OSINT Cybersecurity Tools

Overview

OSINT Cybersecurity Tools

Welcome to the World of OSINT:

An ongoing collection of awesome tools and frameworks, best security software practices, libraries, learning tutorials, frameworks, academic and practical resources about Open-source intelligence (OSINT) in cybersecurity. Thanks to all contributors, you're awesome and wouldn't be possible without you! Our goal is to build a categorized community-driven collection of very well-known resources.

Table of Contents

^ back to top ^

Introduction

Open-source intelligence (OSNIT) is the insight gained from processing and analyzing public data sources such as broadcast TV and radio, social media, and websites. These sources provide data in text, video, image, and audio formats.

osint

According to U.S. public law, Open Source Intelligence:

  • Is produced from publicly available information
  • Is collected, analyzed, and disseminated in a timely manner to an appropriate audience
  • Addresses a specific intelligence requirement

^ back to top ^

General Search

The main search engines used by users.

^ back to top ^

Main National Search Engines

Localized search engines by country.

^ back to top ^

Meta Search

Lesser known and used search engines.

^ back to top ^

Specialty Search Engines

Search engines for specific information or topics.

^ back to top ^

Visual Search and Clustering Search Engines

Search engines that scrape multiple sites (Google, Yahoo, Bing, Goo, etc) at the same time and return results.

  • Carrot2 - Organizes your search results into topics.
  • Yippy - Search using multiple sources at once

Similar Sites Search

Find websites that are similar. Good for business competition research.

Document and Slides Search

Search for data located on PDFs, Word documents, presentation slides, and more.

File Search

Search for all kind of files.

Pastebins

Find information that has been uploaded to Pastebin & alternative pastebin-type sites

Code Search

Search by website source code

Major Social Networks

Real-Time Search, Social Media Search, and General Social Media Tools

Social Media Tools

Twitter

Facebook

^ back to top ^

Instagram

^ back to top ^

Pinterest

Reddit

Tools to help discover more about a reddit user or subreddit.

  • Imgur - The most popular image hosting website used by redditors.
  • Mostly Harmless - Mostly Harmless looks up the page you are currently viewing to see if it has been submitted to reddit.
  • Reddit Archive - Historical archives of reddit posts.
  • Reddit Suite - Enhances your reddit experience.
  • Reddit Investigator - Investigate a reddit users history.
  • Reddit Metrics - Keeps track of the growth of a subreddit.
  • Reddit User Analyser - reddit user account analyzer.
  • SnoopSnoo - Provides reddit user and subreddits analytics.
  • Subreddits - Discover new subreddits.
  • Reddit Comment Search - Analyze a reddit users by comment history.
  • Universal Scammer List - This acts as the website-portion for the subreddit /r/universalscammerlist. That subreddit, in conjuction with this website and a reddit bot, manages a list of malicious reddit accounts and minimizes the damage they can deal. This list is referred to as the "USL" for short.

^ back to top ^

VKontakte

Perform various OSINT on Russian social media site VKontakte.

Tumblr

LinkedIn

  • FTL - Browser plugin that finds emails of people's profiles in LinkedIn.

Telegram

  • Telegago - A Google Advanced Search specifically for finding public and private Telegram Channels and Chatrooms.
  • Telegram Nearby Map - Webapp based on OpenStreetMap and the official Telegram library to find the position of nearby users.

Blog Search

Forums and Discussion Boards Search

Username Check

People Investigations

  • 411 (US) - Search by person, phone number, address, and business. Limited free info, premium data upsell.
  • 192 (UK) - Search by person, business, address. Limited free info, premium data upsell.
  • Ancestry - Premium data, free trial with credit card.
  • Black Book Online - Free. Nationwide directory of public record lookups.
  • Canada411 - Search by person, phone number, and business. Free.
  • Classmates - High-school focused people search. Free acounts allow creating a profile and viewing other members. Premium account required to contact other members.
  • CrunchBase - Business information database, with a focus on investment, acquisition, and executive data. Ancillary focus on market research and connecting founders and investors.
  • facesearch - Handy proxy to search Google face-only image search results.
  • Family Search - Popular genealogy site. Free, but registration requried. Funded by The Church Of Jesus Christ of Latter-day Saints.
  • Federal Bureau of Prisons - Inmate Locator (US) - Search federal inmates incarcerated from 1982 to the present.
  • Fold3 (US Military Records) - Search military records. Search filters limited with free access. Premium access requires subscription.
  • Genealogy Bank - Premium data, free trial with credit card.
  • Genealogy Links - Genealogy directory with over 50K links.
  • Homemetry - Reverse address search and allows searching for properties for sale/rent.
  • Judyrecords - Free. Nationwide search of 400 million+ United States court cases.
  • Kompass - Business directory and search.
  • My Life People Search - People search. Limited free info, premium data upsell.
  • OpenSanctions - Information on sanctions and public office holders.
  • The National Archives (UK) - Search UK national archives.
  • Reunion - People search. Limited free info, premium data upsell.
  • SearchBug - People search. Limited free info, premium data upsell.
  • Spokeo - People search. Limited free info, premium data upsell.
  • UniCourt - Limited free searches, premium data upsell. Nationwide search of 100 million+ United States court cases.
  • White Pages (US) - People search. Limited free info, premium data upsell.
  • ZabaSearch
  • JailBase
  • Black Book Online
  • Mugshots

E-mail Search / E-mail Check

Phone Number Research

  • National Cellular Directory - was created to help people research and reconnect with one another by performing cell phone lookups. The lookup products includes have billions of records that can be accessed at any time, as well as free searches one hour a day, every day.
  • Reverse Phone Lookup - Detailed information about phone carrier, region, service provider, and switch information.
  • Spy Dialer - Get the voicemail of a cell phone & owner name lookup.
  • Twilio - Look up a phone numbers carrier type, location, etc.
  • Phone Validator - Pretty accurate phone lookup service, particularly good against Google Voice numbers.
  • PhoneInfoga - Advanced information gathering & OSINT framework for phone numbers
  • FreeCarrierLookup
  • Sync.ME

Expert Search

Company Research

Job Search Resources

Q&A Sites

Domain and IP Research

Keywords Discovery and Research

Web History and Website Capture

Language Tools

Image Search

Image Analysis

Stock Images

Video Search and Other Video Tools

Radio and Podcasts Tools

Academic Resources and Grey Literature

Books and Reading

Geospatial Research and Mapping Tools

News

News Digest and Discovery Tools

Fact Checking

Data and Statistics

Web Monitoring

Bookmarking

Startpages

Browsers

Offline Browsing

VPN Services

Note-taking

Annotation Tools

Writing and Office Tools

Slide Show and Presentation Tools

Digital Publishing

Newsletter Tools

Digital Storytelling

Infographics and Data Visualization

Image and Photo Editing

Productivity Tools

E-mail Management

Document and Reference Management

PDF Management

OCR Tools

Cloud Storage and File Sharing

Web Automation

Dashboard Tools

Wikis

Collaboration and Project Management

Communication Tools

Calendars and Scheduling

Mind Mapping, Concept Mapping and Idea Generation Tools

Social Network Analysis

Privacy and Encryption Tools

^ back to top ^

DNS

  • Amass - The amass tool searches Internet data sources, performs brute force subdomain enumeration, searches web archives, and uses machine learning to generate additional subdomain name guesses. DNS name resolution is performed across many public servers so the authoritative server will see the traffic coming from different locations. Written in Go.
  • findsubdomains - Automatically scans different sources to collect as many subdomains as can. Validate all the data through various tools and services to provide correct results without waiting.

Other Tools

  • Barcode Reader - Decode barcodes in C#, VB, Java, C\C++, Delphi, PHP and other languages.
  • Belati - Belati - The Traditional Swiss Army Knife For OSINT. Belati is tool for Collecting Public Data & Public Document from Website and other service for OSINT purpose.
  • Datasploit - Tool to perform various OSINT techniques on usernames, emails addresses, and domains.
  • Greynoise - "Anti-Threat Intelligence" Greynoise characterizes the background noise of the internet, so the user can focus on what is actually important.
  • The Harvester - Gather emails, subdomains, hosts, employee names, open ports and banners from different public sources like search engines, PGP key servers and SHODAN computer database.
  • Intrigue Core - Framework for attack surface discovery.
  • Maltego - Maltego is an open source intelligence (OSINT) and graphical link analysis tool for gathering and connecting information for investigative tasks.
  • Hunchly - Hunchly is a web capture tool designed specifically for online investigations.
  • OpenRefine - Free & open source power tool for working with messy data and improving it.
  • Orbit - Draws relationships between crypto wallets with recursive crawling of transaction history.
  • OSINT Framework - Web based framework for OSINT.
  • OsintStalker - Python script for Facebook and geolocation OSINT.
  • Outwit - Find, grab and organize all kinds of data and media from online sources.
  • eScraper - Grab product descriptions, prices, image urls and other data effortlessly
  • Photon - Crawler designed for OSINT
  • Pown Recon - Target reconnaissance framework powered by graph theory.
  • QuickCode - Python and R data analysis environment.
  • SecApps Recon - Information gathering and target reconnaissance tool and UI.
  • sn0int - Semi-automatic OSINT framework and package manager.
  • SpiderFoot - OSINT automation platform with over 200 modules for threat intelligence, attack surface monitoring, security assessments and asset discovery.
  • Zen - Find email addresses of Github users
  • OSINT.SH - Information Gathering Toolset.
  • SpiderFoot - SpiderFoot is an open source intelligence (OSINT) automation tool.
  • FOCA - Tool to find metadata and hidden information in the documents.
  • ^ back to top ^

Threat Intelligence

  • GitGuardian - Public GitHub Monitoring - Monitor public GitHub repositories in real time. Detect secrets and sensitive information to prevent hackers from using GitHub as a backdoor to your business.
  • REScure Threat Intel Feed - REScure is an independent threat intelligence project which we undertook to enhance our understanding of distributed systems, their integration, the nature of threat intelligence and how to efficiently collect, store, consume, distribute it.
  • OTX AlienVault - Open Threat Exchange is the neighborhood watch of the global intelligence community. It enables private companies, independent security researchers, and government agencies to openly collaborate and share the latest information about emerging threats, attack methods, and malicious actors, promoting greater security across the entire community.
  • OnionScan - Free and open source tool for investigating the Dark Web. Its main goal is to help researchers and investigators monitor and track Dark Web sites.
  • Digital Stakeout - DigitalStakeout Scout™ is the leading security intelligence tool to collect data from the surface web, social media, dark web and technical sources to illuminate and investigate external threats.
  • ^ back to top ^

OSINT Videos

OSINT Blogs

Other Resources

Project Management Tools

Project management tools, Scrum tools, and Project Boards.

  • ClickUp - Heavy-weight Task Management
  • Scrumfast - Light-weight, Free Project Management Tool
  • Trello - Free Team Project Board

Contributing

Please read CONTRIBUTING if you wish to add tools or resources.

Credits

This list was taken partially taken from i-inteligence's OSINT Tools and Resources Handbook.

License

MIT License & cc license

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 International License.

To the extent possible under law, Paul Veillard has waived all copyright and related or neighboring rights to this work.

^ back to top ^

Owner
Paul Veillard, P. Eng
Welcome to the most extensive collection of encyclopedic knowledge in the World of CyberSecurity®
Paul Veillard, P. Eng
A Python application to predict what is cooking

ez-cuisine-classifier A Python application to predict what is cooking Environment Python 3.9 Windows 10 Install python -m venv venv .\venv\Scripts\act

Zeheng Li 1 Jun 21, 2022
On-demand scanning for container registries

Lacework registry scanner Install & configure Lacework CLI Integrate a Container Registry Go to Lacework Resources Containers Container Image In

Will Robinson 1 Dec 14, 2021
evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.

Introduction evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files. It can process a high numbe

NVISO 116 Dec 29, 2022
Scan publicly accessible assets on your AWS cloud environment

poro Description Scan for publicly accessible assets on your AWS environment Services covered by this tool: AWS ELB API Gateway S3 Buckets RDS Databas

9rnt 134 Dec 16, 2022
Fetch Chrome, Firefox, WiFi password and system info

DISCLAIMER : OUR TOOLS ARE FOR EDUCATIONAL PURPOSES ONLY. DON'T USE THEM FOR ILLEGAL ACTIVITIES. YOU ARE THE ONLY RESPONSABLE FOR YOUR ACTIONS! OUR TO

Genos 59 Nov 17, 2022
DoSer.py - Simple DoSer in Python

DoSer.py - Simple DoSer in Python What is DoSer? DoSer is basically an HTTP Denial of Service attack that affects threaded servers. It works like this

1 Oct 12, 2021
Meterpreter Reverse shell over TOR network using hidden services

Poiana Reverse shell over TOR network using hidden services Features - Create a hidden service - Generate non-staged payload (python/meterpreter_rev

calfcrusher 80 Dec 21, 2022
Zero-attacker is an multipurpose hacking tool with over 12 tools

Zero Attacker Zero Attacker is bunch of tools which we made for people.These all tools are for purpose of ethical hacking and discord tools. Who is th

Asjad 300 Dec 28, 2022
The best Python Backdoor👌

Backdoor The best Python Backdoor Files Server file is used in all of cases If client is Windows, the client need execute EXE file If client is Linux,

13 Oct 28, 2022
GitHub Advance Security Compliance Action

advanced-security-compliance This Action was designed to allow users to configure their Risk threshold for security issues reported by GitHub Code Sca

Mathew Payne 121 Dec 14, 2022
Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.

GoodHound ______ ____ __ __ / ____/___ ____ ____/ / / / /___ __ ______ ____/ / / / __/ __ \/ __ \/ __

idna 352 Jan 02, 2023
SQLi Google Dork Scanner (new version)

XGDork² - ViraX Google Dork Scanner SQLi Google Dork Scanner by ViraX @ 2021 for Python 2.7 - compatible Android(NoRoot) - Termux A simple 'naive' pyt

8 Dec 20, 2022
TCP/UDP port scanner on python, usong scapy and multiprocessin

Port Scanner TCP/UDP port scanner on python, usong scapy and multiprocessing. Usage python3 scanner.py [OPTIONS] IP_ADDRESS [{tcp|udp}[/[PORT|PORT-POR

Egor Krokhin 1 Dec 05, 2021
MayorSec DNS Enumeration Tool

MayorSecDNSScan MSDNSScan is used to identify DNS records for target domains and check for zone transfers. There really isn't much special about it, a

Joe Helle 68 Dec 12, 2022
An interactive python script that enables root access on the T-Mobile (Wingtech) TMOHS1, as well as providing several useful utilites to change the configuration of the device.

TMOHS1 Root Utility Description An interactive python script that enables root access on the T-Mobile (Wingtech) TMOHS1, as well as providing several

40 Dec 29, 2022
A curated list of amazingly awesome Cybersecurity datasets

A curated list of amazingly awesome Cybersecurity datasets

758 Dec 28, 2022
Execution After Redirect (EAR) / Long Response Redirection Vulnerability Scanner written in python3

Execution After Redirect (EAR) / Long Response Redirection Vulnerability Scanner written in python3, It Fuzzes All URLs of target website & then scan them for EAR

Pushpender Singh 9 Dec 12, 2022
Python-based proof-of-concept tool for generating payloads that utilize unsafe Java object deserialization.

Python-based proof-of-concept tool for generating payloads that utilize unsafe Java object deserialization.

Astro 9 Sep 27, 2022
This is simple python FTP password craker. To crack FTP login using wordlist based brute force attack

This is simple python FTP password craker. To crack FTP login using wordlist based brute force attack

Varun Jagtap 5 Oct 08, 2022
Web3 Pancakeswap Sniper & honeypot detector Take Profit/StopLose bot written in python3, For ANDROID WIN MAC & LINUX

🏆 Pancakeswap BSC Sniper Bot web3 with honeypot detector (ANDROID WINDOWS MAC LINUX) 🥇 ⭐️ ⭐️ ⭐️ First SNIPER BOT for ANDROID & WINDOWS with honeypot

Mayank 12 Jan 07, 2023