SearchIn for threat intelligence analysts
Infrastructure, leaks, and actor identifiers without vendor portal fatigue.
Threat intel analysts use SearchIn to enrich IOCs and actor-linked identifiers — domains, IPs, emails, usernames — across WHOIS, DNS, host intel, and breach sources. Keep enrichment in investigations and pay only for the queries that advance a report.
Who it's for
- CTI analysts enriching IOCs and actor infrastructure
- Managed intel teams supporting SOC escalations
- Researchers tracking phishing and malware C2 domains
- Analysts who want API access to the same providers as the UI
Common SearchIn workflows
Product-led workflows that match how this role typically uses SearchIn.
Recommended integrations
Start with these SearchIn providers — each has a full capability page.
Frequently asked questions
Does SearchIn replace a TIP or MISP?
No. Use SearchIn to enrich identifiers; keep your threat intel platform for storage, sharing, and detection content.
Can enrichment be automated from our pipeline?
Yes. Call the SearchIn API from enrichment workers using the same provider contracts as the UI.
Which providers are most relevant for CTI?
Domain/DNS (SecurityTrails, WhoisXML, Whoxy), host intel (Shodan), and breach databases for email/username context.
How do we control spend on enrichment?
Prepaid wallet with per-query pricing. Team wallets help CTI squads share a budget without per-seat vendor contracts.
Related use cases
Ready to run your first search?
Open SearchIn, pick a provider, and pay only for the queries you run.