41 tools
This category gathers useful OSINT tools that do not fit neatly into a single theme: automation frameworks, correlation and enrichment utilities, barcode and data decoders, reconnaissance suites, and other specialist helpers. Think of it as the toolbox drawer of the directory, where you find the odd but valuable instrument that solves a specific problem a mainstream category does not cover.
Because these tools vary widely, judge each on its own merits: what data it consumes, what it outputs, whether it is maintained, and how it fits your workflow. Many are command-line utilities aimed at analysts comfortable chaining tools together. Use them within scope and applicable law, and verify results against independent sources. If you are new to assembling a toolkit, start with our OSINT tools for beginners guide or browse the full OSINT directory.
Provides tools and insights for advanced analysis and security testing of Azure Active Directory (AAD) and Microsoft 365.
Decode barcodes in C#, VB, Java, C\C++, Delphi, PHP and other languages.
The Traditional Swiss Army Knife For OSINT. Belati is tool for Collecting Public Data & Public Document from Website and other service for OSINT purpose.
A unified command line interface and python library for using BeVigil OSINT API to search for assets such as subdomains, URLs, applications indexed from mobile applications.
A self-hosted application, available as a Dockerized, for effortless searching and reputation checking of observables. Extracts IoCs from raw input and check their reputation using multiple services.
CyberGordon is a threat intelligence search engine. It leverages 30+ sources.
An open source, free, and collaborative IPS/IDS software written in Go, able to analyze visitor behavior & provide an adapted response to all kinds of attacks.
Tool to perform various OSINT techniques on usernames, emails addresses, and domains.
Artificial intelligence that generates advanced search queries to find specific or hidden information on the internet.
A simple DuckDuckGo URL scraper.
Searches multiple OSINT tools to find information across various sources.
Tool to find metadata and hidden information in the documents.
Retrieve all mails of users related to a git repository, a git user or a git organization.
"Anti-Threat Intelligence" Greynoise characterizes the background noise of the internet, so the user can focus on what is actually important.
Hunchly is a web capture tool designed specifically for online investigations.
LinkScope Client Github repository.
LinkScope is an open source intelligence (OSINT) graphical link analysis tool and automation platform for gathering and connecting information for investigative tasks.
Maltego is an open source intelligence (OSINT) and graphical link analysis tool for gathering and connecting information for investigative tasks.
Free & open source power tool for working with messy data and improving it.
Draws relationships between crypto wallets with recursive crawling of transaction history.
Web based framework for OSINT.
A browser extension that gives you access to a suite of OSINT utilities (Dehashed, Epieos, Domaintools, Exif data, Reverse image search, etc) directly on any webpage you visit.
Information Gathering Toolset.
Python script for Facebook and geolocation OSINT.
Find, grab and organize all kinds of data and media from online sources.
Crawler designed for OSINT
Target reconnaissance framework powered by graph theory.
Greynoise Python Library
Python and R data analysis environment.
Online database of default router passwords.
Scrapes Google search and 25+ search engines with ease and retruns a raw JSON. Supports 10 API wrappers.
Powerful PHP script designed to allow you to leverage the power of dorking straight from the comfort of your command line. Analyzes data from Google, Bing, Yahoo, Yandex, and Badiu.
Sintelix is an open source intelligence (OSINT) and graphical link analysis tool for gathering and connecting information for investigative tasks.
Semi-automatic OSINT framework and package manager.
SpiderFoot Github repository.
SpiderFoot is an open source intelligence (OSINT) automation platform with over 200 modules for threat intelligence, attack surface monitoring, security assessments and asset discovery.
An advance, cross-platform, GUI web security crawler.
A research-grade suite of tools for intelligence gathering & target mapping with both active and passive(100+ modules) intelligence gathering capabilities.
Gather emails, subdomains, hosts, employee names, open ports and banners from different public sources like search engines, PGP key servers and SHODAN computer database.
Unfurl analyzes and breaks down URLs into useful forensic components for digital investigation.
Find email addresses of Github users urls and other data effortlessly
It is a catch-all for OSINT utilities that do not fit a dedicated category, including automation and correlation frameworks, data decoders, enrichment scripts, and niche reconnaissance helpers. The common thread is usefulness rather than theme, so the category spans many different tasks and skill levels across the investigative workflow.
Start from the problem, not the tool. Identify the input data you have and the output you need, then look for a utility that bridges the two. Check that it is actively maintained, read its documentation, and test it on known data before trusting results in a live case. Combine several tools when needed.
Most are legitimate research utilities, but legality depends on how you use them. Collecting publicly available data is generally lawful, while bypassing access controls, scraping in violation of terms, or exceeding an authorized scope is not. Verify each tool's behavior, respect rate limits and privacy law, and stay within the scope of your investigation.
Search all 1,200+ OSINT tools instantly, or run a target through the investigation console.
Open the OSINT directory →