SecurityCipher
Home Blog About Us
Resources ▼
✅ Security Checklists Hub 🗺️ Penetration Testing Roadmap 🤖 OWASP Top 10 for LLM Applications 🧠 LLM AI Security Checklist 🛠️ Security Tools 🎯 Penetration Testing Tricks 📄 Secure Code Explain 📖 Vulnerability Explain ☁️ AWS Cloud Security Checklist
My Resume
Our ServicesServices
New On-Call Drive Drive the neon city, jack in, and clear security tickets Play now →
← Security Tools View on GitHub

mitaka

Browser extension that makes threat intel lookups from selected IOCs one click away.

Mitaka

Build Status CodeFactor Coverage Status

Mitaka is a browser extension that makes your OSINT (Open Source Intelligence) search & scan easier.

demo

  • Key features:
    • Auto IoC (indicators of compromise) selection with refanging.
      • E.g. example[.]com to example.com, test[at]example.com to test@example.com, hxxp://example.com to http://example.com, etc.
    • Supports 65+ services.

Install

Chrome

Firefox

Features

Supported IoCs (Indicators of Compromise)

NameDesc.E.g.
ANSASNAS13335
BTCBTC address1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa
CVECVE numberCVE-2018-11776
DomainDomain namegithub.com
EmailEmail addresstest@test.com
ETHEthereum address0x32be343b94f860124dc4fee278fdcbd38c102d88
GaPubIDGoogle Adsense Publisher IDpub-9383614236930773
GaTrackIDGoogle Analytics Tracker IDUA-67609351-1
HashMD5, SHA1, SHA25644d88612fea8a8f36de82e1278abb02f
IPIPv4 address8.8.8.8
URLURLhttps://github.com

Supported Search Engines

NameURLSupported types
AbuseIPDBhttps://www.abuseipdb.comIP
AnyRunhttps://app.any.runHash
archive.orghttps://archive.orgURL
Blockchain.comhttps://www.blockchain.comBTC
BlockCypherhttps://live.blockcypher.comBTC
Censyshttps://censys.ioIP, domain, ASN, email
Checkphishhttps://checkphish.aiIP, domain
Coalitionhttps://ess.coalitioninc.comCVE
crt.shhttps://crt.shDomain
CVEhttps://cve.orgCVE
DNS Coffeehttps://dns.coffeeDomain
DNSlyticshttps://search.dnslytics.comIP, domain
DomainToolshttps://www.domaintools.comIP, domain
EmailRephttps://emailrep.ioEmail
Google Safe Browsinghttps://transparencyreport.google.comDomain, URL
GreyNoisehttps://viz.greynoise.ioIP, domain, ASN, CVE
Host.iohttps://host.ioDomain
Hurricane Electrichttps://bgp.he.net/IP, domain, ASN
HybridAnalysishttps://www.hybrid-analysis.comIP, domain, hash
Intezerhttps://analyze.intezer.comHash
IPinfohttps://ipinfo.ioIP, ASN
Joe Sandboxhttps://www.joesandbox.comHash
Maltiversehttps://www.maltiverse.comDomain, hash
MalwareBazaarhttps://bazaar.abuse.chHash
NVDhttps://nvd.nist.govCVE
OOCPRhttps://data.occrp.orgEmail
OpenTIPhttps://opentip.kaspersky.comHash
OTXhttps://otx.alienvault.comIP, domain, CVE, URL, hash
Pulsedivehttps://pulsedive.comIP, domain, URL, hash
Radarhttps://radar.cloudflare.comIP, domain
Robtexhttps://www.robtex.comIP, domain
SecurityTrailshttps://securitytrails.comIP, domain
Shodanhttps://www.shodan.ioIP, domain, ASN
Sploitushttps://sploitus.comCVE
SpyOnWebhttps://spyonweb.netIP, domain, gaPubID, gaTrackID
Taloshttps://talosintelligence.comIP, domain
ThreatBookhttps://threatbook.ioIP, domain
ThreatConnecthttps://app.threatconnect.comIP, domain, email
ThreatMinerhttps://www.threatminer.orgIP, domain, hash
TIPhttps://threatintelligenceplatform.comIP, domain
Triagehttps://tria.geHash, URL
URLhaushttps://urlhaus.abuse.chIP, domain
urlscan.iohttps://urlscan.ioIP, domain, ASN, URL
URLVoidhttps://www.urlvoid.comDomain
ViewDNShttps://viewdns.infoIP, domain, email
VirusTotalhttps://www.virustotal.comIP, domain, URL, hash
VMRayhttps://www.vmray.comHash
Vulmonhttps://vulmon.comCVE
WebCheckhttps://web-check.xyzDomain
X-Force Exchangehttps://exchange.xforce.ibmcloud.comIP, domain, hash
ZoomEyehttps://www.zoomeye.aiIP

Supported Scan Engines

nameurlsupported types
Browserlinghttps://www.browserling.comURL
HybridAnalysishttps://www.hybrid-analysis.comURL
urlscan.iohttps://urlscan.ioIP, domain, URL
VirusTotalhttps://www.virustotal.comURL

How To Use

  • Use Mitaka to Perform In-Browser OSINT to Identify Malware, Sketchy Sites, Shady Emails & More

Note: Please set your API keys in the options for enabling HybridAnalysis, urlscan.io and VirusTotal scans.

Options

You can enable/disable a search engine on the options page based on your preference.

"options.png

[!NOTE] Basic preferences are stored in storage.sync. Thus they will be synced across devices. But API keys are stored in storage.local. You have to set API keys per device.

Permissions

[!NOTE] I don't and will never collect any information from the users. You can verify it by reviewing the source code.

Firefox

Please allow "Access your data for all websites" permission. Otherwise this extension does not work.

Screenshot 2023-07-15 at 8 27 26

Privacy Policy

  • Privacy policy for the extension

Common Questions

  • Q. The context menu is not displayed.
    • A. Sometimes it takes a while for the context menus to appear. Or something goes wrong while refreshing the context menus. This glitch can be solved by waiting for a second. Please take a breath after selecting and then right-click.

Alternatives or Similar Tools

  • CrowdScrape
  • Gotanda
  • SOC Multi-tool
  • Sputnik
  • ThreatConnect Integrated Chrome Extension
  • ThreatPinch Lookup
  • VTchromizer

How It Works

flowchart LR
  CS[Content Script] --> |1 - Send Selection| BSW[Background Service Worker]
  BSW --> |2 - Create Context Menus| CS
  CS --> |3 - Click Context Menu| BSW
  BSW --> |4 - Search/Scan| T[New Tab]

Contribute

Read the contribution guide and join the contributors.

Penetration Testing Services

penetration Testing Services

Web Application Security Quiz

Web Application Security Quiz

Daily Bug Bounty Writeups - Twitter

Daily Bug Bounty Writeups

Download our Latest Android Application

Guide for Penetration Testing

Daily Bug Bounty Writeups - Telegram

Daily Bug Bounty Writeups

Author

Piyush
Senior Product Security Engineer

Ethical Hacker || Penetration Tester || Gamer || Blogger || Product Security Engineer || AI Security

READ ARTICLE

Donate

Buy me a Coffee

Recent Posts

  • Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    September 8, 2026/
    0 Comments
  • DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    August 27, 2026/
    0 Comments
  • The CVE Flood Is a Lie: How to Hunt When AI Dumps 36% More Bugs But Exploitation Only Grows 10%
    The CVE Flood Is a Lie: How to Hunt When AI Dumps 36% More Bugs But Exploitation Only Grows 10%
    August 25, 2026/
    0 Comments

Follow Us

SecurityCipher

Practical security guides, vulnerability deep-dives, and hands-on resources for bug bounty hunters and penetration testers.

Useful Links

  • Security Checklists
  • Cybersecurity Jobs
  • Blogs
  • About
  • Contact
© 2026 SecurityCipher. All rights reserved. Privacy Policies · Terms & Conditions