Skip to main content
Beat the adversary with 22B+ events a day

The most complete public map of the internet

Revisit more than 400 million services every day across more protocols than web-first internet search, with first-party observations connected to DNS, fingerprints, network attribution, proxy intelligence, exposed content, and reporting.

One connected map

Ask questions that cross datasets

Combine direct observations and derived context in one search. Find infrastructure classified as a proxy, serving a particular application, in a specific country-then pivot into its DNS history, fingerprints, reports, and exposed files.

InfraQL

Work with the data

Keep the investigation moving

Projects

Keep investigations, indicators, notes, saved queries, and activity together.

InfrAI

Ask InfrAI to explore evidence and build a connected investigation graph.

External Surface

Inventory what your organisation exposes and work the findings raised against it.

Get started

Follow an analyst workflow

Start with a real question, follow the evidence, then adapt the query to your own indicators.

investigate-ip

Investigate an IP

Build host context, inspect services, pivot through DNS, and find related reporting.
passive-dns

Pivot through passive DNS

Move between names and addresses and understand when each relationship was observed.
service-hunting

Hunt exposed services

Combine protocol, network, HTTP, TLS, fingerprint, and tag evidence.

Build with Infrawatch

From first query to production integration

Learn InfraQL

Use typed fields, time windows, correlation, patterns, and validation.

Explore the API

Browse authentication, endpoint contracts, schemas, and examples.

Inspect the fields

Find public fields, types, operators, and dataset-specific semantics.