function: osint
248 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| sherlock-project/sherlock Sherlock is a Python CLI tool that hunts down social media accounts by username across 400+ social networks. It is widely used for OSINT re… | 70 | 90369 | active |
| Z4nzu/hackingtool An all-in-one, menu-driven Python toolkit that aggregates 215 curated security testing tools across 21 categories such as recon, OSINT, web… | 77 | 79125 | active |
| soxoj/maigret Maigret is a Python CLI OSINT tool that builds a dossier on a person from just a username, checking thousands of sites for accounts and ext… | 99 | 37084 | active |
| mukul975/Anthropic-Cybersecurity-Skills A large open-source library of structured cybersecurity skills (Markdown files with YAML frontmatter) for AI coding agents, mapped to frame… | 78 | 31259 | active |
| qeeqbox/social-analyzer Social Analyzer is an OSINT tool available as a Web App, CLI, and API that finds and analyzes a person's profile across 1000+ social media … | 60 | 23835 | active |
| smicallef/spiderfoot SpiderFoot is an open-source OSINT automation tool that integrates with over 200 data sources to gather and analyze intelligence about targ… | 57 | 21441 | active |
| mxrch/GHunt GHunt is an offensive Google framework focused on OSINT, usable both as a CLI tool and as a Python library. It can gather information about… | 57 | 19425 | active |
| laramies/theHarvester theHarvester is a Python CLI tool that gathers open-source intelligence (emails, subdomains, hostnames, IPs, names, URLs, ASNs) about a dom… | 91 | 17202 | active |
| owasp-amass/amass OWASP Amass is a Go-based framework for in-depth attack surface mapping and external asset discovery using OSINT gathering and active recon… | 81 | 15047 | active |
| HunxByts/GhostTrack GhostTrack is a Python-based OSINT CLI tool for gathering information about IP addresses, phone numbers, and usernames across social media.… | 30 | 14943 | active |
| projectdiscovery/subfinder Subfinder is a fast, passive subdomain discovery tool written in Go that enumerates valid subdomains for target domains using online passiv… | 95 | 14315 | active |
| megadose/holehe Holehe is an OSINT tool that checks whether an email address is registered on 120+ sites (Twitter, Instagram, Snapchat, etc.) by abusing th… | 32 | 14278 | active |
| Datalux/Osintgram Osintgram is a Python-based OSINT tool for Instagram that provides an interactive shell to collect and analyze information about Instagram … | 40 | 14147 | active |
| calesthio/Crucix Crucix is a self-hosted OSINT intelligence terminal that aggregates 27 open-source data feeds (satellite fire detection, flight tracking, r… | 52 | 11566 | active |
| 1N3/Sn1per Sn1per is an open-source automated penetration testing and attack surface management platform that chains reconnaissance, scanning, exploit… | 63 | 11043 | active |
| BigBodyCobain/Shadowbroker ShadowBroker is a self-hosted OSINT platform that aggregates 60+ real-time public intelligence feeds—aircraft, ships, satellites, CCTV, GPS… | 81 | 10971 | active |
| blacklanternsecurity/bbot BBOT is a recursive, multipurpose internet scanner built in Python for automating OSINT reconnaissance, bug bounty hunting, and attack surf… | 99 | 10508 | active |
| shmilylty/OneForAll OneForAll is a powerful Python-based subdomain collection and enumeration tool for reconnaissance. It gathers subdomains via brute forcing,… | 59 | 10029 | active |
| yogeshojha/rengine reNgine is a self-hosted automated web reconnaissance and vulnerability scanning framework with configurable recon engines, data correlatio… | 64 | 8795 | active |
| six2dez/reconftw reconFTW is an open-source (MIT) automated reconnaissance framework written in Shell that orchestrates 80+ security tools to perform full r… | 86 | 8025 | active |
| p1ngul1n0/blackbird Blackbird is a Python CLI OSINT tool that searches for user accounts by username or email across 600+ social networks and platforms, levera… | 46 | 7861 | active |
| reconurge/flowsint Flowsint is an open-source, self-hosted OSINT platform for visual, graph-based investigations, providing entity relationship visualization … | 87 | 7752 | active |
| j3ssie/osmedeus Osmedeus is a security-focused declarative orchestration engine that lets users define reconnaissance and vulnerability-scanning pipelines … | 93 | 6538 | active |
| apurvsinghgautam/robin Robin is an AI-powered dark web OSINT investigation tool that uses LLMs to refine queries, filter results from dark web search engines, and… | 84 | 6438 | active |
| alpkeskin/mosint Mosint is an automated email OSINT tool written in Go that investigates target email addresses by consolidating multiple services. It check… | 23 | 6008 | active |
| lanmaster53/recon-ng Recon-ng is a full-featured, modular reconnaissance framework for conducting web-based open source intelligence (OSINT) gathering. It offer… | 32 | 5871 | active |
| DedSecInside/TorBot TorBot is a Python CLI tool for OSINT on the dark web, crawling .onion sites over the Tor network and building link trees. It can save craw… | 97 | 4716 | active |
| intelowlproject/IntelOwl IntelOwl is an open-source, self-hosted application for managing threat intelligence at scale, querying many online analyzers and malware a… | 92 | 4683 | active |
| megadose/toutatis Toutatis is a Python CLI tool that extracts public information from Instagram accounts, such as emails, phone numbers, follower counts, and… | 32 | 4240 | active |
| Lucksi/Mr.Holmes Mr.Holmes is a Python-based OSINT (open-source intelligence) CLI tool that gathers information about usernames, domains, phone numbers, and… | 53 | 4112 | active |
| jasonxtn/Argus Argus is a Python-based all-in-one information gathering and reconnaissance toolkit with an interactive console and modular architecture. I… | 47 | 4082 | active |
| alexandreborges/malwoverview Malwoverview is a Python command-line first-response tool for threat hunting that queries many threat intelligence sources such as VirusTot… | 97 | 4075 | active |
| sundowndev/phoneinfoga PhoneInfoga is an information gathering framework for scanning international phone numbers, built in Go. It collects basic data like countr… | 67 | 17648 | maintenance |
| snooppr/snoop Snoop is a Python-based OSINT CLI tool that searches for a given username/nickname across ~5400+ websites, with a focus on the CIS region. … | 75 | 4009 | active |
| leebaird/discover A collection of custom Bash and Python scripts that automate penetration testing tasks including reconnaissance, scanning, enumeration, and… | 77 | 3928 | active |
| Findomain/Findomain Findomain is a fast subdomain enumeration tool written in Rust that discovers subdomains via Certificate Transparency logs and APIs without… | 76 | 3786 | active |
| ibnaleem/gosearch GoSearch is a Go-based CLI OSINT tool that searches a username across 300+ websites to find a person's digital footprint, serving as a Sher… | 84 | 3640 | active |
| arxhr007/Aliens_eye Aliens Eye is an AI-powered OSINT CLI tool that scans 840+ social media and web platforms to find accounts associated with a given username… | 94 | 3587 | active |
| opsdisk/pagodo pagodo is a Python CLI tool that automates passive Google dork searches by scraping the Google Hacking Database (GHDB) and running those qu… | 49 | 3387 | active |
| BloodHound Community Edition BloodHound Community Edition is a free, open-source application that uses graph theory to reveal hidden relationships and attack paths in A… | 91 | 3355 | active |
| kaifcodec/user-scanner A 2-in-1 Python CLI OSINT suite that performs email and username intelligence across 440+ scan vectors (170+ email sites, 270+ username pla… | 83 | 3319 | active |
| s0md3v/Photon Photon is a fast Python-based web crawler designed for OSINT (open-source intelligence) tasks. It extracts URLs, emails, social media accou… | 66 | 13146 | maintenance |
| projectdiscovery/uncover uncover is a Go CLI tool that queries multiple internet search engines (Shodan, Censys, FOFA, ZoomEye, and others) via their APIs to quickl… | 84 | 3042 | active |
| Alfredredbird/tookie-osint Tookie-OSINT is an open-source Python OSINT tool that finds social media accounts and gathers information based on user inputs. It offers a… | 82 | 2841 | active |
| xnl-h4ck3r/waymore waymore is a Python CLI tool that retrieves URLs from multiple web archive and intelligence sources (Wayback Machine, Common Crawl, Alien V… | 90 | 2732 | active |
| aboul3la/Sublist3r Sublist3r is a Python command-line tool that enumerates subdomains of a target domain using OSINT sources such as Google, Bing, Yahoo, Baid… | 23 | 11023 | maintenance |
| Moham3dRiahi/Th3inspector Th3inspector is an all-in-one Perl CLI tool for information gathering (OSINT reconnaissance). It bundles lookups such as website info, whoi… | 40 | 2662 | active |
| musana/CF-Hero CF-Hero is a Go-based reconnaissance CLI tool that discovers the real origin IP addresses of Cloudflare-protected web applications. It aggr… | 66 | 2632 | active |
| thewhiteh4t/pwnedOrNot pwnedOrNot is a Python command-line OSINT tool that checks email addresses against the HaveIBeenPwned v3 API for past breaches and then sea… | 66 | 2628 | active |
| TermuxHackz/X-osint X-osint is an open-source Python-based OSINT framework for gathering information about phone numbers, email addresses, IP addresses, VINs, … | 72 | 2627 | active |
| v0id4real/Void-Tools Void-Tools is a Python terminal multitool with a Rich TUI dashboard bundling 150+ utilities for OSINT research, network diagnostics, and Di… | 54 | 2524 | active |
| kpcyrd/sn0int sn0int is a semi-automatic OSINT framework and package manager written in Rust that enumerates attack surface by processing public informat… | 60 | 2515 | active |
| NetSPI/MicroBurst MicroBurst is a PowerShell toolkit for assessing Microsoft Azure security, including service discovery, weak configuration auditing, and po… | 73 | 2426 | active |
| hisxo/gitGraber gitGraber is a Python3 command-line tool that monitors GitHub search results in real time to find leaked sensitive data such as API keys an… | 66 | 2376 | active |
| samugit83/redamon RedAmon is an AI-powered agentic red team framework that automates offensive security operations end-to-end, chaining reconnaissance, explo… | 81 | 2354 | active |
| h9zdev/WireTapper WireTapper is a wireless OSINT tool that passively detects and maps nearby radio-emitting devices such as Wi-Fi access points, Bluetooth de… | 51 | 2310 | active |
| jofpin/trape Trape is an OSINT analysis and research tool for tracking people online and executing real-time social engineering attacks, built in Python… | 32 | 8978 | maintenance |
| spyboy-productions/CloakQuest3r CloakQuest3r is a Python-based open-source security research tool that identifies potential origin IP exposure of websites protected by Clo… | 54 | 2250 | active |
| hanc00l/nemo_go Nemo is an automated information-gathering platform for penetration testing that integrates common recon tools (Masscan, Nmap, Subfinder, H… | 88 | 2086 | active |
| AzizKpln/Moriarty-Project Moriarty Project is a web-based phone number investigation tool written in Python that gathers information about a given phone number. It a… | 23 | 2074 | active |
| megadose/ignorant Ignorant is a Python CLI tool and library that checks whether a phone number is registered on sites like Instagram, Snapchat, and Amazon wi… | 32 | 2030 | active |
| kkbo8005/mitan Mitan (密探) is an all-in-one penetration testing and security assessment desktop application integrating asset mapping, subdomain brute-forc… | 79 | 1955 | active |
| nitefood/asn A Bash-based command-line tool and self-hostable server for looking up ASN, RPKI validity, BGP stats, IP prefixes, AS paths, IP reputation,… | 87 | 1926 | active |
| bellingcat/octosuite Octosuite is a terminal-based toolkit for analyzing GitHub data, usable as an interactive TUI, a CLI, or a Python library. It queries user,… | 76 | 1895 | active |
| evildevill/instahack Instahack is a Bash and Python-based brute-force tool for testing Instagram account password strength, routing traffic through Tor for anon… | 62 | 1888 | active |
| nsonaniya2010/SubDomainizer SubDomainizer is a Python CLI tool that discovers hidden subdomains and secrets in webpages, external JavaScript files, GitHub, and local f… | 66 | 1886 | active |
| ninoseki/mitaka Mitaka is a browser extension for Chrome and Firefox that simplifies OSINT (Open Source Intelligence) searches. It automatically detects an… | 94 | 1846 | active |
| pirxthepilot/wtfis wtfis is a Python command-line tool that performs passive lookups of hostnames, domains, and IP addresses using OSINT services like VirusTo… | 74 | 1827 | active |
| iojw/socialscan socialscan is a Python library and CLI tool that checks whether usernames and email addresses are taken, available, or invalid across onlin… | 66 | 1826 | active |
| initstring/linkedin2username A Python OSINT tool that scrapes LinkedIn employee lists for a target company and generates multiple probable username formats (e.g., first… | 76 | 1825 | active |
| 1N3/BlackWidow BlackWidow is a Python-based web application spider that crawls a target site to collect URLs, dynamic parameters, subdomains, email addres… | 57 | 1821 | active |
| unicodeveloper/globalthreatmap A real-time global threat and event intelligence map that plots security events, conflicts, military bases, and geopolitical developments o… | 56 | 1810 | active |
| bellingcat/telegram-phone-number-checker A Python CLI tool by Bellingcat that checks whether phone numbers are registered with Telegram accounts, retrieving usernames, names, and I… | 87 | 1771 | active |
| HackUnderway/SearchPhone SearchPhone is a Python CLI OSINT toolkit for investigating phone numbers across multiple sources, including Google (SerpAPI), DuckDuckGo, … | 66 | 1765 | active |
| josh0xA/darkdump Darkdump is an open-source OSINT tool for querying multiple dark web search engines and scraping onion site results for emails, metadata, k… | 70 | 1757 | active |
| IvanGlinkin/Fast-Google-Dorks-Scan A shell-based OSINT tool that automates Google dork searches against a target website to uncover admin panels, exposed file types, and path… | 46 | 1742 | active |
| j3ssie/metabigor Metabigor is a Go-based command-line OSINT tool that maps a target's infrastructure—IP ranges, subdomains, related domains, open ports, and… | 86 | 1735 | active |
| utkusen/urlhunter urlhunter is a Go-based recon CLI tool that searches URLs exposed via shortener services like bit.ly and goo.gl. It downloads daily URLTeam… | 24 | 1697 | active |
| michenriksen/gitrob Gitrob is a Go-based reconnaissance tool that scans GitHub users' and organizations' public repositories for potentially sensitive files by… | 10 | 6198 | maintenance |
| michenriksen/aquatone Aquatone is a Go CLI tool for visual inspection of websites across many hosts, taking screenshots via headless Chrome/Chromium and generati… | 10 | 5961 | maintenance |
| 4lbH4cker/ALHacking ALHacking is a shell-script-based toolkit bundling a menu of so-called ethical hacking utilities, including social media account attacks, p… | 32 | 1601 | active |
| m3n0sd0n4ld/GooFuzz GooFuzz is a Bash-based CLI tool that performs fuzzing-style reconnaissance using advanced Google searches (Google Dorking) via the Google … | 57 | 1585 | active |
| m8sec/CrossLinked CrossLinked is a Python CLI tool that enumerates LinkedIn employee names for an organization by scraping search engine results, without nee… | 23 | 1582 | active |
| Clats97/ClatScope ClatScope Info Tool is a Python-based OSINT utility offering 70+ reconnaissance features including geolocation, DNS, WHOIS, phone, email, a… | 48 | 1537 | active |
| jasperan/whatsapp-osint A Python CLI tool that uses Selenium to track when WhatsApp contacts go online/offline, logging presence sessions to SQLite. It exports dat… | 76 | 1511 | active |
| GONZOsint/geowifi A Python command-line tool that queries multiple public WiFi geolocation databases (Wigle, Apple, Google, Mylnikov, WiFiDB, Combain, Freifu… | 32 | 1495 | active |
| OpenOSINT/OpenOSINT OpenOSINT is an AI-powered OSINT framework offering 19 investigation tools behind a natural-language agent, usable as an interactive REPL, … | 81 | 1470 | active |
| momosecurity/FindSomething FindSomething is a passive browser extension for Chrome and Firefox that extracts potentially sensitive information (like emails, API keys,… | 32 | 1458 | active |
| urbanadventurer/username-anarchy Username Anarchy is a Ruby command-line tool that generates lists of likely usernames from people's first and last names for use in penetra… | 23 | 1458 | stable |
| khast3x/h8mail h8mail is a Python CLI tool for email OSINT and password breach hunting. It queries breach services like HaveIBeenPwned and Hunter.io, or s… | 23 | 5273 | maintenance |
| tillson/git-hound GitHound is a Go-based CLI tool that hunts for exposed API keys, secrets, and credentials across all of GitHub using GitHub dorks, pattern … | 70 | 1451 | active |
| superhedgy/AttackSurfaceMapper AttackSurfaceMapper is a Python CLI reconnaissance tool that expands a target's attack surface using OSINT and active techniques like subdo… | 32 | 1405 | active |
| Flangvik/TeamFiltration TeamFiltration is a cross-platform penetration testing framework for enumerating, password spraying, exfiltrating data from, and backdoorin… | 55 | 1399 | active |
| fasnow/fine Fine is a Chinese-language cyberspace asset mapping and reconnaissance tool integrating FOFA, Hunter, Quake, ZoomEye, and Shodan APIs, plus… | 82 | 1366 | active |
| BullsEye0/shodan-eye Shodan Eye is a Python command-line tool that queries the Shodan search engine to collect information about all devices directly connected … | 75 | 1352 | active |
| mishakorzik/UserFinder UserFinder is a shell-based OSINT tool that searches for user profiles across social networks and other sites by username. It runs as a sim… | 56 | 1348 | active |
| sockysec/Telerecon Telerecon is a Python-based OSINT reconnaissance framework for researching and investigating Telegram. It scrapes user profiles, messages, … | 28 | 1324 | active |
| MrTuxx/SocialPwned SocialPwned is a Python-based OSINT tool that harvests emails published on Instagram, LinkedIn, and Twitter to find credential leaks via Pw… | 10 | 1320 | active |
| colonelpanichacks/flock-you Flock-You is ESP32-S3 firmware that turns a Seeed XIAO ESP32-S3 into a passive 2.4 GHz promiscuous-mode WiFi sniffer for detecting Flock su… | 62 | 1312 | active |
| freelabz/secator secator is a task and workflow runner for security assessments that unifies dozens of well-known security tools (subfinder, httpx, ffuf, nm… | 93 | 1306 | active |
page 1 / 3 next →