leaf 03 · live

Interrogate any indicator.

IP address, domain, URL or file hash — the tool auto-detects what you paste and checks it against threat intelligence aggregated from multiple security vendors.

what it checks

Under this leaf.

IPsReputation and reported malicious activity for any IPv4 address.
DomainsThreat history and reputation for domains and hostnames.
HashesMD5, SHA-1 and SHA-256 lookups to identify known malware samples.
URLsSafety checks for links associated with phishing, malware or spam.
why it matters

Why run this scan?

Indicators of compromise are the fingerprints of an attack. A strange IP in your server logs, an unknown file hash from a download, a domain your firewall flagged — each can be checked here in seconds.

The search aggregates verdicts from multiple security vendors, so you see a consensus rather than a single opinion — the same workflow SOC analysts use, without the enterprise tooling.

questions, answered

Frequently asked questions

What is an IOC (indicator of compromise)?

An IOC is a piece of forensic data that identifies potentially malicious activity — typically an IP address, domain name, URL or file hash observed during an attack.

Which hash types are supported?

MD5, SHA-1 and SHA-256. The input field auto-detects the hash type by its length as you type.

Where does the threat intelligence come from?

Results are aggregated from multiple security vendors' feeds, giving you a multi-source consensus on each indicator's reputation.