Universal Selector Search
Search normalized intelligence by email, phone, domain, IP, CIDR, URL, username, hostname, file hash, ASN, crypto address, certificate fingerprint, organization, and supported text.
IntelFortes is a defensive OSINT, exposure-intelligence, threat-intelligence, investigation, and digital-forensics search platform designed for security researchers, investigation teams, enterprises, and MSSPs.
security@example.org
EMAIL
Sanitized demonstration record. Production results attach source, provenance, collection time, and evidence context.
IntelFortes organizes intelligence around Documents → Selectors → Observations, then builds cases, correlations, alerts, entities, graph relationships, enrichment, and AI-assisted investigation on top of traceable evidence.
Feature availability is controlled by deployment, plan entitlements, organization policy, and provider configuration.
Search normalized intelligence by email, phone, domain, IP, CIDR, URL, username, hostname, file hash, ASN, crypto address, certificate fingerprint, organization, and supported text.
Distinguish First Seen, Last Seen, Collected, Indexed, Published, and Source Updated dates so historical context remains precise and auditable.
Organize searches, notes, evidence, timelines, graph views, alerts, and reports into investigations with source provenance and tenant-scoped collaboration.
Pivot from exact selector overlap to weighted correlations and evidence-backed graph relationships without presenting inference as identity proof.
Evidence-grounded investigation assistance can summarize entities, build timelines, explain relationships, and generate reports using authorized IntelFortes tools and cited evidence.
Event-driven monitoring for selectors, domains, infrastructure, organizations, brands, and watchlist assets with deduplicated notifications.
Plugin-based enrichment for supported providers such as VirusTotal, Shodan, Censys, DNS/RDAP, and DeHashed where contractually and operationally permitted.
REST API, signed webhooks, STIX 2.1, TAXII, and SIEM integrations for security operations and threat-intelligence workflows.
HMAC-based redaction directives, role masking, tenant isolation, immutable audit trails, retention policy, and export-time policy enforcement.
Collection and query paths are separated so ingestion, customer access, and compliance controls can scale independently.
Registered sources and authorized imports create collection targets.
Source, tenant, retention, rate, and collection policy are evaluated first.
Approved adapters fetch through Direct, Managed Proxy, or Tor egress.
Documents and selectors are parsed, normalized, deduplicated, and classified.
Evidence is archived and indexed as Documents, Selectors, and Observations.
Search, alerts, graph, cases, enrichment, and AI operate over authorized evidence.
Search & Export and other narrowly scoped products can query a dedicated read-only projection containing only fields allowed by that entitlement.
IntelFortes-hosted search, cases, alerts, graph, AI, API, and billing with strict tenant isolation.
Customer-controlled deployment using a signed IntelFortes license. Local data stays on customer infrastructure unless explicitly configured otherwise.
Private local intelligence combined with explicitly permitted cloud queries. Private data is not uploaded to IntelFortes Cloud by default.
Parent organizations manage isolated customer tenants using explicit delegated access without implicit cross-customer visibility.
Proxy type is a transport capability. Routing does not authorize access and is not used to defeat authentication, CAPTCHAs, rate restrictions, or source blocking.
Every acquisition request passes source policy before IntelFortes selects Direct, Managed Proxy, or Tor transport. Proxy pools track health, geography, session capability, concurrency, and cost without hard-coded provider credentials.
user@example.com+1 202 555 0147example.org203.0.113.0/24https://example.net/pathsample_userhost.example.orgsha256:…AS64500[sanitized address]fingerprint:…Example OrganizationThe preview below is synthetic and demonstrates the result shape, temporal fields, redaction behavior, and evidence confidence labels.
| Source | Identifier | Secondary | First Seen | Last Seen | Confidence |
|---|---|---|---|---|---|
| example.org/security | security@example.org | +1 202 555 0147 | 2025-11-20 | 2026-09-01 | High |
| [sanitized .onion source] | analyst@example.net | [REDACTED] | 2026-01-08 | 2026-08-27 | Medium |
| example.com/archive | [HIDDEN] | 203.0.113.42 | 2024-06-02 | 2026-07-16 | High |
Provider adapters are entitlement-aware, quota-aware, timeout-protected, and circuit-breaker controlled. Results are normalized into a unified intelligence profile.
Argon2id, MFA, JWT/refresh rotation, scoped API keys, RBAC + ABAC, SSO/SCIM path.
Global intelligence + current tenant visibility only; cross-tenant tests block deployment.
Ingestion, search, rendering, graph, AI, cache, API, reports, and exports.
Read-only projections separate lower-privilege/high-volume search from master intelligence stores.
Rate limits, result caps, export entitlements, WAF controls, anomaly scoring, re-auth, and suspension workflow.
Sensitive searches, exports, admin actions, licensing events, and policy changes generate audit events.
Pricing shown below matches the current public offering. Exact quotas and capabilities should be rendered from the IntelFortes plan catalog, not hard-coded in production templates.
Narrowly scoped intelligence lookup with isolated read-only access.
For security researchers and investigators who need deeper workflows.
For security teams, regulated organizations, and advanced investigations.
Feature updates, connector patches, and security fixes according to license terms.
Turnkey infrastructure option for supported deployment sizes.
Deployment assistance for supported customer infrastructure.
Plan limits are enforced through the entitlement engine and may vary by contract, deployment, provider quotas, and risk policy. “Unlimited” is not used as an operational promise.
deployment_id: if-deploy-••••••••
installation_id: ••••••••
IntelFortes Private uses signed licenses, deployment IDs, optional attestation, update entitlements, and audited migration/reset workflows instead of brittle permanent MAC/CPU locking.
IntelFortes is a defensive OSINT, exposure-intelligence, threat-intelligence, investigation, and digital-forensics search platform built around traceable Documents, Selectors, and Observations.
No. Master Architecture 1.0 supports Cloud, Private, Hybrid, and MSSP deployment models from the same platform architecture.
No. The architecture uses a dedicated read-only Search Access Plane projection for narrowly scoped or high-volume access. It contains only fields permitted by the user's entitlement and remains subject to tenant, redaction, rate, and audit controls.
Registered source adapters pass through a Source Policy Engine before a permitted request is routed through Direct, Managed Proxy, or Tor SOCKS5h transport. Routing is not authorization and is not used to defeat access controls or source blocking.
The Plugin Manager supports provider adapters such as VirusTotal, Shodan, Censys, DNS/RDAP, and DeHashed where provider terms and IntelFortes policy permit. Organization-specific BYOK credentials can also be supported.
Redaction is enforced across ingestion, search, rendering, graph, AI retrieval, APIs, cache, reports, and exports. HMAC-based selector tokens and auditable redaction workflows prevent a search-only blacklist from being the sole control.
IntelFortes provides privacy, redaction, retention, access-control, and audit capabilities that can support an organization's compliance program. Actual legal compliance depends on the operator's data sources, lawful basis, configuration, jurisdiction, policies, and use.
Signed licenses use deployment and installation IDs with optional attestation and online entitlement checks. IP/country changes can be treated as risk signals, while legitimate VPS or hardware migrations use an audited migration workflow.
Choose a plan, request an Enterprise deployment, or contact MediaXtreme about Private, Hybrid, MSSP, integrations, or implementation.
Send us your deployment model, data-handling constraints, and the workflow you need to support. A MediaXtreme engineer replies with a scoped answer — not a generic brochure.