lookup

The Vault — Three Intelligence Surfaces

More than indicator lookup.

Source Material

Global threat reporting, full text.

Full-text search across threat advisories, vendor blogs, and government publications. Filter by geopolitical origin bloc, sector, publication tier, or date. Search expands synonyms automatically — “phishing” finds spearphishing, credential harvesting, and BEC variants.

Sources Monitored
Explore source material →

Threat Actor Profiles

Profiles, not just names.

Searchable, tiered profiles for every tracked threat actor and campaign. Each profile maps known aliases, suspected origin, attributed campaigns, MITRE ATT&CK techniques, associated IOCs, and every article in the corpus that mentions them.

Campaign-linkedWell documentedDocumented
Browse threat actors →

Indicators, CVEs & Techniques

One box for IOCs, CVEs, and TTPs.

Paste an IP, domain, file hash, CVE ID, or technique name — results are grouped by type. IOCs show actor attribution and active status. CVEs show CISA KEV inclusion, ransomware use, and linked actors. Techniques map to the actors and campaigns that use them.

IPv4 / IPv6DomainHashCVETechnique
Search indicators →

Featured Threat Actors

View all →

Recent Source Material

View all →

With An Account

From raw reporting to finished intelligence product.

The Vault gives you the data. An account gives you the workspace to structure it, annotate it, and turn it into something you can share.

01 · Investigations

A workspace for everything you find.

Collect actors, IOCs, CVEs, articles, and techniques into a named investigation. Set a scope — sector, technology, actor, or raw indicator. An article feed surfaces matching new reporting automatically as it's ingested. Triage articles through a kanban board (New → Reviewing → Included → Archived), add inline annotations, and build a structured evidence base.

02 · Reporting

Build the brief. Export it.

The report builder pulls from your investigation — drag sections to reorder (Executive Summary, Sector Exposure, Actor Profiles, IOC Inventory, TTP Analysis). Generate AI-written summaries at four tiers: CISO-level, Manager, Analyst, or SOC. Save report templates for repeating engagements. Export to a formatted Word document (.docx), ready to send.

Get access

What's Free

Vault access is free. No account, no limit.

Free · No Account

The entire Vault — IOC, CVE, domain, and hash lookup
Threat actor profiles and campaign maps
Full-text search across the source material corpus
All indicator, technique, and vulnerability data

Requires Account

Creating and managing investigations
AI-generated report summaries
Report builder and .docx export
Saved searches and alert preferences
Open the Vault — FreeCreate AccountCompare plans →