Intelligence X
email · username · phone · domain · IP
Searches the Intelligence X index across leaks, pastes, darknet captures and document dumps. Each hit records the bucket, source name, date and a direct record link so you can cite exactly where an artefact came from.
Reach for it when: Deep historical exposure on an identifier that returned nothing from public endpoints.
DeHashed
email · username · name · phone · domain · IP
Queries DeHashed for breach-exposure links between identifiers and breach sources. Command One keeps the useful identifiers and breach provenance but deliberately discards password and hash fields before findings are stored.
Reach for it when: Confirming whether an identity or infrastructure lead appears in known breach data without retaining credential material.
Hunter.io
domain · email
Discovers public professional email addresses associated with a domain and verifies individual addresses with Hunter.io confidence and deliverability signals.
Reach for it when: Expanding a company domain into likely contact addresses, or checking whether an email lead is deliverable before deeper analysis.
BreachDirectory
email · username · phone
Tells you which breach corpora expose an identifier, with source names, record counts and password hash hints. Fast enough to triage a list of addresses before committing to a full workup.
Reach for it when: Account-security assessments and confirming whether a lead's credentials are already public.
Phone Intelligence
phone
Carrier-grade lookup for a subscriber number: current carrier, line type, country routing, portability and validity — the data public parsing libraries cannot infer on their own.
Reach for it when: Deciding whether a number is a real mobile subscriber, a VoIP throwaway or a landline.