IntelBase
Turns an email into a digital footprint: registered accounts, profile details, breach hits, and infostealer-log exposure, with a timeline of activity.

- Categories
- Email OSINTBreach DataPeople Search
- Price
- Freemium
- Setup
- Some setup
IntelBase starts with one email and tries to build the rest of the footprint while you wait. Registered accounts stream in as each module answers. Profile fields, avatars, and activity dates land on the same page. Breach hits and infostealer-log exposure sit next to a first-seen / last-seen timeline.
The company sells this to security teams, investigators, and government buyers. In practice the useful part is that you can start reading before the scan finishes.
Why it is a Gem
I keep it next to Behind the Email, not as a replacement. Behind the Email is better at turning an address into a professional identity. IntelBase is better at telling you where that address is registered, when it was last seen, and whether a stealer log already has the cookies.
Stealer logs are the expensive part of this market, and they are why I will pay for IntelBase. A basic breach hit says an email and password appeared in a dump. A stealer hit can include the login URL, the browser, the machine name, stolen cookies, and files pulled off the box. You need that when the question is account takeover, not “was this person in LinkedIn 2021.”
Pro is $24.99 a month on annual billing for 400 lookups a day, with graph view and PDF export. Business is $83.99 and adds seats, a shared workspace, bulk lookup, monitoring, and webhook alerts. Infostealer detail is a summary on Business and the full set on Enterprise. The API is paid: 10 requests a minute on Pro, 30 on Business, with IP allowlists. The free plan does not get an API key.
It is real money. It is still cheaper than three separate tools and a shared spreadsheet.
What comes back
The documented POST /lookup/email call takes an address, an optional timeout, and flags for which modules to include. A response can contain:
identifier.accounts: each hit has a module (site, type, domain) and a flat map of harvested fieldsvalidator.registeredandvalidator.unregistered: services that confirmed the address versus those that did notdata_breaches: a total count plus results with source name and date. Rows can be redacted by planstealer_logs: count, origin, login, and whether the record is redacted on your planmeta: first seen, last seen, and a timeline when at least two dated events exist
Timeouts under 5 seconds skip slower modules such as Dropbox, Google, and Gravatar. You can exclude modules you do not want to wait on.
Paid plans add an interactive graph so you can drop in more than one email and see shared usernames, accounts, and breaches. Monitoring watches emails, domains, or usernames for new exposure. The homepage says Business includes 5 monitored identifiers with daily alerts, and Enterprise can do custom frequency and webhooks.
Limits
Results depend on the plan. Breach rows and stealer rows can be redacted until you pay. The product is an enrichment service. It is not a warrant and not a consumer report. If you need a named, well-documented public breach for a civilian check, Have I Been Pwned is still the cleaner citation. IntelBase is for the case where you already have authorization and you need speed.



