Intel

◈ IP INTEL geo, ASN, ISP, VPN flags — any target ◈ CARD CHECK luhn + BIN issuer intelligence ◈ MAG-LAB browser magstripe studio — ISO 7811 encode, read, batch issue (closed-loop only) ◈ MAIL FORENSICS true origin, relay delays, spoof flags, .eml import ◈ IMAGE FORENSICS EXIF, GPS, ELA, edit detection ◈ PHONE LOOKUP carrier, line type, region, timezone — any number ◈ USERNAME SLEUTH find one handle across 12+ platforms ◈ DOMAIN RECON RDAP whois, DNS, nameservers, subdomains

Operate

◈ SMS RENTAL 30-min numbers, refundable ◈ PROXY LAB residential egress, geo builder ◈ STEGO LAB hide words in pictures ◈ BURNER MAIL receive-only mailboxes, countdown

Hunt

◈ TRACK FILE opens report back: IP, city, ISP ◈ CANARY TRAPS links, pixels & honeytokens — instant alerts ◈ DEAD-DROP burn-after-read encrypted notes ◈ SCREENSHOT page capture or rendered-text fallback ◈ FRAUD-SCORE composite IP + email + BIN risk 0-100 ◈ FREE TOOLS DNS, headers, JWT, hasher ◈ PHONE LOOKUP osint: carrier + line type + region ◈ USERNAME SLEUTH osint: handle across platforms ◈ DOMAIN RECON osint: RDAP + DNS + subdomains ◈ DMS dead man switch: silence releases pre-written payload dead-drops ◈ HASH-CHAIN Tamper-evident chain-of-custody logs — edits break the chain at the exact link ◈ GHOST-TEXT hide secret messages in invisible characters inside innocent text ◈ CHAFF deterministic throwaway personas — same seed, same identity, zero storage ◈ LEAK-TRACER per-recipient invisible watermarks — leaks name the leaker ◈ TRACEOUT network traceroute with per-hop geo ◈ TRAP-CHAIN breadcrumb tripwires — each fired trap feeds them the next, maps their path

Account

◈ INBOX no-KYC messaging ◈ SIGN UP username + password, 10 seconds, no KYC ◈ API KEYS account, balance, metered keys ◈ PASS everything's free now — no pass needed ◈ AGENT PASSPORT machine-readable badge

TRACK FILE

Upload any file or picture and get a tracked link for it. The moment anyone opens that link — or views the email version — their IP, city, ISP, device and language fire back into your INBOX. The image-IP trick, weaponized and clean.

1 · Name your bait
How it works: your file gets a secret link — every open is logged (time, IP, device) and lands in your inbox with geo. You also get an HTML copy with an embedded tracking pixel: email THAT and every view fires too. Login (no KYC) to see events.
API: POST /api/track/create (filename) → upload_url · POST /api/track/upload?token= (file) → tracked_link + pixel + email_html · GET /api/track/events?token=
EXAMPLE FLOW — learn who opens your 'photo'
  1. you create a trackable named sunset.jpg — free, instant, and the upload page opens.
  2. you upload the actual photo. You get back: a tracked link, a pixel URL, and an email-ready HTML copy.
  3. you send the link — 'hey check out this pic'. That's the whole trick.
  4. them taps it. The image renders normally in their browser — but the page quietly pings home first.
  5. you INBOX lights up: sunset.jpg opened — IP 203.0.113.7 · Rotterdam NL · KPN · Android Chrome · timezone Europe/Amsterdam.
  6. the HTML copy works over email too — every preview pane that loads images fires the pixel, no click needed.
HOW IT WORKS
  1. Free now — click create and the upload opens instantly, no payment.
  2. Upload your file or picture: you get a secret tracked link plus an email-ready HTML copy.
  3. Email the HTML copy or share the link — every open fires back.
  4. Each open reports: exact time, real IP, city/country, ISP, timezone, VPN flag, device, language, referrer.
  5. Alerts land in your INBOX the second it happens; full event log via the API.
✦ REACH THE DEV
⚙