Universal Selector Search
One search experience for normalized email, phone, domain, hostname, IP, CIDR, URL, file hash, CVE, ASN, username, organization and supported text selectors.
Search domains, emails, IPs, phones, URLs, hashes, CVEs and other indicators across a continuously growing intelligence corpus. Trace historical evidence, correlate relationships, monitor authorized assets, and investigate from IntelFortes Cloud or infrastructure you control.
security@example.org
EMAIL
Synthetic demonstration record. Production results trace each observation to its document, source, collection event and preserved evidence context.
IntelFortes continuously collects permitted intelligence, normalizes it into Documents → Selectors → Observations, preserves source provenance and history, then builds correlation, monitoring, cases, graph analysis, enrichment and evidence-grounded AI on top of that evidence model.
Feature availability is controlled by deployment, plan entitlements, organization policy, and provider configuration.
One search experience for normalized email, phone, domain, hostname, IP, CIDR, URL, file hash, CVE, ASN, username, organization and supported text selectors.
See First Seen, Last Seen, Collected, Published, Indexed and source-update context; preserve record versions so current state never silently overwrites what IntelFortes previously observed.
Pivot from a selector to evidence-backed emails, phones, subdomains, IPs, ASNs, URLs, certificates, entities and related observations. Correlation is shown as evidence, not identity proof.
Continuously monitor customer-controlled assets only after authorization. Domain monitoring uses proof-of-control; an ordinary search never becomes a permanent monitoring request.
Turn a search into an investigation with referenced evidence, notes, timelines, relationships, graph views, collaborators, alerts and reports without copying away source provenance.
Event-driven watchlists surface new observations and meaningful changes for permitted selectors and verified assets with deduplicated notifications and auditable state.
AI assistance works through authorized IntelFortes tools and cited evidence, distinguishing observed facts, correlations, inferences and hypotheses rather than presenting model output as fact.
Optionally enrich stored intelligence with authorized providers such as Shodan, Censys, VirusTotal, DNS/RDAP and DeHashed, plus REST API, webhooks, STIX 2.1, TAXII and SIEM workflows.
Tenant isolation, HMAC-backed redaction, retention controls, audit trails, entitlement enforcement, and Cloud, Private, Hybrid or MSSP deployment from one platform architecture.
IntelFortes builds the corpus before and between customer searches. Collection, evidence preservation, customer search and monitoring are separate control paths so each can be governed and scaled independently.
Registered public-security feeds, permitted public-web sources, public onion sources, authorized APIs and customer imports create candidate collection targets.
Source, tenant, authorization, retention, collection cadence and risk policy are evaluated before acquisition.
Approved adapters fetch through Direct, managed commercial proxy, or internal Tor transport according to source policy.
Each feed record becomes its own document; selectors are normalized, evidence is deduplicated, and identity remains source-scoped.
Raw evidence is content-addressed and searchable Documents, Selectors and Observations are indexed with First Seen / Last Seen history.
Customers search the accumulated corpus, follow evidence, correlate relationships, monitor verified assets, enrich selectively and build cases.
Search & Export and other customer-facing search paths query a dedicated read-only projection containing only fields allowed by the user’s entitlement and tenant policy. Searching a third-party domain is a question; it does not register, verify or monitor that domain.
IntelFortes-hosted search, cases, alerts, graph, AI, API, and billing with strict tenant isolation.
Customer-controlled deployment with signed licensing. Private corpus, imported evidence, cases and investigations remain on customer infrastructure unless explicitly configured otherwise.
Customer-controlled private intelligence combined with explicitly permitted cloud intelligence and enrichment. Private data is not uploaded to IntelFortes Cloud by default.
Parent organizations manage isolated customer tenants using explicit delegated access without implicit cross-customer visibility.
Proxy type is a transport capability. Routing does not authorize access and is not used to defeat authentication, CAPTCHAs, rate restrictions, or source blocking.
Every acquisition request passes the Source Policy Engine before transport is selected. Direct is the normal clear-web route; contracted proxy pools provide approved routing capabilities; internal Tor handles permitted public .onion sources. Transport never creates authorization.
user@example.com+1 202 555 0147example.org203.0.113.0/24https://example.net/pathsample_userhost.example.orgsha256:…AS64500CVE-2026-1234fingerprint:…Example OrganizationThe preview remains synthetic. Production search should show where a result came from, when it was first and last observed, how it is related, and why IntelFortes considers a relationship relevant.
| Source | Identifier | Secondary | First Seen | Last Seen | Confidence |
|---|---|---|---|---|---|
| example.org/security | security@example.org | +1 202 555 0147 | 2025-11-20 | 2026-09-01 | High |
| [sanitized .onion source] | analyst@example.net | [REDACTED] | 2026-01-08 | 2026-08-27 | Medium |
| example.com/archive | [HIDDEN] | 203.0.113.42 | 2024-06-02 | 2026-07-16 | High |
Production requirement: populate from a read-only public telemetry endpoint. If unavailable, show unavailable — never substitute marketing estimates.
IntelFortes searches its accumulated corpus first. Optional provider adapters can add fresh infrastructure, malware, reputation, DNS/RDAP or exposure context without making every search dependent on an external API.
Argon2id, MFA, short-lived sessions, scoped API keys, permission-based RBAC/ABAC, and SSO/SCIM where entitled.
Global intelligence plus current-tenant or explicitly delegated intelligence only. Cross-tenant visibility regression tests are deployment gates.
Redaction and policy apply across ingestion, search, history, correlation, graph, AI, cache, API, reports and exports.
A customer search does not create ownership or collection. Continuous domain monitoring requires registration, DNS proof-of-control and an explicit monitoring switch.
Rate limits, result caps, export entitlements, WAF controls, anomaly/risk signals, re-authentication and suspension workflows protect the search plane.
Sensitive searches, exports, monitoring authorization, admin actions, licensing events, policy changes and redaction workflows produce audit events.
Plans define entitlements, quotas and deployment eligibility. In production, names, prices, quotas and capabilities must come from the IntelFortes plan catalog/API rather than being authorization logic in this template.
Narrowly scoped intelligence lookup with isolated read-only access.
For security researchers and investigators who need deeper workflows.
For security teams, regulated organizations, and advanced investigations.
Feature updates, connector patches, and security fixes according to license terms.
Turnkey infrastructure option for supported deployment sizes.
Deployment assistance for supported customer infrastructure.
Plan limits are enforced through the entitlement engine and may vary by contract, deployment, provider quotas, and risk policy. “Unlimited” is not used as an operational promise.
deployment_id: if-deploy-••••••••
installation_id: ••••••••
IntelFortes Private uses signed licenses, deployment IDs, optional attestation, update entitlements, and audited migration/reset workflows instead of brittle permanent MAC/CPU locking.
IntelFortes is searchable intelligence infrastructure for evidence-driven security, exposure, threat-intelligence and investigation workflows, built around traceable Documents, Selectors, and Observations.
No. Master Architecture 1.0 supports Cloud, Private, Hybrid, and MSSP deployment models from the same platform architecture.
No. The architecture uses a dedicated read-only Search Access Plane projection for narrowly scoped or high-volume access. It contains only fields permitted by the user's entitlement and remains subject to tenant, redaction, rate, and audit controls.
Registered source adapters pass through a Source Policy Engine before a permitted request is routed through Direct, Managed Proxy, or Tor SOCKS5h transport. Routing is not authorization and is not used to defeat access controls or source blocking.
The Plugin Manager supports provider adapters such as VirusTotal, Shodan, Censys, DNS/RDAP, and DeHashed where provider terms and IntelFortes policy permit. Organization-specific BYOK credentials can also be supported.
Redaction is enforced across ingestion, search, rendering, graph, AI retrieval, APIs, cache, reports, and exports. HMAC-based selector tokens and auditable redaction workflows prevent a search-only blacklist from being the sole control.
IntelFortes provides privacy, redaction, retention, access-control, and audit capabilities that can support an organization's compliance program. Actual legal compliance depends on the operator's data sources, lawful basis, configuration, jurisdiction, policies, and use.
Signed licenses use deployment and installation IDs with optional attestation and online entitlement checks. IP/country changes can be treated as risk signals, while legitimate VPS or hardware migrations use an audited migration workflow.
No. Search, registration, verification and monitoring are separate operations. Searching an arbitrary domain queries existing intelligence; it does not create an organization-domain claim, collector job or permanent watch.
Customer domains must be registered and verified through proof-of-control before monitoring can be enabled. DNS TXT verification is the default control path. Monitoring can be turned off immediately.
No. IntelFortes builds and searches its own accumulated evidence corpus. Authorized providers such as Shodan, Censys, VirusTotal, DNS/RDAP or DeHashed can optionally supplement a result with fresh enrichment where terms, policy and entitlements allow.
No. Public accessibility and public-domain legal status are different concepts. Source policy, provider terms, retention, redaction and applicable legal obligations remain part of the collection and use decision.
Choose Search & Export, deploy Researcher, or request an Enterprise, Private, Hybrid or MSSP environment built around your evidence, retention, integration and investigation requirements.
Designed for cybersecurity, threat intelligence, corporate security, fraud investigation, digital forensics, exposure monitoring, incident response and authorized research.
Send us your deployment model, data-handling constraints, and the workflow you need to support. A MediaXtreme engineer replies with a scoped answer — not a generic brochure.