Verify exact identifier matches
Find where an email, username, domain, or wallet appears and keep every match tied to its source.
Autonomous cyber investigations
Enter an email, username, domain, URL, or crypto wallet. DefenceCore runs the OSINT workflow for you — it discovers where the identifier appears, follows connected public signals, and returns a sourced investigation with every match, relationship, and uncertainty ready for review. Built for fraud operations, trust and safety, and compliance teams.
Every result includes its supporting source and match reasoning.
Platform
Replace scattered OSINT lookups and single-purpose enrichment tools with a structured map of exact matches, related signals, and supporting evidence.
Find where an email, username, domain, or wallet appears and keep every match tied to its source.
Pivot from the starting identifier to related handles, domains, accounts, infrastructure, and public mentions.
Separate verified links, possible connections, and unsupported assumptions in one reviewable investigation.
How it works
The agent runs the pivots. You see what connected, why it connected, and what remains uncertain.
Enter an email address, username, domain, URL, or crypto wallet already present in your case.
DefenceCore checks exact appearances, discovers connected signals, and evaluates each potential link.
See the connection map, supporting sources, confidence, and unresolved questions in one workspace.
Use cases
Investigate suspicious accounts, wallets, domains, and digital infrastructure from one evidence-led workspace.
Expand a suspicious email, username, domain, or wallet during signup and payment fraud triage, before escalating a case.
Connect reused handles, public profiles, wallet records, and web mentions across abuse and impersonation reports, without assuming ownership.
Trace public website, domain, organization, and wallet signals when verifying a counterparty or clearing an alert.
Turn manual OSINT pivots across scattered tools into a structured, attributable evidence trail.
Free tools
Two public OSINT tools you can run right now — then open a full investigation when one identifier is not enough.
Free screening for Ethereum and Bitcoin addresses — sanctions, scam reports, and on-chain risk signals.
Screen a wallet address →Free reputation check on any number — line type, carrier, origin, and fraud signals.
Run a free check →Evidence and trust
DefenceCore keeps conclusions close to their supporting evidence and makes the limits of public-source research visible.
Findings retain the public source and context used to support them.
Possible matches, contradictions, and coverage limits remain explicit.
A proposed connection can be reviewed, confirmed, or rejected by a human.
Pricing
Start free, then move to a plan when your investigation volume grows.
1 investigation, one time
10 investigations per month
30 investigations per month
For lawful, authorized fraud prevention, security, and investigative work.
Recent articles
Guides to investigating emails, usernames, domains, wallets, and connected risk signals.
A repeatable open-source method for investigating an organization: resolve the entity, expand the domain footprint, check registries, read operating evidence, and corroborate across independent sources.
Read article →A due-diligence check for vendors, partners, and counterparties: confirm the legal entity, read the registry record, verify the domain, look for evidence of operation, and weigh the signals before you commit.
Read article →Expand from one confirmed domain to a company’s full web estate using published links, DNS records, and certificate transparency — and attribute each property with evidence instead of assumption.
Read article →Questions
A concise overview of how DefenceCore approaches public-source investigation.
DefenceCore investigates digital identifiers: email addresses, usernames, domains, URLs, and crypto wallet addresses. It finds exact public appearances, follows connected signals, and organizes the results into one sourced investigation.
You enter one identifier already present in your case. The agent chooses relevant checks, follows useful findings into additional pivots, compares possible connections, and returns an evidence-led report. You do not have to manually search and combine results from multiple tools.
Start with an email address, username, domain, URL, or supported crypto wallet address. A single identifier is enough to open an investigation.
Depending on the identifier and available evidence, DefenceCore can find exact web mentions, reused handles, related domains, public profiles, organization references, wallet intelligence records, and other connected identifiers. Coverage varies, and a missing result is not proof that no connection exists.
A report includes the starting identifier, exact matches, a connection graph, risk or context signals, confidence assessments, unresolved questions, and the evidence supporting each finding.
No. A shared handle, transaction, domain reference, or public mention can be an investigative lead without proving common ownership or real-world identity. DefenceCore keeps those distinctions visible and leaves confirmation to the investigator.
DefenceCore is built for cybersecurity, fraud operations, trust and safety, compliance, and open-source research teams conducting lawful, authorized investigations.
Manual OSINT means an analyst pivoting across a dozen tabs and stitching the results together by hand. Single-purpose lookup tools each return one slice from one data source and leave the correlation to you. DefenceCore runs the whole investigation — the pivots, the correlation, and the stitching — across multiple relevant sources, and returns one sourced report with evidence and uncertainty in a single workspace.
OSINT — open-source intelligence — is the practice of collecting and analyzing publicly available information to build a complete picture of an account, identifier, or piece of infrastructure. DefenceCore automates the OSINT workflow: instead of manually pivoting across sources, its agent gathers and correlates public appearances of an email, username, domain, URL, or crypto wallet into a single sourced investigation.
No. DefenceCore is available to verified organizations for fraud prevention and security investigations only. It is not a consumer reporting agency; reports may not be used for credit, employment, housing, or insurance decisions, and the platform does not support locating individuals.
No. Automation plans research steps and organizes findings, but it does not turn weak evidence into a confirmed fact. Investigators review the sources, confidence, and contradictions before deciding how to use a result.
Start an investigation
Start with an email, username, domain, or wallet. Review every connection and its evidence.