Compilation, procedures, tools and ethics for open source research
This repository is dedicated to the responsible and ethical practice of Open-Source Intelligence (OSINT). All information, tools, and methodologies provided herein are intended solely for educational, research, and lawful investigative purposes. Users are strongly encouraged to adhere to ethical guidelines, respect privacy rights, comply with applicable laws and regulations, and obtain necessary permissions before conducting any investigations. Misuse of this information for illegal activities, harassment, or violation of privacy is strictly prohibited and may result in legal consequences. By accessing this repository, you agree to use the content responsibly and ethically.
1. Fundamentals | 2. 4-Step Methodology | 3. Tools Mind Map | 4. Internet Search | 5. Social Networks | 6. Geoint & Images | 7. Domain / IP / DNS | 8. Deep & Dark Web | 9. Automation (Python) | 10. Report Templates | 11. Legal Considerations | 12. Extra Resources | 13. AI Intelligence | 14. Facial Recognition | 15. Email/Phone Investigation | 16. Data Breaches | 17. Blockchain/Crypto | 18. Transport OSINT | 19. WiFi/Wardriving | 20. Content Verification | 21. Username Enumeration | 22. Web Scraping | 23. Metadata Extraction | 24. Network Scanning | 25. Dark Web | 26. All-in-One Frameworks | 27. Advanced Maltego | 28. Professional Methodologies | 29. Advanced Google Dorks | 30. Learning Resources | 31. People Investigations | 32. Company Research | 33. Threat Intelligence Feeds
| Concept | Quick Definition |
|---|---|
| OSINT | Intelligence obtained from public sources without violating logical or physical access |
| OPSEC | Minimize footprint: VPN → VM → alias → metadata strip |
| Intelligence Cycle | Direction → Collection → Processing → Analysis → Dissemination |
| PII | Information that identifies: email, phone, RFC, CURP, IP, IMEI, MAC |
| Primary Source | Original publication (tweet, official PDF, photo EXIF) |
| Secondary Source | Article citing the primary (validate) |
- Define question → What do I want to know?
- Identify sources → Table below |
- Collect → Manual + automations |
- Validate and document → Screenshots, hash, date, URL, archive.org |
| Data Type | Usual Location | Star Tool |
|---|---|---|
| Name | LinkedIn, Facebook | Maigret |
| Data breaches, newsletters | HIBP | |
| Phone | WhatsApp Business, TrueCaller | Infobel |
| Username | Forums, gaming, GitHub | Snoop |
| Photo | Geolocation, EXIF | Exiftool |
| Domain | WHOIS, certificates | Amass |
| IP | Scanning, Shodan | Shodan |
| Crypto wallet | Blockchain explorers | BlockCypher |
graph TD
A[OSINT] --> B(Search)
A --> C(Social Networks)
A --> D(Geo)
A --> E(Domain/IP)
A --> F(DeepDark)
A --> G(Automate)
B --> B1(Google Dorks)
B --> B2(Useful Dorks)
C --> C1(Twint-fork)
C --> C2(Maigret)
C --> C3(Instaloader)
D --> D1(Overpass-turbo)
D --> D2(Satellites.pro)
D --> D3(ExifTool)
E --> E1(Amass)
E --> E2(CRT.sh)
E --> E3(DNSDumpster)
F --> F1(Onionscan)
F --> F2(Ahmia)
G --> G1(Recon-ng)
G --> G2(SpiderFoot)
| Objective | Dork | Example |
|---|---|---|
| Government PDFs | site:gov filetype:pdf "contract" |
Mexico |
| Exposure | intitle:"index of" passwords.txt |
— |
| IP Cameras | inurl:viewer/live/index.html |
— |
| Emails | site:linkedin.com "@company.com" |
— |
| Subdomains | site:*.target.com -www |
— |
- DuckDuckGo "bangs" →
!archive - Yandex → best results CIS
- Baidu → Asia
- Startpage → no logs
- Shodan → IoT, ICS, SCADA
- Censys → cert + banner
- FOFA → China, free API
- ZoomEye → similar to Shodan
- BinaryEdge → global scanning
- Hunter.io → corporate emails
- PublicWWW → search in source code
- SearchCode → search in 75B lines of code
- SimilarSites → similar sites
- Netlas → internet intelligence
- CriminalIP → search in connected internet
- NerdyData → website technologies
- GreyNoise → internet noise
- Intezer Analyze → malware analysis
- Kaspersky OpenTIP → threat scanning
- VirusTotal → file/URL analysis
- AlienVault OTX → threat exchange
- ExploitDB → exploit database
- MalwareBazaar → malware samples
- Malware Domain List → malicious domains
- PhishTank → phishing URLs
- URLhaus → malware URLs
- ThreatMiner → threat intelligence
- YARAify → YARA rules
- PulseDive → IOC search
- ThreatFox → malware IOCs
- Breach Directory → breach searches
- Have I Been Pwned → breach verification
- DNSViz → DNSSEC visualization
- DNS Twister → similar domains
- DNSdumpster → DNS enumeration
- SpyOnWeb → related sites
- Yark → archive YouTube
- CovertAction → investigative journalism
- Trellix Research → threat research
- CP Research → Checkpoint research
- Wikistrat → collaborative analysis
- PolySwarm → threat scanning
- HackerOne Hacktivity → public vulnerabilities
- WikiLeaks → leaked documents
- Talos Reports → vulnerability reports
- MalAPI → malware APIs
- UserSearch → user search
- SecureList → Kaspersky blog
- SPLC Hate Map → hate map
- ICSR → radicalization studies
- Militant Wire → militancy analysis
- START Publications → terrorism publications
- SPLC Resources → SPLC resources
- Tracking Terrorism → terrorism tracking
- Mapping Militants → mapping militants
- Naval Institute → naval news
- Institute of International Relations → international relations
- Janes → defense intelligence
- TASS News → Russian news
- Sputnik News → Sputnik news
- PIPS → Pakistan peace studies
- PICSS → Pakistan conflict studies
- Reuters → news agency
- RT → Russia Today
- InternetActivism → humanitarian tools
- IISS → international studies institute
- CFR → council on foreign relations
- SciHub → access to scientific papers
- ResearchHub → research discussion
- IDCrawl → people search
- Osint Industries → email/phone search
- ESPY → phone search
- SUNDERS → surveillance cameras
- Privacy Watch → OSINT tools
- Deepinfo → internet intelligence
- Session → private messaging
- Consortium News → independent journalism
- Tutanota → encrypted email
- Committee to Protect Journalists → journalist protection
- SecurityWeek → security news
- NCRI → network contagion research
- Geopolitical Economy Report → geopolitical reports
- The Grayzone → independent journalism
- The Moscow Times → Russian news
- FlightAware → flight tracking
- FlightRadar24 → flight radar
- MarineTraffic → maritime traffic
- VesselFinder → ship search
- NewspaperArchive → newspaper archives
- The Indian Express → Indian news
- Daily Excelsior → Jammu Kashmir news
- DNA India → Indian news
- Greater Kashmir → Kashmir news
- Nagaland Post → Nagaland news
- RFE/RL → Radio Free Europe
- Akto → API security
- Generated Photos → AI photos
- Factinsect → AI fact-checking
- HDRobots → AI tools directory
- Channel 4 News → British news
- ThreatMon Reports → threat reports
- 0t.rocks Search → people search
- Israel Datasets → Israeli datasets
- Simplex 3D → 3D maps Israel
- AI Dubbing → AI dubbing
- Budget Key → Israel budget
- Ship Spotting → ship photos
- Broadcastify → police audio
- OpenCelliD → cell tower database
- AviationStack → aviation API
- DigitalSide TI → threat intelligence
- DocumentCloud → document management
- IDRW → Indian defense
- XFE → X-Force exchange
- Scumware → malware research
- Ukraine Live Cams → Ukraine cameras
- TWN → webcam network
- Opentopia → public webcams
- Transparency → anti-corruption
- Maigret → user search
- OCCRP → organized crime
- Qdorks → dork generator
- Radio Garden → world radios
- LolArchiver OSINT → OSINT search
- BreachBase → breach base
- WorldCam → world webcams
- Webcam Galore → webcams
- WiFi Map → WiFi hotspots
- OpenTrafficCamMap → traffic cameras
- KrooozCams → cruise webcams
- Skyline Webcams → skyline webcams
- Pictimo → world webcams
- Instances.social → Mastodon recommender
- CamHacker → public webcams
- Labs TIB Geoestimation → geographic estimation
- Picarta → photo location prediction
- Tiny Scan → URL scanning
- ZeroDay → zero-day vulnerabilities
- Predicta Search → digital search
- Ventusky → weather maps
- OSV → open source vulnerabilities
- Certs → certificate information
- Coalition ESS → exploit scoring
- Validin → attack surface mapping
- CastrickClues → OSINT search
- CIRCL PDNS → passive DNS
- InTheWild → exploits in wild
- TheWebCo → people intelligence
- 360 Quake → cyberspace mapping
- Cloudflare Radar → internet trends
- Crisis24 → security risk management
- arXiv → scientific papers
- Wayback Machine
- CachedView (Google + Archive.is)
- URLScan → capture + DOM + requests
- Ubikron → AI-powered evidence collection & entity extraction
- Screenshot Guru → screen test
- Stored Website → cached pages
- ThreatMiner → IOC context
- YARAify → YARA rules
- PulseDive → IOC search
- ThreatFox → malware IOCs
- Breach Directory → breaches
- Have I Been Pwned → breach verification
- DNSViz → DNSSEC
- DNS Twister → similar domains
- DNSdumpster → DNS enumeration
- SpyOnWeb → related sites
- Yark → archive YouTube
| Task | Tool | Notes |
|---|---|---|
| Download all tweets | Twint-docker | docker run -it --rm twint -u user --since 2024-01-01 |
| Network analysis | Network Tool | RT graph |
| Deleted tweets | Deleted Tweet Finder | Aggregated API |
| Sentiment | Sentiment140 | CSV bulk |
| Task | Tool | Risk |
|---|---|---|
| Photos + metadata | Instaloader | Low |
| Anonymous stories | StoriesIG | Low |
| Profile analysis | SOLG | Medium |
| World map | Picuki | Low |
| Task | Tool | Legal Note |
|---|---|---|
| Employees | CrossLinked | Scrape = ToS |
| Email pattern | Hunter | 25 free/month |
| Photo URL | LinkedIn-sniper | Public only |
- Facebook Recover Lookup - Link: Facebook Recover Lookup - Description: Used to check if a given email or phone number is associated with any Facebook account or not.
- CrowdTangle Link Checker - Link: CrowdTangle Link Checker - Description: Shows the specific Facebook posts, Instagram posts, tweets, and subreddits that mention this link.
- Social Searcher - Link: Social Searcher - Description: Allows you to monitor all public social mentions in social networks and the web.
- Lookup-id.com - Link: Lookup-id.com - Description: Helps you find the Facebook ID of anyone's profile or a Group.
- Who posted this - Link: Who posted this - Description: Facebook keyword search for people who work in the public interest. It allows you to search keywords on specific dates.
- Facebook Search - Link: Facebook Search - Description: Allows you to search on Facebook for posts, people, photos, etc., using some filters.
- Facebook Graph Searcher - Link: Facebook Graph Searcher - Description: To search someone on Facebook.
- Facebook People Search - Link: Facebook People Search - Description: Search on Facebook by victim's name.
- DumpItBlue - Link: DumpItBlue+ - Description: helps to dump Facebook stuff for analysis or reporting purposes.
- Export Comments - Link: Export Comments - Description: Easily exports all comments from your social media posts to Excel file.
- Facebook Applications - Link: Facebook Applications - Description: A collection of online tools that automate and facilitate Facebook.
- Social Analyzer - Link: SocialAnalyzer - Social Sentiment & Analysis - Description: a free tool of social media monitoring and analysis.
- AnalyzeID - Link: AnalyzeID - Description: Just looking for sites that supposedly may have the same owner. Including a FaceBook App ID match.
- SOWsearch - Link: sowsearch - Description: a simple interface to show how the current Facebook search function works.
- Facebook Matrix - Link: FacebookMatrix - Description: Formulas for Searching Facebook.
- Who posted what - Link: Who Posted What - Description: A non public Facebook keyword search for people who work in the public interest. It allows you to search keywords on specific dates.
- StalkFace - Link: StalkFace - Description: Toolkit to stalk someone on Facebook.
- Search is Back - Link: Search is Back - Description: ind people and events on Facebook Search by location, relationships, and more!.
- FB-Search - Link: FB-Search - Description: busca por teléfono o correo.
- FB-Posts-scraper - Link: FB-Posts-scraper - Description: (Python).
- FB-Video-downloader - Link: FB-Video-downloader - Description: .
- SnapInsta - Link: SnapInsta - Description: Download Photos, Videos, IGTV & more from a public Instagram account.
- IFTTT Integrations - Link: IFTTT Instagram integrations - Description: Popular Instagram workflows & automations.
- Pickuki - Link: Pickuki - Description: Browse publicly available Instagram content without logging in.
- IMGinn.io - Link: IMGinn.io - Description: view and download all the content on the social network Instagram all at one place.
- Instaloader - Link: Instaloader - Description: Download pictures (or videos) along with their captions and other metadata from Instagram.
- SolG - Link: SolG - Description: The Instagram OSINT Tool gets a range of information from an Instagram account that you normally wouldn't be able to get from just looking at their profile.
- Osintgram - Link: Osintgram - Description: Osintgram is an OSINT tool on Instagram to collect, analyze, and run reconnaissance.
- Toutatis - Link: toutatis - Description: It is a tool written to retrieve private information such as Phone Number, Mail Address, ID on Instagram accounts via API.
- instalooter - Link: instalooter - Description: InstaLooter is a program that can download any picture or video associated from an Instagram profile, without any API access.
- Exportgram - Link: Exportgram - Description: A web application made for people who want to export instagram comments into excel, csv and json formats.
- Profile Analyzer - Link: Profile Analyzer - Description: Analyze any public profile on Instagram – the tool is free, unlimited, and secure. Enter a username to take advantage of precise statistics.
- Find Instagram User Id - Link: Find Instagram User Id - Description: This tool called "Find Instagram User ID" provides an easy way for developers and designers to get Instagram account numeric ID by username.
- Instahunt - Link: Instahunt - Description: Easily find social media posts surrounding a location.
- InstaFreeView - Link: InstaFreeView - Description: InstaFreeView Private Instagram Profile Viewer is a free app to view Instagram profile posts without login.
- InstaNavigation - Link: instanavigation - Description: Anonymous story viewing on Instagram.
- TikTok-scraper-dl - Link: TikTok-scraper-dl - Description: .
- Musicaldown - Link: Musicaldown - Description: web.
- RecruitEm - Link: RecruitEm - Description: Allows you to search social media profiles. It helps recruiters to create a Google boolean string that searches all public profiles.
- RocketReach - Link: RocketReach - Description: Allows you to programmatically search and lookup contact info over 700 million professionals and 35 million companies.
- Phantom Buster - Link: Phantom Buster - Description: Automation tool suite that includes data extraction capabilities.
- linkedprospect - Link: LinkedIn Boolean Search - Description: Build a targeted list of LinkedIn people using boolean search.
- ReverseContact - Link: Reverse Email Lookup - Description: Find Linked Profiles associated with any email.
- LinkedIn Search Engine - Link: Programmable Search Engine - Description: Programmable Search Engine for LinkedIn profiles.
- Free People Search Tool - Link: Free People Search Tool - Description: Find people easily online.
- IntelligenceX Linkedin - Link: IntelligenceX Linkedin - Description: A webbased tool for searching someone on Linkedin.
- Linkedin Search Tool - Link: Linkedin Search Tool - Description: Provides you a interface with various tools for Linkedin Osint.
- LinkedInt - Link: LinkedInt - Description: Providing you with Linkedin Intelligence.
- InSpy - Link: InSpy - Description: InSpy is a python based LinkedIn enumeration tool.
- CrossLinked - Link: CrossLinked - Description: CrossLinked is a LinkedIn enumeration tool that uses search engine scraping to collect valid employee names from an organization.
- TweetDeck - Link: TweetDeck - Description: Offers a more convenient Twitter experience by allowing you to view multiple timelines in one easy interface.
- FollowerWonk - Link: FollowerWonk - Description: Helps you find Twitter accounts using bio and provides many other useful features.
- Twitter Advanced Search - Link: Twitter Advanced Search - Description: Allows you to search on Twitter using filters for better search results.
- Wayback Tweets - Link: Wayback Tweets - Description: Display multiple archived tweets on Wayback Machine and avoid opening each link manually.
- memory.lol - Link: memory.lol - Description: a tiny web service that provides historical information about twitter users.
- SocialData API - Link: SocialData API - Description: an unofficial Twitter API alternative that allows scraping historical tweets, user profiles, lists and Twitter spaces without using Twitter's API.
- Social Bearing - Link: Social Bearing - Description: Insights & analytics for tweets & timelines.
- Tinfoleak - Link: Tinfoleak - Description: Search for Twitter users leaks.
- Network Tool - Link: Network Tool - Description: Explore how information spreads across Twitter with an interactive network using OSoMe data.
- Foller - Link: Foller - Description: Looking for someone in the United States? Our free people search engine finds social media profiles, public records, and more!
- SimpleScraper OSINT - Link: SimpleScraper OSINT - Description: This Airtable automatically scrapes OSINT-related twitter accounts ever 3 minutes and saves tweets that contain coordinates.
- Deleted Tweet Finder - Link: Deleted Tweet Finder - Description: Search for deleted tweets across multiple archival services.
- Twitter Search Tool - Link: Twitter search tool - Description: On this page you can create advanced search queries within Twitter.
- Twitter Video Downloader - Link: Twitter Video Downloader - Description: Download Twitter videos & GIFs from tweets.
- Download Twitter Data - Link: Download Twitter Data - Description: Download Twitter data in csv format by entering any Twitter handle, keyword, hashtag, List ID or Space ID.
- Twitonomy - Link: Twitonomy - Description: Twitter #analytics and much more.
- tweeterid - Link: tweeterid - Description: Type in any Twitter ID or @handle below, and it will be converted into the respective ID or username.
- BirdHunt - Link: BirdHunt - Description: Easily find social media posts surrounding a location.
- DownAlbum - Link: DownAlbum - Description: Google Chrome extension for downloading albums of photos from various websites, including Pinterest.
- Experts PHP: Pinterest Photo Downloader - Link: Pinterest Photo Downloader - Description: Website providing a tool to download photos from Pinterest.
- Pingroupie - Link: Pingroupie - Description: A Meta Search Engine for Pinterest that lets you discover Collaborative Boards, Influencers, Pins, and new Keywords.
- Tailwind - Link: Tailwind - Description: Social media scheduling and management tool that supports Pinterest.
- Pinterest Guest - Link: Pinterest Guest - Description: Mozilla Firefox add-on for browsing Pinterest without logging in or creating an account.
- SourcingLab: Pinterest - Link: SourcingLab: Pinterest - Description: Pinterest search feature for finding pins, boards, and users.
- F5BOT - Link: F5BOT - Description: Receive notifications for new Reddit posts matching specific keywords.
- Karma Decay - Link: Karma Decay - Description: Reverse image search for finding similar or reposted images on Reddit.
- Mostly Harmless - Link: Mostly Harmless - Description: A suite of tools for Reddit, including user analysis, subreddit comparison, and more.
- OSINT Combine: Reddit Post Analyzer - Link: OSINT Combine: Reddit Post Analyzer - Description: Analyze and gather information from Reddit posts for OSINT purposes.
- Phantom Buster - Link: Phantom Buster - Description: Automation tool suite that includes Reddit data extraction capabilities.
- rdddeck - Link: rdddeck - Description: Real-time dashboard for monitoring multiple Reddit communities.
- Readr for Reddit - Link: Readr for Reddit - Description: Google Chrome extension for an improved reading experience on Reddit.
- Reddit Archive - Link: Reddit Archive - Description: Archive of Reddit posts and comments for historical reference.
- Reddit Comment Search - Link: Reddit Comment Search - Description: Search for specific comments and conversations on Reddit.
- Redditery - Link: Redditery - Description: Explore Reddit posts and comments based on various criteria.
- Reddit Hacks - Link: Reddit Hacks - Description: Collection of Reddit hacks and tricks for advanced users.
- Reddit List - Link: Reddit List - Description: Directory of popular subreddits organized by various categories.
- reddtip - Link: reddtip - Description: Show appreciation to Reddit users by sending them tips in cryptocurrencies.
- Reddit Search - Link: Reddit Search (realsrikar) - Description: Various tools and websites for searching and discovering content on Reddit.
- Reddit Shell - Link: Reddit Shell - Description: Command-line interface for browsing and interacting with Reddit.
- Reddit Stream - Link: Reddit Stream - Description: Live-streaming of Reddit comments for real-time discussions.
- Reddit Suite - Link: Reddit Enhancement Suite (Chrome Extension) - Description: Browser extension that enhances the Reddit browsing experience with additional features.
- Reddit User Analyser - Link: Reddit User Analyser - Description: Analyze and visualize the activity and behavior of Reddit users.
- redditvids - Link: redditvids - Description: Watch Reddit videos and browse popular video subreddits.
- Redective - Link: Redective - Description: Investigate and analyze Reddit users based on their post history.
- Reditr - Link: Reditr - Description: Desktop Reddit client with a clean and intuitive interface.
- Reeddit - Link: Reeddit - Description: Simplified and clean Reddit web interface for a distraction-free browsing experience.
- ReSavr - Link: ReSavr - Description: Retrieve and save deleted Reddit comments for later viewing.
- smat - Link: smat - Description: Social media analytics tool that includes Reddit for tracking trends and engagement.
- socid_extractor - Link: socid_extractor - Description: Extract user information from Reddit and other social media platforms.
- Suggest me a subreddit - Link: Suggest me a subreddit - Description: Get recommendations for new subreddits to explore based on your preferences.
- Subreddits - Link: Subreddits - Description: Directory of active subreddits organized by various categories.
- uforio - Link: uforio - Description: Generate word clouds from Reddit comment threads.
- Universal Reddit Scraper (URS) - Link: Universal Reddit Scraper (URS) - Description: Python-based tool for scraping Reddit data for analysis.
- Vizit - Link: Vizit - Description: Visualize and analyze relationships between Reddit users and subreddits.
- Wisdom of Reddit - Link: Wisdom of Reddit - Description: Curated collection of insightful quotes and comments from Reddit.
- Awesome Lists - Link: Awesome Lists - Description: A curated list of awesome lists for various programming languages, frameworks, and tools.
- CoderStats - Link: CoderStats - Description: A platform for developers to track and showcase their coding activity and statistics from GitHub.
- Commit-stream - Link: Commit-stream - Description: A tool for monitoring and collecting GitHub commits in real-time.
- Digital Privacy - Link: Digital Privacy - Description: A collection of resources and tools for enhancing digital privacy and security.
- Find Github User ID - Link: Find Github User ID - Description: A web tool for finding the unique identifier (ID) of a GitHub user.
- GH Archive - Link: GH Archive - Description: A project that provides a public dataset of GitHub activity, including events and metadata.
- Git-Awards - Link: Git-Awards - Description: A website that ranks GitHub users and repositories based on their contributions and popularity.
- GitGot - Link: GitGot - Description: A semi-automated, feedback-driven tool for auditing Git repositories.
- gitGraber - Link: gitGraber - Description: A tool for searching and cloning sensitive information in GitHub repositories.
- git-hound - Link: git-hound - Description: A tool for finding sensitive information exposed in GitHub repositories.
- Github Dorks - Link: Github Dorks - Description: A collection of GitHub dorks, which are search queries to find sensitive information in repositories.
- Github Stars - Link: Github Stars - Description: A website that showcases GitHub repositories with the most stars and popularity.
- Github Trending RSS - Link: Github Trending RSS - Description: An RSS feed generator for trending repositories on GitHub.
- Github Username Search Engine - Link: Github Username Search Engine - Description: A search engine to find GitHub usernames based on various filters and criteria.
- Github Username Search Engine - Link: Github Username Search Engine - Description: Another search engine to find GitHub usernames with advanced filtering options.
- GitHut - Link: GitHut - Description: A website that provides statistics and visualizations of programming languages on GitHub.
- addmeContacts - Link: addmeContacts - Description: A platform to find and connect with new contacts on various social media platforms.
- AddMeSnaps - Link: AddMeSnaps - Description: A website for discovering and adding new Snapchat friends.
- ChatToday - Link: ChatToday - Description: An online chat platform for connecting and chatting with people from around the world.
- Gebruikersnamen: Snapchat - Link: Gebruikersnamen: Snapchat - Description: A website for finding Snapchat usernames.
- GhostCodes - Link: GhostCodes - Description: An app for discovering new Snapchat users and their stories.
- OSINT Combine: Snapchat MultiViewer - Link: OSINT Combine: Snapchat MultiViewer - Description: A tool for viewing multiple Snapchat accounts simultaneously.
- Snap Map - Link: Snap Map - Description: Snapchat's feature that allows users to share their location and view Snaps from around the world.
- Snapchat-mapscraper - Link: Snapchat-mapscraper - Description: A tool for scraping public Snapchat Stories from the Snap Map.
- Snap Political Ads Library - Link: Snap Political Ads Library - Description: Snapchat's library of political ads displayed on the platform.
- Social Finder - Link: Social Finder - Description: A platform to search and discover social media profiles on various platforms.
- SnapIntel - Link: SnapIntel - Description: a python tool providing you information about Snapchat users.
- AddMeS - Link: AddMeS - Description: The 'Add Me' directory of Snapchat users on web.
- checkwa - Link: checkwa - Description: An online tool to check the status and availability of WhatsApp numbers.
- WhatsApp Fake Chat - Link: WhatsApp Fake Chat - Description: An online tool to generate fake WhatsApp conversations for fun or pranks.
- Whatsapp Monitor - Link: Whatsapp Monitor - Description: A tool for monitoring and analyzing WhatsApp messages and activities.
- whatsfoto - Link: whatsfoto - Description: A Python script to download profile pictures from WhatsApp contacts.
- addmeContacts - Link: addmeContacts - Description: A platform to find and connect with new contacts on various social media platforms.
- ChatToday - Link: ChatToday - Description: An online chat platform for connecting and chatting with people from around the world.
- Skypli - Link: Skypli - Description: A website for discovering and connecting with new Skype contacts.
- ChatBottle: Telegram - Link: ChatBottle: Telegram - Description: A directory of Telegram bots for various purposes.
- ChatToday - Link: ChatToday - Description: An online chat platform for connecting and chatting with people from around the world.
- informer - Link: informer - Description: A Python library for retrieving information about Telegram channels, groups, and users.
- _IntelligenceX: Telegram - Link: _IntelligenceX: Telegram - Description: IntelligenceX's Telegram tool for searching and analyzing Telegram data.
- Lyzem.com - Link: Lyzem.com - Description: A website to search and find Telegram groups and channels.
- Telegram Channels - Link: Telegram Channels - Description: A directory of Telegram channels covering various topics.
- Telegram Channels - Link: Telegram Channels - Description: A platform to discover and browse Telegram channels.
- Telegram Channels Search - Link: Telegram Channels Search - Description: A search engine to find Telegram channels by keywords.
- Telegram Directory - Link: Telegram Directory - Description: A comprehensive directory of Telegram channels, groups, and bots.
- Telegram Group - Link: Telegram Group - Description: A website to search and join Telegram groups.
- telegram-history-dump - Link: telegram-history-dump - Description: A Python script to dump the history of a Telegram chat into a SQLite database.
- Telegram-osint-lib - Link: Telegram-osint-lib - Description: A Python library for performing open-source intelligence (OSINT) on Telegram.
- Telegram Scraper - Link: Telegram Scraper - Description: A powerful Telegram scraping tool for extracting user information and media.
- Tgram.io - Link: Tgram.io - Description: A platform to explore and search for Telegram channels, groups, and bots.
- Tgstat.com - Link: Tgstat.com - Description: A comprehensive platform for analyzing and tracking Telegram channels and groups.
- Tgstat RU - Link: Tgstat RU - Description: A Russian platform for analyzing and monitoring Telegram channels and groups.
- DiscordOSINT - Link: DiscordOSINT - Description: This Repository Will contain useful resources to conduct research on Discord.
- Discord.name - Link: Discord.name - Description: Discord profile lookup using user ID.
- Lookupguru - Link: Lookupguru - Description: Discord profile lookup using user ID.
- Discord History Tracker - Link: Discord History Tracker - Description: Discord History Tracker lets you save chat history in your servers, groups, and private conversations, and view it offline.
- Top.gg - Link: Top.gg - Description: Explore millions of Discord Bots.
- Unofficial Discord Lookup - Link: Unofficial Discord Lookup - Description: Search for discord profile using id.
- Disboard - Link: Disboard - Description: DISBOARD is the place where you can list/find Discord servers.
- OnlyFans Finder - Link: The Favourite OnlyFans search - Description: The tools allow easy searching via advanced filtering capabilities and sorting functionality, making it easy to access desired material.
- OnlyFam - Link: OnlyFam - Description: OnlyFans Search & Model Finder - Find Creators in the World's Largest OnlyFans Database
- OnlyFinder - Link: OnlyFinder - Description: OnlyFans Search Engine - OnlyFans Account Finder.
- OnlySearch - Link: OnlySearch - Description: Find OnlyFans profiles by searching for key words.
- Sotugas - Link: SóTugas - Description: Encontra Contas do OnlyFans Portugal 🇵🇹.
- Fansmetrics - Link: Fansmetrics - Description: Use this OnlyFans Finder to search in 3,000,000 OnlyFans Accounts.
- Findr.fans - Link: Findr.fans - Description: Only Fans Search Tool.
- Hubite - Link: Hubite - Description: Advanced OnlyFans Search Engine.
- Similarfans - Link: Similarfans - Description: Blog for OnlyFans content creators.
- Fansearch - Link: Fansearch - Description: Fansearch is the best OnlyFans Finder to search in 3,000,000 OnlyFans Accounts.
- Fulldp - Link: Fulldp - Description: Download Onlyfans Full-Size Profile Pictures.
- Mavekite - Link: Mavekite - Description: Search the profile using username.
- TikTok hashtag analysis toolset - Link: TikTok hashtag analysis toolset - Description: The tool helps to download posts and videos from TikTok for a given set of hashtags over a period of time.
- TikTok Video Downloader - Link: TikTok Video Downloader - Description: ssstiktok is a free TikTok video downloader without watermark tool that helps you download TikTok videos without watermark (Musically) online.
- Exolyt - Link: exolyt - Description: The best tool for TikTok analytics & insights.
exiftool -a -u foto.jpg | grep -i "gps\|date\|camera"
# strip before publishing
exiftool -all= foto_sanitizada.jpg- Google Earth Pro → temporal displacement
- Suncalc → shadow = time
- Geolocation-verification
- Overpass-turbo → POI within radius
- FlightAware → flight tracking
- FlightRadar24 → flight radar
- MarineTraffic → maritime traffic
- VesselFinder → ships
- WiGLE → geolocated WiFi database
- OpenCelliD → cell towers
- Broadcastify → police audio
- AviationStack → aviation API
- Labs TIB Geoestimation → geographic estimation
- Picarta → photo location prediction
- Ventusky → weather maps
- Simplex 3D → 3D maps Israel
- Ukraine Live Cams → Ukraine cameras
- TWN → webcam network
- Opentopia → public webcams
- WorldCam → world webcams
- Webcam Galore → webcams
- OpenTrafficCamMap → traffic cameras
- KrooozCams → cruise webcams
- Skyline Webcams → skyline webcams
- Pictimo → world webcams
- CamHacker → public webcams
- Sentinel-Hub → 10m resolution, free
- NASA-FIRMS → real-time fires
- Zoom Earth → METAR overlay
- FlightRadar24 → flight radar
- ADS-B Exchange → no military filters
- FlightAware → flight history
- PiAware (Raspberry Pi) → own ADS-B receiver
- MarineTraffic → global AIS tracking
- VesselFinder → free alternative
- FleetMon → fleet monitoring
- ShipSpotting → ship photo database
| Objective | Tool | Quick Command |
|---|---|---|
| Subdomains | Amass | amass enum -d target.com -o subs.txt |
| Certificates | CRT.sh | curl https://crt.sh/?q=%25.target.com&output=json |
| Historical DNS | SecurityTrails | Free API 50/month |
| Neighbor IPs | BGP.he | CIDR |
| Reputation | VirusTotal | vt ip_info <ip> |
| Quick scan | Nmap-online | no VPN |
| Subdomains | Subdomain Center | https://www.subdomain.center |
| Subdomains | SubdomainRadar | https://www.subdomainradar.io |
| Historical DNS | DNSTrails | https://dnstrails.com/ |
| Historical DNS | DNS History | http://dnshistory.org |
| Reputation | Talos | https://www.talosintelligence.com/ |
| Scan | Binary Defense | https://www.binarydefense.com/banlist.txt |
| BGP Ranking | CIRCL BGP | https://bgpranking.circl.lu |
| Botnet Tracker | MalwareTech | https://intel.malwaretech.com/ |
| BOTVRIJ.EU | BOTVRIJ | http://www.botvrij.eu/ |
| C&C Tracker | Bambenek | http://osint.bambenekconsulting.com/feeds/c2-ipmasterlist.txt |
| CertStream | CertStream | https://certstream.calidog.io/ |
| CCSS Forum | CCSS Forum | http://www.ccssforum.org/malware-certificates.php |
| CI Army List | CINS Score | http://cinsscore.com/#list |
| Cisco Umbrella | Cisco Umbrella | http://s3-us-west-1.amazonaws.com/umbrella-static/index.html |
| Cloudmersive | Cloudmersive | https://cloudmersive.com/virus-api |
| Critical Stack | Critical Stack | https://intelstack.com/ |
| CrowdSec | CrowdSec | https://app.crowdsec.net/ |
| Cyber Cure | Cyber Cure | https://www.cybercure.ai/ |
| Cyware | Cyware | https://cyware.com/community/ctix-feeds |
| DataPlane | DataPlane | https://dataplane.org/ |
| Focsec | Focsec | https://focsec.com |
| DigitalSide | DigitalSide | https://osint.digitalside.it/ |
| Disposable Domains | Disposable Domains | https://github.com/martenson/disposable-email-domains |
| Emerging Threats | Emerging Threats | http://rules.emergingthreats.net/fwrules/ |
| ExoneraTor | ExoneraTor | https://exonerator.torproject.org/ |
| Exploitalert | Exploitalert | http://www.exploitalert.com/ |
| FastIntercept | FastIntercept | https://intercept.sh/threatlists/ |
| Feodo Tracker | Feodo Tracker | https://feodotracker.abuse.ch/ |
| FireHOL | FireHOL | http://iplists.firehol.org/ |
| FraudGuard | FraudGuard | https://fraudguard.io/ |
| Grey Noise | Grey Noise | http://greynoise.io/ |
| Hail a TAXII | Hail a TAXII | http://hailataxii.com/ |
| HoneyDB | HoneyDB | https://riskdiscovery.com/honeydb/ |
| Icewater | Icewater | https://github.com/SupportIntelligence/Icewater |
| Infosec CERT-PA | Infosec CERT-PA | https://infosec.cert-pa.it |
| InQuest Labs | InQuest Labs | https://labs.inquest.net |
| I-Blocklist | I-Blocklist | https://www.iblocklist.com/lists |
| IPsum | IPsum | https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt |
| James Brine | James Brine | https://jamesbrine.com.au |
| Kaspersky Feeds | Kaspersky | https://support.kaspersky.com/datafeeds |
| Maldatabase | Maldatabase | https://malcore.io |
| Malpedia | Malpedia | https://malpedia.caad.fkie.fraunhofer.de/ |
| MalShare | MalShare | http://www.malshare.com/ |
| Maltiverse | Maltiverse | https://www.maltiverse.com/ |
| MalwareBazaar | MalwareBazaar | https://bazaar.abuse.ch/ |
| Malware Domain List | Malware Domain List | https://www.malwarepatrol.net/ |
| MetaDefender | MetaDefender | https://www.opswat.com/developers/threat-intelligence-feed |
| Netlab OpenData | Netlab | https://data.netlab.360.com/ |
| NoThink! | NoThink! | http://www.nothink.org |
| NormShield | NormShield | https://services.normshield.com |
| NovaSense | NovaSense | https://novasense-threats.com |
| Obstracts | Obstracts | https://www.obstracts.com/ |
| OpenPhish | OpenPhish | https://openphish.com/phishing_feeds.html |
| 0xSI_f33d | 0xSI_f33d | https://feed.seguranca-informatica.pt/index.php |
| PhishTank | PhishTank | https://www.phishtank.com/developer_info.php |
| PickupSTIX | PickupSTIX | https://www.celerium.com/pickupstix |
| REScure | REScure | https://rescure.fruxlabs.com/ |
| RST Cloud | RST Cloud | https://rstcloud.net/ |
| Rutgers IPs | Rutgers | https://report.cs.rutgers.edu/mrtg/drop/dropstat.cgi?start=-86400 |
| SANS ICS | SANS ICS | https://isc.sans.edu/suspicious_domains.html |
| SecurityScorecard | SecurityScorecard | https://github.com/securityscorecard/SSC-Threat-Intel-IoCs |
| Stixify | Stixify | https://www.stixify.com/ |
| signature-base | signature-base | https://github.com/Neo23x0/signature-base |
| Spamhaus | Spamhaus | https://www.spamhaus.org/ |
| Sophos Intelix | Sophos | https://www.sophos.com/intelix |
| Spur | Spur | https://spur.us |
| SSL Blacklist | SSL Blacklist | https://sslbl.abuse.ch/ |
| Statvoo | Statvoo | https://statvoo.com/dl/top-1million-sites.csv.zip |
| Strongarm | Strongarm | https://strongarm.io |
| SIEM Rules | SIEM Rules | https://www.siemrules.com |
| Talos | Talos | https://www.talosintelligence.com/ |
| threatfeeds.io | threatfeeds.io | https://threatfeeds.io |
| threatfox | threatfox | https://threatfox.abuse.ch/ |
| Technical Blogs | Technical Blogs | https://www.threatconnect.com/blog/ingest-technical-blogs-reports/ |
| Threat Jammer | Threat Jammer | https://threatjammer.com |
| ThreatMiner | ThreatMiner | https://www.threatminer.org/ |
| ThreatPipes | ThreatPipes | https://www.threatpipes.com |
| ThreatExchange | ThreatExchange | https://developers.facebook.com/docs/threat-exchange/ |
| TypeDB CTI | TypeDB CTI | https://github.com/typedb-osi/typedb-cti |
| VirusBay | VirusBay | https://beta.virusbay.io/ |
| threatnote.io | threatnote.io | https://github.com/brianwarehime/threatnote |
| XFE | XFE | https://exchange.xforce.ibmcloud.com/ |
| Yeti | Yeti | https://yeti-platform.github.io/ |
| 1st Dual Stack | 1st Dual Stack | https://IOCFeed.mrlooquer.com/ |
| Yara-Rules | Yara-Rules | https://github.com/Yara-Rules/rules |
| VirusShare | VirusShare | https://virusshare.com/ |
| CIRCL PDNS | CIRCL PDNS | https://www.circl.lu/services/passive-dns |
| InTheWild | InTheWild | https://inthewild.io |
| 360 Quake | 360 Quake | https://quake.360.net |
| Cloudflare Radar | Cloudflare Radar | https://radar.cloudflare.com/traffic |
| Validin | Validin | https://app.validin.com |
| OSV | OSV | https://osv.dev |
| Coalition ESS | Coalition ESS | https://ess.coalitioninc.com |
| Certs | Certs | https://certs.io |
| CastrickClues | CastrickClues | https://castrickclues.com |
| TheWebCo | TheWebCo | https://thewebco.ai |
site:*.target.com filetype:pdf
site:*.target.com intitle:"dashboard"
site:*.target.com intext:"confidential"
| Need | Solution | URL |
|---|---|---|
| Search .onion | Ahmia | clean index |
| Check if data leaked | HaveIBeenPwned | API |
| Markets | DarkOwl (paid) | — |
| Forums | Onionscan (cli) | docker run --rm -it onionscan -service http://forum.onion |
| Credentials | DeHashed (freemium) | — |
| Search .onion | TOR Link | https://tor.link |
| Scanner services | OnionScan | https://github.com/s-rah/onionscan |
| Verified directory | Dark.fail | https://dark.fail |
| Old searcher | Torch | (only .onion) |
| Scraper onion | DarkDump | https://github.com/josh0xA/darkdump |
| Tor Project | Tor Project | https://torproject.org |
| Public webcams | TWN | http://www.the-webcam-network.com |
| Public webcams | Opentopia | http://www.opentopia.com |
| World webcams | WorldCam | https://worldcam.eu |
| Webcams | Webcam Galore | https://www.webcamgalore.com |
| Traffic cameras | OpenTrafficCamMap | https://otc.armchairresearch.org/map |
| Cruise webcams | KrooozCams | https://www.kroooz-cams.com |
| Skyline webcams | Skyline Webcams | https://www.skylinewebcams.com/en/webcm |
| World webcams | Pictimo | https://www.pictimo.com |
| Public webcams | CamHacker | https://www.camhacker.com |
| Surveillance cameras | SUNDERS | https://sunders.uber.space |
| Ukraine cameras | Ukraine Live Cams | https://nagix.github.io/ukraine-livecams |
OPSEC for .onion
- TailsOS → USB → bridge-Tor → NO extra proxies
- Disable scripts Noscript → max
- Never maximize window (fingerprint)
- Never use VPN + Tor (traffic correlation)
- Use bridges if Tor is blocked
- NoScript to max
- No window resizing
- No downloading to persistent disk
python -m venv osint-env
source osint-env/bin/activate
pip install twint-fork recon-ng selenium requests beautifulsoup4 shodan#!/usr/bin/env python3
# mini_osint.py
import shodan, requests, json, sys
from bs4 import BeautifulSoup
API_KEY = 'YOUR_SHODAN_API'
s = shodan.Shodan(API_KEY)
domain = sys.argv[1]
# 1. Subdomains via CRT.sh
crt = requests.get(f'https://crt.sh/?q=%25.{domain}&output=json').json()
subs = sorted(set([r['name_value'] for r in crt]))
print('[+] Found subdomains:', len(subs))
# 2. IPs from resolution
ips = set()
for sub in subs[:20]: # demo limit
try:
ips.add(socket.gethostbyname(sub))
except:
pass
# 3. Shodan quick look
for ip in ips:
try:
info = s.host(ip)
print(ip, info['org'], info.get('vulns', 'N/A'))
except:
passrecon-ng
> marketplace install all
> workspaces add target
> use domains-domains/brute_force
> set SOURCE target.com
> run
> use hosts-hosts/resolve
> run
> use reporting/csv
> runFolder /templates/ in your repo. Mandatory YAML front-matter:
---
investigator: your-alias
date: 2025-12-16
objective: "Target Name"
scope: domain + RRSS
status: draft # draft | reviewed | delivered
---
# Executive Summary
(5 lines)
# Primary Sources
- URL | date | capture hash
# Chronology
- 2024-10-01: Domain registration
- 2025-01-15: First leak
# Annexes
- Screenshots folder `/annexes/`
- CSV extracts| Country | Framework | Key |
|---|---|---|
| Mexico | PDP Law 2018 | Explicit consent for PII |
| Spain | LOPD-GDPR | Art. 6.1-f: legitimate interest (research) |
| USA | CFAA | No bypass to authentication |
| Europe | GDPR | DPIA if >1000 people |
| — | OSINT-Code-Ethics | No doxxing, no stalking, no data selling |
Ethical checklist ☐ Is the source 100% public? ☐ Is the data sensitive PII? → minimize ☐ Is there verifiable public interest? ☐ Can it be de-identified?
- SEINT (SANS 487)
- OSINT-Do-jo – daily challenges
- Michel Bacchus – YouTube OSINT in Spanish
AI-powered tools for OSINT 2025:
| Tool | Function | URL | Note |
|---|---|---|---|
| anonchatgpt | Anonymous ChatGPT client | https://anonchatgpt.com | No account needed |
| ai-toolkit | Essential AI toolkit for journalists | https://huggingface.co/spaces/JournalistsonHF/ai-toolkit | Free and open-source |
| Decktopus | Professional presentations | https://www.decktopus.com/ | Create in minutes |
| Monica | ChatGPT copilot in Chrome | https://monica.im/ | Summarize, translate, define |
| Poised | Communication coach | https://www.poised.com/ | Real-time feedback |
| StockimgAI | AI image creation | https://stockimg.ai/ | Logos, wallpapers, covers |
| ChatPDF | Ask questions to PDFs | https://www.chatpdf.com/ | Simple and free |
| SheetplusAI | Excel formulas with AI | https://sheetplus.ai/ | Save 80% time |
| 10web | AI website builder | https://10web.io/ | Fill form to build |
| BabelX | Multilingual OSINT platform with AI | https://www.babelstreet.com | Text analysis in 200+ languages |
| Fivecast | Predictive analysis with ML | https://www.fivecast.com | Real-time threat detection |
| HyperVerge | Deepfake detection | https://hyperverge.co | AI biometric verification |
| ShadowDragon | Social Darkint with AI | https://shadowdragon.io | Behavior analysis |
| Talkwalker | Media monitoring with AI | https://www.talkwalker.com | Advanced sentiment analysis |
| DorkGPT | AI dork generator | https://www.dorkgpt.com | Automatically creates Google dorks |
| SearchDorks | Dorks for multiple engines | https://kriztalz.sh/search-dorks | FOFA, Shodan, Censys, ZoomEye |
Beyond basic searches:
| Tool | Capability | URL | Cost |
|---|---|---|---|
| PimEyes | Facial search on internet | https://pimeyes.com | Freemium |
| OSINT by PimEyes | Pro version for professionals | https://osint.pimeyes.com | Paid |
| FaceCheck.ID | Search in social networks | https://facecheck.id | Freemium |
| Clearview AI | Police facial recognition | (Requires authorization) | Professional |
Usage methodology:
- Capture high-quality image
- Use FaceCheck.ID for social networks
- PimEyes for broad web search
- Validate results by crossing platforms
| Tool | Function | URL |
|---|---|---|
| Holehe | Find associated accounts to email | https://github.com/megadose/holehe |
| GHunt | Investigate Google accounts | https://github.com/mxrch/GHunt |
| Epieos | Email + phone reverse lookup | https://epieos.com |
| h8mail | Search in data breaches | https://github.com/khast3x/h8mail |
| EmailHippo | Email verification | https://tools.emailhippo.com |
| Hunter.io | Find corporate emails | https://hunter.io |
| Tool | Function | URL |
|---|---|---|
| Phoneinfoga | Investigation framework | https://github.com/sundowndev/phoneinfoga |
| Truecaller | Call identifier | https://www.truecaller.com |
| Infobel | International search | https://www.infobel.com |
| Numverify | Validation API | https://numverify.com |
Automation script (Python):
# email_osint_checker.py
import holehe
import requests
def check_email_accounts(email):
"""Checks in 120+ platforms"""
modules = holehe.import_submodules('holehe.modules')
for module in modules:
# Execute verification
passAlternatives and complements to HIBP:
| Platform | Database | URL | Access |
|---|---|---|---|
| DeHashed | 17+ billion records | https://dehashed.com | Freemium |
| Snusbase | Recent breaches | https://snusbase.com | Paid |
| LeakCheck | Real-time search | https://leakcheck.io | Freemium |
| Intelligence X | Dark web + breaches | https://intelx.io | Freemium |
| h8mail | Local breach search | GitHub | Free |
| Hudson Rock | Infostealer intelligence | https://www.hudsonrock.com/threat-intelligence-cybercrime-tools | Free |
Quick command:
# h8mail - mass search
h8mail -t targets.txt -bc local_breach_folder/ --power-allSpecialized tools:
| Tool | Blockchain | URL | Function |
|---|---|---|---|
| Chainalysis Reactor | Multi-chain | https://www.chainalysis.com | Forensic analysis professional |
| Elliptic | Bitcoin, Ethereum | https://www.elliptic.co | Money laundering detection |
| Arkham Intelligence | Multi-chain | https://www.arkhamintelligence.com | Entity mapping with AI |
| Glassnode | On-chain analytics | https://glassnode.com | Advanced metrics |
| Etherscan | Ethereum | https://etherscan.io | Main explorer |
| Blockchain.info | Bitcoin | https://www.blockchain.com/explorer | Classic explorer |
| BlockCypher | Multi-chain API | https://www.blockcypher.com | Free API |
| Wallet Explorer | Bitcoin | https://www.walletexplorer.com | Wallet analysis |
Investigation methodology:
1. Identify wallet address
2. Search in Arkham Intelligence (known labels)
3. Analyze transactions in Etherscan/Blockchain.info
4. Trace fund flow with BlockCypher
5. Check in Chainalysis if available
| Tool | Function | URL |
|---|---|---|
| VINCheck | Free VIN decoder | https://www.vehiclehistory.com |
| OpenALPR | License plate recognition | https://github.com/openalpr/openalpr |
| Carfax | Vehicle history (US) | https://www.carfax.com |
| Cybergliknet Vehicle OSINT | Multiple functions | https://cybergliknet.com/blog-detail.php?slug=vehicle-osint |
| Tool | Function | URL |
|---|---|---|
| FlightRadar24 | Live tracking | https://www.flightradar24.com |
| ADS-B Exchange | No military filters | https://globe.adsbexchange.com |
| FlightAware | Flight history | https://flightaware.com |
| PiAware (Raspberry Pi) | Own ADS-B receiver | https://flightaware.com/adsb/piaware |
Setup of homemade ADS-B receiver:
# Configure PiAware on Raspberry Pi
sudo apt-get install piaware
sudo piaware-config <options>
sudo systemctl restart piaware| Tool | Function | URL |
|---|---|---|
| MarineTraffic | Global AIS tracking | https://www.marinetraffic.com |
| VesselFinder | Free alternative | https://www.vesselfinder.com |
| FleetMon | Fleet monitoring | https://www.fleetmon.com |
| ShipSpotting | Photo database | http://www.shipspotting.com |
| Tool | Function | URL/Installation |
|---|---|---|
| WiGLE | Global WiFi database | https://wigle.net |
| WiGLE WiFi Wardriving (Android) | Mapping app | Google Play |
| Kismet | WiFi/Bluetooth detector | https://www.kismetwireless.net |
| Aircrack-ng | WiFi audit suite | https://www.aircrack-ng.org |
OSINT use case:
1. Search unique SSID in WiGLE
2. Find approximate router location
3. Correlate with other geolocation data
4. Identify movements/locations of target
Fact-checking tools:
| Tool | Function | URL | Type |
|---|---|---|---|
| InVID & WeVerify | Video verification plugin | https://weverify.eu/verification-plugin | Extension |
| FotoForensics | ELA image analysis | https://fotoforensics.com | Web |
| Forensically | Visual analysis suite | https://29a.ch/photo-forensics | Web |
| HyperVerge Deepfake Detector | AI detection | https://hyperverge.co | API |
| Sensity AI | Deepfakes detection | https://sensity.ai | Professional |
| Content Authenticity Initiative | Origin verification | https://contentauthenticity.org | Standard |
Verification process:
1. Extract metadata with ExifTool
2. Analyze with FotoForensics (ELA)
3. Check consistencies with Forensically
4. For video: use InVID for keyframes
5. Reverse image search in TinEye/Google
Beyond Maigret and Sherlock:
| Tool | Platforms | URL | Highlight |
|---|---|---|---|
| Sherlock | 400+ platforms | https://github.com/sherlock-project/sherlock | Faster |
| Maigret | 500+ platforms | https://github.com/soxoj/maigret | More precise |
| WhatsMyName | 600+ platforms | https://github.com/WebBreacher/WhatsMyName | Most complete |
| Snoop | 320+ (RU/CIS emphasis) | https://github.com/snooppr/snoop | Russian/CIS |
| Blackbird | 200+ with PDF report | https://github.com/p1ngul1n0/blackbird | Export |
| UserSearch | 600+ platforms | https://usersearch.org | Largest Reverse User Search Online |
Speed comparison:
# Benchmark (10 usernames)
sherlock: ~45 seconds
maigret: ~90 seconds (more precise)
blackbird: ~60 seconds (with report)| Tool | Function | URL | Level |
|---|---|---|---|
| Photon | Ultra-fast crawler | https://github.com/s0md3v/Photon | Intermediate |
| Scrapy | Complete framework | https://scrapy.org | Advanced |
| Playwright | Browser automation | https://playwright.dev | Advanced |
| Selenium | Classic automation | https://www.selenium.dev | Intermediate |
| Beautiful Soup | HTML/XML parser | https://www.crummy.com/software/BeautifulSoup | Basic |
Basic Photon script:
python photon.py -u https://target.com \
--export=json \
--dns \
--keys \
--threads 10Complete suite:
| Tool | File Type | URL | Platform |
|---|---|---|---|
| ExifTool | Images, PDF, Office | https://exiftool.org | CLI |
| FOCA | Office, PDF (GUI) | https://github.com/ElevenPaths/FOCA | Windows |
| Metagoofil | Public documents | https://github.com/laramies/metagoofil | CLI |
| MAT2 | Metadata cleaner | https://0xacab.org/jvoisin/mat2 | CLI |
Metadata workflow:
# 1. Extract metadata
exiftool -a -u -g1 document.pdf > metadata.txt
# 2. Search sensitive info
grep -i "author\|creator\|email\|gps" metadata.txt
# 3. Clean before publishing
mat2 --inplace clean_document.pdfAdvanced tools:
| Tool | Speed | URL | Ideal Use |
|---|---|---|---|
| Nmap | Medium | https://nmap.org | Complete scan |
| Masscan | Very fast | https://github.com/robertdavidgraham/masscan | Internet-scale |
| RustScan | Very fast | https://github.com/RustScan/RustScan | Modern port |
| Nuclei | Templates | https://github.com/projectdiscovery/nuclei | Vulnerabilities |
Speed comparison:
# Scan 65k ports on 1 IP
nmap: ~5 minutes
rustscan: ~10 seconds → then nmap
masscan: ~5 seconds (less detail)Specialized tools:
| Tool | Function | URL | Requirement |
|---|---|---|---|
| Ahmia | .onion searcher | https://ahmia.fi | Web browser |
| OnionScan | Service scanner | https://github.com/s-rah/onionscan | Tor installed |
| Dark.fail | Verified directory | https://dark.fail | Tor Browser |
| Torch | Old searcher | (only .onion) | Tor Browser |
| DarkDump | Onion scraper | https://github.com/josh0xA/darkdump | Python + Tor |
Dark Web OPSEC:
1. Operating system: Tails OS (amnesic)
2. Never use VPN + Tor (traffic correlation)
3. Use bridges if Tor is blocked
4. NoScript to max
5. No window resizing
6. No downloading to persistent disk
All-in-one platforms:
| Framework | Language | URL | Strength |
|---|---|---|---|
| Ubikron | Browser Ext | https://ubikron.com | AI-powered case management & entity extraction |
| SpiderFoot | Python | https://github.com/smicallef/spiderfoot | Total automation |
| Recon-ng | Python | https://github.com/lanmaster53/recon-ng | Modular |
| theHarvester | Python | https://github.com/laramies/theHarvester | Email/subdomain |
| OSRFramework | Python | https://github.com/i3visio/osrframework | Spanish suite |
| Maltego | Java | https://www.maltego.com | Visualization |
| Spiderfoot HX | Python | https://www.spiderfoot.net/hx | Commercial version |
SpiderFoot setup:
git clone https://github.com/smicallef/spiderfoot.git
cd spiderfoot
pip3 install -r requirements.txt
python3 sf.py -l 127.0.0.1:5001
# Open http://localhost:5001Essential plugins:
| Transform Hub | Function | Note |
|---|---|---|
| Standard Transforms | 150+ official transforms | Free |
| Shodan Transform | Shodan integration | Requires API |
| VirusTotal | Malware/URL analysis | Requires API |
| Netlas Transform | Similar to Shodan | https://netlas.io |
| Hunter.io | Email search | Requires account |
| Builtwith | Site technologies | Requires API |
Create custom transform:
# my_transform.py
from maltego_trx.entities import Person, EmailAddress
from maltego_trx.transform import DiscoverableTransform
class PersonToEmail(DiscoverableTransform):
@classmethod
def create_entities(cls, request, response):
person_name = request.Value
# Your logic here
response.addEntity(EmailAddress, f"{person_name}@example.com")
return response1. Identification: What are we investigating?
2. Preservation: Archive EVERYTHING (archive.is, wayback)
3. Verification: Triangulate with 3+ sources
4. Contextualization: Complete chronology
5. Documentation: Screenshots + hash + timestamp
6. Validation: Peer review before publishing
PHASE 1: DIRECTION
├── Define questions (RFI)
├── Establish legal limits
└── Approve scope
PHASE 2: COLLECTION
├── Passive sources
├── Semi-passive sources
└── Save evidence
PHASE 3: PROCESSING
├── Normalize data
├── Translate languages
└── Structure information
PHASE 4: ANALYSIS
├── Link analysis (Maltego)
├── Timeline creation
├── Pattern recognition
└── Cross validation
PHASE 5: DISSEMINATION
├── Executive report
├── Technical report
├── Visual presentation
└── Evidence archive
2025 Dorks (specific):
# Sensitive information leaks
site:pastebin.com "password" "@company.com"
site:github.com "api_key" OR "api_secret" "company"
site:trello.com intext:"password" OR intext:"passwd"
# Exposed corporate documents
site:*.s3.amazonaws.com ext:xls | ext:xlsx "confidential"
filetype:pdf intext:"internal use only" site:gov
# IP cameras and IoT devices
inurl:/view/view.shtml
intitle:"webcamXP 5"
# Exposed admin panels
intitle:"index of" "admin"
intitle:"Dashboard" inurl:login
inurl:wp-admin intitle:"Dashboard"
# Exposed databases
intitle:"phpMyAdmin" "Welcome to phpMyAdmin"
inurl:"/phpmyadmin/index.php"
"#mysql dump" filetype:sql
# Employee information
site:linkedin.com "company name" "CEO" | "CTO" | "CISO"
site:*.linkedin.com "@companymail.com"
# Subdomains (combine with crt.sh)
site:*.target.com -www
site:*.*.target.com
📺 YouTube Channels (Spanish):
- Ethical Hacking - Pablo González
- CyberSecurityJobs
- DragonJAR
- José Luis García
- Security Hacklabs
📚 Recommended Books:
- "Open Source Intelligence Techniques" - Michael Bazzell (8th ed., 2024)
- "OSINT for Threat Intelligence" - Scott J Roberts
- "The OSINT Handbook" - i-intelligence
🎓 Certifications:
- GOSI (GIAC Open Source Intelligence) - SANS
- CSCTP (Certified Social Media Intelligence Expert) - McAfee Institute
- OSINT Professional Certification - OSINT Combine
🔗 Communities:
- Reddit: r/OSINT, r/OpenSourceIntelligence
- Discord: IntelTechniques Server, OSINT-FR
- Telegram: OSINT Latam, OSINT Dojo
- Twitter/X: #OSINT, #OSINTfor Good
Tools for investigating individuals:
| Tool | Function | URL |
|---|---|---|
| Pipl | People search engine | https://pipl.com |
| Spokeo | Background checks | https://www.spokeo.com |
| BeenVerified | Public records search | https://www.beenverified.com |
| Intelius | People finder | https://www.intelius.com |
| Whitepages | Phone and address lookup | https://www.whitepages.com |
| ZabaSearch | Free people search | https://www.zabasearch.com |
| PeopleFinder | Comprehensive search | https://www.peoplefinder.com |
| Instant Checkmate | Background reports | https://www.instantcheckmate.com |
| TruthFinder | Public records | https://www.truthfinder.com |
| US Search | People search | https://www.ussearch.com |
Tools for investigating companies:
| Tool | Function | URL |
|---|---|---|
| Crunchbase | Company database | https://crunchbase.com |
| AngelList | Startup database | https://angel.co |
| PitchBook | Private company data | https://pitchbook.com |
| ZoomInfo | Business contacts | https://www.zoominfo.com |
| Hoovers | Company profiles | https://www.hoovers.com |
| Dun & Bradstreet | Business credit reports | https://www.dnb.com |
| EDGAR | SEC filings | https://www.sec.gov/edgar |
| OpenCorporates | Global company registry | https://opencorporates.com |
| Company House | UK company registry | https://find-and-update.company-information.service.gov.uk |
| Bloomberg | Financial data | https://www.bloomberg.com |
- Fork ➜ 2. Branch
new-tool➜ 3. PR with tested URL (screenshot mandatory)
Read CONTRIBUIR.md before.
GPL-3 – Educational and research use. Don't be naughty.
«Information wants to be free, but privacy wants to be respected.»
— unknown