|
In This Issue
| ▪ |
Domain Search — the largest multi-source domain search in the industry, combining bespoke UserSearch techniques with integrated data sources including Shodan, HudsonRock, SpamHaus and IntelX |
| ▪ |
Favicon Intelligence — find phishing clones and hidden infrastructure from a site icon |
| ▪ |
Linked IDs — connects websites through 83 tracking IDs across 83 advertisers — a technique unique to UserSearch |
| ▪ |
Fully AI-integrated — question the results in the dashboard, or hand the whole job to SargeBot |
| ▪ |
Free for premium subscribers — run Domain Search at no extra cost |
| ▪ |
Free live webinar, 15 September — Telegram, Reddit & open forum intelligence with Mark Bentley, ex-NCA & CEOP — register free |
usersearch.com · Member login · Watch the walkthrough
|
▪ The Headline Update
|
Domain Search 2.0
Enter any website or domain and UserSearch investigates it across 18 different data types and third-party data sources — who owns it, what it runs, where it's been, who it's linked to, and what's leaked from it.
Run everything at once, or pick and choose your sources. Every result lands in the dashboard for review — or hand the entire investigation to SargeBot and let the AI take it from there.
|
|
Watch the v2.0.22 update walkthrough
|
A completed Domain Search in the dashboard
|
|
Free For Premium
Deselect the two breach-data sources (IntelX and Dehashed) and the entire search is completely free for premium subscribers.
|
|
Pick & Choose
Run all 18 data types in one go, or select only the sources your investigation needs.
|
| |
|
Ask The AI
Question the on-screen results directly in the dashboard — or pass the whole search to SargeBot and let it run the investigation end to end.
|
|
One-Click Reports
Export the full results to PDF, PDF+ or CSV with a single click.
|
▪ Two Capabilities You Won't Find Anywhere Else
|
Flagship — Bespoke Technique
Favicon Intelligence
A site's icon lives on the server, not the domain name — so hunting the web for that icon finds sites the domain itself never mentions. Domain Search fingerprints the target's favicon and scans for every other server using it, exposing phishing clones and impersonating sites built on stolen branding — and, just as usefully, a domain's own secondary services: staging copies, mirrors and related infrastructure nobody documented.
The icon is hashed in every format the host-search engines expect — searched automatically via Shodan and HunterHow, with ready-made search links prepared for the engines that can only be searched by hand.
|
|
Flagship — Exclusive To UserSearch
Linked IDs
Linked IDs scans a site — and its historic archives — for 83 tracking IDs across 83 advertisers, then finds every other website carrying the same ones — revealing sites owned by the same person, even with no visible link between them. Unique and bespoke to UserSearch.
|
Linked IDs connecting sites through shared identifiers
|
▪ The Full Domain Search Toolkit
Infrastructure & Footprint
|
DNS Records
Where the domain points — hosting, email and name servers, plus SPF, DKIM and DMARC checks. Missing safeguards can flag a throwaway domain.
|
|
Subdomains & Certificates
Subdomains from public SSL records — mail servers, staging sites, admin panels linked from nowhere, including ones offline for years.
|
| |
|
Passive DNS
Every IP the domain has ever resolved to, with first- and last-seen dates — spot owner changes, migrations and shared infrastructure.
|
|
Hosts
Internet-facing servers identifying as the domain — open ports, running software and known vulnerabilities, via Shodan.
|
History & Ownership
|
Ownership
Who has owned the domain, now and in the past — names, contact details and when each change took effect.
|
|
Archived Snapshots
Saved copies of the site going back years — read what a page said before it was edited or deleted.
|
| |
|
Observed URLs
Individual pages seen by public scanners — login pages, hidden sections and evidence of past phishing activity.
|
|
|
Threat & Reputation
|
Domain Reputation
A SpamHaus reputation score with tags explaining what the domain has been listed for — spam, phishing or malware.
|
|
Domain Threat
People connected to the domain whose machines were hit by infostealer malware — infections that often expose logins to the domain's own systems. Via HudsonRock.
|
| |
|
Malware URLs
Pages on the domain seen distributing malware — often a sign the site was compromised rather than built for it.
|
|
|
Breach & Leak Data — optional paid data sources
|
Paste Bins
Text on public paste sites mentioning the domain — credentials and internal documents often surface here first. Via IntelX. Sensitive credentials are never displayed.
|
|
Public Credentials
Breach records referencing the domain, often naming staff and customer accounts. Via Dehashed. Passwords are never displayed.
|
|
One search. Every source. One dashboard.
Shodan
HunterHow
HudsonRock
SpamHaus
urlscan.io
AlienVault OTX
CertSpotter
Web Archive
IntelX
Dehashed
UserSearch Exclusive Data
OSINT Industries
Epieos
Predicta Search
PIPL
Think-Pol
FaceCheck.id
GeoSeer
+ Many More
|
▪ In Other News — Live Free Webinars
|
Webinar 03 In The Series — 15 September, 4:00pm UK
Telegram, Reddit & Open Forums: Unlocking What People Say When They Think Nobody's Watching
Mark Bentley — ex-UK National Crime Agency and CEOP, a career police officer who specialised in online investigations — shows you, step by step, how to turn forum platforms into a rich source of intelligence: from harvesting posts and uncovering hidden networks to monitoring threats in real time, all without exposing yourself.
Covered
| ▪ |
Investigative opportunities — why open forums remain one of the most underused sources of intelligence, and what they reveal that social media can't |
| ▪ |
Real-time threat monitoring — continuous monitoring of forum platforms to catch threats, leaks and chatter as they happen |
| ▪ |
Advanced technical tradecraft — the tools and methods professionals actually use across open forum platforms |
| ▪ |
Harvesting forum data — capturing posts, comments, messages, aliases and timestamps, and mapping the networks between users |
| ▪ |
OPSEC & data capture — protecting your identity and infrastructure while you collect, without tipping off your target |
| ▪ |
Evidencing your findings — court-ready capture with tamper-proof audit trails using UserSearch Forensic Capture |
Whether you're an investigator, fraud examiner, journalist or security analyst — learn how to unlock the intelligence hiding in plain sight. Live, free to attend, and registration is open now.
Register Free →
|
|
Missed The Earlier Sessions?
Webinar 01 — How to Investigate a Suspect Online: A Live Walkthrough — watch on YouTube
Webinar 02 — Mastering Visual OSINT: How to Turn Any Image into Actionable Intelligence — watch on YouTube
|
v2.0.22 is live now. Run your first Domain Search and see the full picture for yourself.
|