OVERVIEW
OPERATIONAL
|
--:--:--
MONARX // GLOBAL INTELLIGENCE NETWORK
LIVE 00:00:00 UTC
// TOP SECRET / SI / TK / NOFORN / MONARX EYES ONLY //
IOCs ANALYZED
0
extracted entities
ACTIVE THREATS
0
0 new today
SIGNALS INTERCEPTED
0
matched exposures
ORBITAL ASSETS
0
tracked live · 24/7
⦿ INTEL STREAM
SOURCES:
1
OSINT SEARCH
Netlas · VirusTotal · GreyNoise · AbuseIPDB · Hunter.io · Censys · GOD EYE Map
CHECKING…
2
THREAT INTELLIGENCE
OTX AlienVault · URLhaus · LeakIX · Cisco Talos · MITRE ATT&CK · OpenPhish · Pulsedive
FREE SOURCES
3
🧅
DARK WEB INTELLIGENCE
Tor Browser · Phishing Feed · IntelX · DeHashed
CHECKING…
4
DARK FORUM INTELLIGENCE
Ransomware tracker · CVE intel · exploit intel · 20K+ victims
LIVE FEEDS
6
🛰
SATELLITE TRACKER
Starlink · GPS · ISS · OneWeb · Real-time SGP4 orbital propagation
LIVE DATA
7
📡
MESSENGER INTELLIGENCE
NumVerify carrier lookup · Cell tower triangulation · Phone OSINT
CHECKING…
⟟ RECENT QUERY LOG
0 ENTRIES
META SEARCH
Upload an image or any file to extract every embedded metadata tag — EXIF, GPS, camera, author, timestamps, document properties, hashes and more. Files are analysed on your server and never stored.
Drop a file here, or click to browse
Images · PDF · Office docs · audio · video · any file — up to 64 MB
🛰 LIVE SATELLITE TRACKER LOADING TLE DATA
Loading satellites...
STARLINK
ONEWEB
GPS
ISS / CREWED
IRIDIUM
OTHER
FETCHING TLE DATA FROM CELESTRAK
Initializing orbital mechanics...
SATELLITES — CLICK TO SELECT
abuse.ch · malware URL / host / hash intelligence
checking key…
AUTO
openphish.com · community phishing feed
public feed · no key
Enter a full URL and press SEARCH — OpenPhish checks whether the URL (or its host) is in the live community phishing feed.
internetdb.shodan.io · IP exposure — ports · CVEs · software · tags
public API · no key
Enter an IP — Shodan InternetDB returns exposed ports, known CVEs, detected software (CPEs), hostnames, and tags. No API key required.
threatfox.abuse.ch · IOC lookup — malware C2 · hashes · domains · IPs
abuse.ch key
TRY: IP domain
Search ThreatFox for an indicator of compromise (IP, domain, URL, or file hash). Uses your shared abuse.ch Auth-Key — the same key also powers URLhaus and MalwareBazaar.
leakix.net · exposed services · open DBs · misconfig & leak intelligence
checking key…
HOST · IPv4
Pick an action above and press SEARCH — LeakIX indexes services, leaks, open DBs, phishing kits, and breach markers.
IP · Domain · Sender — No API key required · Powered by SenderBase
Enter an IP address, domain, or email sender address above to check its reputation across Cisco Talos threat intelligence.
⚔ MITRE ATT&CK — Intelligence Matrix
Enterprise adversary TTPs · techniques · threat groups · software · mitigations
CLICK TO LOAD
Techniques
Sub-Techniques
Threat Groups
Software / Tools
Quick Tactic Filter
Load ATT&CK data to see tactics →
🎯 APT Group Profiler — TTP Mapper
Select a threat actor · map all ATT&CK techniques · download Navigator layer
IDLE
OTX AlienVault — Threat Pulses
DARK WEB INTELLIGENCE OPS
ALL SOURCES FREE · NO PAYMENT REQUIRED · LIVE THREAT TRACKING
PHISHING URLS
🎣 PHISHING FEED
🌐 EXPOSURE SCAN
🦠 IOC LOOKUP
OPENPHISH — LIVE PHISHING INTELLIGENCE
Real-time phishing URL feed — completely free, no API key required
NOT LOADED
TOTAL PHISHING URLS
UNIQUE DOMAINS
LAST UPDATED
Phishing URL
Domain
Copy
Click LOAD PHISHING FEED to fetch live threat data
HACKERTARGET — FREE EXPOSURE SCANNER
DNS · Reverse IP · Host Discovery · HTTP Headers · GeoIP — 10 free queries/day per tool, no API key needed
» Target reconnaissance output will appear here » Enter an IP or domain and select a tool above » All tools use HackerTarget.com free API (10 req/day)
📖 TOOL REFERENCE
hostsearch — Find subdomains
dnslookup — A, MX, NS, TXT records
reverseiplookup — Other domains on IP
httpheaders — Server fingerprint
geoip — Country, city, ASN
whois — Registration data
⚠ Rate limit: 10 free queries/day per tool. Upgrade at hackertarget.com for more.
PULSEDIVE — FREE IOC ENRICHMENT
Enrich any IOC — IP, domain, URL, email — with threat context from Pulsedive. Uses the free demo key (no registration required).
🔍 SINGLE IOC LOOKUP
📡 LIVE THREAT FEEDS
Browse critical and high-risk active threats from Pulsedive's global feed aggregation.
Select a risk level to browse live threats
📱 Telegram
📞 Phone Intel
🔍 Username OSINT
💬 WhatsApp
📡 Platform Links
TELEGRAM Public channel / group / user lookup via t.me
ℹ️ Works for public channels, groups, and user profiles. Private accounts return limited data.
UNIFIED THREAT LIVE FEED
ℹ️ Merged live feed — server-scraped every 60s, newest-first.
TELEGRAM BOT DETECTOR
PHONE INTELLIGENCE Number format · carrier · country · type · OSINT
PHONE BLACKLIST CHECK
Cross-checks number against spam/scam phone databases
USERNAME OSINT Probe username across messenger & social platforms
WHATSAPP INTELLIGENCE
⚠ WhatsApp does not expose a public OSINT API. The tools below work without authentication.
CLICK-TO-CHAT LINK
MESSENGER PLATFORM OSINT RESOURCES
Defensive exposure monitoring. Add sources you may lawfully access and selectors (a client's domains, emails, brand). MonarX collects, extracts entities, and raises a signal when a selector matches — secrets shown redacted.

Customer Selectors

No selectors yet.

🔐 Authenticated Sources forums you have an account on

Log into the forum in your browser, copy the Cookie header (DevTools → Network → any request → Request Headers), and paste it below. Your password is never stored. Collection is read-only: it searches your keywords and reads matching threads — it never posts or messages.
Search field: paste the plain search page (e.g. https://forum.example/search.php) — MonarX drives the forum's own search form and handles its security token. Don't paste a results URL containing sid=; those are one-time links that expire.
No authenticated sources yet.

Exposure Signals

No signals yet. Add sources + selectors, then Run Collection.
Backend Service UNTESTED
Optional. Leave blank to use the service that hosts this page. Set a URL only if you run a separate backend. This enables full API support including header-based auth.
CORS Proxy (Optional — alternative to local backend) UNTESTED
Auto-rotation enabled. Leave this field blank and MonarX will automatically rotate through a built-in pool of public CORS proxies (corsproxy.io, allorigins, codetabs, thingproxy, cors.eu.org) — failing proxies are put on a 60-second cooldown; the last-working one is tried first.
Set your own prefix below to override the pool (e.g. https://corsproxy.io/?url=).
⚠ Public CORS proxies only work for APIs that accept their key in the URL (Hunter, OpenTracker). Header-auth APIs (Netlas, VirusTotal, AbuseIPDB) require the backend service.
Backup & Restore Keys
Your API keys are stored in this browser only. Download a backup file to keep them safe — then restore in one click on any browser or device (e.g. after switching between the IP address and your domain).
Danger Zone
■ Intelligence Newsletter Not yet generated
TLP:WHITE · UNCLASSIFIED · SINGLE-OPERATOR
MonarX Daily Threat Briefing
Click GENERATE to compile today's intelligence
THREAT LEVEL
🔎Keyword Watch
Keyword monitoring lives in Dark Collect — add your companies, domains and terms there once and they're watched continuously, with every hit classified (data leak · credentials · access sale) and alerted.
Ransomware Victims
Active IOCs
Cyber News Items
OSINT Queries Today
Ransomware Intelligence
Waiting for data…
Active Threat IOCs — ThreatFox · Feodo C2 · MalwareBazaar
Waiting for data…
📡Cyber News — BleepingComputer · Krebs · CISA · SANS · Unit42
Waiting for data…
🧅Dark Web & Hacker Group Activity
Waiting for data…
📋Operator OSINT Activity Log
Waiting for data…
MonarX OSINT Intelligence Platform · Self-hosted · Single-operator · TLP:WHITE
📡 INTEL FEEDS
☠ RANSOMWARE TRACKER
🔒 CVE INTEL
💥 EXPLOIT INTEL
🔑 FREE SOURCES
Threat Intelligence Feed Aggregator
12 curated live sources — CISA · BleepingComputer · Krebs · The Hacker News · The Record · Cisco Talos · Unit 42 · SecureList · SANS ISC · Dark Reading · Help Net Security · Schneier
Select a feed source above or click LOAD ALL FEEDS
Ransomware.live — Global Victim Tracker
NOT LOADED
Total Victims
Groups
Countries
Sectors
GLOBAL RANSOMWARE FLOW ● VICTIM ↗ FLOW ARC drag = rotate · wheel = zoom
◉ RANSOMWARE GLOBAL INTEL
3D · WGS84 · LIVE FEED
NIST NVD — CVE Vulnerability Intelligence
Official US National Vulnerability Database · CVSS scores · descriptions · affected products · free, no key required
NOT LOADED
Select a severity above or search by keyword to load CVE intelligence
💥 Exploit Intelligence — CISA KEV + NVD CVE
Official vulnerability databases — free, authoritative, updated daily by US government agencies
Select a source above to load exploit intelligence
📚 All Free Intelligence Sources
🌐 Dark Web Intelligence (No Key Required)
OpenPhish — Live phishing URL feed · openphish.com
HackerTarget — Network recon tools · hackertarget.com
Pulsedive (demo key) — IOC enrichment + threat feeds · pulsedive.com
⚠ Vulnerability Intelligence (No Key Required)
CISA KEV — Known Exploited Vulnerabilities catalog · cisa.gov
NVD (NIST) — National Vulnerability Database · nvd.nist.gov
Ransomware.live — Global ransomware victim tracker · ransomware.live
engine · unknown version · — modules · —

New Scan

domain ip email phone username asn
The footprint / investigate / passive profiles only activate modules whose per-module API keys have been configured on the engine. Start with All modules until keys are set.

Scans

No scans yet
Select a scan on the left, or start a new one.