OSINT CHEAT SHEET - List OSINT Tools
Contains a list of OSINT tools, OSINT tips, datasets, Maltego transform and others. There are free and paid tools you can use and owner is not responsible, only for knowledge or educational purposes. Sorry if some of the resources have closed the service or error owner doesn't always check what's going on with the resources here, thank you
Tips and trick safe guide using resources
- Use virtual machine, fake host or docker image
- Use private network e.g vpn, tor, p2p
- Use second account (not you real account)
- Read ToS the resouces
- Enable your firewall and IDS
- Dont upload your private files make sure you have clean personal file in folder
Linux Distribution for OSINT
You can build it with VM or Live USB make sure you have sandbox machine
EXIF TOOL COMMAND
Exif tag name and data type
Artist string
Author string
Caption string
Categories string
Collections string
DateTime date
DPP lang-alt
EditStatus string
FixtureIdentifier string
Keywords string
Notes string
ObjectCycle string
OriginatingProgram string
Rating real
Rawrppused boolean
ReleaseDate string
ReleaseTime string
RPP lang-alt
Snapshots string
Tagged boolean
More : man exiftool (Run on your terminal)
Site :
Write metadata
- exiftool -tagname="string" file
example : exiftool -Author="Bayu" test.txt
you can add multiple tag and multiple file
Delete metadata
- exiftool -tagname="" file
example : exiftool -Author="" test.txt
Delete mass metadata
- exiftool -all="" file
example : exiftool -all="" file
#Usage : man exiftool or read documentation exiftool.org
Not there are tag no writetable, make sure tagname can write
!Note
Use fresh file, if your file has been compressed or edit metadata you got a default metadata You can use xmp format for edit, write and delete metadata Check the documentation
SOCMINT
- Instagram Be carefull using this tool
- Tinfoleak
- SOCMINT tool
- Graph Search
- Alfred
- Blackbird
Collection Dataset
- Kaggle
- AWS open data
- Open Network
- WHO Data
- Gpt OSINT
- Humdata
- datasetsearch
- OSINT Collection
- Academic Torrent
- Torrent API
- API OSINT TORRENT
- Microsoft Building Fingerprints
- MAXAR Satellite imagery
- Satellite Collection
- Open measure
Forums & Sites
- Bellingcat Discord
- Independent OSINT
- OSINT.Team
- Seccodeid
- Reddit OSINT
- TraceLabs Discord
- IntelTechniques
General Search
Meta Search
Code Search
- Chromium Code Search
- Android Code Search
- Code Finder
- CodeSeek
- Debian Code Search
- Scala
- SearchCode
- SourceCodeOnline
- Woboq
Competitive Programming
File & FTP
- Archie
- 4shared
- FileSearching
- File chef
- Global File Search
- Search Shared
- MMNT
- Pdf analyzer
- Tools pdf24
Social Media Search and Monitoring
- Awario
- Brand24
- Samdesk
- Social Links
- Social Searcher
- Social Analyzer
- SNSCRAPE - Scraper
- OSINT compass
- Phantom Buster
- Open measure
Social Media Management and Content Discovery
Web Intelligence
- Better Whois
- DNS History
- DNS Spy
- DNS Checker
- HackerTarget
- RedHunt Labs Attack Surface Recon API
- Shodan
- Wappalyzer
- Sudomy
- Testssl
- Nmap
- builtwith
- VirusTotal
- Nessus
- Nikto
- Webshag
- wayback machine
- Whoxy
- Farsight DNSDB Transforms for Maltego
- Web Screnshhot Maltego Transforms
- Nuclei
- Netcraft
- DNSX
- cachedview
- Zoomeye
- securitytrails
- hakrawler
- Dork Lab
- Websecreenshoot
- Leakos
- Pastos
- SNYK
- Similar Sites
- Similar Web
- spyonweb
- analyzeid
- Zeus-Scanner
- CloudFail
- Real IP Discover
- Mend Io
Analysing URLs
- Unfurl
- VirusTotal
- Archive Org
- Iplocation
- Smallseotools
- Abuse IP
- Check Phish
- Radar By Cloudflare
- Is it Phishing
- Kaspersky
- PolySwarm
- Threat Miner
- Netcraft
- Malwareworld
- DNS TWIST
- URL CRAZY - Phishing detector
- CRT - Find cert ssl and etc
- Phishing catcher
- Open Phish
- Phishtalk
- URL Haus
Researching Cyber Threats
- Apility.io
- Alien Vault
- AutoShun
- Blacklist Check Tool
- Censys
- CVE Details
- IBM X-Force Exchange
- JoeSandbox Cloud
- Is It Hacked?
- Is It Phishing
- Kaspersky Threat
- Malware Domain List
- Malware URL Website
- Quttera
- Virus total
- Virus Share
- Web Cookies Scanner
- Yara
- Spiderfoot
- NVD
- Seclist
- CVE Mitre
- Malicious Check
- Email Header Analysis
- Url Scan
- AnyRun
- Hybrid Analysis
- VMRay Sandbox
- Browser Sandbox
- Fillter Bypass
- Abuse IP DB
- Talos CTI
- Phishing Analysis Tool
- Phish Verification System
- PolySwarm
- ThreatCrowd
- HYAS Insight
- Phishstats
- GitGuardian
- Rescure
- PolySwarm
- Darkfeed
- Header Email
- Badan Pemeriksa APK
- SPAMHAUS
- Spiderfoot HX You must have account
- Flare
- Malwareworld
- DNS TWIST
- URL CRAZY - Phishing detector
- CRT - Find cert ssl and etc
- Phishing catcher
- Blackite
- Open Phish
- Phish Talk
- Threat Feeds
- Threat Miner
- Intel OWL
- RiskIQ
- LOKI
- Mandiant
- Mend Io
IoT Search Engines
- LeakIX
- Binary Edge
- Shodan
- Shodan Filters
- Shodan Scripts
- Kamerka
- airportwebcams
- Earthcam
- tvway
- Cameraftp
- Insecam
- Webcams
IP Addresses
- Whats my ip This tools can show your ip address isp provider
- Ip 2 location This tools can show your ip address isp provider and geo location
Wireless Network
- Wigle Maps and database of 802.11 wireless networks, with statistics, submitted by wardrivers, netstumblers, and net huggers
- Fing Net Scan
- Wifianalyzer
- Signalmonitoring
- Angry Ip
- Advanced ip scanner
- Wifimap
- Fon
- SolarWInds
SOC & Threat Hunting
Tips
You can find the file hash or other threat indicator
- Alien Vault
- Exploit db
- AT&T
- Yara
- Virustotal
- Joesandbox
- Spiderfoot
- Open CTI
- Solarwinds
- VMware Carbon Black Endpoint
- Insightidr
- MISP
- NVD
- Seclist
- CVE Mitre
- Whois Record
- Abuse IP DB
- Talos CTI
- Darkfeed
- Flare
- Mihari
- Processhacker
- Koodous
- Blackite
- Open Phish
- Phish Talk
- Sophos
- Signature Base
- SIEM Rules
- Threat Feed
- Threat Connect
- Threat Miner
- Virus Share
- Intel OWL
- RiskIQ
- TypeDB
- Goosint
- Google APT search
- LOKI
- Mandiant
- IoC Editor
- CREST Threat Intel
- Intel471
Automation Dorking
Dorking
Dorking is a wonderful thing, you can use this technique to search for anything such as index of a website, looking for live online camera server and other specifics, as for dorking commands that you can do for example
- intitle: Search for specific titles
- inurl: Search for specific urls or paths
- intext: Search for specific words or contects
- filetype: Search for files
- site: Search from a specified target
- Wildcard or symbol * (star) Find all web pages, for example: seccodeid*
- Define:term Search for all things with specified terms, example define:seccodeid
- cache page Take a snapshot of an indexed page. Google uses this to find the right page for the query you're looking for. Website or target specifically
- allintext: Searches for specific text contained on a web page
- allinurl: Find various keywords in a URL
- allintitle: Restricts results to those containing all terms specified in a title
- link: List of web pages that have links to the specified URL
- (|) Pipe. This is a logical operator, | "tips" will show all the sites which contain either, or both words
- (+) Used to concatenate words, useful to detect pages that use more than one specific key
- (-) Minus operator avoids showing results that contain certain words, e.g. security -trails will show pages that use "security" in their text, but not those that have the word "trails"
Example
".mlab.com password"
"access_key"
"access_token"
"amazonaws"
"api.googlemaps AIza"
"api_key"
"api_secret"
"apidocs"
"apikey"
"apiSecret"
"app_key"
"app_secret"
"appkey"
"appkeysecret"
"application_key"
"appsecret"
"appspot"
"auth"
"auth_token"
"authorizationToken"
"aws_access"
"aws_access_key_id"
"aws_key"
"aws_secret"
"aws_token"
"AWSSecretKey"
"bashrc password"
"bucket_password"
"client_secret"
"cloudfront"
"codecov_token"
"config"
"conn.login"
"connectionstring"
"consumer_key"
"credentials"
"database_password"
"db_password"
"db_username"
"dbpasswd"
"dbpassword"
"dbuser"
"dot-files"
"dotfiles"
"encryption_key"
"fabricApiSecret"
"fb_secret"
"firebase"
"ftp"
"gh_token"
"github_key"
"github_token"
"gitlab"
"gmail_password"
"gmail_username"
"herokuapp"
"internal"
"irc_pass"
"JEKYLL_GITHUB_TOKEN"
"key"
"keyPassword"
"ldap_password"
"ldap_username"
"login"
"mailchimp"
"mailgun"
"master_key"
"mydotfiles"
"mysql"
"node_env"
"npmrc _auth"
"oauth_token"
"pass"
"passwd"
"password"
"passwords"
"pem private"
"preprod"
"private_key"
"prod"
"pwd"
"pwds"
"rds.amazonaws.com password"
"redis_password"
"root_password"
"secret"
"secret.password"
"secret_access_key"
"secret_key"
"secret_token"
"secrets"
"secure"
"security_credentials"
"send.keys"
"send_keys"
"sendkeys"
"SF_USERNAME salesforce"
"sf_username"
"site.com" FIREBASE_API_JSON=
"site.com" vim_settings.xml
"slack_api"
"slack_token"
"sql_password"
"ssh"
"ssh2_auth_password"
"sshpass"
"staging"
"stg"
"storePassword"
"stripe"
"swagger"
"testuser"
"token"
"x-api-key"
"xoxb "
"xoxp"
[WFClient] Password= extension:ica
access_key
bucket_password
dbpassword
dbuser
extension:avastlic "support.avast.com"
extension:bat
extension:cfg
extension:env
extension:exs
extension:ini
extension:json api.forecast.io
extension:json googleusercontent client_secret
extension:json mongolab.com
extension:pem
extension:pem private
extension:ppk
extension:ppk private
extension:properties
extension:sh
extension:sls
extension:sql
extension:sql mysql dump
extension:sql mysql dump password
extension:yaml mongolab.com
extension:zsh
filename:.bash_history
filename:.bash_history DOMAIN-NAME
filename:.bash_profile aws
filename:.bashrc mailchimp
filename:.bashrc password
filename:.cshrc
filename:.dockercfg auth
filename:.env DB_USERNAME NOT homestead
filename:.env MAIL_HOST=smtp.gmail.com
filename:.esmtprc password
filename:.ftpconfig
filename:.git-credentials
filename:.history
filename:.htpasswd
filename:.netrc password
filename:.npmrc _auth
filename:.pgpass
filename:.remote-sync.json
filename:.s3cfg
filename:.sh_history
filename:.tugboat NOT _tugboat
filename:_netrc password
filename:apikey
filename:bash
filename:bash_history
filename:bash_profile
filename:bashrc
filename:beanstalkd.yml
filename:CCCam.cfg
filename:composer.json
filename:config
filename:config irc_pass
filename:config.json auths
filename:config.php dbpasswd
filename:configuration.php JConfig password
filename:connections
filename:connections.xml
filename:constants
filename:credentials
filename:credentials aws_access_key_id
filename:cshrc
filename:database
filename:dbeaver-data-sources.xml
filename:deployment-config.json
filename:dhcpd.conf
filename:dockercfg
filename:environment
filename:express.conf
filename:express.conf path:.openshift
filename:filezilla.xml
filename:filezilla.xml Pass
filename:git-credentials
filename:gitconfig
filename:global
filename:history
filename:htpasswd
filename:hub oauth_token
filename:id_dsa
filename:id_rsa
filename:id_rsa or filename:id_dsa
filename:idea14.key
filename:known_hosts
filename:logins.json
filename:makefile
filename:master.key path:config
filename:netrc
filename:npmrc
filename:pass
filename:passwd path:etc
filename:pgpass
filename:prod.exs
filename:prod.exs NOT prod.secret.exs
filename:prod.secret.exs
filename:proftpdpasswd
filename:recentservers.xml
filename:recentservers.xml Pass
filename:robomongo.json
filename:s3cfg
filename:secrets.yml password
filename:server.cfg
filename:server.cfg rcon password
filename:settings
filename:settings.py SECRET_KEY
filename:sftp-config.json
filename:sftp-config.json password
filename:sftp.json path:.vscode
filename:shadow
filename:shadow path:etc
filename:spec
filename:sshd_config
filename:token
filename:tugboat
filename:ventrilo_srv.ini
filename:WebServers.xml
filename:wp-config
filename:wp-config.php
filename:zhrc
HEROKU_API_KEY language:json
HEROKU_API_KEY language:shell
HOMEBREW_GITHUB_API_TOKEN language:shell
jsforce extension:js conn.login
language:yaml -filename:travis
msg nickserv identify filename:config
org:Target "AWS_ACCESS_KEY_ID"
org:Target "list_aws_accounts"
org:Target "aws_access_key"
org:Target "aws_secret_key"
org:Target "bucket_name"
org:Target "S3_ACCESS_KEY_ID"
org:Target "S3_BUCKET"
org:Target "S3_ENDPOINT"
org:Target "S3_SECRET_ACCESS_KEY"
password
path:sites databases password
private -language:java
PT_TOKEN language:bash
redis_password
root_password
secret_access_key
SECRET_KEY_BASE=
shodan_api_key language:python
WORDPRESS_DB_PASSWORD=
xoxp OR xoxb OR xoxa
s3.yml
.exs
beanstalkd.yml
deploy.rake
.sls
AWS_SECRET_ACCESS_KEY
API KEY
API SECRET
API TOKEN
ROOT PASSWORD
ADMIN PASSWORD
GCP SECRET
AWS SECRET
"private" extension:pgp
intext:"hacking" site:seccodeid.com
inurl:login site:seccodeid.com
intext:username filetype:log
site:www.github.com ext:doc | ext:docx | ext:odt | ext:rtf | ext:sxw | ext:psw | ext:ppt | ext:pptx | ext:pps | ext:csv
Bash Dorking Script
PRO TIPS!
You can add other headers, regex and search engine endpoints for refinement and to encode queries
- BING SEARCH
WEB
for ((i=1;i<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" "https://www.bing.com/search?pglt=2081&q=.php?id=" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep ".php?id" | sort -u ;done
Hunt Username
for ((i=1;1<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/119.0;Accept: */*;Accept-Language: id,en-US;q-0.7,en;q-0.3;Accept-Encoding: gzip, deflate, br;Referer: https: //www.bing.com/;DNT: 1;Connection: keep-alive;Cookie: 1P_JAR=2023-11-05-19;Sec-Fetch-Dest:empty;Sec-Fetch-Mode:cors;Sec-Fetch-Site: same-origin;TE: trailers" "https://www.bing.com/search?pglt=2081&q=Jieyab89" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep -E "Jieyab89|github" | sort -u ;done
Hunt Username
for ((i=1;1<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/119.0;Accept: */*;Accept-Language: id,en-US;q-0.7,en;q-0.3;Accept-Encoding: gzip, deflate, br;Referer: https: //www.bing.com/;DNT: 1;Connection: keep-alive;Cookie: 1P_JAR=2023-11-05-19;Sec-Fetch-Dest:empty;Sec-Fetch-Mode:cors;Sec-Fetch-Site: same-origin;TE: trailers" "Your Bing Request URL Header" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep -E "Jieyab89|github" | sort -u ;done
- GOOGLE SEARCH
Hunt Username
for ((i=1;1<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/119.0;Accept: */*;Accept-Language: id,en-US;q-0.7,en;q-0.3;Accept-Encoding: gzip, deflate, br;Referer: https: //www.google.com/;DNT: 1;Connection: keep-alive;Cookie: 1P_JAR=2023-11-05-19;Sec-Fetch-Dest:empty;Sec-Fetch-Mode:cors;Sec-Fetch-Site: same-origin;TE: trailers" "https://www.google.com/search?sourceid=chrome-psyapi2&ion=1&espv=2&ie=UTF-8&start=${i}0&q=Jieyab89" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep -E "Jieyab89|github" | sort -u ;done
WEB
for ((i=1;i<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" "https://www.google.com/search?sourceid=chrome-psyapi2&ion=1&espv=2&ie=UTF-8&start=${i}0&q=.php?id=" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep ".php?id" | sort -u ;done
Google Advanced Search Tools
Other Search Engines
- us.searchboth.net
- Archive.org
- Yandex
- Pastebin
- Topix.com
- search.carrot2.org/stable/search
- Shodan
- Piratebays
- Onesearch
- Searchencrypt
- Duckgo
- Waymore
- StartPage
- Searx
- CommonCrawl
- Similar Sites
- Zap Meta
- Carrot Search
- Goo Search
- swisscows
- odp
Internet Archive
- DMCA
- Wayback Machine
- Intelligence X
- Openlibrary
- Archive Fo
- UKWA
- Archive today
- Waymore
- Cached Pages
- cachedview
- ArchivEye
- Twitter Archive
- Archive Today
- Wayback Downloader
- How to archive tele content
Data Breached OSINT
- Dehashed
- Haveibeenpwned
- Intelligence X
- Wiki Leaks
- DDO Secrets
- Breached Availabe on Darkweb
- Stealthmole
- Doxbin
- Search0t
- Search0t MAP
- What Breach
- Breach Directory
- Snusbase
- Flare
- Leaklookup
- Pastos
- Blackkite
- Facebook Data Breach Cheker
- pwnedOrNot
- Intel471
Crack Jurnals
- SCI HUB This domain will always change
Search Jurnals
Blogs Search Engine
Darkweb Search Engines
- Thehiddenwiki
- Onion Link
- MEMEX
- Onion
- Onion city
- Ahmia
- TorBot
- Darkfeed
- Torch
- Onionsearch
- Darkweeb w Google
- Darknet Book
Tracking Website Changes
Company Reconnaissance Sites (Passive)
- whois
- Netcraft
- Hunter
- SignalHire
- Spiderfoot
- Spiderfoot HX You must have account
- Rocket Reach
- Glasdoor
- Indeed
- ZoomInfo
- Crunchbase
- Apolo
- Lusha
- Jobstreet
- BOTW
- opencorporates
- Data OCCRP
- OSINT Maps
People Searching
- spokeo
- 123people
- peepdb
- reversegeni
- PDDIKTI
- SINTA
- Social Searcher
- Pimeyes
- Rocketreach
- SignalHire
- Thatsthem
- Freepeoplesearch
- Epios
- anymailfinder
- getprospect
- ZoomInfo
- Apolo
- Family Tree
- Radaris
- beenverified
Phone Numbers
- argali
- ciddb
- cellrevealer
- spydialer
- Twilio
- Reverse lookup
- PhoneInfoga
- Sync
- National cell
- Getcontact
- Moriarty-Project
- Get Contact
- True Caller
- Cell Id Lookup
- Device Info
- Cell Finder
- Unkownphone
- Whocallsme
- elenchitelefonici
- nationalcellulardirectory
- phonebooks
- International Phone Directories
- PhoneInfoga
- Spy Dialer
- Phone Validator
- Fone finder
- 411 reverse phone
- Number guru
- Zaba reverse phone
- FullContact
- HLR Lookup
- Ceebydith HLR Lookup
- Free HLR
- HLR Lookup API
- Maltego Phone Search
- SignalHire
- Emobiletracker
- OpenCNAM
- Fullcontact
- seon
- Thatsthem
- Freepeoplesearch
- Epios
- anymailfinder
- getprospect
- ZoomInfo
- Spam Calls
Public Records
Finding Usernames
- Namechk
- Knowem
- Nexfil
- Sherlock
- Instantusername
- Snitch
- Checkusernames
- Maigret
- Picuki
- ZoomInfo
- Alfred
- Blackbird
- Bellingcat Username
Social Networks
- Facebook lookup id
- Sherlock
- Socialsearcher Users
- Sherlock
- Nexfil
- Googlesocialsearch
- Google Social Network Transforms
- FullContact
- maigret
- Blackbird
Google Queries for Facebook
Group Search: site:facebook.com inurl:group
Group Wall Posts Search: site:facebook.com inurl:wall
Pages Search: site:facebook.com inurl:pages
Public Profiles: allinurl: people ‘‘name’’ site:facebook.com
Facebook Query Language (FQL)
Photos By - https://www.facebook.com/search/taget_id/photos-by
Photos Liked - https://www.facebook.com/search/taget_id/photos-liked
Photos Of - https://www.facebook.com/search/taget_id/photos-of
Comments - https://www.facebook.com/search/taget_id/photos-commented
Friends - https://www.facebook.com/search/taget_id/friends
Videos Tagged - https://www.facebook.com/search/taget_id/videos
Videos By - https://www.facebook.com/search/taget_id/videos-by
Videos Liked - https://www.facebook.com/search/taget_id/videos-liked
Videos Commented - https://www.facebook.com/search/taget_id/videos-commented
Events Attended - https://www.facebook.com/search/taget_id/events-joined
Relatives - https://www.facebook.com/search/taget_id/relatives
or you can use dork for spesific example
id site:facebook.com
page site: facebook.com
id site:facebook.com *
page site: facebook.com *
The Ultimate Facebook Investigation Tool
- Intel Technique
- DumpItBlue
- Facebook Search
- Fb-sleep-stats
- Lookup-ID.com
- SearchIsBack
- Wolfram Alpha Facebook Report
- Facebook Recover Lookup
- Who posted facebook
- sowsearch
- Hastag Analzer
- Export comment
- Facebook endpoint
- Facebook Graph
- Facebook live
- Facebook vid downloader
- Fb Sleep Stats
- Skopenow FB Hunter
- Facebook Data Breach Cheker
- Hashtagify
- Iconosquare
- Picodash
- Toutatis
- SearchMyBio
- Dumpor
- Hookgram
- Picuki
- Inflact
- Greatfon
- Save Free
- Insta Location Search
- Insta story visual maps
- Snap Insta
- Insta Profiler
- Insta Loader
Youtube
- search.twitter.com
- twitter advanced
- twitter who_to_follow
- Backtweets BackTweets is a Twitter analytics tool that allows users to search through a Tweet archive.
- First Tweet
- Foller.me
- Followerwonk
- GeoSocial Footprint
- Gigatweeter
- Harvard TweetMap
- Hashtagify
- Hashtags.org
- MyTweetAlerts A tool to create custom email alerts based on Twitter search.
- OneMillionTweetMap
- SnapBird
- Social Bearing
- Social Rank First Follower
- Spoonbill
- Tagdef
- TeachingPrivacy
- Tinfoleak
- Trends24
- TrendsMap
- Ttrends
- twbirthday
- TwChat
- tweepsect
- TweetArchivist
- TweetDeck
- Tweeten
- TweetMap
- TweetMap
- TweetPsych
- Tweetreach
- TweetStats
- TweetTunnel
- Twellow
- Tweriod
- Twiangulate
- Twilert
- Twipho
- Twitonomy
- TwitRSS
- Twitter Advanced Search
- Twitter Audit
- Twitter Chat Schedule
- Twitter Counter
- Twitterfall
- Twitter Search
- TWUBS Twitter Chat
- Schedule Warble
- Twint
- Twitwork
- Twitter Account Profiler
- Twitter Account Profiler
- Twitter Archive
- History Twitter
- Wayback Twitter
- Twitter BOT
- Treverse
- Tweetbinder
- onemilliontweetmap
- birdhunt
Github
Snapchat
Twitter Search Engines
Google queries for LinkedIn
Public Profiles: site:linkedin.com inurl:pub
Updated Profiles: site:linkedin.com inurl:updates
Company Profiles: site:linkedin.com inurl:companies
- LinkedInDumper
- Weakestlink
- GatherContacts
- Rocket reach
- Phantom Buster
- reversecontact
- Linkedin Search OSINT
- Linkedin Overlay Remover
MySpace
Google queries for MySpace
Profiles: site: myspace.com inurl:profile
Blogs: site:myspace.com inurl:blogs
Videos: site:myspace.com inurl:vids
Jobs: site:myspace.com inurl:jobs
Videos: site:myspace.com ‘‘TARGET NAME’’ ‘‘videos’’
Comments: site:myspace.com ‘‘TARGET NAME’’ ‘‘comments’’
Friends: site:myspace.com ‘‘TARGET NAME’’ ‘‘friends’’
Tiktok
Parler
Monitoring & Alerting
EXIF Analysis
- regex
- FindExif
- metapicz
- imageforensic
- metapicz
- jimpl
- pic2map
- labs.tib.eu
- imago-forensics
- Renrot Exif
Documents
Email Tracking
- ip-adress
- whatismyipaddress
- hunter
- email-checker
- verifyemailaddress
- SignalHire
- Holehe
- Holehe Maltego Transforms
- Spokeo
- Mx Toolbox - Header Email
- getnotify
- epieos
- seon
- Eye
- Thatsthem
- Freepeoplesearch
- Headmail
- Poastal
- anymailfinder
- getprospect
- Email Hippo
- Buster
- Gravatar Email Cheker
- EmailRep
- pwnedOrNot
Shodan Query Options
https://pen-testing.sans.org/blog/2015/12/08/effective-shodan-searches
Capturing Information
- DownloadHelper Firefox plugin that will assist in downloading all media from a website
- Exif Viewer
- HTTrack
- Wayback Machine
- cachedview
OSINT TOOLS
- bbot
- Meta OSINT
- Shrelock
- Maltego
- OSINT Framework
- Twint
- Telegram OSINT
- Recon-Ng
- tinfoleak
- maigret
- mosint
- osint_stuff_tool_collection
- instaloctrack
- SpyScrap
- osintteye
- metagoofil
- Harvester
- Geo creepy
- trape
- ReconDog
- iKy
- Ghunt
- Moriarty-Project
- Mr.Holmes
- octosuite Advanced Github OSINT Framework
- Toutatis
- A tool for OSINT based threat hunting
- K𝚊𝚛𝚖𝚊 𝚟𝟸 is a Passive Open Source Intelligence
- Secure ELF parsing/loading library for forensics reconstruction of malware, and robust reverse engineering tools
- OSINT tool that allows you to find a person's accounts and emails + breached email
- A tool to search Aviation-related intelligence from public sources
- PoC OSINT Discord user and guild information harvester
- Automate downloading archived deleted Tweets
- Discover the location of nearby Telegram users
- OSINT Tool on Twitter and Instagram
- The World's simplest facial recognition api for python and the command line
- Automation and automation of digital forensic tools
- E4GL30S1NT
- Commit stream finding Github repositories by extracting commit
- SingleFile copy of an entire web page in a single HTML file
- Photon Incredibly fast crawler designed for OSINT
- infoooze
- Eye
- More
OSINT Online Tool
- Echosec
- Foller
- Tweet Deck
- Tweet Trips
- Tweet Tonomy
- Twinangulate
- Geosocial
- Hash tracking
- Bellingcat
- Socmint tool
- Spyse
- OSINT Combine
- Cell Id Lookup
- Device Info
- Cell Finder
- GRABIFY IP
- Cek Rekening
- Thatsthem
- IntelligenceX
Telegram Tool
Search channel, username anymore
- Telegago
- TelegramDB
- Telegram Search Engine
- Telegram Database: channels, groups and users
- Telegram channels and groups catalog
- Telegago
- Social Finder
- Lyzem Search
- Discover The Best Telegram Channels
- Tele Channel Overiview
- telegram-phone-number-checker
- Telepathy
- Telemetr
- Telegramtrac
- TGDev
- IntelX Telegram
- Tele Geo Int
- Tele Phone Number Checker - Bellingcat
- Telegram Geogramint
- Telegram-Trilateration
Document and Slides Search
- Authorstream
- Find-pdf-doc
- Free Full PDF
- PDF Search Engine
- RECAP
- SlideShare
- Scribd
- soPDF.com
- FileChef
- File Search Engine
- FilePursuit
- NAPALM FTP Indexer
- Cryptome
- Finda PDF
- Find PDF Doc
- Pdf analyzer
- Tools pdf24
- ArchivEye
Real-Time Search, Social Media Search, and General Social Media Tools
- Buffer
- Hashtatit
- Rival IQ
- SocialBakers
- SociaBlade
- Social Searcher
- Mail.Ru Social Network Search
- WATools
- Profil3r
- Oblivion
- Social Analyzer
- Snsscrape
- stratosphere
- OSINT compass
Image Search
- 7Photos
- Baidu Images
- Bing Images
- Clarify
- Flickr
- GoodSearch Image Search
- Google Image
- Image Identification Project
- MyPicsMap
- PhotoBucket
- Picsearch
- PicTriev
- StolenCameraFinder
- TinEye - Reverse image search engine.
- Worldcam
- Yahoo Image Search
- Yandex Images
- Betaface
- Search4faces
- Pimeyes
- Reminiai
- Search4face
- Vkfacewatch
- Facecheck
- Findmyclone
- Face++
- AWS-Recon
- Azure vidio indexer
- Webcams
- Mever
- InVID Verification
- Google Lens
- Robots Verify
- Amazon Face Recon
- VGG Image Search Engine (VISE)
- Fake face detector
Image Analysis
- ExifTool
- Exif Search
- FotoForensics
- Gbimg.org
- Ghiro
- ImpulseAdventure
- Jeffreys Image Metadata Viewer
- JPEGsnoop
- Metapicz
- Forensically
- DiffChecker
- ImgOps
- Pimeyes
- Reminiai
- Search4face
- Vkfacewatch
- Facecheck
- Findmyclone
- Face++
- AWS-Recon
- Image Analyzer
- Pelock
- OCR Image
- labs.tib.eu
- Webcams
- imago-forensics
- Face recon
- Cleanup pictures
- Mever
- InVID Verification
- Google Lens
- Exif Purge
- VGG Image Classification
- VGG Image Search Engine (VISE)
- Fake face detector
Stock Images
- AlltheFreeStock
- Death to Stock
- Freeimages
- Freestocks.org
- Gratisography
- IM Free
- ISO Republic
- iStockphoto
- Kaboompics
- LibreStock
- Life of Pix
- NegativeSpace
- New Old Stock
- Pixabay
- Pexels
- Stocksnap
- Shutterstock
- tookapic
- Unsplash
- Pimeyes
Video Search and Other Video Tools
- Aol Videos
- Bing Videos
- Blinkx
- Clarify
- Clip Blast
- DailyMotion
- Deturl
- DownloadHealper
- Earthcam
- Insecam
- Frame by Frame Browser plugin that allows you to watch YouTube videos frame by frame.
- Geosearch
- Internet Archive: Open Source Videos
- LiveLeak
- Metacafe
- Metatube
- Montage
- Veoh
- Vimeo
- Voxalead
- Yahoo Video Search
- YouTube
- YouTube Data Viewer
- ccSUBS Download Closed Captions & Subtitles from YouTube
- YouTube Metadata
- YouTube Geofind
- Video Stabilization Methods
- Azure vidio indexer
- Bilibili scraper
- Webcams
- Kamerka
- airportwebcams
- airportwebcams
- Earthcam
- tvway
Geospatial Research and Mapping Tools
- Atlasify
- Batchgeo
- Bing Maps
- CartoDB
- Colorbrewer
- CrowdMap
- Dominoc925
- DualMaps
- GeoGig
- GeoNames
- Esri
- Flash Earth
- Google Earth
- Google Earth Pro
- Google Maps
- Google Maps Streetview Player
- Google My Maps
- GPSVisualizer
- GrassGIS
- Here
- Hyperlapse
- Inspire Geoportal
- InstantAtlas
- Instant Google Street View
- Kartograph
- Leaflet
- MapAList
- MapBox
- Mapbuildr
- Mapchart.net
- Maperitive
- MapHub
- MapJam
- Mapline
- Map Maker
- Mapquest
- Modest Maps
- NGA GEOINT
- OpenLayers
- Polymaps
- Perry Castaneda Library
- Open Street Map
- QGIS
- QuickMaps
- Scribble Maps
- Terrapattern
- Tableau
- Timescape
- View in Google Earth
- Wikimapia
- World Aeronautical Database
- WorldMap Harvard
- ViaMichelin
- Yahoo Maps
- Zeemaps
- Sentinel Hub
- Maxar
- USGS (EarthExplorer)
- Zoom Earth
- Remote Pixel
- SunCalc
- ArcGIS
- Pic2Map
- Mapillary
- KartaView
- Satellites Pro
- Liveuamap
- Descartes Labs
- Baidu Maps
- MapChecking
- Windy
- SOAR
- digiKam
- geoq
- gvision
- OSM Bellingcat
- labs.tib.eu
- sketchmapper
- github sketchmapper
- byt-georagging
- CSIS maps
- Humdata maps
- Planet - satellite maps
- OSM Finder
- OSM Finder - Web based
- Wayback Geospatial
- Twitter Geo
- Insta Geo
- NASA EARTH
- EARTH DATA NASA
- peakvisor
- peakfinder
- Calc Map Coordinate
- Latlong Calc
- Gps Visualizer
- Iq Air
- NASA Earth Data
- NASA World View
- Earth Exploer
- Sky Watch Earth Cache
- Sentinel Hub
- Skylens
- Geocreepy
- garmin
Nearby Map From Geospatial
Fact Checking
- About Urban Legends
- Captin Fact
- Check
- Citizen Desk
- Emergent
- Fact Check
- Full Fact
- MediaBugs
- Snopes The definitive Internet reference source for urban legends, folklore, myths, rumors, and misinformation.
- Verification Handbook
- Verification Junkie
- Verily
- Google Fact
- Open Measures
- Hoaxy
Server Information Gathering
CTF Analysis & Exploit
- Cybercheff
- Bettercap Framework to perform MITM (Man in the Middle) attacks.
- Yersinia A framework for layer 2 attacks
- FeatherDuster An automated, modular cryptanalysis tool
- Hash Extender A utility tool for performing hash length extension attacks
- Hashcat Password cracking
- DLLInjector Inject dlls in processes
- Metasploit Penetration testing software and exploit
- Pwntools CTF framework and exploit development library
- ROPgadget Framework for ROP exploitation
- Exiftool Read, write and edit file metadata
- Malzilla Malware hunting tool
- Zmap An open-source network scanner.
- Nmap Net mapping and port scanner
- Wireshark Analyze the network dumps
- Apktool Android Decompiler
- Ninja Binary Binary analysis framework
- Binwalk Analyze, reverse engineer, and extract firmware images
- GDB The GNU project debugger
- GEF Advanced debugging capabilities for exploit devs & reverse engineers on Linux
- IDA Most used Reversing software
- PEDA Python Exploit Development Assistance for GDB
- Radare2 UNIX-like reverse engineering framework and command-line toolset
- Windbg Windows debugger distributed by Microsoft
- Boomerang Decompile x86 binaries to C
- Detox A Javascript malware analysis tool
- SmartDeblur Restoration of defocused and blurred photos/images
- HitPaw Enhance image, video and media quality with AI is free and paid
- ImageMagick Tool for manipulating images
- Exiv2 Image metadata manipulation tool
- Stegbreak Launches brute-force dictionary attacks on JPG image
- Steghide Hide data in various kind of images
- Stegsolve Apply various steganography techniques to images
- SearchSploit Command line search tool for Exploit-DB
- Exploitalert List exploiting and vuln
- Lollabs Windows exploiting
- GtfoBins Linux exploiting
- Hacktricks List exploit and vuln cheat sheet walkthrough
- Payload all the things Example and payload injection
- All about bug bounty Bypasses, payloads, Reconnaissance and etc
- DnsSpy Desktop NET debugger and assembly editor
Zero Day
Cryptocurrency Investigation
- Blockchain
- Flashpoint
- Intel471
- Tatum
- Ciphertrace
- Bitcoin Abuse
- Blockchain-Info
- GraphSense
- Blockhain Explorer
- blockcypher
- BTC Scan
Cell Investigation
- Opencellid
- CellTower Locator - Cell2gps
- Cell-id Query
- Location API
- Cell Mapping
- Global Internet Infrastructure Map
- Spy Dialer
- Phone Validator
- Free Operator Search
- HLR Lookup
- Ceebydith HLR Lookup
- Free HLR
- HLR Lookup API
- Maltego Phone Search
- Emobiletracker
- Phone Validator
- Reverse Phone
- Reverse Phone Lookup
- OpenCNAM
- Search Country Operator (IMSI)
- Analysis of IMSI numbers
- World MCC & MNC Code
- World MCC & MNC Code 2
- World Mobile Network Code
- World Network Coverage
- Profone GSM Tracker
- Thatsthem
- Freepeoplesearch
- IMSI imei info
- cellebrite
IMEI Investigation
Chat Apps Investigation
- Analyze your WhatsApp Chat
- Chat Visualizer
- WhatsApp Group Links
- Download WhatsApp Profile Picture
- WhatsApp Group Links 2
- Wa tools
Telegram
- TelegramDB
- Telegram Search Engine
- Telegram Database: channels, groups and users
- Telegram channels and groups catalog
- Telegago
- Social Finder
- Lyzem Search
- Discover The Best Telegram Channels
- Tele Channel Overiview
- Telegramtrac
- TGDev
- Telegram Geogramint
- Telegram-Trilateration
Build Sockpuppet Accounts
Build your sockpuppet account and proctect your privacy
- Roop Image face swap from AI
- Thispersondoesnotexist
- Protonmail
- Nordvpn
- NOX
- Browser Extension
- Burner Phone Number
- Phone Burner
- Hushed
- Temp Phone Number
- Temp Mail 1
- Temp Mail 2
- Temp Mail 3
- Cryptocurrency Payment Monero
- Cryptocurrency Payment Bitcoin
- Openpgp
- Operating System
- Zmail
- Open DNS
- I2P
- TOR
Social Network and blogging
- Wordpress
- Blogger
- Medium
Enhance Image Quality
- Letsenhance
- Cutout
- Upscale
- Canva
- Adobe
- Picwish
- Fotor
- SIUN
- DPED
- neural-enhance
- neural-enhance
- Reminiai
- Depix
- Realesrgan
- HitPaw
- Cleanup Pictures
- Gfpgan
Locations Data Mapping
- Google maps
- Social geo lens
- Open street map
- Google Maps Geocoding
- Googleearthengine
- OSM Bellingcat
- byt5-geotagging
- CSIS maps
- Humdata maps
- Planet - satellite maps
- OSM Finder
- OSM Finder - Web based
Discord Server Search
Darkweb Intelligence
- Stealthmole
- Darkweb bookmarks
- Maltego digital shadows transform
- Maltego cybersixgill transform
- Doge Darknet Osint Graph Explorer
- Maltego social links professional transform
- TorBot
- Darkfeed
- Flare
- pryingdeep
- Maltego
- Darknet Book
Digital Forensics
- Yggdrasil
- MISP
- Maltego
- Filesec
- Lolbas
- Logstash kibana
- Kibana
- Extundelete Ext3 or ext4 partition recovery
- TestDisk
- VirusTotal
- Avilla Forensics
- Autopsy
- Recuva
- Magnetforensics
- Opentxt
- Ntfstool Forensics
- Sleuthkit
- SIFT SANS
- SIFT CLI
- HYAS Insight
- imago-forensics
- SimpleImager
- Processhacker
- Koodous
- Nirsoft Bwowsing History
- dfrlab.org
- atlanticcouncil
- Mever
- cellebrite
- MOBSF
- RMS - Mobile Pentest
- APK Leaks
Write Your Investigation
Securing Your Privacy
- Eraser
- Thunderbird
- Ublock origin
- Zmail
- Open DNS
- I2P
- Gnupg
- HTTPS Everywhere
- Pelock
- Tails OS
- WOT
- Temp Mail 1
- Temp Mail 2
- Temp Mail 3
- Phone Burner
- Hushed
- Privacy Badger
- Blur IMG Extension
Payment
Password Manager
Fraud Checker
- Cek Rekening - Indonesian By Kominfo
- Kredibel - Indonesian
- Verihub - Indonesian
- Scamadviser
- Ipqualityscore
- OpenCNAM
- Fullcontact
- Spam Calls
Content Removal & Strict Media Content
Search people missing and abuse, strict, removing, takedown and minimize your data on the internet
- Google image removal Remove your image from Google
- Stopncii Free tool designed to support victims of Non-Consensual Intimate Image (NCII) abuse
- Bing content removal Chech the detail on here
- Google content removal Check the detail on here
- Web archiver remover Check the detail here and here view detail on Help web archive
- Facebook Privacy Strict and disable bot crawl search engine index account
- Instagram Privacy Strict and disable bot crawl search engine index account
- Missing Kids Remove nudes or sexually-exploitive images or videos taken when you were a child out there on the internet
- Takeit Down Help remove online nude, partially nude
- Inhope Report suspected child sexual abuse images or videos
- ReportIWF Indonesia Proctect and remove sexualy, nudes on internet
- ReportIWF Proctect and remove sexualy, nudes on internet
- 411
- 411 Info-
- Absolute People Search
- Acxiom
- Addresses
- Address Search
- Archives
- Apollo
- Arivify
- Azerch
- Background Alert
- Background Check
- Background Checkers
- BatchSkipTracing
- BatchLeads
- BatchDialer
- BatchDriven
- Been Verified
- Buzzfile
- Call Truth
- Caller Smart
- Centeda
- Check People
- Check Secrets
- Checkr
- City-Data
- ClickSearch
- Clustr Maps
- Complete Investigation Services
- Confidential Phone Lookup
- Contact Out
- Connected Investors
- Corporation Wiki
- Councilon
- Cyber Background Checks
- Data Axle
- DataVeria
- DataChk
- Dehashed
- DelvePoint
- DexKnows
- DirectMail
- DMA Choice | DMA Choice
- Epsilon-Main
- Epsilon-Abacus
- Epsilon-CFD
- Epsilon-Shopper
- Fama
- FamilySearch
- Family Tree Now
- Fast People Fast
- Fast People Search
- Fax VIN
- Find People Search
- Free Background Checks
- Free People Directory
- Free Phone Tracer
- Free Public Profile
- FindRec
- Glad I Know
- GoLookup
- Grey Pages
- Haines & Company
- Hometry
- HPCC-USA
- ID Crawl
- ID True
- Infopay
- Infospace
- Infotracer
- Infotracer UK
- Instant Check Mate
- InstantPeopleFinder
- Intelius
- IntelligenceX
- IRBSearch
- Kiwi Searches
- LexisNexis/Accurint
- LexisNexis Direct Marketing
- Locate Family
- Locate People
- MashPanel
- Mastercard,
- Mastercard
- MugshotLook
- MyHeritage
- MyLife
- National Cellular Directory
- Neighbor Report
- NewEnglandFacts
- Number Guru
- Numberville
- Nuwber
- Official USA
- Old Friends
- Ownerly
- PeekYou
- Peep Lookup
- PeopleBackgroundCheck
- People By Name
- People By Phone
- People Data Labs
- People Finder
- People Finders
- People Looker
- People Search 123
- People Search Expert
- People Finder
- People Finders
- People Looker
- People Search 123
- People Search Now
- People Searcher
- People Smart
- People Trace UK
- People’s Check
- People Whiz
- Phonebook BT
- Pub360
- Public Data Digger
- Public Data USA
- Public Info Services
- Public Records
- Public Records Now
- Quick People Trace
- Radaris
- Reveal Name
- Reveal Phone Owner
- Sales Spider
- Search Bug
- Search People Free
- Selfie Systems
- Smart Background Checks
- Social Catfish
- Spy Dialer
- Spokeo
- SpyFly
- Spytox
- State Records
- Super Pages
- Sync Me
- Telephone Directories
- Tenn Help
- That’s Them
- The Real Yellow Pages
- Thomson Reuters/Westlaw/CLEAR
- TLO
- Tower Data
- True Caller
- True People Search
- True People Search.net
- Truth Finder
- United States Phonebook
- Unmask
- USA People Search
- US Phone Pro
- US Phonebook
- USA Trace
- US Search
- Valassis
- Valpak/Cox
- Verecor
- Vericora
- Veriforia
- Veripages
- Verispy
- Veritora
- Visa
- Voter Records
- White Pages
- WYTY
- XLEK
- Yellow Book
- Yellow Pages
- ZoomInfo
- Get Contact Unlisting
*NB : Please read carefully and check the ToS or privacy statment. Its taking to long, you need to patiently. For this point, your data is not guaranteed to be lost 100% on the internet, but this is to minimize the spread of your data and data breaches
Vehicle OSINT
Aircraft Tracking
Ship Tracking
Railways
GPT OSINT
OSINT for Red Team
- Phishious Secure Email Gateway (SEG) for phishing email header (escape detection)
- Operative framework investigation OSINT framework, you can interact with multiple targets
- Mod Login Credentials reuse
- Cr3dOv3r Credential reuse
- Crackmapexec Password Spray
- Datasploit OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc
- CloudFail DNS and old database records to find hidden IP's behind the CloudFlare network
- cloudgazer Find Real IPs hidden behind Cloudflare with Criminal IP(criminalip.io), security OSINT Tool
- Rustcan Port scanner
- NMAP Port scanner
- Getrails Dork hacking that work with Google, Duckduckgo and Torch
- OWASP Maryam open-source framework based on OSINT and data gathering
- Metabigor Intelligence tool, its goal is to do OSINT tasks and more but without any API key
- OSINT BBOT A recursive internet scanner for hackers.
- Spiderfoot A Scrapping web tool
- Zeus-Scanner A web scanner
- Zenrows Bypassing captcha and WAF
- Scrapfly Bypassing captcha and WAF
- Puppeter For web scrapper and info gath
- MOBSF Mobile Pentest Tool
- RMS - Mobile Pentest Mobile Pentest Tool
- Mortar Mortar evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)
- APK Leaks
Audio OSINT
- Audio metadata
- Google Translate by speech
- Microsoft Translator
- Yandex Translate
- Apple Translate by speech
- translatedlabs
- Adobe Audition
- Sound classification with YAMNet
- Praat
- phonexia
Audio enchange quality
OSINT Network
Detect a fake network and VPN
Medical OSINT
OSINT Military
- militaryfactory
- Military and other uniform badges
- SMALL ARMS SURVEY
- dfrlab.org
- atlanticcouncil
- NASA EARTH
- EARTH DATA NASA
- peakvisor
- peakfinder
- Geoconfirmed
- Air Wars
- Copernicus
- Ej Atlas
- Intro OSINT Military
- Telegram Geogramint
- Skylens
- Geocreepy
- Kamerka
- Earthcam
- onemilliontweetmap
- birdhunt
- garmin
Academic Search Tools
Academic Literature
- Academic Literature on Open Source Research & Methods
- OSINT ethics
- G Drive - Navigating digital media
Web Directory
Torrent
SDR OSINT
API for OSINT
Resources and collection for your make tool OSINT