Originaly Corvid started as a fork of dev-lu/osint_toolkit with an updated stack, and has since diverged substantially.
If your daily routine is a wall of browser tabs — VirusTotal in one, Shodan in another, three more for a username or a phishing domain — Corvid replaces that wall with a single keyboard-first search bar. Paste an IP, domain, hash, email, or username and it's routed to the right tools automatically; type a tool name to jump straight to it.
Corvid is self-hostable and built for single-user operation: it runs in one Docker container on your own infrastructure, so investigation data and API keys never pass through a third-party SaaS. It's a workbench, not a data warehouse — no long-term case management, just fast, on-demand IOC lookups, email/image forensics, phishing-domain discovery, identity correlation (Reddit, GitHub, usernames), and detection-rule authoring, with generative AI wired in to speed up analysis and write-ups along the way.
curl -fsSL https://raw.githubusercontent.com/z0rats/corvid/main/install.sh | bashPulls pre-built images and starts the app at http://localhost:4000 — no auto-update, see Deploy with docker for details and the build-from-source alternative.
- Integrated services
- Features
- Keyboard-first navigation
- Notifications
- Deploy with docker
- Disclaimer
- License
IOC lookups auto-route to the right services based on the type you paste in:
- IPs — AbuseIPDB, AlienVault, CheckPhish.ai, CrowdSec, GitHub, IPQualityScore, LeakIX, Maltiverse, Pulsedive, Reddit, Shodan, ThreatFox, Twitter/X, VirusTotal
- Domains — AlienVault, CheckPhish.ai, GitHub, Library of Leaks, Maltiverse, Pulsedive, Reddit, Shodan, ThreatFox, Twitter/X, URLScan, VirusTotal
- URLs — AlienVault, CheckPhish.ai, GitHub, Google Safe Browsing, Maltiverse, Pulsedive, Reddit, Shodan, ThreatFox, Twitter/X, URLScan, VirusTotal
- Emails — Emailrep.io, GitHub, Have I Been Pwned, Hunter.io, Library of Leaks, Reddit, Twitter/X
- Hashes — AlienVault, GitHub, Maltiverse, Pulsedive, Reddit, ThreatFox, Twitter/X, VirusTotal
- CVEs — GitHub, NIST NVD
- Crypto addresses (EVM & Bitcoin) — screened against a self-hosted blacklist built from the OFAC SDN sanctions list and ScamSniffer's open phishing-address dataset, refreshed daily in the background; no API key or third-party calls required
Full write-up of every module (settings, gotchas, endpoints) lives on the docs site — this is the short version.
Aggregates cybersecurity news from trusted sources, extracts IOCs automatically, and analyzes
articles with AI. → Docs

Analyze IPs, domains, URLs, hashes, emails, and crypto addresses against VirusTotal, AlienVault,
AbuseIPDB, Shodan, and more, single or in bulk, plus Domain Finder (WHOIS/RDAP, Certificate
Transparency, HackerTarget/RapidDNS subdomains, Wayback history, and a keyless Web Check panel —
TLS cert, security headers, DNSSEC, DNS blocklist). → Docs

Parse .eml files, run header/security checks, extract IOCs, and get an AI-assisted read on
suspicious messages. → Docs
Inspect EXIF/GPS/hash metadata, reverse-image search with no API keys, an optional AI photo geolocation hypothesis, and an opt-in ChronoVerify provenance/C2PA check. → Docs
Reusable AI prompt templates for log analysis, email analysis, and source-code explanation. →
Docs

Score a vulnerability with CVSS 3.1 or 4.0 and export it. → Docs
A GUI for creating Sigma, Yara, and Snort/Suricata rules. → Docs
A Reddit user's full post/comment history, including removed/deleted content, no API key required. → Docs
Find accounts and mail providers registered to a username, across hundreds of sites. → Username Search docs / Email Search docs
Correlate names, emails, and GitHub logins from commit history via gitcolombo. → Docs
Run parameterized search-engine dorks against a domain, username, or email. → Docs
Due-diligence check on a Russian legal entity or sole proprietor by ИНН/name — ЕГРЮЛ/ЕГРИП extract, disqualified-persons registry check, and arbitration case history, no API key required. Russian-only UI. → Docs
A minimal Chrome extension ("Corvid Quick Send") lets you select text on any page and send it
straight to IOC Tools lookup, with no build step — load it unpacked from the
extension/ folder. →
Docs
Corvid is built around a single search bar instead of hunting through menus — press / or
⌘K/Ctrl+K from anywhere to open it. Paste a raw IOC value to get routed to the right tool,
type a tool's name to jump to it, or combine both (john_doe reddit) to open a tool pre-filled.
See the Command Palette docs for the
full grammar (tags, filters, quick actions, defang/fang, playbooks).
Optionally get a Telegram message when a scan finishes (or fails) or a background job starts or
stops failing, on top of the in-app alerts inbox — and optionally run /lookup, /digest, and
/help commands from the chat itself. Configured entirely from Settings → Telegram — no
.env entry needed. See the
Telegram Notifications docs
for setup.
- Docker Engine 24+ with the Docker Compose v2 plugin (the
docker composecommand, not the legacy standalonedocker-composebinary) - Linux, macOS, or Windows (via Docker Desktop/WSL2)
- At least ~1 GB free disk for the app itself; more if you enable
email_search's optional headless checkers, which lazily download a Chromium binary (~150-300 MB) on first use — see Disk usage - Outbound HTTPS access for the third-party services you configure (VirusTotal, Shodan, etc.) — no inbound ports need to be exposed
- No GPU or special hardware needed. CPU/RAM haven't been formally benchmarked, but as a single-user tool with no background crawling by default, it's light — a small VM (1-2 vCPU, 2 GB RAM) is comfortable for typical use
Option A — one-line install (pre-built images). Pulls ready-made images from GHCR instead of
building from source. Installs into ~/corvid by default (override with CORVID_DIR):
curl -fsSL https://raw.githubusercontent.com/z0rats/corvid/main/install.sh | bashOnce it's running, open http://localhost:4000. There's no auto-update — new versions aren't
pulled without your say-so. To update later, run ./update.sh from the install directory (it
pulls the latest images and recreates the containers).
Option B — build from source. Gives you a local build instead of pulling from a registry, and lets you review the Dockerfiles before anything runs:
- Download the repository and extract the files
- Navigate to the directory where the
docker-compose.yamlfile is located - Start the application:
make up— start backend and frontend without rebuildingmake rebuild— rebuild images (e.g. after dependency or Dockerfile changes) and startmake up-backend/make up-frontend— start a single service without rebuildingmake rebuild-backend/make rebuild-frontend— rebuild and start a single servicemake help— list all available targets, includingdown/logs/ps/migrate
- Once the container is running, you can access the application in your browser at http://localhost:4000
Database migrations run automatically on container startup — no manual step needed after
make rebuild. If you need to run one by hand (e.g. to check for pending migrations without
starting the app), you can still run: make migrate
The app has no user accounts, so it's protected by a single access token instead of a login form.
On first startup, a token is generated automatically and printed to the backend logs
(make logs) and saved to data/.access_token on the host. Open
http://localhost:4000, and you'll be asked to paste that token once — it's then remembered in
the browser.
To set your own fixed token instead of the auto-generated one, set API_ACCESS_TOKEN in .env
before starting the container.
If the token is ever exposed, regenerate it from Settings → About → Access Token → Regenerate
(unavailable if API_ACCESS_TOKEN is set) — this immediately signs out every other browser
tab/device and the browser extension, which then need the new token entered manually.
Copy .env.example to .env to override any setting (all of them have working
defaults, so this is optional). .env is read automatically by docker compose up. Per-service
API keys and app-level preferences are configured from within the app itself instead — see
Settings Reference.
Settings → Backup lets you download/restore a full backup (database + encryption key,
optionally passphrase-encrypted) from the browser, no shell access needed. Covered in depth on
the docs site: Backup & Operational Security
— what's under data/, the in-app flow vs. a manual host-level backup, disk-usage expectations,
and practices worth following for sensitive engagements (isolating the instance, routing through
Tor/a proxy, key rotation, and more).
Corvid is a tool, not a policy — how you point it is on you. It's built for legitimate use cases: internal security teams triaging IOCs, threat intel analysts enriching indicators, researchers investigating abuse, and similar authorized work. It is not built for stalking, harassment, unauthorized surveillance, or investigating people without a lawful basis for doing so.
Several modules (Reddit Search, Git Recon, Image Tools' reverse-search, email/username lookups) pull together data that's technically public but can still identify or locate a real person when combined. Before running them against an individual rather than an IOC or organization, make sure you have a legitimate basis to do so and that it complies with the laws of your jurisdiction and the target's (data protection/privacy law, computer-misuse law, and your organization's own policies, at minimum). Some integrated services carry their own terms of use and rate limits that are yours to respect — Corvid doesn't police that for you.
None of this constitutes legal advice, and the author takes no responsibility for how the tool ends up being used. When in doubt, check with your legal/compliance function before running an investigation, not after.
Corvid is licensed under the GNU Affero General Public License v3.0.
You are free to use, modify, and distribute this software, provided that any modified versions or services built on it are also made available under AGPL-3.0, including when offered as a network service.
If AGPL-3.0 doesn't fit your use case — for example, if you want to integrate Corvid into a proprietary product or offer it as a managed service without open-sourcing your modifications — a commercial license is available.
Contact: [z0rats.dev@gmail.com]
Versions up to and including v0.1.0 were released under the MIT License and remain available under those terms.