Free OSINT Tools: Open-Source and Free Tools by Task

Free OSINT tools can cover most of the early work in an investigation: finding accounts behind a username, mapping a domain, reading company filings, checking an image or seeing whether an email appears in a breach. This guide lists free and open-source tools by task, with the license, release status and limits of each, checked on 10 October 2026.

  • Open source and free public services
  • Licenses and last releases
  • Free-tier limits stated plainly
  • How to run unknown code safely

Based on official repositories, package registries, vendor documentation and pricing pages, checked 10 October 2026. Not a ranking. OSINT-S has no affiliation with any project listed.

Short answer

Free OSINT tools come in four kinds: open-source scripts such as Sherlock, Maigret and theHarvester; free public records such as Companies House and SEC EDGAR; services free only for non-commercial use, such as TinEye and OpenSanctions; and free tiers of paid platforms such as Maltego Basic and Intelligence X. Check the license, the limits and the last release before relying on any of them.

What Counts as a Free OSINT Tool?

Free can mean open-source code, a free public service, free for non-commercial use only, or a limited tier of a paid product; each has different rules.

Yes, you can do OSINT for free, but "free" hides four different deals. The difference matters most when the work is for a client or an employer.

ModelWhat you getExamplesWatch for
Open sourceCode you can run, inspect and modify under its licenseSherlock (MIT), theHarvester (GPL-2.0), GHunt (AGPL-3.0)Maintenance, API keys, broken site modules
Free public serviceOfficial records searchable at no chargeCompanies House, SEC EDGAR, ICIJ Offshore LeaksCoverage limited to one country or data set
Free for non-commercial useFull or partial access if you are not using it commerciallyTinEye (terms), OpenSanctions (CC BY-NC 4.0)Paid client work usually counts as commercial
Freemium tierA capped version of a paid platformMaltego Basic, Epieos Member, Intelligence X Free, Shodan, CensysDaily caps, watermarks, missing modules

Many open-source tools are also only as free as the data sources behind them. theHarvester, for example, works without keys on sources such as certificate transparency logs but needs API keys, some of them paid, for Shodan, Censys, Hunter and others (repository). For a broader view that includes commercial platforms, see the full catalog of OSINT tools by task.

Free Username and Email Search Tools

Open-source username checkers and email lookups are the most popular free OSINT tools; their value depends on how recently they were updated.

ToolLicenseRelease status (checked 10 October 2026)What it does
SherlockMIT0.16.2, 10 September 2026 (PyPI)Finds a username across 400+ social networks; installs with pipx, pip, uv or Docker (repository)
MaigretMIT0.6.6, 18 September 2026 (PyPI)3,000+ sites (500 by default), recursive search, HTML and PDF reports, no API keys (repository)
WhatsMyNameCC BY-SA 4.0 (data)Community-maintained data file, no versioned releasesCommunity list of 700+ sites, with a free web search; the project now maintains data, not checker scripts (repository)
BlackbirdPublic GitHub repositoryNo tagged release listedUsername and email account search built on WhatsMyName data, with an optional AI summary that has a daily limit (repository)
HoleheGPL-3.01.61, 21 July 2022 (PyPI)Checks whether an email is registered on sites through password-recovery flows; older modules may fail
GHuntAGPL-3.02.3.4, 16 March 2026 (PyPI)Google account investigation framework that needs your own Google session cookies (repository)
PhoneInfogaGPL-3.0Stable but unmaintained, per its READMEInformation gathering for phone numbers (repository)

Sherlock, Maigret, WhatsMyName and Blackbird overlap: all check whether a handle exists on many sites. Maigret covers the most sites and builds reports, WhatsMyName is the shared data set behind several tools, and Sherlock is the simplest to install. Running two of them and comparing results reduces misses. Every hit is still a lead: a matching username on two sites does not prove the same person runs both. When it matters, our username investigation and email address investigation services verify the link.

Free Recon Tools for Domains and Infrastructure

Three open-source frameworks and three free tiers cover most passive domain and infrastructure research at no cost.

ToolFree on what termsNotes
theHarvesterOpen source, GPL-2.0Emails, subdomains and hosts from search engines, certificate transparency logs, DNS data and code repositories; many sources need keys (repository)
SpiderFootOpen source, MIT200+ modules for threat intelligence and attack surface mapping; last tagged release v4.0 (repository)
Recon-ngOpen source, GPL-3.0Modular reconnaissance framework for web-based sources (repository)
ShodanFree API plan with every accountA $49 one-time membership raises limits; all API plans are capped at one request per second (Shodan)
CensysFree accountBasic visibility into standard ports and services (Censys)
urlscan.ioFree API plan5,000 public, 1,000 unlisted and 50 private scans a day; public scans are visible to anyone (urlscan.io)

All of these are passive or close to it when used for lookups. SpiderFoot and Recon-ng can also run modules that touch the target directly, so check each module before running it against systems you do not own. Our website and domain investigations combine these sources with registrar and hosting records.

Free Public Records for Companies, Sanctions and Leaks

Official registries and journalist-built databases are free, authoritative and often more reliable than any third-party tool.

  • Companies House (UK). Free company search with registered details, current and resigned officers, filed documents, charges and insolvency information (GOV.UK).
  • SEC EDGAR full-text search. The full text of US electronic filings since 2001 (SEC).
  • ICIJ Offshore Leaks Database. More than 810,000 offshore companies, foundations and trusts from the Pandora Papers, Paradise Papers, Bahamas Leaks, Panama Papers and Offshore Leaks, with data available under open licenses that require attribution (ICIJ).
  • OpenCorporates. Company data from 140+ jurisdictions, searchable on the website; the API is paid, but the company offers free at-scale access to investigative journalists, NGOs and universities on request (OpenCorporates).
  • OpenSanctions. Sanctions, PEP and watchlist data licensed CC BY-NC 4.0: free for non-commercial use, with paid licenses for business use (licensing).

Free registries answer "what is on file"; they rarely answer "who really controls this company". Cross-border ownership questions usually need several registries, filings in other languages and paid data, which is where company investigations and due diligence come in.

Free Image, Video and Satellite Tools

Reverse image search, a verification plugin, a metadata reader and free satellite imagery cover most first checks on a photo or video.

ToolFree on what termsUse it to
TinEyeFree for non-commercial use, up to 100 searches a day and 300 a week (TinEye help)Find earlier copies of an image and where it first appeared
InVID-WeVerify pluginFree Chrome extension from AFP Medialab; some advanced features need registration as a journalist or researcher (WeVerify)Run forensic filters, similarity search and OCR on images and video
ExifToolFree software; version 13.59, 27 May 2026 (ExifTool)Read GPS, camera and editing metadata from files you hold
Copernicus BrowserFree for individual use under quotas (Copernicus Data Space)Compare Sentinel satellite imagery over time

Uploading an image to any online service shares it with that service, so do not upload sensitive client material without checking the provider's terms. When an image or video supports a legal or editorial decision, geolocation verification adds documented, reviewed analysis.

Free OSINT Tools for Breach and Dark Web Checks

Free breach and dark web tools tell you whether an identifier has been exposed; they do not show the full leaked records, and they should not.

  • Have I Been Pwned. Free browser search for an email address across known breaches, plus free Pwned Passwords; API access is paid (HIBP).
  • Intelligence X. Two selector searches a day without an account and 50 a day with a free account, without downloads or exports (Intelligence X).
  • Ahmia. Free, open-source search engine for Tor onion services, with a blocklist for abuse material (Ahmia).

Free checks are enough to learn that an address was exposed. They are not enough to know what was exposed, whether stealer logs or session cookies are circulating, or whether your company is being discussed. Never buy leaked data or test leaked credentials. For continuous coverage, see dark web monitoring.

Free Capture, Monitoring and Analysis Tools

Free tools can preserve pages, watch for changes, chart networks and map live public data, which covers the back half of most small investigations.

ToolLicense or termsUse it to
Wayback MachineFree Save Page Now, one page at a time (Internet Archive)Create a public, third-party copy of a page
ArchiveWeb.pageAGPL-3.0; Chromium extension and desktop app (Webrecorder)Archive pages as you browse and export WARC or WACZ files
Auto ArchiverMIT; Bellingcat; 1.2.9, 1 September 2026 (PyPI)Archive social media posts and media in bulk
changedetection.ioApache 2.0; 0.60.8, 28 September 2026 (PyPI)Get alerts when a web page changes
Google AlertsFree with a Google account (Google)Receive new web and news mentions by email
GephiFree, GPL; desktop app and Gephi Lite in the browser (Gephi)Visualize networks of people, companies and accounts
ShadowBrokerAGPL-3.0; self-hosted with Docker (repository)Map 40+ public layers such as flights, ships and earthquakes
OsirisMIT (repository)Run a self-hosted situational awareness dashboard

The paid counterpart most investigators add first is a capture tool such as Hunchly, which records every page visited during a case; it has a 30-day free trial (Hunchly). Note that the recon toolkits inside ShadowBroker and Osiris include port and vulnerability scanning, which you may only run against systems you are authorized to test.

Free Tiers of Paid OSINT Platforms

Several commercial OSINT tools have permanent free tiers; they are useful for learning and occasional lookups, not for regular casework.

PlatformFree tier (checked 10 October 2026)Main limit
MaltegoBasic plan with Graph Community Edition and 200 credits; business or government users may get Basic+ with 1,000 (pricing)Credits; paid plans start at €3,000 a year
EpieosMember plan with the Google, email checker and Skype modules (pricing)Heavy watermark; other modules need Osinter at €29.99 a month
Intelligence X50 searches a day after sign-up, plus a 7-day trial (pricing)No downloads or exports on the free plan
Shodan and CensysFree API plan (Shodan) and free account (Censys)Filters, credits and history
OSINT IndustriesNo free plan; trials for eligible parties (pricing)Paid plans from £19 a month

Free tiers change often, so recheck limits before planning work around them.

Running Free OSINT Tools Safely

Install from the official source, isolate the code, keep your own accounts out of it and protect what it collects.

  1. Install from the official sourceUse the project's own repository or package page. Sherlock warns that some third-party distribution packages are broken and recommends its own install methods.
  2. Isolate the codeRun community scripts in a virtual machine or a container, not on a laptop that holds client files. Several tools, including Sherlock, publish Docker images.
  3. Check maintenance before you rely on itLook at the last release and open issues. A tool last released in 2022 may silently miss sites that changed since.
  4. Keep personal accounts outGHunt logs in with your Google session cookies, and Osintgram's README advises against using your primary Instagram account. Use dedicated research accounts and accept the platform-terms risk knowingly, or avoid such tools.
  5. Guard API keysStore keys outside shared folders and code repositories, and rotate them if a machine is compromised.
  6. Mind what online tools publishPublic urlscan.io scans are visible to anyone, and uploaded images are shared with the provider.
  7. Protect and minimize resultsResults contain personal data. Keep only what the task needs, under a lawful purpose (GDPR Article 14 sets duties for data not collected from the person).

Free Directories and Learning Resources

Directories help you find tools; structured, free training helps you use them well.

  • OSINT Framework. An MIT-licensed tree of free OSINT resources, with markers for tools that must be installed locally (T), Google dorks (D), sites that need registration (R) and URLs you edit by hand (M) (repository).
  • Bellingcat's Online Investigations Toolkit. Tool descriptions in 12 categories, from maps and satellites to archiving; most tools listed can be used for free, and staff check each entry before it goes online (Bellingcat).
  • OSINT Dojo. Free resources, simple challenges, a learning path and badges for newcomers (OSINT Dojo).

Lists only go so far. Teams that need methodology, legal grounding and practice on realistic cases can use structured OSINT training.

Where Free Tools Stop

Free tools find leads; turning leads into a defensible answer takes licensed data, verification and time.

Free tools struggle with five things: identity resolution across sources, coverage of countries without open registries, history (old records, deleted pages), evidence that will stand up to challenge, and scale. They also produce false positives that someone has to rule out. If your decision depends on the answer, such as a hire, a deal, a dispute or a threat, compare the time you would spend verifying free results with the cost of help.

OSINT-S uses free and paid tools alongside licensed sources, with a senior analyst review before reporting. Focused checks start from 10 business days, comprehensive work takes up to about a month, and every engagement has a fixed quote after written scoping. See OSINT investigations, hiring an OSINT investigator, or the full range of paid OSINT services.

Free Tools Found a Lead? We Can Verify It

Send us what you found and the decision it supports. We scope the check in writing and return a sourced, reviewed answer.

Free OSINT Tools FAQ

I'm a freelance researcher with no budget for subscriptions — which free OSINT tools can I realistically use for usernames, emails, domains and images without paying anything at all?

You can cover the basics with free OSINT tools alone. For usernames, use Sherlock or Maigret plus the WhatsMyName web search; for emails, Have I Been Pwned and Epieos's free Member plan; for domains, theHarvester, SpiderFoot and the free Shodan and Censys accounts; for images, TinEye, the InVID-WeVerify plugin and ExifTool. For companies, use official registries such as Companies House and SEC EDGAR. Check commercial-use terms if you are paid for the work.

Is OSINT free to do at all, or do the free tools quietly push me into paid plans once I start using them for real casework?

OSINT itself is free to practice, but free tiers are designed for occasional use. Open-source scripts and public registries stay free; freemium platforms cap you with daily searches, credits or watermarks, such as 50 searches a day on Intelligence X or 200 credits on Maltego Basic. Regular casework usually ends up needing at least one paid source, mostly for identity resolution and history. Budget for that, or for analyst time spent working around the limits.

Can I use free OSINT tools for paid client work, or do non-commercial terms on services like OpenSanctions and TinEye stop me from doing that?

Open-source tools under licenses such as MIT, GPL or Apache can be used commercially; the license mainly governs how you redistribute the code. Services marked non-commercial are different: TinEye is free only for non-commercial use, with commercial use through its API, and OpenSanctions data is licensed CC BY-NC 4.0, with paid licenses for business use. Paid client work normally counts as commercial, so read each service's terms.

I want to install Sherlock and Maigret on my company laptop — what precautions should I take so I don't run malicious code or leak what I'm searching for?

Install from the official repository or package page, ideally inside a virtual machine or container rather than on the laptop's main system; Sherlock publishes a Docker image. Avoid unofficial forks and bundles. Keep API keys out of shared folders. Remember that these tools send requests from your IP address to hundreds of sites, so run them from a separate research environment, and store results securely because they contain personal data.

What is the actual difference between Sherlock, Maigret, WhatsMyName and Blackbird, and do I need all four for a username search on someone who scammed us?

They overlap heavily, so two are usually enough. WhatsMyName is a community data set of 700+ sites with a free web search, and Blackbird builds on it. Sherlock checks 400+ networks and is the simplest to install. Maigret checks 3,000+ sites, searches recursively and writes reports. Run Maigret plus one other, compare results and verify each account by hand. For fraud recovery, keep evidence and report to the police; beware of recovery scams.

Our startup wants to check whether employee email addresses show up in data breaches using free tools — is Have I Been Pwned enough, or are we missing important leaks?

Have I Been Pwned is a good free first check of known breaches, but it does not show stealer-log infections, session cookies or discussion of your company on criminal forums. Intelligence X's free account adds 50 searches a day across pastes and leaks without exports. For a whole domain or ongoing alerts, you need paid API access or a monitoring service. Never test leaked passwords against accounts to confirm them.

I'm learning OSINT on my own and keep finding endless tool lists online — where should I start, and are there free training resources that aren't just more lists?

Start with method, not tools. OSINT Dojo offers free resources, challenges and a learning path with badges, and Bellingcat's Online Investigations Toolkit explains tools in 12 categories with checked descriptions. Use the OSINT Framework as a directory once you know what you need. Practice on your own digital footprint or public challenges rather than on private individuals, and learn the legal limits early.

Do free online OSINT search engines keep a record of what I search for, and could that alert the person or company I'm looking into?

Some do, so read each service's privacy terms before entering sensitive identifiers. Public urlscan.io scans, for example, are visible to anyone, and uploaded images are shared with the provider. Tools that log in with your accounts, such as GHunt, act as you. Targets rarely see a lookup directly, but self-hosted, open-source tools run from a separate research environment reduce the trail you leave.

Sources and Notes

Sources checked 10 October 2026. Licenses, release dates and free-tier limits are as published by each project or vendor on that date. OSINT-S has not run independent tests of these tools and has no affiliation with any project or vendor listed. This page is a catalog, not a ranking.

Related pages