← All OSINT tools

Speciality Search Engines — OSINT Tools

28 tools

Specialty search engines index a narrow slice of the web that general engines cover poorly or not at all. Rather than crawling everything, each focuses on a vertical such as security and threat data, IP and domain reputation, scholarly literature, code, or multilingual content. For investigators, these tools reach primary and technical sources that mainstream search buries, and they usually expose fields and filters tailored to that domain, so you can query by attributes a general engine would never expose.

Choosing the right specialty engine starts with knowing exactly what kind of data you need, since each is deep but deliberately narrow. Check what it indexes, how current the data is, and whether an account or API key is required for full access. These engines are strongest as part of a larger workflow, so combine them with the broader OSINT directory. Respect each provider's terms and use the data lawfully and ethically.

2lingual Search

Abusech

Hunt across all abuse.ch platforms with one simple query

Abuseipdb

Repository of abuses reported by system administrators for IPs, Domains, and subnets

BeVigil

Search for assets like Subdomains, URLs, Parameters in mobile applications

Biznar

Browserleaks

BrowserLeaks tests your browser for privacy and fingerprinting leaks

Censys

Searcher that monitors and analyzes devices.

Cisco Talos Intelligence

IP and Domain Reputation Center for real-time threat detection

CiteSeerX

Criminal IP

Cyber Threat Intelligence Search Engine and Attack Surface Management(ASM) platform

CRT Certificate Search

Allows you to search for public SSL/TLS certificates recorded in Certificate Transparency logs

Fofa

Asset search and analysis tool.

Google Custom Search

GrayhatWarfare

Searches and indexes open Amazon S3 buckets, allowing users to find and explore potentially exposed data.

Harmari (Unified Listings Search)

Intelligence X

Paid OSINT Tool Allowing users to search for information across various sources including the dark web and public data leaks.

Internet Archive

Islegitsite

Checks if a website is trustworthy by analyzing its reputation, domain, and security based on public sources.

MalwareBazaar

Search and download confirmed malware samples by hash, family, tag, and other criteria.

Mamont

Million Short

Netlas.io

OCCRP Aleph

Shadowserver

Dashboard with global statistics on cyber threats collected by the Shadowserver Foundation.

Shodan

Shodan is a search engine for the IOT(Internet of Things) that allows you to search variety of servers that are connected to the internet using various searching filters.

WIPO

Wpscan

Scan your WordPress site and get an instant report on its security.

Zanran

Frequently asked questions

What are specialty search engines used for in OSINT?

Specialty engines index a focused vertical, such as security feeds, IP reputation, academic papers, or source code, that general engines cover poorly. Investigators use them to reach technical and primary sources with domain-specific filters. Because each is deep but narrow, you pick the engine that matches the exact data type you need rather than expecting one tool to do everything.

How do I pick the right specialty search engine?

Start from the data you actually need, then match it to an engine built for that vertical. Check what the tool indexes, how fresh its data is, and whether full access requires an account or API key. Since these engines are intentionally narrow, expect to use several across an investigation rather than relying on a single one.

Do specialty search engines require an account?

Many offer basic queries for free but gate advanced filters, higher rate limits, or bulk and API access behind an account or key. Security and threat-intelligence tools in particular often require registration to see full results. Review each engine's access model before you build a workflow around it, and confirm the terms permit your intended use.

Search all 1,200+ OSINT tools instantly, or run a target through the investigation console.

Open the OSINT directory →