GDE-058 |
Intelligence X (IntelX) | |||||||
Breach and leaked-data search | ||||||||
September 2026 | ||||||||
01
What it is
Intelligence X is the practice of using intelx.io, a search engine indexing data breaches, leaked documents, darknet content, historical WHOIS records and paste-site dumps, to search an email address, domain, phone number or other selector across sources most conventional search engines do not index.
Intelligence X is a specialist search engine and data archive that indexes material conventional search engines generally do not: data breach dumps, paste-site content, leaked documents, darknet pages, and a large historical WHOIS record archive going back further than most registrars retain. A limited free search is available without an account; deeper search history, bulk export and API access require a paid subscription.
It sits in the same investigative category as Have I Been Pwned for breach exposure, but with a materially broader scope: rather than only confirming whether an address appears in a known breach, it can surface the actual leaked content, historical domain ownership records, and darknet mentions tied to a selector.
| When to use this guide
|
02
How do you search Intelligence X effectively?
Six steps from a first free search through to handling any exposed leaked content responsibly.
The following resources are used across the steps below.
Intelligence X: Free limited search, paid tiers for deeper history and API access. The core search engine.
Signal & Shadow's Have I Been Pwned guide: Free. A narrower, free-first alternative for confirming breach exposure alone.
| Before you begin Stop at the login. A limited free search on Intelligence X requires no account. Full search history, bulk export and API access require a paid account of your own; nothing in this workflow uses another person's or organisation's credentials. Legal considerations. Material surfaced by Intelligence X, including leaked personal data, breach dumps and darknet content, is often unlawfully obtained by the original leaker even where the search engine itself operates lawfully as an indexer. Downloading, redistributing or further exposing leaked personal data can itself violate data-protection law regardless of how it was found; treat any leaked content as evidence to document and report through appropriate channels, not material to store, republish or act on directly. |
Search the email address, domain or phone number through the free tier to see whether any results exist at all before deciding whether deeper access is warranted.
Use the platform's bucket filters to distinguish formal breach dumps from paste-site content, leaked documents and darknet mentions, since each carries different reliability and context.
Search a domain directly to pull its historical WHOIS records, useful for identifying a prior registrant before privacy protection or a change of ownership.
Where a selector returns a hit, check the same address through Have I Been Pwned to confirm the exposure is documented in a known, named breach rather than an unverified dump.
Do not download, screenshot beyond what is necessary for documentation, or redistribute leaked personal data; treat it as evidence to report or reference, not material to act on directly.
Note which source bucket, such as a named breach, a paste site or a darknet index, a result came from and when the search was run, since new material is indexed continuously.
|
03
What are the pitfalls of using Intelligence X?
Broader coverage than a breach checker also means broader risk of mishandling what it surfaces.
A darknet or paste-site hit mistaken for a verified breach: unlike a named, confirmed breach, paste-site and darknet content can be unverified, fabricated or recycled from an older leak. Verifying check: treat unverified-source hits as leads requiring corroboration, not as confirmed exposure on their own.
A limited free search mistaken for comprehensive coverage: the free tier surfaces only a subset of what the platform indexes. Verifying check: treat a clean free-tier result as inconclusive rather than as proof of no exposure.
Historical WHOIS data mistaken for current ownership: a historical record shows who registered a domain at some point, not necessarily who controls it now. Verifying check: cross-check any historical WHOIS finding against the domain's current registration before treating it as present-day ownership.
Chain of custody: because results can include unlawfully leaked personal data, custody obligations here are stricter than for an ordinary public-source finding.
Document the existence and source bucket of a finding without retaining or redistributing the underlying leaked content itself.
Record the search date and query used, separate from when any underlying leak occurred.
Note whether a hit was corroborated against a named, confirmed breach or remains an unverified darknet or paste-site mention.
Route any significant exposure discovered through appropriate legal or organisational reporting channels rather than acting on it unilaterally.
04
Go deeper
The narrower breach-checking guide this pairs with, and the wider email-OSINT workflow.
GUIDE · GDE-050
Have I Been Pwned for OSINT: reading breach exposure right
A narrower, free-first way to confirm a named breach before turning to Intelligence X.
GUIDE · GDE-005
Email OSINT: trace an address to accounts and infrastructure
The wider email-tracing workflow Intelligence X's breach and leak search feeds into.
Evidentiary standard
Signal & Shadow operates to the LST-001 evidentiary standard. All claims are graded against the LST-001 v1.0.3 confidence tiers (Confirmed, Corroborated, Reported, Alleged) per the canonical voice and structural specification.
About Signal & Shadow
Signal & Shadow is an independent forensic investigation and methodology practice publishing tutorials, reference cards, and forensic dossiers for working practitioners. Founded by Derek Bowler.




