Forensia · by OverWatch Labs

Know what you're dealing with.

Forensia correlates live public intelligence into a single investigation console. Start with anything suspicious, an IP, a domain, a hash, a CVE, a repository, and get a verdict with the evidence that produced it.

185.220.101.4 Look up

VerdictC2-linked

3.9M+Indicators indexed
7+Artifact types
CitedEvery verdict
FreeNo account needed

The investigation

One paste, four moves.

The console stays put. Watch what happens to a single indicator as it travels from a suspicious string to a decision you can defend.

forensia · investigation consolelive intelligence
IPv4 185.220.101.4 Type detected automatically · no query language
InputPasted from an alert, unmodifiedAccepted
Parsed asIPv4 address, routable, not reservedAuto
Routed toReputation, network context and reporting surfaces5 checks
AccountNot required for a public lookupFree
01

Paste anything. It works out what it is.

One command bar takes indicators, entities, companies and code. There is no syntax to learn and nothing to configure before your first answer.

C2IntelFeedsCommand-and-control infrastructure signalSignal
MalwareBazaarNo sample currently linked to this addressNo data
CISA KEVNot applicable to this artifact typeN/A
Network contextHosting and routing context resolvedContext
CorrelationIndependent evidence kept attached to each claimCited
02

Every source, asked at once.

Forensia queries its sources in parallel and shows you which ones agree, which returned nothing, and which do not apply. Silence from a source is reported as silence, never folded into the answer.

C2-linked 185.220.101.4 Verdict first, then the evidence that produced it
EvidenceEach finding carries its source and the time it was seenAttached
Coverage gapStated in the result, not left for you to discoverExplicit
HostingLocation is where infrastructure sits, not who runs itNot attribution
No signalAbsence of evidence is never presented as safeNever "clean"
03

A verdict you can put in a ticket.

The answer leads with the call, then shows its work: what was found, where it came from, and exactly what Forensia could not verify. That last part is what makes the first part usable.

Pivot · network

Hosting and routing

What else sits on the same infrastructure, and how long it has been there.

Pivot · naming

Domains and URLs

Names that resolve here, and the pages they were serving.

Pivot · samples

Files and reporting

Samples seen calling home, and the public reporting that mentions them.

Next actionEscalate, block, monitor or close, with the evidence to justify itYour call
04

One answer opens the next question.

A verdict is rarely the end of the work. Every result hands you the pivots worth taking next, so one indicator becomes an investigation instead of a dead end.

Coverage

Seven things you can paste.

One field takes all of them. What comes back is shaped by what you gave it.

IP address 185.220.101.4 Sightings and classification, command-and-control signal, hosting and routing context, related public reporting.
Domain acme-login[.]com Lookalike and abuse signal, registration and resolution context, the infrastructure it points at.
URL hxxps://acme-login[.]com/sso Destination and delivery analysis, phishing and staging signal, where the link actually ends up.
File hash a94f2b1c9e3d0871… Known-sample matches, family and behaviour tags, first-seen context and the reporting around it.
CVE CVE-2026-3218 Known-exploited status from CISA KEV, affected products, and whether anyone is actually using it.
Repository github.com/example/tool Code and execution-path review, so you can read what a tool does before you run it.
Ransomware claim a victim or group name Public leak-site claims connected to victim, group and the reporting context around the campaign.

Who uses it

One console, eight different decisions.

The evidence is the same. The path through it, and the action at the end, is not. Drag to see them all.

01

SOC and IR

Turn an unfamiliar indicator into an escalate, block, monitor or close decision, with the sightings and infrastructure context behind it.

"Is this alert actionable right now?"

02

Threat intelligence

Connect indicators, reports and actors into one investigation instead of a folder of unrelated lookups.

"Does this connect to anything we already track?"

03

Fraud and brand

Check a lookalike domain or a suspicious page against current abuse signal before you send the takedown.

"Is someone impersonating us right now?"

04

Vulnerability and AppSec

Separate the CVEs being exploited in the wild from the hundreds that are not, before you plan the sprint.

"Is this one actually being used?"

05

Developers

Read the execution path of a repository or a tool before it reaches your machine or your pipeline.

"Is this safe to pull in?"

06

MSSPs and advisors

Answer a client question in minutes with evidence they can read, rather than a screenshot of a tool.

"Can I show my working on this?"

07

Business and risk

Translate an indicator into exposure, in language that survives the meeting it gets repeated in.

"What does this actually mean for us?"

08

Researchers and media

Trace a claim back to the source that made it, with the provenance attached and the gaps stated.

"Can I cite this, and where did it come from?"

Access

Start open. Go deeper when the work demands it.

01 · Anonymous

Look something up now.

One-off lookups across IP, domain, URL, hash and CVE, with evidence, provenance and honest unknowns. No sign-in, no card.

Free, and staying that way

02 · Free account

Keep the work you started.

Everything in the public lookup, plus saved investigations, so repeat research builds on itself instead of starting over.

Free

03 · Pro

Monitor what changes next.

Continuous coverage, deeper investigation modules, briefings and API workflows for teams that do this every day.

Early access, coming soon

Forensia

Paste something suspicious.

The public lookup is free, needs no account, and is the fastest way into every part of Forensia. Or talk to the operators who built it.