User guide

How to use Lookup

Lookup is personal indicator research — paste an IP, domain, URL, hash, review vendor context and a transparent score, ask the investigation assistant, and export or share a report. This guide covers the full path from signup to daily use.

Get started

Lookup signup screen with plan picker and Continue with Google or Microsoft
Sign up — choose Free, Pro, or Max, then continue with Google, Microsoft, or email.
  1. 1
    Create an account
    Go to Sign up. Choose Free, Pro, or Max, accept Terms and Privacy, then continue with Google, Microsoft, or email.
  2. 2
    Or sign in
    From the landing page, use Sign In. Lookup sign-in is separate from the enterprise platform.
  3. 3
    Open Lookup
    After authentication you land on Lookup. The first visit may show a short welcome checklist — choose Start researching when you are ready.
Lookup sign-in screen with email, password, and social options
Sign in — email and password, or Continue with Google / Microsoft.

Verify your account

Before you can research indicators, Lookup asks you to verify recovery contact details. This protects your account and unlocks the workspace.

  • Email signup — confirm the link in your inbox and/or complete the phone code when prompted.
  • Google or Microsoft signup — add and confirm a phone number on the verify screen.

If you signed up for a paid plan, billing completes after verification. You can review plan and usage anytime from Account.

Run your first lookup

Lookup home with top search bar, History panel, and Intellescope wordmark
Lookup home — search from the top bar; History and Collections sit on the left.
  1. 1
    Enter an indicator
    In the top search bar, paste a single value — or several values separated by commas for a bulk run.
  2. 2
    Press Enter
    Lookup opens a session for that indicator (or a bulk results view). Prior lookups appear in the left History panel so you can reopen them later.
  3. 3
    Watch usage
    Daily quotas reset at 00:00 UTC. If the search bar says usage is exhausted, wait for reset or upgrade under Plan & usage.

Read a result

Lookup indicator detail for 1.1.1.1 with Overview tab, threat score, and assessment
After a lookup — Overview shows score and assessment. Use Intelligence, ATT&CK, and Reports for deeper context.

Each lookup opens a detail view. Work left to right through the tabs:

  • Overview — threat score, assessment, community remarks, and your notes.
  • Intelligence — related indicators and source resources. Use Refresh from sources when your plan includes refreshes.
  • ATT&CK — MITRE technique context tied to the session.
  • Reports — generate, preview, download, or share a report (see below).

Scores and vendor claims are presented for you to inspect — Lookup does not auto-publish analytical conclusions on your behalf.

Investigation assistant

Open the Investigation assistant from the top bar (right rail). Ask about the open lookup, compare two indicators, refresh enrichment, or request cited web context.

  • Starter prompts appear until you ask your first question.
  • Installed Skills can load a playbook when your question matches (slash name or description overlap).
  • The assistant stays scoped to research — it will not invent findings or act as your enterprise workbench.
  • Agent turns count toward your daily Lookup usage pool.

Reports & sharing

  1. 1
    Open the Reports tab
    On an indicator session, choose Reports, set TLP if prompted, and generate.
  2. 2
    Export
    Download PDF, Word, STIX, or ATT&CK Navigator formats when offered.
  3. 3
    Share
    Create a share link for a read-only report page. Recipients can open the shared report without your full account history.

Report generation counts against your daily report quota.

Plan, usage & settings

Lookup Account Plan and usage with meters and Free Pro Max plans
Avatar menu → Account → Plan & usage for quotas and upgrades.
  • Plan & usage — meters for lookups, refreshes, reports, and agent activity; upgrade Free ↔ Pro ↔ Max.
  • Settings — name, password, language, and email notification preferences.
  • Connections — research connectors and Skills for the Investigation assistant.
  • API & MCP — personal tokens and the remote MCP endpoint (Remote MCP docs).
  • Support — email support and FAQ.

Ready to research?

Open Lookup or create an account to follow this guide in the product.