The most powerful free OSINT tool on earth. Use Google dork operators — site:, inurl:, filetype:, intitle:, cache: — to surface hidden data, exposed files, and indexed sensitive information that most people never find.
Visual link analysis and OSINT investigation platform. Maps relationships between people, organisations, domains, IPs, and social accounts using graph-based visualisations. Automated transforms pull data from hundreds of sources in one workspace.
A full-featured web reconnaissance framework with an interface similar to Metasploit. Modules gather intelligence from public sources, social media, and online databases — ideal for the initial phases of any investigation.
Automated OSINT and threat intelligence tool. Queries 200+ data sources about IP addresses, domain names, email addresses, names, and more — producing a comprehensive intelligence report with a built-in web UI.
Gathers emails, subdomains, hosts, employee names, and open ports from public sources — Google, Bing, LinkedIn, Shodan, Hunter, and more. A staple of the OSINT recon phase and included in Kali Linux by default.
A set of open-source intelligence linking tools — username checks across 200+ platforms, email lookup, alias generation, and cross-platform profile correlation. Includes usufy.py, mailfy.py, and more.