Free OSINT Tools: Open-Source and Free Tools by Task
Free OSINT tools can cover most of the early work in an investigation: finding accounts behind a username, mapping a domain, reading company filings, checking an image or seeing whether an email appears in a breach. This guide lists free and open-source tools by task, with the license, release status and limits of each, checked on 10 October 2026.
- Open source and free public services
- Licenses and last releases
- Free-tier limits stated plainly
- How to run unknown code safely
Free OSINT tools come in four kinds: open-source scripts such as Sherlock, Maigret and theHarvester; free public records such as Companies House and SEC EDGAR; services free only for non-commercial use, such as TinEye and OpenSanctions; and free tiers of paid platforms such as Maltego Basic and Intelligence X. Check the license, the limits and the last release before relying on any of them.
What Counts as a Free OSINT Tool?
Free can mean open-source code, a free public service, free for non-commercial use only, or a limited tier of a paid product; each has different rules.
Yes, you can do OSINT for free, but "free" hides four different deals. The difference matters most when the work is for a client or an employer.
| Model | What you get | Examples | Watch for |
|---|---|---|---|
| Open source | Code you can run, inspect and modify under its license | Sherlock (MIT), theHarvester (GPL-2.0), GHunt (AGPL-3.0) | Maintenance, API keys, broken site modules |
| Free public service | Official records searchable at no charge | Companies House, SEC EDGAR, ICIJ Offshore Leaks | Coverage limited to one country or data set |
| Free for non-commercial use | Full or partial access if you are not using it commercially | TinEye (terms), OpenSanctions (CC BY-NC 4.0) | Paid client work usually counts as commercial |
| Freemium tier | A capped version of a paid platform | Maltego Basic, Epieos Member, Intelligence X Free, Shodan, Censys | Daily caps, watermarks, missing modules |
Many open-source tools are also only as free as the data sources behind them. theHarvester, for example, works without keys on sources such as certificate transparency logs but needs API keys, some of them paid, for Shodan, Censys, Hunter and others (repository). For a broader view that includes commercial platforms, see the full catalog of OSINT tools by task.
Free Username and Email Search Tools
Open-source username checkers and email lookups are the most popular free OSINT tools; their value depends on how recently they were updated.
| Tool | License | Release status (checked 10 October 2026) | What it does |
|---|---|---|---|
| Sherlock | MIT | 0.16.2, 10 September 2026 (PyPI) | Finds a username across 400+ social networks; installs with pipx, pip, uv or Docker (repository) |
| Maigret | MIT | 0.6.6, 18 September 2026 (PyPI) | 3,000+ sites (500 by default), recursive search, HTML and PDF reports, no API keys (repository) |
| WhatsMyName | CC BY-SA 4.0 (data) | Community-maintained data file, no versioned releases | Community list of 700+ sites, with a free web search; the project now maintains data, not checker scripts (repository) |
| Blackbird | Public GitHub repository | No tagged release listed | Username and email account search built on WhatsMyName data, with an optional AI summary that has a daily limit (repository) |
| Holehe | GPL-3.0 | 1.61, 21 July 2022 (PyPI) | Checks whether an email is registered on sites through password-recovery flows; older modules may fail |
| GHunt | AGPL-3.0 | 2.3.4, 16 March 2026 (PyPI) | Google account investigation framework that needs your own Google session cookies (repository) |
| PhoneInfoga | GPL-3.0 | Stable but unmaintained, per its README | Information gathering for phone numbers (repository) |
Sherlock, Maigret, WhatsMyName and Blackbird overlap: all check whether a handle exists on many sites. Maigret covers the most sites and builds reports, WhatsMyName is the shared data set behind several tools, and Sherlock is the simplest to install. Running two of them and comparing results reduces misses. Every hit is still a lead: a matching username on two sites does not prove the same person runs both. When it matters, our username investigation and email address investigation services verify the link.
Free Recon Tools for Domains and Infrastructure
Three open-source frameworks and three free tiers cover most passive domain and infrastructure research at no cost.
| Tool | Free on what terms | Notes |
|---|---|---|
| theHarvester | Open source, GPL-2.0 | Emails, subdomains and hosts from search engines, certificate transparency logs, DNS data and code repositories; many sources need keys (repository) |
| SpiderFoot | Open source, MIT | 200+ modules for threat intelligence and attack surface mapping; last tagged release v4.0 (repository) |
| Recon-ng | Open source, GPL-3.0 | Modular reconnaissance framework for web-based sources (repository) |
| Shodan | Free API plan with every account | A $49 one-time membership raises limits; all API plans are capped at one request per second (Shodan) |
| Censys | Free account | Basic visibility into standard ports and services (Censys) |
| urlscan.io | Free API plan | 5,000 public, 1,000 unlisted and 50 private scans a day; public scans are visible to anyone (urlscan.io) |
All of these are passive or close to it when used for lookups. SpiderFoot and Recon-ng can also run modules that touch the target directly, so check each module before running it against systems you do not own. Our website and domain investigations combine these sources with registrar and hosting records.
Free Public Records for Companies, Sanctions and Leaks
Official registries and journalist-built databases are free, authoritative and often more reliable than any third-party tool.
- Companies House (UK). Free company search with registered details, current and resigned officers, filed documents, charges and insolvency information (GOV.UK).
- SEC EDGAR full-text search. The full text of US electronic filings since 2001 (SEC).
- ICIJ Offshore Leaks Database. More than 810,000 offshore companies, foundations and trusts from the Pandora Papers, Paradise Papers, Bahamas Leaks, Panama Papers and Offshore Leaks, with data available under open licenses that require attribution (ICIJ).
- OpenCorporates. Company data from 140+ jurisdictions, searchable on the website; the API is paid, but the company offers free at-scale access to investigative journalists, NGOs and universities on request (OpenCorporates).
- OpenSanctions. Sanctions, PEP and watchlist data licensed CC BY-NC 4.0: free for non-commercial use, with paid licenses for business use (licensing).
Free registries answer "what is on file"; they rarely answer "who really controls this company". Cross-border ownership questions usually need several registries, filings in other languages and paid data, which is where company investigations and due diligence come in.
Free Image, Video and Satellite Tools
Reverse image search, a verification plugin, a metadata reader and free satellite imagery cover most first checks on a photo or video.
| Tool | Free on what terms | Use it to |
|---|---|---|
| TinEye | Free for non-commercial use, up to 100 searches a day and 300 a week (TinEye help) | Find earlier copies of an image and where it first appeared |
| InVID-WeVerify plugin | Free Chrome extension from AFP Medialab; some advanced features need registration as a journalist or researcher (WeVerify) | Run forensic filters, similarity search and OCR on images and video |
| ExifTool | Free software; version 13.59, 27 May 2026 (ExifTool) | Read GPS, camera and editing metadata from files you hold |
| Copernicus Browser | Free for individual use under quotas (Copernicus Data Space) | Compare Sentinel satellite imagery over time |
Uploading an image to any online service shares it with that service, so do not upload sensitive client material without checking the provider's terms. When an image or video supports a legal or editorial decision, geolocation verification adds documented, reviewed analysis.
Free OSINT Tools for Breach and Dark Web Checks
Free breach and dark web tools tell you whether an identifier has been exposed; they do not show the full leaked records, and they should not.
- Have I Been Pwned. Free browser search for an email address across known breaches, plus free Pwned Passwords; API access is paid (HIBP).
- Intelligence X. Two selector searches a day without an account and 50 a day with a free account, without downloads or exports (Intelligence X).
- Ahmia. Free, open-source search engine for Tor onion services, with a blocklist for abuse material (Ahmia).
Free checks are enough to learn that an address was exposed. They are not enough to know what was exposed, whether stealer logs or session cookies are circulating, or whether your company is being discussed. Never buy leaked data or test leaked credentials. For continuous coverage, see dark web monitoring.
Free Capture, Monitoring and Analysis Tools
Free tools can preserve pages, watch for changes, chart networks and map live public data, which covers the back half of most small investigations.
| Tool | License or terms | Use it to |
|---|---|---|
| Wayback Machine | Free Save Page Now, one page at a time (Internet Archive) | Create a public, third-party copy of a page |
| ArchiveWeb.page | AGPL-3.0; Chromium extension and desktop app (Webrecorder) | Archive pages as you browse and export WARC or WACZ files |
| Auto Archiver | MIT; Bellingcat; 1.2.9, 1 September 2026 (PyPI) | Archive social media posts and media in bulk |
| changedetection.io | Apache 2.0; 0.60.8, 28 September 2026 (PyPI) | Get alerts when a web page changes |
| Google Alerts | Free with a Google account (Google) | Receive new web and news mentions by email |
| Gephi | Free, GPL; desktop app and Gephi Lite in the browser (Gephi) | Visualize networks of people, companies and accounts |
| ShadowBroker | AGPL-3.0; self-hosted with Docker (repository) | Map 40+ public layers such as flights, ships and earthquakes |
| Osiris | MIT (repository) | Run a self-hosted situational awareness dashboard |
The paid counterpart most investigators add first is a capture tool such as Hunchly, which records every page visited during a case; it has a 30-day free trial (Hunchly). Note that the recon toolkits inside ShadowBroker and Osiris include port and vulnerability scanning, which you may only run against systems you are authorized to test.
Free Tiers of Paid OSINT Platforms
Several commercial OSINT tools have permanent free tiers; they are useful for learning and occasional lookups, not for regular casework.
| Platform | Free tier (checked 10 October 2026) | Main limit |
|---|---|---|
| Maltego | Basic plan with Graph Community Edition and 200 credits; business or government users may get Basic+ with 1,000 (pricing) | Credits; paid plans start at €3,000 a year |
| Epieos | Member plan with the Google, email checker and Skype modules (pricing) | Heavy watermark; other modules need Osinter at €29.99 a month |
| Intelligence X | 50 searches a day after sign-up, plus a 7-day trial (pricing) | No downloads or exports on the free plan |
| Shodan and Censys | Free API plan (Shodan) and free account (Censys) | Filters, credits and history |
| OSINT Industries | No free plan; trials for eligible parties (pricing) | Paid plans from £19 a month |
Free tiers change often, so recheck limits before planning work around them.
Running Free OSINT Tools Safely
Install from the official source, isolate the code, keep your own accounts out of it and protect what it collects.
- Install from the official sourceUse the project's own repository or package page. Sherlock warns that some third-party distribution packages are broken and recommends its own install methods.
- Isolate the codeRun community scripts in a virtual machine or a container, not on a laptop that holds client files. Several tools, including Sherlock, publish Docker images.
- Check maintenance before you rely on itLook at the last release and open issues. A tool last released in 2022 may silently miss sites that changed since.
- Keep personal accounts outGHunt logs in with your Google session cookies, and Osintgram's README advises against using your primary Instagram account. Use dedicated research accounts and accept the platform-terms risk knowingly, or avoid such tools.
- Guard API keysStore keys outside shared folders and code repositories, and rotate them if a machine is compromised.
- Mind what online tools publishPublic urlscan.io scans are visible to anyone, and uploaded images are shared with the provider.
- Protect and minimize resultsResults contain personal data. Keep only what the task needs, under a lawful purpose (GDPR Article 14 sets duties for data not collected from the person).
Free Directories and Learning Resources
Directories help you find tools; structured, free training helps you use them well.
- OSINT Framework. An MIT-licensed tree of free OSINT resources, with markers for tools that must be installed locally (T), Google dorks (D), sites that need registration (R) and URLs you edit by hand (M) (repository).
- Bellingcat's Online Investigations Toolkit. Tool descriptions in 12 categories, from maps and satellites to archiving; most tools listed can be used for free, and staff check each entry before it goes online (Bellingcat).
- OSINT Dojo. Free resources, simple challenges, a learning path and badges for newcomers (OSINT Dojo).
Lists only go so far. Teams that need methodology, legal grounding and practice on realistic cases can use structured OSINT training.
Where Free Tools Stop
Free tools find leads; turning leads into a defensible answer takes licensed data, verification and time.
Free tools struggle with five things: identity resolution across sources, coverage of countries without open registries, history (old records, deleted pages), evidence that will stand up to challenge, and scale. They also produce false positives that someone has to rule out. If your decision depends on the answer, such as a hire, a deal, a dispute or a threat, compare the time you would spend verifying free results with the cost of help.
OSINT-S uses free and paid tools alongside licensed sources, with a senior analyst review before reporting. Focused checks start from 10 business days, comprehensive work takes up to about a month, and every engagement has a fixed quote after written scoping. See OSINT investigations, hiring an OSINT investigator, or the full range of paid OSINT services.
Free Tools Found a Lead? We Can Verify It
Send us what you found and the decision it supports. We scope the check in writing and return a sourced, reviewed answer.
Free OSINT Tools FAQ
I'm a freelance researcher with no budget for subscriptions — which free OSINT tools can I realistically use for usernames, emails, domains and images without paying anything at all?
You can cover the basics with free OSINT tools alone. For usernames, use Sherlock or Maigret plus the WhatsMyName web search; for emails, Have I Been Pwned and Epieos's free Member plan; for domains, theHarvester, SpiderFoot and the free Shodan and Censys accounts; for images, TinEye, the InVID-WeVerify plugin and ExifTool. For companies, use official registries such as Companies House and SEC EDGAR. Check commercial-use terms if you are paid for the work.
Is OSINT free to do at all, or do the free tools quietly push me into paid plans once I start using them for real casework?
OSINT itself is free to practice, but free tiers are designed for occasional use. Open-source scripts and public registries stay free; freemium platforms cap you with daily searches, credits or watermarks, such as 50 searches a day on Intelligence X or 200 credits on Maltego Basic. Regular casework usually ends up needing at least one paid source, mostly for identity resolution and history. Budget for that, or for analyst time spent working around the limits.
Can I use free OSINT tools for paid client work, or do non-commercial terms on services like OpenSanctions and TinEye stop me from doing that?
Open-source tools under licenses such as MIT, GPL or Apache can be used commercially; the license mainly governs how you redistribute the code. Services marked non-commercial are different: TinEye is free only for non-commercial use, with commercial use through its API, and OpenSanctions data is licensed CC BY-NC 4.0, with paid licenses for business use. Paid client work normally counts as commercial, so read each service's terms.
I want to install Sherlock and Maigret on my company laptop — what precautions should I take so I don't run malicious code or leak what I'm searching for?
Install from the official repository or package page, ideally inside a virtual machine or container rather than on the laptop's main system; Sherlock publishes a Docker image. Avoid unofficial forks and bundles. Keep API keys out of shared folders. Remember that these tools send requests from your IP address to hundreds of sites, so run them from a separate research environment, and store results securely because they contain personal data.
What is the actual difference between Sherlock, Maigret, WhatsMyName and Blackbird, and do I need all four for a username search on someone who scammed us?
They overlap heavily, so two are usually enough. WhatsMyName is a community data set of 700+ sites with a free web search, and Blackbird builds on it. Sherlock checks 400+ networks and is the simplest to install. Maigret checks 3,000+ sites, searches recursively and writes reports. Run Maigret plus one other, compare results and verify each account by hand. For fraud recovery, keep evidence and report to the police; beware of recovery scams.
Our startup wants to check whether employee email addresses show up in data breaches using free tools — is Have I Been Pwned enough, or are we missing important leaks?
Have I Been Pwned is a good free first check of known breaches, but it does not show stealer-log infections, session cookies or discussion of your company on criminal forums. Intelligence X's free account adds 50 searches a day across pastes and leaks without exports. For a whole domain or ongoing alerts, you need paid API access or a monitoring service. Never test leaked passwords against accounts to confirm them.
I'm learning OSINT on my own and keep finding endless tool lists online — where should I start, and are there free training resources that aren't just more lists?
Start with method, not tools. OSINT Dojo offers free resources, challenges and a learning path with badges, and Bellingcat's Online Investigations Toolkit explains tools in 12 categories with checked descriptions. Use the OSINT Framework as a directory once you know what you need. Practice on your own digital footprint or public challenges rather than on private individuals, and learn the legal limits early.
Do free online OSINT search engines keep a record of what I search for, and could that alert the person or company I'm looking into?
Some do, so read each service's privacy terms before entering sensitive identifiers. Public urlscan.io scans, for example, are visible to anyone, and uploaded images are shared with the provider. Tools that log in with your accounts, such as GHunt, act as you. Targets rarely see a lookup directly, but self-hosted, open-source tools run from a separate research environment reduce the trail you leave.
Sources and Notes
- Sherlock repository (GitHub)
- Sherlock on PyPI
- Maigret repository (GitHub)
- Maigret on PyPI
- WhatsMyName repository (GitHub)
- Blackbird repository (GitHub)
- Holehe on PyPI
- GHunt repository (GitHub)
- GHunt on PyPI
- PhoneInfoga repository (GitHub)
- theHarvester repository (GitHub)
- SpiderFoot repository (GitHub)
- Recon-ng repository (GitHub)
- Shodan: pricing
- Censys: pricing
- urlscan.io: pricing
- GOV.UK: get information about a company
- SEC: EDGAR full-text search
- ICIJ Offshore Leaks Database
- OpenCorporates: plans and pricing
- OpenSanctions: licensing
- TinEye: is TinEye free to use?
- TinEye: search limits
- WeVerify: InVID-WeVerify verification plugin
- ExifTool by Phil Harvey
- Copernicus Data Space Ecosystem: about
- Have I Been Pwned: subscriptions
- Intelligence X: product and pricing
- Ahmia: about
- Internet Archive: using the Wayback Machine
- Webrecorder: ArchiveWeb.page
- Auto Archiver on PyPI
- changedetection.io on PyPI
- Gephi
- ShadowBroker repository (GitHub)
- Osiris repository (GitHub)
- Hunchly: pricing
- Maltego: pricing
- Epieos: pricing
- OSINT Industries: pricing
- Osintgram repository (GitHub)
- OSINT Framework repository (GitHub)
- Bellingcat: Online Investigations Toolkit
- OSINT Dojo
- GDPR Article 14
Sources checked 10 October 2026. Licenses, release dates and free-tier limits are as published by each project or vendor on that date. OSINT-S has not run independent tests of these tools and has no affiliation with any project or vendor listed. This page is a catalog, not a ranking.