SecurityCipher
Home Blog About Us

Learn Paths, courses, and reference docs

  • 🚀 Start Here Beginner path through the site
  • 🗺️ Penetration Testing Roadmap Structured path to become a pentester
  • 🎓 Free Security Courses Current free Udemy coupon listings
  • 📄 Secure Code Explain Vulnerable vs secure code side by side
  • 🎯 Penetration Testing Tricks Field notes for real engagements
  • 📖 Vulnerability Explain How common vulns actually work

Checklists Interactive reviews and LLM risks

  • ✅ Security Checklists Hub All interactive security checklists
  • 📋 Writeup Checklists Steps derived from real writeups
  • 🧠 LLM AI Security Checklist Controls for LLM apps
  • 🤖 OWASP LLM Top 10 LLM Top 10 risks mapped out
  • 🧰 Burp Suite Guide Step-by-step Burp tutorials
  • 📘 Payload Field Manual Safe-first probes and signals

Practice Browser labs, games, and explorers

  • 🔬 Interactive Labs SQL injection, AI, architecture review
  • 🎮 Security Games Phishing, JWT, WAF, and more
  • 🚗 On-Call Drive Neon-city arcade security missions
  • • Shift Zero SOC desk: phish, OTP, malware, tickets
  • ❓ Application Security Quiz Web, secure coding, and cloud quizzes
  • 🗺️ OWASP Top 10 Explorer Clickable risk map with signals
  • 🔀 Interactive Attack Paths Recon-to-impact chains

Tools & Career Databases, jobs, and community

  • 🛠️ Security Tools Curated recon, SAST, and bounty tools
  • 🔎 CVE Lookup Multi-source CVE intelligence
  • 💰 Bug Bounty Programs Live public scopes to search
  • 💼 Cybersecurity Jobs Roles from company career pages
  • 🧑‍💻 Security Researchers Community profiles and submissions
  • 🎤 Security Conferences Upcoming and past events
Browse all Security resources hub Freelance Security →
My Resume
Freelance SecurityFreelance
New Security Researchers Join the directory - submit your profile for review Submit profile →
← Security Tools View on GitHub

mitaka

Browser extension that makes threat intel lookups from selected IOCs one click away.

Mitaka

Build Status CodeFactor Coverage Status

Mitaka is a browser extension that makes your OSINT (Open Source Intelligence) search & scan easier.

demo

  • Key features:
    • Auto IoC (indicators of compromise) selection with refanging.
      • E.g. example[.]com to example.com, test[at]example.com to test@example.com, hxxp://example.com to http://example.com, etc.
    • Supports 65+ services.

Install

Chrome

Firefox

Features

Supported IoCs (Indicators of Compromise)

NameDesc.E.g.
ANSASNAS13335
BTCBTC address1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa
CVECVE numberCVE-2018-11776
DomainDomain namegithub.com
EmailEmail addresstest@test.com
ETHEthereum address0x32be343b94f860124dc4fee278fdcbd38c102d88
GaPubIDGoogle Adsense Publisher IDpub-9383614236930773
GaTrackIDGoogle Analytics Tracker IDUA-67609351-1
HashMD5, SHA1, SHA25644d88612fea8a8f36de82e1278abb02f
IPIPv4 address8.8.8.8
URLURLhttps://github.com

Supported Search Engines

NameURLSupported types
AbuseIPDBhttps://www.abuseipdb.comIP
AnyRunhttps://app.any.runHash
archive.orghttps://archive.orgURL
Blockchain.comhttps://www.blockchain.comBTC
BlockCypherhttps://live.blockcypher.comBTC
Censyshttps://censys.ioIP, domain, ASN, email
Checkphishhttps://checkphish.aiIP, domain
Coalitionhttps://ess.coalitioninc.comCVE
crt.shhttps://crt.shDomain
CVEhttps://cve.orgCVE
DNS Coffeehttps://dns.coffeeDomain
DNSlyticshttps://search.dnslytics.comIP, domain
DomainToolshttps://www.domaintools.comIP, domain
EmailRephttps://emailrep.ioEmail
Google Safe Browsinghttps://transparencyreport.google.comDomain, URL
GreyNoisehttps://viz.greynoise.ioIP, domain, ASN, CVE
Host.iohttps://host.ioDomain
Hurricane Electrichttps://bgp.he.net/IP, domain, ASN
HybridAnalysishttps://www.hybrid-analysis.comIP, domain, hash
Intezerhttps://analyze.intezer.comHash
IPinfohttps://ipinfo.ioIP, ASN
Joe Sandboxhttps://www.joesandbox.comHash
Maltiversehttps://www.maltiverse.comDomain, hash
MalwareBazaarhttps://bazaar.abuse.chHash
NVDhttps://nvd.nist.govCVE
OOCPRhttps://data.occrp.orgEmail
OpenTIPhttps://opentip.kaspersky.comHash
OTXhttps://otx.alienvault.comIP, domain, CVE, URL, hash
Pulsedivehttps://pulsedive.comIP, domain, URL, hash
Radarhttps://radar.cloudflare.comIP, domain
Robtexhttps://www.robtex.comIP, domain
SecurityTrailshttps://securitytrails.comIP, domain
Shodanhttps://www.shodan.ioIP, domain, ASN
Sploitushttps://sploitus.comCVE
SpyOnWebhttps://spyonweb.netIP, domain, gaPubID, gaTrackID
Taloshttps://talosintelligence.comIP, domain
ThreatBookhttps://threatbook.ioIP, domain
ThreatConnecthttps://app.threatconnect.comIP, domain, email
ThreatMinerhttps://www.threatminer.orgIP, domain, hash
TIPhttps://threatintelligenceplatform.comIP, domain
Triagehttps://tria.geHash, URL
URLhaushttps://urlhaus.abuse.chIP, domain
urlscan.iohttps://urlscan.ioIP, domain, ASN, URL
URLVoidhttps://www.urlvoid.comDomain
ViewDNShttps://viewdns.infoIP, domain, email
VirusTotalhttps://www.virustotal.comIP, domain, URL, hash
VMRayhttps://www.vmray.comHash
Vulmonhttps://vulmon.comCVE
WebCheckhttps://web-check.xyzDomain
X-Force Exchangehttps://exchange.xforce.ibmcloud.comIP, domain, hash
ZoomEyehttps://www.zoomeye.aiIP

Supported Scan Engines

nameurlsupported types
Browserlinghttps://www.browserling.comURL
HybridAnalysishttps://www.hybrid-analysis.comURL
urlscan.iohttps://urlscan.ioIP, domain, URL
VirusTotalhttps://www.virustotal.comURL

How To Use

  • Use Mitaka to Perform In-Browser OSINT to Identify Malware, Sketchy Sites, Shady Emails & More

Note: Please set your API keys in the options for enabling HybridAnalysis, urlscan.io and VirusTotal scans.

Options

You can enable/disable a search engine on the options page based on your preference.

"options.png

[!NOTE] Basic preferences are stored in storage.sync. Thus they will be synced across devices. But API keys are stored in storage.local. You have to set API keys per device.

Permissions

[!NOTE] I don't and will never collect any information from the users. You can verify it by reviewing the source code.

Firefox

Please allow "Access your data for all websites" permission. Otherwise this extension does not work.

Screenshot 2023-07-15 at 8 27 26

Privacy Policy

  • Privacy policy for the extension

Common Questions

  • Q. The context menu is not displayed.
    • A. Sometimes it takes a while for the context menus to appear. Or something goes wrong while refreshing the context menus. This glitch can be solved by waiting for a second. Please take a breath after selecting and then right-click.

Alternatives or Similar Tools

  • CrowdScrape
  • Gotanda
  • SOC Multi-tool
  • Sputnik
  • ThreatConnect Integrated Chrome Extension
  • ThreatPinch Lookup
  • VTchromizer

How It Works

flowchart LR
  CS[Content Script] --> |1 - Send Selection| BSW[Background Service Worker]
  BSW --> |2 - Create Context Menus| CS
  CS --> |3 - Click Context Menu| BSW
  BSW --> |4 - Search/Scan| T[New Tab]

Contribute

Read the contribution guide and join the contributors.

Press Escape to close the search panel.

Donate

Buy me a Coffee

Penetration Testing Services

penetration Testing Services

Web Application Security Quiz

Web Application Security Quiz

Daily Bug Bounty Writeups - Twitter

Daily Bug Bounty Writeups

Download our Latest Android Application

Guide for Penetration Testing

Daily Bug Bounty Writeups - Telegram

Daily Bug Bounty Writeups

Author

Piyush
Senior Product Security Engineer

Ethical Hacker || Penetration Tester || Gamer || Blogger || Product Security Engineer || AI Security

READ ARTICLE

Donate

Buy me a Coffee

Recent Posts

  • AI-Generated Code Security Bugs: A Vibe Coding Case Study
    AI-Generated Code Security Bugs: A Vibe Coding Case Study
    October 7, 2026/
    0 Comments
  • Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    September 8, 2026/
    0 Comments
  • DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    August 27, 2026/
    0 Comments

Follow Us

SecurityCipher

Practical security guides, vulnerability deep-dives, and hands-on resources for bug bounty hunters and penetration testers.

Useful Links

  • Security Checklists
  • Cybersecurity Jobs
  • Blogs
  • About
  • Contact
© 2026 Security Cipher. All rights reserved. Privacy Policy · Terms & Conditions