SOC field reference

OSINT Field Toolkit

The tools I actually reach for once a phishing sample lands in front of me — tracing the sender and domain, pivoting on IPs and infrastructure, detonating suspicious links and attachments safely, checking phishing-specific feeds and breach data, and running down a threat actor's footprint. Built around Phase 5 — URL Analysis and Phase 6 — IOC Extraction, expanded to cover the full recon sweep.

Click any tool for usage notes, input/output, and an OPSEC reminder before you query it.

Email & Domain Investigation

Phase 5 · Phase 6

Trace the sender, the sending domain, and the header path before touching a single link.

IP & Infrastructure

Phase 5 · Phase 6

Once a link or attachment resolves to an IP, this is where I check who owns it, what's running on it, and what it's been used for.

URL & File Analysis

Phase 5

For when a link or attachment needs to run somewhere that isn't your own machine.

Phishing Intelligence & Reporting

Phase 5 · Phase 6

Feeds and scanners built specifically around phishing URLs — check if it's already known, and where to report it.

Threat & Breach Intelligence

Phase 6 · Attribution

Wider context once you have an IOC in hand — where it's been seen before and how it fits the bigger picture.

Frameworks & Methodology

Analysis & Reporting

Not lookup tools — the reference models that shape how you weigh an indicator and write the incident up once you've found it.

Social & Identity OSINT

Attribution

When an IOC points to a person, not just infrastructure — running down a handle or name across the web.

Image & Metadata Analysis

Phase 6

Verifying a logo, a screenshot, or a file's origin — where a picture has been before and what it's hiding.

No tools match that filter.