domain: osint
284 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| josh0xA/darkdump Darkdump is an open-source OSINT tool for querying multiple dark web search engines and scraping onion site results for emails, metadata, k… | 70 | 1757 | active |
| IvanGlinkin/Fast-Google-Dorks-Scan A shell-based OSINT tool that automates Google dork searches against a target website to uncover admin panels, exposed file types, and path… | 46 | 1742 | active |
| j3ssie/metabigor Metabigor is a Go-based command-line OSINT tool that maps a target's infrastructure—IP ranges, subdomains, related domains, open ports, and… | 86 | 1735 | active |
| utkusen/urlhunter urlhunter is a Go-based recon CLI tool that searches URLs exposed via shortener services like bit.ly and goo.gl. It downloads daily URLTeam… | 24 | 1697 | active |
| michenriksen/gitrob Gitrob is a Go-based reconnaissance tool that scans GitHub users' and organizations' public repositories for potentially sensitive files by… | 10 | 6198 | maintenance |
| michenriksen/aquatone Aquatone is a Go CLI tool for visual inspection of websites across many hosts, taking screenshots via headless Chrome/Chromium and generati… | 10 | 5961 | maintenance |
| ghostop14/sparrow-wifi Sparrow-WiFi is a Python 3 GUI-based WiFi and Bluetooth analyzer for Linux that combines 2.4/5 GHz scanning, BLE/Classic discovery, SDR spe… | 74 | 1614 | active |
| Altimis/Scweet Scweet is a Python library and CLI for scraping tweets, profile timelines, followers, following lists, and user profiles from Twitter/X wit… | 78 | 1604 | active |
| 4lbH4cker/ALHacking ALHacking is a shell-script-based toolkit bundling a menu of so-called ethical hacking utilities, including social media account attacks, p… | 32 | 1601 | active |
| Autumn-27/ScopeSentry ScopeSentry is a self-hosted attack surface and asset mapping platform that combines subdomain enumeration, port scanning, fingerprinting, … | 88 | 1587 | active |
| m3n0sd0n4ld/GooFuzz GooFuzz is a Bash-based CLI tool that performs fuzzing-style reconnaissance using advanced Google searches (Google Dorking) via the Google … | 57 | 1585 | active |
| m8sec/CrossLinked CrossLinked is a Python CLI tool that enumerates LinkedIn employee names for an organization by scraping search engine results, without nee… | 23 | 1582 | active |
| hakluke/hakrevdns hakrevdns is a small, fast Go CLI tool that performs reverse DNS (PTR) lookups on large batches of IP addresses. It maps IPs to hostnames, … | 75 | 1572 | stable |
| Clats97/ClatScope ClatScope Info Tool is a Python-based OSINT utility offering 70+ reconnaissance features including geolocation, DNS, WHOIS, phone, email, a… | 48 | 1537 | active |
| jasperan/whatsapp-osint A Python CLI tool that uses Selenium to track when WhatsApp contacts go online/offline, logging presence sessions to SQLite. It exports dat… | 76 | 1511 | active |
| GONZOsint/geowifi A Python command-line tool that queries multiple public WiFi geolocation databases (Wigle, Apple, Google, Mylnikov, WiFiDB, Combain, Freifu… | 32 | 1495 | active |
| OpenOSINT/OpenOSINT OpenOSINT is an AI-powered OSINT framework offering 19 investigation tools behind a natural-language agent, usable as an interactive REPL, … | 81 | 1470 | active |
| momosecurity/FindSomething FindSomething is a passive browser extension for Chrome and Firefox that extracts potentially sensitive information (like emails, API keys,… | 32 | 1458 | active |
| urbanadventurer/username-anarchy Username Anarchy is a Ruby command-line tool that generates lists of likely usernames from people's first and last names for use in penetra… | 23 | 1458 | stable |
| khast3x/h8mail h8mail is a Python CLI tool for email OSINT and password breach hunting. It queries breach services like HaveIBeenPwned and Hunter.io, or s… | 23 | 5273 | maintenance |
| tillson/git-hound GitHound is a Go-based CLI tool that hunts for exposed API keys, secrets, and credentials across all of GitHub using GitHub dorks, pattern … | 70 | 1451 | active |
| ThoughtfulDev/EagleEye EagleEye is a Python-based OSINT tool that identifies social media profiles (Instagram, Facebook, Twitter, YouTube) of a person using face … | 32 | 5197 | maintenance |
| blacklanternsecurity/MANSPIDER MANSPIDER is a Python CLI tool that crawls SMB shares across entire networks to find files by filename or content, with regex support and t… | 77 | 1406 | active |
| superhedgy/AttackSurfaceMapper AttackSurfaceMapper is a Python CLI reconnaissance tool that expands a target's attack surface using OSINT and active techniques like subdo… | 32 | 1405 | active |
| CIRCL/AIL-framework AIL framework is an open-source Python platform for collecting, crawling, processing, and analyzing unstructured data from the clear web, T… | 67 | 1378 | active |
| thalesgroup-cert/Watcher Watcher is an open-source, self-hosted cyber threat intelligence and hunting platform built with Django and React JS. It uses AI to analyze… | 97 | 1372 | active |
| fasnow/fine Fine is a Chinese-language cyberspace asset mapping and reconnaissance tool integrating FOFA, Hunter, Quake, ZoomEye, and Shodan APIs, plus… | 82 | 1366 | active |
| BullsEye0/shodan-eye Shodan Eye is a Python command-line tool that queries the Shodan search engine to collect information about all devices directly connected … | 75 | 1352 | active |
| mishakorzik/UserFinder UserFinder is a shell-based OSINT tool that searches for user profiles across social networks and other sites by username. It runs as a sim… | 56 | 1348 | active |
| wotschofsky/domain-digger Domain Digger is a web application for in-depth domain analysis, offering DNS lookups across global resolvers, WHOIS queries, IP geolocatio… | 75 | 1340 | active |
| sockysec/Telerecon Telerecon is a Python-based OSINT reconnaissance framework for researching and investigating Telegram. It scrapes user profiles, messages, … | 28 | 1324 | active |
| MrTuxx/SocialPwned SocialPwned is a Python-based OSINT tool that harvests emails published on Instagram, LinkedIn, and Twitter to find credential leaks via Pw… | 10 | 1320 | active |
| freelabz/secator secator is a task and workflow runner for security assessments that unifies dozens of well-known security tools (subfinder, httpx, ffuf, nm… | 93 | 1306 | active |
| dwisiswant0/go-dork go-dork is a fast command-line dork scanner written in Go that automates Google dorking across multiple search engines. It supports Google,… | 23 | 1301 | stable |
| Te-k/harpoon Harpoon is a Python CLI tool that aggregates open source intelligence and threat intelligence lookups across many services (Censys, crt.sh,… | 70 | 1289 | active |
| misiektoja/instagram_monitor A Python-based OSINT tool that tracks Instagram users' activities in real time, including story updates, profile changes, and follower shif… | 91 | 1286 | active |
| xploitstech/Xteam Xteam is an all-in-one, menu-driven hacking toolkit written in Python and launched via bash scripts, bundling Instagram information gatheri… | 42 | 1268 | active |
| saeeddhqan/Maryam OWASP Maryam is a modular open-source OSINT framework for harvesting data from open sources, search engines, and social networks. It provid… | 10 | 1228 | active |
| boy-hack/ksubdomain KSubdomain is a fast, stateless subdomain enumeration and DNS verification tool written in Go. It uses raw sockets via pcap to bypass the k… | 68 | 1212 | active |
| taranis-ai/taranis-ai Taranis AI is a self-hosted open-source OSINT platform that collects news articles from web sources and uses NLP/AI to enrich, cluster, and… | 95 | 1207 | active |
| opensemanticsearch/open-semantic-search An open-source integrated search server and ETL framework for processing, analyzing, and exploring large document collections. It combines … | 40 | 1203 | active |
| pielco11/fav-up Fav-up is a Python CLI tool and library that finds the real IP address behind services like Cloudflare by hashing a website's favicon and s… | 25 | 1199 | active |
| niudaii/zpscan zpscan is a Go-based command-line information gathering and reconnaissance tool for security assessments. It bundles subdomain enumeration,… | 23 | 1196 | active |
| N0rz3/Phunter Phunter is a Python CLI OSINT tool that gathers information about phone numbers, including operator, line type, location, reputation, spam … | 26 | 1175 | active |
| v4lkyr0/Buildware-Tools Buildware-Tools is a Python-based terminal multitool combining OSINT reconnaissance, network diagnostics, Discord automation, cryptography … | 78 | 1167 | active |
| 0x727/ShuiZe_0x727 ShuiZe_0x727 is a Python-based automated information gathering (reconnaissance) tool for red team operators. Given a root domain, C-segment… | 23 | 4019 | maintenance |
| evyatarmeged/Raccoon Raccoon is a Python-based offensive security CLI tool for reconnaissance and information gathering. It performs DNS lookups, WHOIS, TLS ana… | 67 | 4001 | maintenance |
| random-robbie/My-Shodan-Scripts A collection of Python 3 scripts for querying the Shodan search engine to find exposed devices and services on the internet. It bundles man… | 60 | 1146 | active |
| kevthehermit/PasteHunter PasteHunter is a Python 3 application that queries public pastebin-style sites (pastebin.com, GitHub gists, slexy, stackexchange, etc.) and… | 50 | 1137 | active |
| atiilla/GeoIntel GeoIntel is a Python tool that uses Google's Gemini API to estimate where a photo was taken through AI-powered geolocation analysis. It off… | 58 | 1128 | active |
| projectdiscovery/asnmap asnmap is a Go CLI tool and library that maps organizations to their network ranges (CIDR blocks) using ASN information. It supports lookup… | 67 | 1121 | active |
| bellingcat/auto-archiver A Python tool by Bellingcat that automatically archives web content such as videos, images, social media posts, and webpages from URLs supp… | 92 | 1109 | active |
| tracelabs/tlosint-vm Trace Labs OSINT VM is a Kali Linux-based virtual machine distribution pre-loaded with open-source intelligence (OSINT) tools and Firefox h… | 87 | 1101 | active |
| hakluke/hakoriginfinder hakoriginfinder is a Go CLI tool that discovers the origin host behind a reverse proxy or WAF. It sends requests with the original Host hea… | 75 | 1101 | active |
| Tuhinshubhra/RED_HAWK RED_HAWK is a PHP-based all-in-one reconnaissance and vulnerability scanning tool for websites. It performs information gathering (whois, D… | 32 | 3748 | maintenance |
| AlephNullSK/dnsgen DNSGen is a Python CLI tool that generates intelligent permutations of domain names to aid subdomain discovery during security assessments.… | 32 | 1076 | active |
| knownsec/Kunyu Kunyu is a Python command-line tool for efficient corporate asset collection using cyberspace mapping engines like ZoomEye and Seebug. It h… | 25 | 1074 | active |
| soxoj/socid-extractor socid_extractor is a Python library and CLI that extracts structured account metadata and stable internal identifiers (usernames, UIDs, GAI… | 92 | 1073 | active |
| qiwentaidi/Slack Slack is an integrated security services toolkit built with Go and the Wails desktop framework, bundling website fingerprinting and vulnera… | 78 | 1073 | active |
| Junyi-99/ChatGPT-API-Scanner A Python CLI tool that scans GitHub for publicly leaked OpenAI API keys using Selenium browser automation. It is intended for security rese… | 58 | 1073 | active |
| tomnomnom/assetfinder A Go command-line tool that discovers domains and subdomains potentially related to a given domain by querying multiple passive sources lik… | 23 | 3666 | maintenance |
| h9zdev/GeoSentinel GeoSentinel is a geospatial monitoring platform that tracks global movement in real time, aggregating ship and flight routes, live coordina… | 57 | 1069 | active |
| N0rz3/Zehef Zehef is a Python command-line OSINT tool for investigating email addresses. It checks for pastes, data leaks, and linked social media acco… | 29 | 1062 | active |
| ElevenPaths/FOCA FOCA is a Windows desktop application that finds metadata and hidden information in documents discovered via search engines (Google, Bing, … | 23 | 3622 | maintenance |
| madneal/gshark GShark is a self-hosted sensitive information detection and management platform that scans repositories exposed by providers like GitHub, G… | 100 | 1055 | active |
| Zarcolio/sitedorks A Python CLI tool that runs Google dork-style searches across multiple search engines (Google, Bing, DuckDuckGo, Yandex, Yahoo, Ecosia, Bra… | 76 | 1053 | active |
| robotshell/magicRecon MagicRecon is a Bash shell script that automates reconnaissance and vulnerability scanning of target domains, including subdomain enumerati… | 23 | 1052 | active |
| Dheerajmadhukar/karma_v2 karma_v2 is a Bash-based passive OSINT reconnaissance framework that automates Shodan queries to enumerate assets, exposed services, CVEs, … | 42 | 1020 | active |
| mxrch/GitFive GitFive is a Python-based OSINT CLI tool for investigating GitHub user profiles. It uncovers usernames, name history, email addresses, and … | 43 | 1019 | active |
| AKCodez/hackingtool-plugin A Claude Code plugin that wraps 183+ pentesting and OSINT tools from Z4nzu/hackingtool, letting Claude automatically select and run securit… | 50 | 1016 | active |
| techchipnet/hound Hound is a lightweight PHP-based information gathering tool that captures a target device's exact GPS coordinates along with system and ISP… | 30 | 1016 | active |
| 0x6rss/matkap Matkap is a self-hosted web application for hunting malicious Telegram bots used as malware command-and-control infrastructure. It validate… | 65 | 1008 | active |
| JackJuly/linkook Linkook is a Python-based OSINT command-line tool that discovers linked social media accounts and associated email addresses across multipl… | 53 | 1008 | active |
| dedsec1121fk/DedSec DedSec Project is an educational cybersecurity and Termux toolkit for Android that bundles scripts, utilities, local web interfaces, and pr… | 88 | 1005 | active |
| ki9mu/ARL-plus-docker A Docker-based fork of ARL (Asset Reconnaissance Lighthouse) v2.6.2 that performs automated asset discovery and vulnerability scanning for … | 35 | 1005 | active |
| gwen001/pentest-tools A collection of small custom security scripts in Bash, Python, and PHP for penetration testing and bug bounty quick tasks, covering DNS enu… | 23 | 3323 | maintenance |
| s-rah/onionscan OnionScan is a free and open source Go CLI tool for investigating Tor hidden services (.onion sites) on the Dark Web. It scans sites for op… | 23 | 3290 | maintenance |
| 0x0be/yesitsme A Python CLI script for OSINT investigations that finds Instagram profiles matching a given name, e-mail, or phone number. It scrapes dumpo… | 32 | 3046 | maintenance |
| rajkumardusad/IP-Tracer IP-Tracer is a command-line tool for Linux and Termux that retrieves geolocation and information about any IP address using the ip-api serv… | 23 | 2983 | maintenance |
| Threezh1/JSFinder JSFinder is a Python command-line tool that crawls a website's JavaScript files and extracts URLs and subdomains using regex parsing. It su… | 32 | 2976 | maintenance |
| christophetd/CloudFlair CloudFlair is a Python CLI tool that finds the origin servers of websites protected by Cloudflare or CloudFront by searching Censys interne… | 41 | 2972 | maintenance |
| bhavsec/reconspider ReconSpider is an open-source OSINT framework written in Python for scanning IP addresses, emails, websites, and organizations to gather in… | 23 | 2778 | maintenance |
| martinvigo/email2phonenumber A Python OSINT tool that discovers a target's phone number from just their email address by abusing password reset flows that leak masked p… | 32 | 2747 | maintenance |
| m0rtem/CloudFail CloudFail is a Python 3 command-line reconnaissance tool that attempts to discover the real IP address of servers hidden behind Cloudflare.… | 32 | 2683 | maintenance |
| thewhiteh4t/nexfil Nexfil is an OSINT command-line tool written in Python that finds social media profiles by username across 350+ websites in seconds. It sup… | 32 | 2610 | maintenance |
| obheda12/GitDorker GitDorker is a Python CLI tool that uses the GitHub Search API with a curated list of over 200 dorks to find sensitive information exposed … | 32 | 2577 | maintenance |
| screetsec/Sudomy Sudomy is a Bash-based subdomain enumeration and reconnaissance framework that collects subdomains via active brute-forcing and passive thi… | 23 | 2432 | maintenance |
| alephdata/aleph Aleph is a self-hosted platform for indexing, searching, and browsing large volumes of documents (PDF, Word, HTML) and structured data (CSV… | 70 | 2420 | maintenance |
| ustayready/fireprox FireProx is a Python CLI tool that uses AWS API Gateway to create on-the-fly HTTP pass-through proxies that rotate the source IP address wi… | 32 | 2282 | maintenance |
| hexway/apple_bleee A collection of experimental Python PoC scripts for sniffing and injecting Apple Bluetooth Low Energy (BLE) and AWDL (AirDrop) traffic. It … | 23 | 2184 | maintenance |
| noob-hackers/ipdrone Ipdrone is a simple Python script for IP lookup that retrieves information about a target IP address, including live location with address … | 32 | 2148 | maintenance |
| D4Vinci/Cr3dOv3r Cr3dOv3r is a Python command-line pentesting tool for investigating credential reuse attacks. Given an email, it searches public breach dat… | 57 | 2137 | maintenance |
| initstring/cloud_enum A Python command-line OSINT tool that enumerates publicly exposed resources across AWS, Azure, and Google Cloud using keyword mutations and… | 79 | 2132 | maintenance |
| UnaPibaGeek/ctfr CTFR is a Python command-line tool that enumerates HTTPS website subdomains by querying Certificate Transparency logs (via crt.sh) instead … | 32 | 2117 | maintenance |
| s0md3v/ReconDog ReconDog is a Python-based reconnaissance 'Swiss Army Knife' that gathers information about targets (domains, IPs) using third-party APIs l… | 23 | 2099 | maintenance |
| Aabyss-Team/ARL ARL (Asset Reconnaissance Lighthouse) is a self-hosted asset reconnaissance system that quickly discovers internet-facing assets associated… | 29 | 2055 | maintenance |
| vaguileradiaz/tinfoleak tinfoleak is an open-source Python tool for OSINT/SOCMINT analysis of Twitter accounts, extracting structured intelligence such as user act… | 32 | 1980 | maintenance |
| n0a/telegram-get-remote-ip A Python CLI script that reveals the IP address of a Telegram voice call interlocutor by capturing and analyzing traffic with tshark. It ex… | 32 | 1858 | maintenance |
| fsociety-team/fsociety fsociety is a modular penetration testing framework written in Python that wraps and organizes popular security tools (nmap, sqlmap, Sherlo… | 67 | 1819 | maintenance |
| x0rz/phishing_catcher A Python CLI tool that monitors TLS certificate issuances in near real time via the CertStream API and flags suspicious domains using a con… | 32 | 1819 | maintenance |