OSINT Tools
tip
Please click on the right sidebar → for accessing each section
OSINT Basics
What is OSINT
Open-source intelligence (OSINT) is data collected from publicly available sources to be used in an intelligence context. In the intelligence community, the term "open" refers to overt, publicly available sources (as opposed to covert or clandestine sources). It is not related to open-source software or public intelligence.
What can we find with OSINT?
- Email addresses
- Phone numbers
- Addresses
- Identities
- Background checks
- Social media accounts and information
- Criminal records
- Scams
- Etc.
Who uses OSINT?
- Law enforcement
- Security professionals
- Malicious hackers
- Investigators
- Journalists
General OSINT Tools
Website | Description |
---|---|
Maltego | A comprehensive tool for link analysis and data mining. |
TheHarvester | Gathers emails, subdomains, hosts, employee names, open ports, and banners from various public sources. |
Image OSINT
Website | Description |
---|---|
Pimeyes.com | Upload photo and find out where images are published. |
Exif.tools | A multimedia file metadata tool. |
TinEye | Reverse image search engine. |
Google Images | Reverse image search using Google. |
Email OSINT
Website | Description |
---|---|
Hunter.io | Find professional email addresses in seconds and connect with the people that matter for your business. |
Phonebook.cz | Lists all domains, email addresses, or URLs for the given input domain. Wildcards such as *.gov.uk are allowed. |
Voilanorbert.com | Find anyone's email address. |
emailhippo.com | The only email verification solution trusted by marketers, developers, and fraud fighters. |
Emailrep.io | Simple Email Reputation search. |
Clearbit Connect | Supercharge Gmail - Chrome extension. |
haveibeenpwned | Check if your email or phone is in a data breach. |
Email Hunter | Find and verify email addresses. |
Snusbase | Database search engine for data breaches. |
Social Media OSINT
Website | Description |
---|---|
Lookup-id.com | Find your Facebook profile ID, Group ID, or Page ID. |
Facebook Matrix | Formulas for Searching Facebook. |
Facebook Graph Searcher | Facebook Graph Searcher. |
Facebook Graph, Codes & Operators | Facebook Graph Search Operators. |
Twint | Advanced Twitter scraping tool written in Python. |
Sociotal | Extract data from various social media platforms. |
Foller.me | Analyzes Twitter profiles. |
Domain OSINT
Website | Description |
---|---|
AnalyzeID | Find other websites owned by the same person. |
DomainIQ | View information on the ownership and status of any domain name or IP address. |
ViewDNS Info | Tools for gathering a large amount of data about a given website or IP address. |
whoismind | Search any IP address. |
DNS Dumpster | DNS recon & research, find & lookup DNS records. |
OSINT.SH | All-in-one information gathering tools. |
whoxy | Whois API, Whois History, Reverse Whois. |
whoisology | More than reverse Whois lookups. |
Domain Dossier | Investigate domains and IP addresses. |
Wayback Machine | Browse the history of a website. |
Netcraft | Provides internet security services and research data. |
Web Analytics
Website | Description |
---|---|
Built With | Find out what websites are built with. |
Spy ON Web | Information from public sources structured for quick and convenient search for websites that likely belong to the same owner. |
Online Tools
Website | Description |
---|---|
SSL Labs | Performs a deep analysis of the configuration of any SSL web server on the public internet. |
Zoom Eye | Uses Xmap and Wmap at its core to collect data from open devices/web services and for fingerprint analysis. |
Censys | Helps information security practitioners discover, monitor, and analyze devices accessible from the internet. |
Shodan.io | Search engine for internet-connected devices. |
Dehashed | Hacked database search engine for security analysts, journalists, security companies, and everyday people. |
Xmind | Professional and popular mind mapping tool. |
What U | Shows data that websites 'know' about you. |
Spiderfoot HX | Automate OSINT for threat intelligence, asset discovery, attack surface monitoring, or security assessments. |
TraceLabs | Crowdsourcing OSINT to help find missing people. |
IP 2 Location | Free IP geolocation query. |
Grey Noise | Collects and analyzes untargeted, widespread, and opportunistic scan and attack activity. |
Intelligence X | Powerful search engine and data archive for darknet, document sharing platforms, public data leaks, etc. |
ONYPHE.IO | Cyber defense search engine. |
FOCA | Finds metadata and hidden information in documents. |
IPinfo.io | IP address information and geolocation. |
Metagoofil | Extracts metadata from public documents. |
OSINT Frameworks
Website | Description |
---|---|
OSINT Framework | A web-based framework for OSINT research. |
Username OSINT
Website | Description |
---|---|
Sherlock | Hunt down social media accounts by username across social networks. |
Whats my name | Enumerates usernames across many websites. |
Knowem | Search over 500 popular social networks, over 150 domain names, and the entire USPTO Trademark Database to instantly secure your brand on the internet. |
namecheckr | Tool to research domain and social username availability. |
user search | Find someone by username or email on social networks, dating sites, forums, chat sites, and blogs. 600+ sites supported. |
Name vine | Instantly find a domain name with matching social media profiles. |
Namechk | Checks the availability of usernames across multiple social media platforms. |
UserRecon | Username reconnaissance tool. |
Vehicle OSINT
Website | Description |
---|---|
LICENSE PLATES OF THE WORLD | License plates of the world. |
nomerogram.ru | Find a car by license plate for free (Russian). |
uk.vin-info | Free VIN check/registration check of cars in the UK. |
GitHub
Website | Description |
---|---|
Maryam | OWASP Maryam is a modular open-source framework based on OSINT and data gathering. |
GHunt | GHunt is a modular OSINT tool designed to evolve over the years and incorporates many techniques to investigate Google accounts or objects. |
Default Password sites
Website | Description |
---|---|
Default password sites 1 | Default router username and password list. |
Default password sites 2 | Default router username and password list. |
Default password sites 3 | Default router username and password list. |
Dark Web OSINT
Website | Description |
---|---|
DarkSearch | Search engine for the dark web. |
Tor Browser | Browse the dark web anonymously. |
Tools for Investigators
Website | Description |
---|---|
CaseFile | Tool for simpler link analysis. |
Social Links | Integrates with Maltego to provide data from social networks. |