# Aperture - OSINT Workbench

> Local-first OSINT workbench: IoC detect, playbooks, cases, graph and offline packs. No API keys by default.

Canonical page: [https://chrome-stats.com/d/soc-osint-extension](https://chrome-stats.com/d/soc-osint-extension)

## Overview

- **ID:** `soc-osint-extension`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** Peter Stollery
- **Category:** privacy-security,search-tools
- **Daily users:** 56
- **Weekly downloads:** 5
- **Version:** 4.2.3
- **Last updated:** 2026-08-27
- **First published:** 2025-03-26
- **Size:** 282 KB
- **Data as of:** 2026-09-07
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/soc-osint-extension/)
- **Website:** [https://github.com/petstuk/Aperture-OSINT-Workbench](https://github.com/petstuk/Aperture-OSINT-Workbench)

## Description

Local-first investigation companion for SOC, DFIR, and CTI analysts.

Pivot on indicators across public OSINT tools, keep cases and history on-device, and run playbooks without accounts, API keys, or telemetry — unless you explicitly enable optional Labs features.

<ul><li><strong>Popup launcher</strong> — paste an indicator, classify locally, run quick tools or playbooks</li><li><strong>Dashboard workbench</strong> — triage inbox, bulk extract, cases, playbooks, relationship graph, offline packs, Labs</li><li><strong>On-page detect</strong> (opt-in) — highlight IoCs on any page; click for a pivot card with notes, tags, clipboard packs, and related indicators</li><li><strong>Playbooks</strong> — ordered multi-tool workflows with optional delay, concurrency, and skip-private-IP</li><li><strong>Cases</strong> — group indicators, verdicts, tags, notes, timeline, session capture, JSON/MD/CSV export</li><li><strong>Right-click search</strong> — selection → playbooks and OSINT sites</li><li><strong>Keyboard</strong> — command palette (⌘/Ctrl+K) plus Ctrl+Shift+K / Ctrl+Shift+O</li></ul>

IPs, domains, URLs, emails, hashes, CVEs, BTC, ASNs — plus ETH, ATT&amp;CK IDs, paths, onion addresses, Telegram/Discord links, and more.

VirusTotal, AbuseIPDB, URLScan, Shodan, Censys, AlienVault OTX, ThreatCrowd, IBM X-Force, MalwareBazaar, GreyNoise, Spur, Have I Been Pwned, <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/6d2f6901a05aceb5ecd44b627c6c02b31e02071568a0acb1f3fb3b64a93431a4/http%3A//crt.sh" rel="nofollow">crt.sh</a>, RDAP, Wayback Machine, URLhaus, ThreatFox, NVD, BGP HE, MITRE ATT&amp;CK.

<ul><li>Parsing and enrichment run <strong>on-device</strong></li><li>Network use is <strong>only</strong> when you open OSINT tabs (or enable opt-in Labs adapters/LLM)</li><li>On-page highlights are <strong>off by default</strong></li><li><strong>No telemetry</strong> by default (Firefox data collection: none)</li><li><strong>No API keys required</strong> for core use</li></ul>
<ul><li><strong>Storage</strong> — local history, cases, settings</li><li><strong>Context menus</strong> — right-click search</li><li><strong>Tabs / activeTab</strong> — open OSINT lookups you choose</li><li><strong>Host access</strong> — optional on-page IoC highlights and selection handling</li></ul>
Formerly <strong>SOC OSINT Search</strong>.

## Rankings

- #15,333 — Overall
- #143 — graph
- #167 — work
- #169 — offline
- #189 — telegram

## Permissions and access

### Permissions

- `contextMenus`
- `storage`
- `tabs`
- `activeTab`

### Host permissions

- `<all_urls>`

### Content script matches

- `<all_urls>`

## Safety

- **Risk impact:** High risk impact
- **Risk likelihood:** Moderate risk likelihood

### Analysis details

- Grants access to browser tabs, which can be used to track user browsing habits and history, presenting a privacy concern.
- This extension was recently updated in the past month. New updates may not be stable or safe.

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Similar extensions and apps

- [Sybnet Osint Industries](https://chrome-stats.com/d/osints) — 85 users, 5.00 / 5
- [Sybnet Osint Industries](https://chrome-stats.com/d/sybnet) — 85 users, 5.00 / 5
- [SnapOSINT](https://chrome-stats.com/d/snaposint) — 301 users, 5.00 / 5
- [SOC Multi-tool](https://chrome-stats.com/d/soc-multi-tool) — 88 users
- [SOCx](https://chrome-stats.com/d/socx) — 6 users
- [OSINT IP/URL/SHA-Scanner](https://chrome-stats.com/d/osint-ip-url-sha-scanner) — 3 users
- [Web Explode](https://chrome-stats.com/d/web-explode) — 18 users, 5.00 / 5
- [OWASP Penetration Testing Kit](https://chrome-stats.com/d/owasp-penetration-testing-kit) — 965 users, 5.00 / 5
- [Hashlight](https://chrome-stats.com/d/hashlight)
- [IOC Checker](https://chrome-stats.com/d/ioc-checker) — 4 users
- [🔎 Threat Intel Search](https://chrome-stats.com/d/threat-intel-search) — 3 users
- [IntSights Extend](https://chrome-stats.com/d/intsights-extend) — 1 users

---

Source: [Chrome-Stats](https://chrome-stats.com/d/soc-osint-extension)
