Onsint continuously interrogates fragmented public infrastructure—passive DNS, certificate transparency logs, BGP routing anomalies, and adversary indicators—into an unalterable defense graph.
Live telemetry continuously funnels from decentralized observation points across the globe into the central Onsint Core for instant synthesis.
Input an indicator below or trigger preconfigured reconnaissance simulations.
Heuristic vector correlation indicates active typosquatting and adversarial credential harvesting campaign.
[EXECUTIVE BRIEFING] The domain auth-update-telegram.online replicates legitimate communication infrastructure. Recursive WHOIS correlation identifies shared certificate registrant hashes linked to adversary campaign UNC-4912.
[DIRECTIVE] Flag ASN 202425 subnets across perimeter egress firewalls. Ingest extracted IOC indicators into sovereign SIEM feeds.
Strict non-intrusive operations. Only analyzes public DNS, WHOIS archives, TLS certificates, and public vulnerability registries. Zero active port probing.
Entity relationships dynamically map across hosting clusters, registrant certificates, and AS routes without human intervention.
Containerized for on-premise Kubernetes clusters. Compliant with national intelligence sovereignty directives and data retention laws.