Skip to content

OSINT Kit

A curated collection of tools for researchers, security professionals, and hobbyists to gather publicly available information from the web efficiently.

  • ExifTool — Versatile metadata extraction tool supporting a wide range of file formats including images, videos, and documents.
  • Metagoofil — Extract metadata such as author names, software versions, and file paths from publicly available documents (PDF, DOCX, PPTX, etc.).
  • FOCA — Perform large-scale metadata collection and document fingerprinting to reveal sensitive information in public files.
  • InVID Verification Plugin(Free) — Browser plugin to verify and analyze videos, widely used by journalists.
  • TinEye(Freemium) — Reverse image search engine for identifying image origins and duplicates.
  • Yandex Images(Free) — Reverse image search tool with strong facial and contextual matching capabilities.
  • Forensically(Free) — Web-based tool to detect image manipulations and view metadata.
  • FotoForensics — Web tool for image forensic analysis and error level analysis.
  • SauceNAO — Reverse image search for artwork and media.
  • Have I Been Pwned? — Check if your email or password has been leaked in known data breaches. (Free)
  • Dehashed — Search compromised credentials and leaked databases. (Paid)
  • LeakCheck — Search across dark web data dumps and breach records. (Freemium)
  • Grabify — Track IP addresses using Grabify IP logger.
  • IP Logger — Log and track IP addresses with the IP Logger URL Shortener.
  • IP to Geolocation — Get Geolocation from IP.
  • ipapi.co — Get IP geolocation and other information.
  • Whois — Get information regarding any domain.
  • Shodan — Search engine for internet-connected devices and services.
  • DNSDumpster — Free online tool for DNS and subdomain research.
  • WhoisXML API — Domain, IP, and DNS intelligence APIs.
  • SecurityTrails — Comprehensive domain and DNS intelligence platform.
  • ViewDNS — Multi-purpose domain and DNS lookup tool.
  • Censys — Search engine for internet-connected hosts and domains.
  • Netcraft — Domain and phishing intelligence platform.
  • VirusTotal — Domain intel with passive DNS and WHOIS.

Focus: Extracting and analyzing public data from social networks.

  • TweetDeck / X (Twitter) Advanced Search — Filter by keyword, user, time, and geolocation.
  • Twint — Scrape Twitter data without API access.
  • Sowdust’s Facebook OSINT Tools — Access public Facebook data (pages, groups, etc.).
  • Instagram Graph Explorer — Analyze public Instagram data via API.
  • Social Bearing — Twitter analytics and user insights.
  • Social-Searcher — Search across multiple social platforms.
  • AlternativeTo — Find better apps and services suggested by the crowd.
  • Am I real? — Check if an image looks like it’s from “thispersondoesnotexist.com.”
  • Bouncer — Extract profile IDs from Facebook, Instagram, Twitter, and TikTok in one click.
  • BuyBlitz — Marketplace with various sellers and products.
  • Codebeautify — Format code, view JSON, convert hex values, and more.
  • Cipher 387 — A collection of OSINT cheat sheets.
  • Cipher 387 APIs — APIs for gathering information about phone numbers, addresses, and domains.
  • CTF Search — Find and explore Capture The Flag solutions and writeups.
  • CybDetective — Worldwide OSINT tools map.
  • CyberChef — A web app for encryption, encoding, compression, and data analysis.
  • Digital Methods — Tools developed by Digital Methods Initiative (DMI).
  • Dutch OSINT Guy - Keywords Highlighter — Highlight keywords on visited web pages.
  • Dutch OSINT Guy - OSINT Timeline — OSINT timeline tool.
  • Firefox Translation — Full-page offline translation for Firefox.
  • fs0c131y — Location tracking apps list.
  • Gang Map — A map of gang territories and activities.
  • GIMP — Free image editor for various operating systems.
  • Google Alerts — Monitor the web for new content related to your interests.
  • GoOSINT — 130 web-enabled OSINT and cybersecurity tools.
  • Gravy App List — Location tracking app list.
  • Greasy Fork — Scripts to assist with OSINT.
  • Hachyx — A search engine focused on cybersecurity.
  • Hudson Rock — Free cybercrime and infostealer intelligence toolset.
  • Intel Archives — Intelligence studies and history.
  • JDownloader — Free, open-source download management tool.
  • K2SOsint — A small collection of OSINT bookmarklets.
  • Moon OSINT — Tool for decoding smartphone identifiers.
  • My OSINT Tools — A selection of OSINT bookmarklets.
  • Octopii — Personally identifiable information (PII) scanner.
  • Online PNG Tools — Online tools for editing PNG images.
  • OSINT Leaks — Multi-purpose OSINT search tool.
  • Osintracker — Free app for tracking OSINT investigations.
  • GrapheneOS — A secure mobile phone OS.
  • PopOS — A Linux operating system.
  • UbuntuOS — A popular Linux operating system.
  • Kali Linux — The most advanced penetration testing distribution operating system.
  • Parrot OS — Security-focused Linux distro for pentesting and privacy.
  • Tails — Live OS focused on privacy and anonymity.
  • Fedora — Reliable Linux distro, suitable for security and development.
  • Arch Linux — Minimal, flexible Linux for custom pentesting and OSINT setups.
  • BlackArch — Arch-based penetration testing Linux distribution.
  • Qubes OS — Security-focused OS with strong compartmentalization.
  • BackBox — Ubuntu-based pentesting Linux distribution.
  • Keybase — Secure messaging and file sharing.
  • Keys — OpenPGP keyserver.
  • Keyserver — Global directory keyserver.
  • Mailvelope — OpenPGP keyserver.
  • Mit — PGP public key server.
  • Ubuntu — Hockeypuck OpenPGP keyserver.
  • Pipl API — People data API for identity verification.
  • FullContact API — Person and company enrichment.
  • Clearbit API — Enrich domains and emails with company data.
  • SecurityTrails API — DNS and IP intelligence.
  • AbuseIPDB API — Check IP addresses for malicious activity.
  • Hunter Chrome Extension — Discover and verify email addresses associated with visited websites.
  • RevEye — Perform reverse image searches across multiple search engines in one click.
  • SingleFile — Save full web pages as a single HTML file for offline viewing and evidence preservation.
  • Wayback Machine Add-on — Quickly check archived versions of any webpage.
  • Wappalyzer — Detect and analyze technologies used on websites (CMS, frameworks, analytics tools, etc.).
  • AnyDesk — Remote access software for personal computers and mobile devices.
  • Forensic OSINT — OSINT web capture software to capture evidence quickly.
  • Hunchly — Auditing and recording software.
  • Joplin — Note-taking app.
  • Kazam — Screen recording software.
  • Mindmup — Tool for creating mind maps.
  • Nimbus — Screenshot and screen recording tool.
  • Noteapp — Encyclopedia of note-taking apps.
  • Data.gov — Comprehensive collection of US government open datasets, covering topics like demographics, economics, health, and more.
  • EU Open Data Portal — Access European Union open datasets, including statistics, legislation, and environmental data.
  • WikiData / DBpedia — Structured knowledge bases that provide machine-readable data extracted from Wikipedia and other sources.
  • Kaggle Datasets — Public datasets for data science, cybersecurity, and OSINT research, often including large-scale real-world data.