function: osint
248 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Te-k/harpoon Harpoon is a Python CLI tool that aggregates open source intelligence and threat intelligence lookups across many services (Censys, crt.sh,… | 70 | 1289 | active |
| xploitstech/Xteam Xteam is an all-in-one, menu-driven hacking toolkit written in Python and launched via bash scripts, bundling Instagram information gatheri… | 42 | 1268 | active |
| saeeddhqan/Maryam OWASP Maryam is a modular open-source OSINT framework for harvesting data from open sources, search engines, and social networks. It provid… | 10 | 1228 | active |
| mbrg/power-pwn Power Pwn is an offensive and defensive security toolset for Microsoft 365 Power Platform and AI services, including Copilot Studio, custom… | 63 | 1201 | active |
| pielco11/fav-up Fav-up is a Python CLI tool and library that finds the real IP address behind services like Cloudflare by hashing a website's favicon and s… | 25 | 1199 | active |
| niudaii/zpscan zpscan is a Go-based command-line information gathering and reconnaissance tool for security assessments. It bundles subdomain enumeration,… | 23 | 1196 | active |
| N0rz3/Phunter Phunter is a Python CLI OSINT tool that gathers information about phone numbers, including operator, line type, location, reputation, spam … | 26 | 1175 | active |
| v4lkyr0/Buildware-Tools Buildware-Tools is a Python-based terminal multitool combining OSINT reconnaissance, network diagnostics, Discord automation, cryptography … | 78 | 1167 | active |
| 0x727/ShuiZe_0x727 ShuiZe_0x727 is a Python-based automated information gathering (reconnaissance) tool for red team operators. Given a root domain, C-segment… | 23 | 4019 | maintenance |
| evyatarmeged/Raccoon Raccoon is a Python-based offensive security CLI tool for reconnaissance and information gathering. It performs DNS lookups, WHOIS, TLS ana… | 67 | 4001 | maintenance |
| random-robbie/My-Shodan-Scripts A collection of Python 3 scripts for querying the Shodan search engine to find exposed devices and services on the internet. It bundles man… | 60 | 1146 | active |
| Tuhinshubhra/RED_HAWK RED_HAWK is a PHP-based all-in-one reconnaissance and vulnerability scanning tool for websites. It performs information gathering (whois, D… | 32 | 3748 | maintenance |
| AlephNullSK/dnsgen DNSGen is a Python CLI tool that generates intelligent permutations of domain names to aid subdomain discovery during security assessments.… | 32 | 1076 | active |
| knownsec/Kunyu Kunyu is a Python command-line tool for efficient corporate asset collection using cyberspace mapping engines like ZoomEye and Seebug. It h… | 25 | 1074 | active |
| qiwentaidi/Slack Slack is an integrated security services toolkit built with Go and the Wails desktop framework, bundling website fingerprinting and vulnera… | 78 | 1073 | active |
| Junyi-99/ChatGPT-API-Scanner A Python CLI tool that scans GitHub for publicly leaked OpenAI API keys using Selenium browser automation. It is intended for security rese… | 58 | 1073 | active |
| h9zdev/GeoSentinel GeoSentinel is a geospatial monitoring platform that tracks global movement in real time, aggregating ship and flight routes, live coordina… | 57 | 1069 | active |
| N0rz3/Zehef Zehef is a Python command-line OSINT tool for investigating email addresses. It checks for pastes, data leaks, and linked social media acco… | 29 | 1062 | active |
| ElevenPaths/FOCA FOCA is a Windows desktop application that finds metadata and hidden information in documents discovered via search engines (Google, Bing, … | 23 | 3622 | maintenance |
| Zarcolio/sitedorks A Python CLI tool that runs Google dork-style searches across multiple search engines (Google, Bing, DuckDuckGo, Yandex, Yahoo, Ecosia, Bra… | 76 | 1053 | active |
| PhonePe/mantis Mantis is a command-line security framework that automates asset discovery, reconnaissance, and vulnerability scanning for given top-level … | 67 | 1039 | active |
| EdgeSecurityTeam/EHole EHole (棱洞) is a Go-based fingerprint identification tool for red team reconnaissance that pinpoints high-value, easily attackable systems (… | 23 | 3511 | maintenance |
| Dheerajmadhukar/karma_v2 karma_v2 is a Bash-based passive OSINT reconnaissance framework that automates Shodan queries to enumerate assets, exposed services, CVEs, … | 42 | 1020 | active |
| mxrch/GitFive GitFive is a Python-based OSINT CLI tool for investigating GitHub user profiles. It uncovers usernames, name history, email addresses, and … | 43 | 1019 | active |
| AKCodez/hackingtool-plugin A Claude Code plugin that wraps 183+ pentesting and OSINT tools from Z4nzu/hackingtool, letting Claude automatically select and run securit… | 50 | 1016 | active |
| techchipnet/hound Hound is a lightweight PHP-based information gathering tool that captures a target device's exact GPS coordinates along with system and ISP… | 30 | 1016 | active |
| 0x6rss/matkap Matkap is a self-hosted web application for hunting malicious Telegram bots used as malware command-and-control infrastructure. It validate… | 65 | 1008 | active |
| JackJuly/linkook Linkook is a Python-based OSINT command-line tool that discovers linked social media accounts and associated email addresses across multipl… | 53 | 1008 | active |
| dedsec1121fk/DedSec DedSec Project is an educational cybersecurity and Termux toolkit for Android that bundles scripts, utilities, local web interfaces, and pr… | 88 | 1005 | active |
| 0x0be/yesitsme A Python CLI script for OSINT investigations that finds Instagram profiles matching a given name, e-mail, or phone number. It scrapes dumpo… | 32 | 3046 | maintenance |
| Threezh1/JSFinder JSFinder is a Python command-line tool that crawls a website's JavaScript files and extracts URLs and subdomains using regex parsing. It su… | 32 | 2976 | maintenance |
| christophetd/CloudFlair CloudFlair is a Python CLI tool that finds the origin servers of websites protected by Cloudflare or CloudFront by searching Censys interne… | 41 | 2972 | maintenance |
| bhavsec/reconspider ReconSpider is an open-source OSINT framework written in Python for scanning IP addresses, emails, websites, and organizations to gather in… | 23 | 2778 | maintenance |
| martinvigo/email2phonenumber A Python OSINT tool that discovers a target's phone number from just their email address by abusing password reset flows that leak masked p… | 32 | 2747 | maintenance |
| m0rtem/CloudFail CloudFail is a Python 3 command-line reconnaissance tool that attempts to discover the real IP address of servers hidden behind Cloudflare.… | 32 | 2683 | maintenance |
| thewhiteh4t/nexfil Nexfil is an OSINT command-line tool written in Python that finds social media profiles by username across 350+ websites in seconds. It sup… | 32 | 2610 | maintenance |
| obheda12/GitDorker GitDorker is a Python CLI tool that uses the GitHub Search API with a curated list of over 200 dorks to find sensitive information exposed … | 32 | 2577 | maintenance |
| screetsec/Sudomy Sudomy is a Bash-based subdomain enumeration and reconnaissance framework that collects subdomains via active brute-forcing and passive thi… | 23 | 2432 | maintenance |
| hexway/apple_bleee A collection of experimental Python PoC scripts for sniffing and injecting Apple Bluetooth Low Energy (BLE) and AWDL (AirDrop) traffic. It … | 23 | 2184 | maintenance |
| D4Vinci/Cr3dOv3r Cr3dOv3r is a Python command-line pentesting tool for investigating credential reuse attacks. Given an email, it searches public breach dat… | 57 | 2137 | maintenance |
| initstring/cloud_enum A Python command-line OSINT tool that enumerates publicly exposed resources across AWS, Azure, and Google Cloud using keyword mutations and… | 79 | 2132 | maintenance |
| UnaPibaGeek/ctfr CTFR is a Python command-line tool that enumerates HTTPS website subdomains by querying Certificate Transparency logs (via crt.sh) instead … | 32 | 2117 | maintenance |
| s0md3v/ReconDog ReconDog is a Python-based reconnaissance 'Swiss Army Knife' that gathers information about targets (domains, IPs) using third-party APIs l… | 23 | 2099 | maintenance |
| Aabyss-Team/ARL ARL (Asset Reconnaissance Lighthouse) is a self-hosted asset reconnaissance system that quickly discovers internet-facing assets associated… | 29 | 2055 | maintenance |
| vaguileradiaz/tinfoleak tinfoleak is an open-source Python tool for OSINT/SOCMINT analysis of Twitter accounts, extracting structured intelligence such as user act… | 32 | 1980 | maintenance |
| sense-of-security/ADRecon ADRecon is a PowerShell-based tool that extracts a wide range of artefacts from an Active Directory environment, including users, groups, t… | 32 | 1929 | maintenance |
| cobbr/SharpSploit SharpSploit is a .NET post-exploitation library written in C# that highlights the .NET attack surface for red teamers. It ports and extends… | 32 | 1884 | maintenance |
| 0xInfection/TIDoS-Framework TIDoS is a Python-based offensive web application penetration testing framework with a Metasploit-like console interface and an optional Qt… | 23 | 1868 | maintenance |
| orlyjamie/mimikittenz mimikittenz is a post-exploitation PowerShell tool that uses the Windows ReadProcessMemory() function to extract plain-text passwords and o… | 32 | 1867 | maintenance |
| DanMcInerney/net-creds A Python command-line tool that sniffs passwords, hashes, and other sensitive data from a live network interface or a pcap file. It reassem… | 32 | 1859 | maintenance |
| n0a/telegram-get-remote-ip A Python CLI script that reveals the IP address of a Telegram voice call interlocutor by capturing and analyzing traffic with tshark. It ex… | 32 | 1858 | maintenance |
| fsociety-team/fsociety fsociety is a modular penetration testing framework written in Python that wraps and organizes popular security tools (nmap, sqlmap, Sherlo… | 67 | 1819 | maintenance |
| x0rz/phishing_catcher A Python CLI tool that monitors TLS certificate issuances in near real time via the CertStream API and flags suspicious domains using a con… | 32 | 1819 | maintenance |
| Yvesssn/DetectDee DetectDee is a Go CLI tool for OSINT that hunts down social media accounts by username, email, or phone number across many social networks.… | 20 | 1806 | maintenance |
| mrh0wl/Cloudmare Cloudmare is a Python CLI tool that discovers the origin servers of websites protected by Cloudflare, Sucuri, or Incapsula when their DNS i… | 10 | 1784 | maintenance |
| EASY233/Finger Finger is a Python-based red team tool that performs liveness probing and web system fingerprint detection across large asset lists, identi… | 32 | 1724 | maintenance |
| The404Hacking/AndroRAT AndroRAT is a Remote Administration Tool (RAT) for Android, consisting of a Java Android client that runs as a background service and a Jav… | 32 | 1694 | maintenance |
| Ekultek/WhatBreach WhatBreach is a Python CLI OSINT tool that searches email addresses against known data breaches via services like HIBP, dehashed, hunter.io… | 48 | 1662 | maintenance |
| zidansec/CloudPeler CrimeFlare is a PHP command-line OSINT tool that attempts to reveal the real origin IP address behind websites protected by Cloudflare's WA… | 10 | 1576 | maintenance |
| BishopFox/GitGot GitGot is a semi-automated, feedback-driven CLI tool for searching public GitHub data (code and gists) for exposed sensitive secrets. Users… | 32 | 1571 | maintenance |
| Viralmaniar/BigBountyRecon BigBountyRecon is a C# Windows GUI tool that automates initial reconnaissance on a target organisation using 58 techniques, including Googl… | 23 | 1564 | maintenance |
| th3unkn0n/osi.ig A Python CLI tool that gathers OSINT information about Instagram accounts, including profile details, tags, mentions, emails, and post meta… | 32 | 1552 | maintenance |
| SharadKumar97/OSINT-SPY OSINT-SPY is a Python command-line tool that performs open-source intelligence scans on emails, domains, IP addresses, organizations, Bitco… | 23 | 1543 | maintenance |
| ExpertAnonymous/PhoneInfoga A Termux-oriented shell-script distribution of PhoneInfoga, an OSINT reconnaissance tool for scanning international phone numbers using fre… | 32 | 1523 | maintenance |
| gwen001/github-search A collection of Python, PHP, and Bash scripts that perform targeted searches on GitHub via its search API to find secrets, keys, private re… | 23 | 1511 | maintenance |
| woj-ciech/LeakLooker A Python CLI tool that uses the Binaryedge.io API to find publicly exposed databases and services such as MongoDB, Elasticsearch, CouchDB, … | 10 | 1464 | maintenance |
| twelvesec/gasmask GasMasK is an all-in-one open source OSINT and reconnaissance tool written in Python 3. It aggregates information about a target domain fro… | 23 | 1462 | maintenance |
| sham00n/buster Buster is a Python command-line OSINT tool for email reconnaissance. It finds social accounts linked to an email, data breaches, pastes, re… | 32 | 1395 | maintenance |
| TideSec/Mars Mars is a self-hosted security platform for asset discovery, subdomain enumeration, port and web fingerprinting, and change monitoring of i… | 32 | 1376 | maintenance |
| redhuntlabs/RedHunt-OS RedHunt OS is a pre-configured Linux virtual machine (OVA) bundling adversary emulation and threat hunting tools such as Caldera, Atomic Re… | 33 | 1318 | maintenance |
| laramies/metagoofil Metagoofil is a Python command-line OSINT tool that searches Google for public documents (pdf, doc, xls, ppt) on target websites, downloads… | 32 | 1313 | maintenance |
| vincentcox/bypass-firewalls-by-DNS-history A shell script that attempts to bypass web application firewalls (like Cloudflare, Incapsula, SUCURI) by finding the origin server IP throu… | 32 | 1306 | maintenance |
| c4tcom/Katana Katana-ds is a Python CLI tool that automates advanced Google queries known as Google Dorks (Google Dorking), with optional Tor support for… | 10 | 1304 | maintenance |
| devanshbatham/FavFreak A Python CLI tool that fetches favicon.ico files from lists of URLs, computes their mmh3 hashes, and groups domains/subdomains/IPs by match… | 23 | 1298 | maintenance |
| dchrastil/ScrapedIn A Python CLI tool that scrapes LinkedIn without API restrictions to enumerate employees of a target company for red team or social engineer… | 32 | 1235 | maintenance |
| dagrz/aws_pwn A collection of Python scripts for penetration testing AWS environments, covering reconnaissance, exploitation, stealth, exploration, and p… | 32 | 1223 | maintenance |
| vysecurity/LinkedInt LinkedInt is a Python CLI tool for LinkedIn reconnaissance that scrapes employee profiles for a target company and generates an HTML report… | 10 | 1214 | maintenance |
| Viralmaniar/Powershell-RAT A Python-based remote access trojan (RAT) for red team engagements that backdoors Windows machines via scheduled tasks and exfiltrates scre… | 23 | 1207 | maintenance |
| Viralmaniar/I-See-You ISeeYou is a Bash and JavaScript tool that captures a target's exact GPS coordinates (latitude/longitude) during social engineering or phis… | 32 | 1199 | maintenance |
| tejado/telegram-nearby-map A Node.js web application that uses Telegram's official TDLib to discover nearby Telegram users who have enabled the nearby feature and vis… | 32 | 1189 | maintenance |
| SpiderLabs/HostHunter HostHunter is a Python CLI recon tool that maps IPv4/IPv6 targets to virtual hostnames using OSINT and active reconnaissance techniques suc… | 23 | 1169 | maintenance |
| threatexpress/red-team-scripts A collection of red team focused tools, PowerShell scripts, and notes for offensive security engagements, including host and domain enumera… | 32 | 1146 | maintenance |
| shr3ddersec/Shr3dKit Shr3dKit is a shell script that installs a large curated collection of red team and offensive security tools onto a Kali Linux system (hard… | 32 | 1131 | maintenance |
| hausec/ADAPE-Script A PowerShell script that automates Active Directory assessment and privilege escalation checks by bundling multiple well-known pentest modu… | 32 | 1125 | maintenance |
| mdsecactivebreach/o365-attack-toolkit A Go-based red team toolkit for performing OAuth phishing attacks against Office365 accounts. It uses stolen tokens with the Microsoft Grap… | 32 | 1122 | maintenance |
| devxprite/infoooze Infoooze is a Node.js-based OSINT (Open-Source Intelligence) CLI tool for quickly gathering information about websites, IP addresses, usern… | 23 | 1071 | maintenance |
| daprofiler/DaProfiler DaProfiler is a Python-based OSINT CLI tool that traces a person's digital identity from a first and last name, recovering email addresses,… | 10 | 1040 | maintenance |
| averagesecurityguy/scripts A collection of Python scripts written for use during penetration testing engagements, organized into categories like brute forcing, enumer… | 32 | 1033 | maintenance |
| Malfrats/xeuledoc A Python CLI tool that fetches information about public Google documents across Drive, Docs, Sheets, Slides, and other Google Workspace ser… | 32 | 1023 | maintenance |
| fO-000/bluing Bluing is a Python-based Bluetooth intelligence gathering tool (successor to bluescan) for scanning and probing Bluetooth Classic (BR/EDR) … | 23 | 1019 | maintenance |
| bit4woo/teemo Teemo is a Python command-line reconnaissance tool that collects domains, subdomains, and email addresses for a target organization. It agg… | 32 | 1016 | maintenance |
| paulirish/github-email A small Node.js CLI tool that retrieves a GitHub user's email address even when it is not publicly listed, by querying the GitHub user prof… | 32 | 1011 | maintenance |
| s7ckTeam/Glass Glass is a Python CLI tool for rapid fingerprint identification of asset lists, querying Fofa, ZoomEye, Shodan, and 360 Quake APIs to gathe… | 32 | 1010 | maintenance |
| TideSec/FuzzScanner FuzzScanner is a Ruby/Python-based reconnaissance toolset that batch-collects information about target websites, including subdomains, open… | 32 | 1008 | maintenance |
| s0md3v/Striker Striker is a Python-based offensive reconnaissance and vulnerability scanning suite that discovers subdomains, scans common ports, detects … | 23 | 2341 | experimental |
| m4ll0k/BBTz A collection of bug bounty tools and example scripts written in Python by security researcher m4ll0k. It serves as a set of ideas and refer… | 32 | 1909 | experimental |
| twintproject/twint Twint is a Python CLI tool and library that scrapes tweets, followers, following, and likes from Twitter without using the official API or … | 10 | 16398 | abandoned |
| Greenwolf/social_mapper Social Mapper is a Python 3 OSINT tool that enumerates and correlates social media profiles across sites like LinkedIn, Facebook, Twitter, … | 32 | 4073 | abandoned |
| eth0izzle/shhgit shhgit is a secrets detection tool that scans GitHub, GitLab, Bitbucket repositories and local directories for accidentally committed crede… | 36 | 3977 | abandoned |
| IvanGlinkin/CCTV CCTV (Close-Circuit Telegram Vision) is an open-source OSINT tool that abuses Telegram's 'People Nearby' feature to triangulate and track u… | 28 | 2478 | abandoned |