Investigator Use
Intelligence X, commonly known as IntelX, is a commercial search engine and data archive designed specifically for OSINT and intelligence gathering. It indexes and archives data from sources that mainstream search engines exclude — including the dark web, leaked databases, Telegram, paste sites, and historical snapshots of pages and documents that may have been removed from their original sources.
What investigators use IntelX for: searching for email addresses, domains, IP addresses, and names across breach data and dark web sources, finding leaked documents and credentials, researching cryptocurrency wallet addresses, and accessing archived versions of content that has been deleted from public websites.
What data IntelX exposes: archived content from dark web forums and markets, leaked database dumps, paste site archives, Telegram message archives, WHOIS history, domain intelligence, and document archives including PDFs and Word files linked to organizations or individuals under investigation. IntelX preserves content even after it is removed from its original source.
The selector search is the core feature of IntelX. Submit an email address, domain, IP, phone number, or cryptocurrency address, and the platform returns all indexed records matching that selector. This is particularly powerful for correlating a single email address across multiple breach datasets to understand a target's full exposure history.
IntelX is one of the few platforms that provides accessible dark web search without requiring Tor. It crawls .onion sites and archives their content in a searchable format, making dark web intelligence available to analysts who are not operating in a Tor environment.
Access tiers: IntelX offers a free tier with limited results, a professional tier for law enforcement and corporate investigators, and an enterprise tier with full API access and historical data. The free tier is useful for quick checks, but comprehensive investigation requires a paid account.
In a workflow: use IntelX in the middle phase of an investigation after identifying key selectors like email addresses or domain names. It complements Have I Been Pwned (which focuses on breach notification) by providing the actual leaked content where available. Cross-reference IntelX results with Shodan and SecurityTrails to build a complete infrastructure picture.
Before You Pivot
Record Context
Capture the target, search terms, and why this source is relevant before you leave the page.
Preserve Evidence
Archive volatile pages, save screenshots, and keep timestamps for anything that may change.
Corroborate
Treat one tool as a lead source. Confirm important findings with independent sources.
Related Tools
ARKHAM INTEL
Cryptocurrency OSINT
Arkham Intel is a blockchain analytics platform for on-chain entity attribution, wallet clustering, and cryptocurrency transaction investigation.
BitRef
Cryptocurrency OSINT
Instantly check the balance of any Bitcoin address and view transactions in a clean, easy-to-read format. No signup required — free to use!
Bitcoin WhosWho
Cryptocurrency OSINT
Bitcoin WhosWho looks up Bitcoin address ownership, transaction history, and blockchain attribution data for cryptocurrency investigations.
Block Explorer
Cryptocurrency OSINT
Block Explorer enables searching Bitcoin transactions, wallet addresses, and block confirmations on the Bitcoin blockchain.
Blockchain explorer
Cryptocurrency OSINT
Blockchain.com Explorer provides real-time lookup of Bitcoin, Ethereum, and Bitcoin Cash transactions, addresses, and block data.
Blockonomics
Cryptocurrency OSINT
Check Bitcoin addresses, lookup transactions. Monitor wallet balances using xPub with our block explorer. No signup required, free to use!