pwnHACKER // OSINT

Open Source Intelligence Investigation Tools

// SECURITY ADVISORY — USE A VPN

Your ISP monitors everything you do online. Without encryption, your IP is exposed and your activity is logged. Surfshark masks your traffic, bypasses geo-restrictions, and keeps you anonymous — for less than $0.06/day. We use it. We recommend it. Don't hack unprotected.

⚡ GET SURFSHARK — 87% OFF + 3 MONTHS FREE
— INTELLIGENCE ARCHIVE —
OSINT // SEARCH & FILTER
root@pwnhacker:~$ 46 TOOLS
⌕ Search Engines & Frameworks 6 TOOLS
01
Google Advanced Search / Dorks Free

The most powerful free OSINT tool on earth. Use Google dork operatorssite:, inurl:, filetype:, intitle:, cache: — to surface hidden data, exposed files, and indexed sensitive information that most people never find.

Use Cases Exposed files · Login portals · Sensitive data discovery · Recon
02
Maltego Freemium

Visual link analysis and OSINT investigation platform. Maps relationships between people, organisations, domains, IPs, and social accounts using graph-based visualisations. Automated transforms pull data from hundreds of sources in one workspace.

Website maltego.com ↗
Use Cases Graph analysis · Relationship mapping · Infrastructure recon
03
Recon-ng Free

A full-featured web reconnaissance framework with an interface similar to Metasploit. Modules gather intelligence from public sources, social media, and online databases — ideal for the initial phases of any investigation.

Use Cases Automated recon · Multi-source intelligence · Modular OSINT
04
SpiderFoot Free

Automated OSINT and threat intelligence tool. Queries 200+ data sources about IP addresses, domain names, email addresses, names, and more — producing a comprehensive intelligence report with a built-in web UI.

Use Cases Target profiling · Threat intel · Automated multi-source OSINT
05
theHarvester Free

Gathers emails, subdomains, hosts, employee names, and open ports from public sources — Google, Bing, LinkedIn, Shodan, Hunter, and more. A staple of the OSINT recon phase and included in Kali Linux by default.

Use Cases Email harvesting · Subdomain enum · Employee discovery
06
OSRFramework Free

A set of open-source intelligence linking tools — username checks across 200+ platforms, email lookup, alias generation, and cross-platform profile correlation. Includes usufy.py, mailfy.py, and more.

Use Cases Username OSINT · Email recon · Cross-platform profiling
People & Identity 10 TOOLS
01
Pipl Freemium

The world's largest people search engine, aggregating identity data across social networks, public records, online profiles, and contact information. Used by investigators, HR teams, and journalists.

Website pipl.com ↗
Use Cases Identity verification · Background checks · Contact lookup
02
Spokeo Freemium

Aggregates public records, social media, and contact data into a single people search. Search by name, email, phone, or address to build a comprehensive profile.

Website spokeo.com ↗
Use Cases People search · Address history · Reverse phone lookup
03
That's Them Free

Free reverse lookup tool. Search by name, email, phone, address, or IP to find associated profiles and contact data without requiring an account.

Use Cases Reverse lookup · Email → name · IP → identity
04
Hunter.io Freemium

Find and verify professional email addresses associated with any domain. Reveals email patterns used by companies and surfaces employee contacts from public sources.

Website hunter.io ↗
Use Cases Email discovery · Domain recon · Employee enumeration
05
Intelius

Comprehensive background check and people search service drawing from billions of public records — criminal records, addresses, relatives, and more.

Use Cases Background checks · Criminal records · Address history
06
Have I Been Pwned Free

Check whether an email address has appeared in known data breaches. Aggregates breach data from hundreds of incidents to help users understand their exposure.

Use Cases Breach lookup · Credential exposure · Email enumeration
07
Skiptracer Free

Python-based OSINT scraping framework that aggregates data from free public sites — pastebin, pipl, whois, PGP keys, and more — into a single report.

Use Cases Automated scraping · Multi-source aggregation · CLI recon
08
Maltego Freemium

Visual link analysis and OSINT investigation platform. Maps relationships between people, organizations, domains, IPs, and social accounts using graph-based visualizations and automated transforms.

Website maltego.com ↗
Use Cases Graph analysis · Relationship mapping · Infrastructure recon
09
BeenVerified

Consumer-facing background check and people search platform aggregating public records, social profiles, criminal history, and contact data into clean reports. Good for quick personal-level recon.

Use Cases Background checks · People lookup · Criminal records
10
PeekYou Free

Searches across social networks, news, blogs, and public records to build a web presence profile for any person. Particularly useful for correlating real identities with online aliases.

Website peekyou.com ↗
Use Cases Web presence profiling · Alias correlation · Social footprint
Domain & IP Intelligence 9 TOOLS
01
Shodan Freemium

The search engine for Internet-connected devices. Continuously crawls and indexes open ports, banners, and services across billions of IPs — from routers to industrial systems.

Website shodan.io ↗
Use Cases Device discovery · Banner grabbing · Attack surface mapping
02
Whois Lookup Free

Query domain registration records — owner, registrar, registration dates, name servers, and contact data from public WHOIS databases.

Website whois.com ↗
Use Cases Domain ownership · Registrar lookup · DNS recon
03
ViewDNS.info Free

Suite of DNS investigation tools: reverse IP, reverse whois, DNS history, traceroute, port scanner, and IP geolocation — all in one free interface.

Use Cases Reverse IP · DNS history · Shared hosting lookup
04
Censys Freemium

Scans the entire Internet to index every reachable host and certificate. Provides structured data on TLS certs, open services, and device metadata. Research-grade internet-wide scanning.

Use Cases TLS cert lookup · Internet-wide scanning · Host enumeration
05
VirusTotal Free

Analyze URLs, domains, IPs, and files against 70+ antivirus engines and reputation services simultaneously. Essential for quick threat assessment and IOC validation.

Use Cases Malware lookup · URL reputation · IOC analysis
06
Hurricane Electric BGP Toolkit Free

Query ASN, BGP routing, IP ranges, and DNS records for any organization. Invaluable for mapping an organisation's full internet-facing infrastructure.

Website bgp.he.net ↗
Use Cases ASN lookup · IP range mapping · BGP routing recon
07
DNSDumpster Free

Free domain research tool that discovers hosts related to a domain — subdomains, MX records, name servers — and visualises the DNS map. No API key required.

Use Cases Subdomain discovery · DNS map · MX enumeration
08
BuiltWith Freemium

Identify the technology stack behind any website — CMS, frameworks, analytics, CDN, hosting provider, and more. Invaluable for fingerprinting targets and understanding their infrastructure before engagement.

Use Cases Tech fingerprinting · CMS detection · Infrastructure recon
09
URLScan.io Free

Submit a URL to scan and analyse it in a sandboxed browser. Returns a screenshot, DOM content, outbound requests, redirects, and threat indicators — all without visiting the page yourself. Essential for safely analysing suspicious links.

Website urlscan.io ↗
Use Cases Malicious URL analysis · Phishing detection · Safe browsing recon
Social Media Intelligence 6 TOOLS
01
Sherlock Free

Hunt for a username across 300+ social networks simultaneously via CLI. Written in Python — one of the most-starred OSINT tools on GitHub.

Use Cases Username OSINT · Account discovery · Cross-platform profiling
02
Social Searcher Freemium

Real-time social media search engine monitoring public posts across Twitter, Facebook, Instagram, Reddit, and more. Track keywords, hashtags, and mentions.

Use Cases Keyword monitoring · Mention tracking · Sentiment analysis
03
Twint Free

Advanced Twitter scraping tool that requires no API key. Scrape tweets, followers, following lists, likes, and profile data without rate limits.

Use Cases Tweet harvesting · Follower mapping · Timeline scraping
04
Instaloader Free

Download Instagram profiles, photos, stories, reels, hashtags, and metadata including geotags and timestamps. Powerful CLI tool for Instagram OSINT.

Use Cases Profile archiving · Geotag extraction · Metadata analysis
05
Camas Reddit Search Free

Advanced Reddit search and user history archive. Find deleted posts, search by user, subreddit, keywords, and date ranges — deeper than native Reddit search.

Use Cases Deleted post recovery · User history · Subreddit analysis
06
Osintgram Free

Interactive Instagram OSINT CLI tool — extract followers, following, tagged locations, photos, comments, and captions from any public Instagram profile.

Use Cases Instagram profiling · Location extraction · Follower mapping
Image & Geolocation 6 TOOLS
01
Google Images Reverse Search Free

Upload or paste an image to find where it appears across the web, discover the original source, identify people and objects, and expose fake or stolen profile photos.

Use Cases Fake profile detection · Source identification · Face search
02
TinEye Freemium

Dedicated reverse image search engine with 62+ billion indexed images. Tracks how images are used, finds earlier versions, and identifies modified or cropped copies.

Website tineye.com ↗
Use Cases Image provenance · Copyright tracking · Modified image detection
03
ExifTool Free

Read and write metadata (EXIF, IPTC, XMP) from images, PDFs, and audio files. Extracts GPS coordinates, camera make/model, timestamps, and software used — often revealing far more than the subject intended.

Use Cases GPS extraction · Camera fingerprinting · File metadata audit
04
Google Earth Pro Free

Geolocate images and videos by matching terrain, buildings, and landmarks against satellite and street-level imagery. Essential for open-source geolocation and confirmation.

Use Cases Image geolocation · Terrain matching · Historical imagery
05
Yandex Image Search Free

Yandex reverse image search is often significantly more powerful than Google for facial recognition and finding Eastern European / Russian-language sources. Frequently surfaces results that Google and TinEye miss entirely — a critical tool in any facial OSINT workflow.

Use Cases Facial search · Reverse image · Cross-language image recon
06
Mapillary Free

Crowdsourced street-level imagery platform covering areas Google Street View doesn't reach. Use it for geolocation confirmation, verifying photo locations, and mapping obscure areas from user-submitted photos.

Use Cases Geolocation verification · Street-level recon · Location confirmation
Network & Infrastructure 6 TOOLS
01
Nmap Free

The gold standard for network discovery and port scanning. Identifies hosts, services, OS versions, and open ports. The recon phase staple for 25+ years.

Website nmap.org ↗
Use Cases Port scanning · OS detection · Service enumeration
02
Wireshark Free

The world's foremost network protocol analyser. Capture and examine network traffic at packet level across hundreds of protocols. Spot anomalies, extract credentials, and study behaviour.

Use Cases Traffic capture · Protocol analysis · Credential extraction
03
Kismet Free

Passive wireless network detector, sniffer, and IDS. Works without transmitting packets — ideal for covert wireless OSINT, wardriving, and Bluetooth / RF device discovery.

Use Cases Wardriving · Passive sniffing · Bluetooth OSINT
04
WiGLE Free

Global wireless network geolocation database with 1+ billion networks mapped. Search networks by SSID, BSSID, or location. The definitive wardriving archive — and the mobile app is the best wardriving tool on Android.

Website wigle.net ↗
Use Cases Network geolocation · SSID lookup · Wardriving archive
05
MTR (My Traceroute) Free

Combines traceroute and ping into a real-time network diagnostic tool. Maps every hop between source and destination — revealing routing paths, latency, and packet loss.

Use Cases Route mapping · Latency analysis · Network path OSINT
06
Masscan Free

The fastest Internet port scanner — capable of scanning the entire IPv4 space in under 6 minutes. Transmits 10 million packets per second. Perfect for large-scale network discovery and complement to Nmap's deeper service analysis.

Use Cases Internet-wide scanning · Mass port discovery · Fast recon
Documents & Metadata 5 TOOLS
01
Xeuledoc Free

Python tool that extracts metadata from public Google Documents — owner name, Gmail address, Google ID, creation date. Works with Docs, Sheets, Slides, Drawings, and more. Non-intrusive: no login required.

Use Cases Google Doc metadata · Account deanonymization · Document OSINT
02
FOCA Free

Extracts hidden metadata from Office and PDF documents — author names, software versions, internal paths, printer names, and more. Automates Google dork searches to find documents to analyse.

Use Cases Document metadata · Author extraction · Internal path disclosure
03
Wayback Machine Free

Access historical snapshots of any website going back to 1996. Recover deleted pages, track site evolution, and find content that was intentionally removed.

Use Cases Deleted page recovery · Site history · Content archaeology
04
Pastebin Search Free

Search paste sites (Pastebin, Ghostbin, etc.) for leaked credentials, source code, API keys, and sensitive data dumps. Often the first place breach data surfaces publicly.

Website psbdmp.ws ↗
Use Cases Credential leak detection · API key exposure · Code dumps
05
Metagoofil Free

Uses Google dorking to harvest documents (PDF, DOC, XLS, PPT) from a target domain, then automatically extracts metadata from every file found — author names, software, internal paths, and server names.

Use Cases Document harvesting · Bulk metadata extraction · Author enumeration
Phone & SMS Intelligence 4 TOOLS
01
Truecaller Freemium

Global reverse phone lookup and caller ID database with 300M+ users contributing number-to-name mappings. Identify unknown callers, detect spam, and look up numbers from almost any country.

Use Cases Reverse phone lookup · Spam identification · Caller ID
02
NumVerify Freemium

API and web tool for phone number validation and carrier lookup. Returns carrier, line type (mobile/landline), location, and country for any global number.

Use Cases Number validation · Carrier lookup · Line type detection
03
CountryCallingCodes.com Free

Reference for international dialling codes and country prefixes. Reverse-lookup phone prefixes to identify country of origin for unknown international numbers.

Use Cases Country prefix ID · International number recon
04
PhoneInfoga Free

Advanced phone number OSINT scanner written in Go. Gathers standard information (country, carrier, line type) then searches Google, Numverify, and other sources for social media profiles and online footprints associated with the number.

Use Cases Phone OSINT · Carrier lookup · Social profile discovery
Dark Web Monitoring 4 TOOLS
01
Tor Browser Free

Access .onion sites and the dark web anonymously via the Tor network. Essential for investigators monitoring dark web forums, marketplaces, and leak sites — use only for lawful research.

Use Cases Dark web access · Anonymous browsing · .onion site monitoring
02
Ahmia Free

Search engine for Tor hidden services. Indexes publicly accessible .onion sites and allows keyword searching without navigating manually — usable from the clearnet or via Tor.

Website ahmia.fi ↗
Use Cases .onion search · Dark web indexing · Hidden service discovery
03
DeHashed Freemium

Search the largest database of leaked credentials and breached data. Query by email, username, IP, password hash, name, phone, or domain to surface exposure across known data breaches.

Use Cases Credential breach search · Dark web data · Account exposure
04
OnionSearch Free

Python script that scrapes multiple dark web search engines simultaneously — Ahmia, Candle, Dark Search, Torch, and others — combining results into a unified report. Ideal for keyword-based dark web monitoring without manual browsing.

Use Cases Multi-engine dark web search · Keyword monitoring · .onion discovery
[ NO TOOLS MATCH QUERY ]

Information is the oxygen of the modern age.

— Ronald Reagan · pwnHACKER OSINT Doctrine

— RESPONSIBLE USE —
ETHICS // OPERATIONAL_DOCTRINE
Purpose Educational & investigative use only
Rule 01 Obtain proper authorisation before investigating individuals or systems
Rule 02 Comply with applicable local, national, and international laws
Rule 03 Respect individual privacy — OSINT ≠ licence to stalk or harass
Operator jT // MajorJoker — 40+ yrs experience, ethical doctrine always
AVAILABLE FOR CONSULTATION & COLLABORATION
OSINT Investigation · Cybersecurity · Network Architecture