Paste anything. It works out what it is.
One command bar takes indicators, entities, companies and code. There is no syntax to learn and nothing to configure before your first answer.
Forensia · by OverWatch Labs
Forensia correlates live public intelligence into a single investigation console. Start with anything suspicious, an IP, a domain, a hash, a CVE, a repository, and get a verdict with the evidence that produced it.
VerdictC2-linked
The investigation
The console stays put. Watch what happens to a single indicator as it travels from a suspicious string to a decision you can defend.
One command bar takes indicators, entities, companies and code. There is no syntax to learn and nothing to configure before your first answer.
Forensia queries its sources in parallel and shows you which ones agree, which returned nothing, and which do not apply. Silence from a source is reported as silence, never folded into the answer.
The answer leads with the call, then shows its work: what was found, where it came from, and exactly what Forensia could not verify. That last part is what makes the first part usable.
Pivot · network
Hosting and routing
What else sits on the same infrastructure, and how long it has been there.
Pivot · naming
Domains and URLs
Names that resolve here, and the pages they were serving.
Pivot · samples
Files and reporting
Samples seen calling home, and the public reporting that mentions them.
A verdict is rarely the end of the work. Every result hands you the pivots worth taking next, so one indicator becomes an investigation instead of a dead end.
Coverage
One field takes all of them. What comes back is shaped by what you gave it.
185.220.101.4
Sightings and classification, command-and-control signal, hosting and routing context, related public reporting.
acme-login[.]com
Lookalike and abuse signal, registration and resolution context, the infrastructure it points at.
hxxps://acme-login[.]com/sso
Destination and delivery analysis, phishing and staging signal, where the link actually ends up.
a94f2b1c9e3d0871…
Known-sample matches, family and behaviour tags, first-seen context and the reporting around it.
CVE-2026-3218
Known-exploited status from CISA KEV, affected products, and whether anyone is actually using it.
github.com/example/tool
Code and execution-path review, so you can read what a tool does before you run it.
a victim or group name
Public leak-site claims connected to victim, group and the reporting context around the campaign.
Who uses it
The evidence is the same. The path through it, and the action at the end, is not. Drag to see them all.
Turn an unfamiliar indicator into an escalate, block, monitor or close decision, with the sightings and infrastructure context behind it.
"Is this alert actionable right now?"
Connect indicators, reports and actors into one investigation instead of a folder of unrelated lookups.
"Does this connect to anything we already track?"
Check a lookalike domain or a suspicious page against current abuse signal before you send the takedown.
"Is someone impersonating us right now?"
Separate the CVEs being exploited in the wild from the hundreds that are not, before you plan the sprint.
"Is this one actually being used?"
Read the execution path of a repository or a tool before it reaches your machine or your pipeline.
"Is this safe to pull in?"
Answer a client question in minutes with evidence they can read, rather than a screenshot of a tool.
"Can I show my working on this?"
Translate an indicator into exposure, in language that survives the meeting it gets repeated in.
"What does this actually mean for us?"
Trace a claim back to the source that made it, with the provenance attached and the gaps stated.
"Can I cite this, and where did it come from?"
Access
01 · Anonymous
One-off lookups across IP, domain, URL, hash and CVE, with evidence, provenance and honest unknowns. No sign-in, no card.
Free, and staying that way
02 · Free account
Everything in the public lookup, plus saved investigations, so repeat research builds on itself instead of starting over.
Free
03 · Pro
Continuous coverage, deeper investigation modules, briefings and API workflows for teams that do this every day.
Early access, coming soon
Forensia
The public lookup is free, needs no account, and is the fastest way into every part of Forensia. Or talk to the operators who built it.