OSINT

Tools for multiple OSINT strategies

36 listed tools Last update on 2025-06-12

Up a Level Contribute

Cyber Kill Chain

Recon: Information gathering stage, where attackers gather as much information as possible about the target.

Weaponization: Crafting of tools or payloads to exploit vulnerabilities.

Delivery: The transmission of the weaponized payload to the target.

Exploitation: Exploiting a vulnerability to gain access to the target system.

Installation: Establishing a foothold on the target system.

Command & Control (C2): Setting up channels for communication with the compromised system.

Actions on Objectives: Achieving the intended goal of the attack, such as data exfiltration or system disruption.

AQUATONE 

Open-source    

Create attack surface maps of subdomains with pre-compiled binaries

Archive.org 

Free    

A digital archive providing historical snapshots of websites and other media for OSINT and research purposes

BlutoRS 

Open-source    

Revived and enhanced DNS reconnaissance and enumeration tool, offering subdomain brute-forcing, email harvesting, and metadata analysis

BuiltWith 

Commercial   Free    

Web technology profiler used for OSINT, competitive analysis, and cyber reconnaissance

C99.nl 

Commercial    

Subdomain scanning tool

Caipora 

Free    

Brazilian OSINT tool listing

Censys 

Commercial   Free    

Threat intelligence and mapping platform

creepy 

Open-source    

Geolocation gathering via social media platforms

crt.sh 

Free    

Certificate Transparency log search engine for discovering issued SSL/TLS certificates

DataSploit 

Open-source    

OSINT framework based around corporate espionage

Debookee 

Commercial    

Network traffic interception and analysis for Mac

Dirsearch 

Open-source    

Command line tool to brute force directories and files

Dnsgen 

Open-source    

This tool generates a combination of domain names from the provided input

Drako OSINT 

Free    

Curated collection of open-source intelligence tools and resources, organized for targeted investigations across various domains

Etherape 

Open-source    

A graphical network monitor for Unix with graphic network activity display

Gau 

Open-source    

Getallurls (gau) fetches known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl

Intelx.io 

Free   Commercial    

OSINT search engine and data archive indexing darknet, leaks, and public records

JSParser 

Open-source    

A python script to parse relative URLs from JavaScript files

Maltego 

Commercial    

Open-source intelligence and graphical link analysis tool for gathering and connecting information for intelligence and forensics.

metagoofil 

Open-source    

Metadata harvester with email extraction functions

MxToolbox 

Free   Commercial        

Email and network diagnostic platform offering tools for blacklist monitoring, DNS lookups, and email deliverability analysis

NetCat 

Open-source    

A networking tool for reading and writing data across networks

Nipper 

Commercial    

Network configuration & audit tool for internal teams

OSINT Resources by Country 

Open-source    

Community-driven repository compiling OSINT tools and resources categorized by country, facilitating targeted open-source investigations

Seclists 

Open-source    

Security testing data repository

Shodan 

Commercial   Free    

Search for Internet-connected devices

SSL Labs 

Free    

Service by Qualys that performs deep analysis of SSL/TLS configurations for public web servers

Subfinder 

Open-source    

A subdomain discovery tool that discovers valid subdomains for websites by using passive online sources

Sublist3r 

Open-souce    

Fast subdomain enumeration tool that uses OSINT sources and brute-force techniques to aid hunters in mapping domain footprints

theHarvester 

Open-source    

Harvest E-mail, subdomain and names via OSINT

Unfurl 

Open-source    

Analyze URLs and estimate entropies to find URLs that might be vulnerable to attack

Waybackurls 

Open-source    

Accept line-delimited domains on stdin, fetch URLs from the Wayback Machine for *.domain and output them on stdout

Web-Check.xyz 

Open-Source    

Open-source website analysis tool to identify potential vulnerabilities and security misconfigurations

Wesley's OSINT 

Free    

Curated collection of open-source intelligence tools and resources, organized for targeted investigations across various domains

XRay 

Open-source    

Recon, mapping, OSINT for public networks

ZoomEye 

Commercial    

Network component search engine