OSINT Tools: Free and Paid Tools by Investigation Task
OSINT tools are the search engines, scripts, databases and platforms investigators use to collect and verify publicly available information. This catalog groups them by the job you need done, from a username or an email address to a company, a domain, a photo or a leak, and shows what is free, what is paid and where the legal limits sit.
- Grouped by investigation task
- Free and paid options side by side
- Prices and licenses checked 10 October 2026
- Legal and OPSEC cautions for each task
OSINT tools fall into ten task groups: people and usernames, emails and phones, companies and ownership, domains and infrastructure, images and geolocation, social media, dark web and leaks, link analysis, capture and evidence, and monitoring. No single tool covers all of them. Most investigators combine free open-source scripts and public registries with one or two paid platforms, then verify every result by hand.
What Are OSINT Tools?
Software and services that find, collect, organize or preserve publicly and commercially available information so an analyst can answer a specific question.
The US intelligence community defines open-source intelligence as intelligence derived exclusively from publicly or commercially available information that addresses specific requirements (IC OSINT Strategy 2024–2026). The tools are the collection and analysis layer under that definition. They do not decide what is relevant, true or lawful to use; the analyst does.
In practice, OSINT investigation tools come in five forms: lookup scripts that check one identifier against hundreds of sites, public registries and databases, recon frameworks that chain data sources, commercial platforms with licensed data and sales-led pricing, and analysis and capture software for link charts, evidence and alerts.
Tool directories such as the OSINT Framework and Bellingcat's Online Investigations Toolkit list hundreds of resources. This page is narrower: a working OSINT toolkit by task, with representative tools in each group and links to our individual reviews in the OSINT tool reviews hub. If you only want zero-cost options, see the separate guide to free OSINT tools.
OSINT Tools List at a Glance
Ten investigation tasks, each with free and paid options; the right mix depends on the question, the jurisdiction and how the result will be used.
| Task | Free or open-source examples | Paid examples |
|---|---|---|
| People and usernames | Sherlock, Maigret, WhatsMyName, Blackbird | OSINT Industries, Opsis, Pipl, Skopenow |
| Emails and phones | Holehe, GHunt, PhoneInfoga, Epieos free plan | OSINT Industries, Epieos Osinter |
| Companies and ownership | Companies House, SEC EDGAR, ICIJ Offshore Leaks, OpenSanctions (non-commercial) | OpenCorporates API, OSINT Combine, Babel Street |
| Domains and infrastructure | theHarvester, SpiderFoot, Recon-ng, Shodan and Censys free tiers | Shodan and Censys paid plans, urlscan.io |
| Images and geolocation | TinEye (non-commercial), InVID-WeVerify, ExifTool, Copernicus Browser | TinEye API |
| Social media | Osintgram (with serious caveats) | Social Links, ShadowDragon, Babel Street, OSINT Combine |
| Dark web and leaks | Ahmia, Have I Been Pwned search, Intelligence X free tier | Intelligence X, Liferaft |
| Link analysis | Gephi, Maltego Basic | Maltego, Lampyre, ShadowDragon Horizon, Cognyte |
| Capture and evidence | ArchiveWeb.page, Auto Archiver, Wayback Machine | Hunchly, Maltego Evidence |
| Monitoring and alerts | Google Alerts, changedetection.io, ShadowBroker, Osiris | Liferaft, ShadowDragon Horizon Monitor, Maltego Monitor |
People and Username Search Tools
Username tools check whether a handle exists on hundreds of sites; people-search platforms add licensed records and identity resolution, at a price.
People often reuse a handle across sites. Username checkers query each site and report where a profile appears to exist; paid platforms resolve emails, phones and names into one identity using data free scripts cannot reach.
| Tool | What it does | Cost model (checked 10 October 2026) |
|---|---|---|
| Sherlock | Command-line search for one username across 400+ social networks (repository) | Free, MIT license |
| Maigret | Checks 3,000+ sites (500 by default), searches recursively and exports reports (repository) | Free, MIT license |
| WhatsMyName | Community dataset of 700+ sites with a free web interface (repository) | Free, CC BY-SA 4.0 data |
| Blackbird | Username and email account search built on WhatsMyName data (repository) | Free, Python |
| Opsis | Web platform for username, email and domain lookups (Opsis) | $14.99 to $49.99 a month for 25 to 150 searches |
| OSINT Industries | Email, phone, username, name and crypto wallet searches (pricing) | £19 to £99 a month; no free plan |
Enterprise identity platforms such as Pipl (identity resolution for fraud and investigations teams, pricing not public) and Skopenow (entity reports and link analysis for qualified organizations, free trial, pricing via sales) sit at the top of this category.
Caution. A matching username is a lead, not an identity. Common handles produce false positives, and a missing result does not prove an account does not exist. If the search supports a hiring or tenancy decision in the US, consumer reporting rules may apply (see legal limits). For a verified answer, see our username investigation service.
Email and Phone Number Lookup Tools
Email and phone tools show which services an identifier is registered with and whether it appears in known breaches; results are signals that need corroboration.
| Tool | What it does | Cost model (checked 10 October 2026) |
|---|---|---|
| Holehe | Checks whether an email is registered on sites via password-recovery flows; last PyPI release July 2022 (PyPI) | Free, GPL-3.0 |
| GHunt | Google account framework that logs in with your own Google session cookies (repository) | Free, AGPL-3.0 |
| Epieos | Email and phone lookups; the free Member plan has limited modules and a heavy watermark (pricing) | Free plan; Osinter €29.99 a month |
| PhoneInfoga | Information-gathering framework for phone numbers; the README says it is stable but unmaintained (repository) | Free, GPL-3.0 |
| Have I Been Pwned | Shows which known breaches include an email address (subscription page) | Free browser search; API from $52.68 a year |
OSINT Industries, listed above, is the common paid option for email and phone pivots. Caution. Tools that probe password-recovery pages or reuse your logged-in session interact with live services, so platform terms and rate limits apply, and the session belongs to you. Never use a client's or subject's credentials. Our email address and phone number investigations explain what a verified check covers.
Company, Ownership and Sanctions Research Tools
Official registries and open datasets are the backbone of company research; paid tools add coverage, history, matching and alerts.
| Tool | What it does | Cost model (checked 10 October 2026) |
|---|---|---|
| Companies House (UK) | Company details, current and resigned officers, filed documents, charges and insolvency information (GOV.UK) | Free to search |
| SEC EDGAR full-text search | Full text of US electronic filings since 2001 (SEC) | Free public tool |
| ICIJ Offshore Leaks Database | More than 810,000 offshore companies, foundations and trusts from five leak investigations (ICIJ) | Free, open license with attribution |
| OpenCorporates | Company records from 140+ jurisdictions; free at-scale access on request for journalists, NGOs and universities (pricing) | API from £2,250 a year |
| OpenSanctions | Consolidated sanctions, PEP and watchlist data under CC BY-NC 4.0 (licensing) | Free for non-commercial use; commercial license quoted |
| OSINT Combine | NexusXplore platform with company data, sanctions search and other modules (OSINT Combine) | Pricing not public |
Commercial risk platforms such as Babel Street add multilingual identity matching and vendor risk intelligence (Babel Street). Caution. Registry coverage and ownership disclosure vary widely by country, and a name in a leak database is not evidence of wrongdoing. Commercial use of non-commercial datasets breaches their license. For ownership questions that registries do not answer, see company investigations and due diligence.
OSINT Tools for Domains and Internet Infrastructure
Domain and infrastructure tools map subdomains, hosts, certificates, exposed services and page behavior, mostly through passive lookups.
| Tool | What it does | Cost model (checked 10 October 2026) |
|---|---|---|
| Shodan and Censys | Search engines for internet-connected devices. Every Shodan account gets a free API plan; membership is $49 once and monthly plans run $69 to $1,099 (Shodan). Censys offers a free account and sales-led plans, with credit packs from $100 (Censys) | Free tiers; paid plans |
| theHarvester | Collects emails, subdomains and hosts from search engines, certificate transparency logs, DNS datasets and code repositories; many sources need API keys (repository) | Free, GPL-2.0 |
| SpiderFoot | Automates collection for threat intelligence and attack surface mapping with 200+ modules; a managed edition, SpiderFoot HX, also exists (repository) | Free, MIT; HX paid |
| Recon-ng | Modular framework for web-based reconnaissance (repository) | Free, GPL-3.0 |
| urlscan.io | Scans and records what a URL loads; the free API plan allows 5,000 public scans a day (pricing) | Free API plan; paid from $5,000 a year |
Caution. Passive lookups read data others have already collected. Active scanning or vulnerability testing of systems you do not own requires written authorization. Public urlscan.io scans are visible to anyone, so never submit a URL that reveals your client or case. Related services: website and domain investigations and red team OSINT reconnaissance.
Image Verification and Geolocation Tools
Reverse image search, metadata readers, video verification plugins and satellite imagery let an analyst test where and when a photo or video was taken.
| Tool | What it does | Cost model (checked 10 October 2026) |
|---|---|---|
| TinEye | Reverse image search; free non-commercial use is limited to 100 searches a day and 300 a week (TinEye help) | Free for non-commercial use; commercial use via API |
| InVID-WeVerify plugin | Browser extension maintained by AFP Medialab with forensic filters, similarity search and OCR; some advanced tools are reserved for registered journalists and fact-checkers (WeVerify) | Free download |
| ExifTool | Reads and writes EXIF, GPS, IPTC and XMP metadata in many file types; version 13.59 was released 27 May 2026 (ExifTool) | Free software |
| Copernicus Browser | View, compare and download Sentinel satellite imagery (Copernicus Data Space) | Free for individual use |
Caution. Uploading a sensitive image to an online service shares it with that service. Face-search services raise separate privacy and biometric-data issues and are outside this catalog. When an image is evidence in a dispute or a news decision, see geolocation verification and image and video verification.
Dark Web and Data Leak Search Tools
Leak and dark web search tools index paste sites, breach data and Tor services so you can see whether an identifier or company has been exposed.
| Tool | What it does | Cost model (checked 10 October 2026) |
|---|---|---|
| Intelligence X | Searches paste sites, darknet services on Tor and I2P, data leaks, WHOIS data and the public web by selector. Two searches a day without login, 50 a day with a free account; Researcher €2,500 and Enterprise €20,000 a year (pricing) | Free tier; paid plans |
| Have I Been Pwned | Breach exposure for an email address (subscription page) | Free browser search; paid API |
| Ahmia | Search engine for Tor onion services; free and open source, with a blocklist for abuse material (Ahmia) | Free |
| Liferaft | Threat monitoring platform drawing on social media, surface, deep and dark web sources, with alerts and case dossiers (Liferaft) | Pricing not public |
Caution. Never buy stolen data or log in with leaked credentials. Minimize and secure any leaked personal data you handle, and expect malware and scams on dark web sites. For ongoing coverage see dark web monitoring and leaked credential monitoring.
Link Analysis and Case Management Software
Link analysis tools turn hundreds of findings into a graph of people, companies, accounts and infrastructure, so connections and gaps become visible.
| Tool | What it does | Cost model (checked 10 October 2026) |
|---|---|---|
| Maltego | Graph link analysis with 100+ data connectors. Basic is free with 200 credits; Entry €3,000 and Professional €7,500 a year; Enterprise via sales (pricing) | Free tier; paid plans |
| Lampyre | Table, map and graph analysis with 100+ data requests, paid in credits called Photons; a one-month trial costs $5 and desktop plans start at $116 a month (pricing) | Paid, credit-based |
| Cognyte | Investigative and threat analytics sold to governments and enterprises for national security and criminal investigations (Cognyte) | Pricing not public |
ShadowDragon Horizon and Skopenow, covered above, also include link analysis modules. A graph is only as good as its inputs: record the source and date of every node, and keep unverified links visually distinct from confirmed ones.
Web Capture and Evidence Preservation Tools
Capture tools save what you saw, with the URL, time and page content, so a finding can be checked and defended after the page changes or disappears.
| Tool | What it does | Cost model (checked 10 October 2026) |
|---|---|---|
| Hunchly | Captures every page you visit during an investigation, with metadata, stored on your own computer; Classic costs $169 or €149 a year after a 30-day trial (pricing). Maltego Entry and higher plans include it | Paid, free trial |
| ArchiveWeb.page | Webrecorder's Chromium extension and desktop app that archive pages as you browse and export WARC or WACZ files (Webrecorder) | Free, AGPL-3.0 |
| Auto Archiver | Bellingcat's open-source tool for archiving online posts and media in bulk; version 1.2.9 was released 1 September 2026 (PyPI) | Free, MIT |
| Wayback Machine | Save Page Now stores a single page in the Internet Archive and lets anyone view it later (Internet Archive help) | Free |
The Berkeley Protocol on Digital Open Source Investigations sets out preservation and documentation practices used by international investigators. When captured posts may go to court, see social media evidence capture.
OSINT Monitoring and Alerting Tools
Monitoring tools repeat searches on a schedule and alert you to new mentions, page changes or events, from free alerts to analyst-grade platforms.
| Tool | What it does | Cost model (checked 10 October 2026) |
|---|---|---|
| changedetection.io | Self-hosted monitoring of web page changes; version 0.60.8 released 28 September 2026 (PyPI) | Free, Apache 2.0; hosted option |
| ShadowBroker | Self-hosted map dashboard with 40+ public data layers such as aircraft, ships, earthquakes and fires (repository) | Free, AGPL-3.0 |
| Osiris | Open-source situational awareness dashboard combining flight tracking, seismic data, news and a recon toolkit (repository) | Free, MIT |
| Liferaft | Threat monitoring with custom alerts for protective intelligence teams (Liferaft) | Pricing not public |
ShadowDragon Horizon Monitor and Maltego Monitor (Enterprise plan) also fit here. Caution. The recon toolkits bundled with some dashboards can scan ports and vulnerabilities; use them only on systems you are authorized to test. For alerts reviewed by analysts, see OSINT monitoring.
How to Choose OSINT Investigation Tools
Start from the question and the jurisdiction, then compare coverage, total cost, maintenance and data handling before you buy anything.
- Write the question firstOwnership questions need registries and sanctions data; account attribution needs username, email and social tools.
- Check coverage for your jurisdictionsAsk vendors which countries and platforms they cover, and test known cases during a trial.
- Count the full costAdd credits, seats, API add-ons and analyst time; a free script that needs a day of fixes is not free.
- Check maintenanceCheck the last release and open issues; scripts break quietly when sites change.
- Read the terms and data handlingConfirm where searches and results are stored, whether commercial use is allowed and what the license requires.
Building an OSINT Workflow, Step by Step
Good workflows move from requirements to collection, verification, capture, analysis and a sourced report, with one tool per job.
- Set requirements and a lawful purposeRecord what you need to know, why, and your legal basis.
- Prepare a clean environmentUse a dedicated browser profile or virtual machine and turn on capture before you start.
- Collect broadly, then narrowRun identifier lookups and registry searches, then follow only the leads that answer the question.
- Verify with a second sourceConfirm each key finding through an independent source.
- Capture and logSave pages, timestamps and URLs as you go, with notes on how each item was found.
- Analyze connectionsChart people, companies and accounts, marking confirmed and inferred links.
- Report with sourcesState findings, confidence and limits, and cite every source so a reader can check the work.
OPSEC Basics for Online Investigators
Keep your identity, your client and your case out of the tools you use, and assume every lookup leaves a trace somewhere.
- Separate identities. Never research from personal social accounts. Some platforms show profile visitors, and logged-in tools act as you.
- Mind what online tools keep. Search terms, images and URLs may be stored or published by the service.
- Isolate unknown code. Run community scripts in a virtual machine or container, installed from the official repository.
- Protect the results. Encrypt case files, restrict access and delete what you no longer need.
- Use managed attribution where the risk justifies it. Commercial platforms offer it for sensitive research; a VPN alone does not hide behavior patterns.
Legal Limits No Tool Removes
Public does not mean free to use for any purpose: data protection, consumer reporting, platform terms and computer misuse laws still apply.
- Data protection. Under the GDPR, organizations that collect personal data from sources other than the person must generally tell that person, subject to exceptions (Article 14 GDPR). Have a legitimate purpose and keep only what you need.
- Employment and tenancy screening in the US. Information compiled by a third party for hiring decisions can be a consumer report under the Fair Credit Reporting Act, with notice and consent duties for the employer (FTC guidance).
- Platform terms and scraping. Regulators expect platforms to protect public personal data against unlawful scraping (joint statement).
- No intrusion. No hacking, no pretexting, no fake profiles to reach private content, no purchase of stolen data, and no locating people without a lawful purpose. Tools do not change any of these rules.
When to Hire Investigators Instead of Buying Tools
Hire help when the stakes are high, the subject spans several countries, the result must stand up in court or nobody has time to verify what tools produce.
Tools collect; people verify and decide. A team that runs one investigation a quarter rarely recovers the cost of licenses, training and upkeep. Outsourcing makes sense when a deal, a hire, a dispute or a threat depends on the answer and false positives would be expensive.
OSINT-S uses many of the tools above alongside licensed sources and manual research, with a senior analyst review before reporting. Focused checks start from 10 business days, comprehensive work can take up to about a month, and urgent delivery carries a 50% surcharge. Each engagement has a fixed quote after written scoping. Compare OSINT investigations, hiring an OSINT investigator and working with an OSINT agency, or see all of our OSINT services.
Need the Answer, Not Another Tool?
Tell us the question, the subject and the deadline. We scope it in writing, run the checks lawfully and return a sourced report.
OSINT Tools FAQ
I'm putting together a list of OSINT tools for a new three-person corporate investigations team — which ones should we start with, and roughly what should we budget for the first year?
Start with free registries and open-source scripts for each task, then add capture software and one or two paid platforms that match your usual cases. On 10 October 2026, Hunchly Classic cost $169 a year, OSINT Industries £19 to £99 a month, and Maltego ran from a free Basic plan to €7,500 a year for Professional. Budget for analyst training and time too; that is where most of the cost sits.
I keep seeing people argue about which OSINT tool is the best for 2026 — is there actually one tool that does everything, or do investigators always end up combining several?
No single tool covers every task, so investigators combine several. Username scripts, company registries, infrastructure search engines, reverse image search, capture software and link analysis each solve a different part of a case. Commercial platforms bundle more data but still leave gaps by country and platform. Pick tools by the question, not by popularity, and verify key findings with a second source.
I found a Python OSINT tool on GitHub that claims to find every account linked to an email address — is it safe to run on my work laptop, and can I trust what it reports?
Run it in an isolated virtual machine or container, not on your work laptop, and treat its output as leads. Install only from the official repository, check the last release date and open issues, and keep API keys out of shared folders. Tools that test password-recovery pages return false positives when sites change; Holehe's last PyPI release dates from July 2022. Confirm each account through a second source.
Our compliance team wants to screen counterparties for sanctions and adverse media with free OSINT tools — can open datasets replace a commercial screening database, or would we be taking a regulatory risk?
Open datasets help with research but rarely replace a commercial screening system for regulated onboarding. OpenSanctions data is licensed CC BY-NC 4.0, so commercial use needs a paid license, and free tools lack audit trails, tuned name matching and ongoing alerts. Use registries, leak databases and sanctions data to investigate hits and complex ownership, and document the process for your regulator.
I'm an HR manager and want to run a job candidate's username through a few search tools to see their online presence — are there legal limits I need to know about before I start?
Yes. In the US, information compiled by a third party for hiring decisions can be a consumer report under the Fair Credit Reporting Act, which requires disclosure, written authorization and adverse action notices. Under the GDPR you need a lawful basis and must generally inform the candidate. Username matches also produce false positives. Keep checks job-relevant and documented, or use a compliant background screening process.
We're a law firm and might have to put social media posts and web pages in front of a court — which tools help us capture them in a way that will hold up later?
Use capture tools that record the URL, time and full page content, and log how each item was found. Hunchly saves every page visited with metadata, ArchiveWeb.page exports WARC and WACZ archives, and Bellingcat's Auto Archiver preserves posts and media in bulk. The Berkeley Protocol describes preservation practices used by international investigators. Check authentication rules in your jurisdiction with your litigation team.
Our security team uses Shodan and a few recon scripts — is it legal for us to look up our suppliers' infrastructure with OSINT tools, or do we need their permission first?
Passive lookups in Shodan, Censys or certificate transparency logs read data that has already been collected and are generally used without the supplier's permission. Port scanning, vulnerability testing or login attempts against systems you do not own need written authorization. Agree the scope with the supplier, or stay with passive sources and share findings responsibly.
How do I keep my own identity hidden while using OSINT investigation tools, so the person or company I'm researching doesn't notice that I'm looking into them?
Separate your research identity from your personal one. Use a dedicated browser profile or virtual machine, never log in with personal accounts, and remember that some platforms show who viewed a profile. Check what online tools publish: public urlscan.io scans are visible to anyone. For sensitive work, managed attribution hides more than a VPN alone.
We bought an expensive link analysis license last year but nobody on the team has time to use it — when does it make more sense to hire an outside OSINT team instead of buying more tools?
Hire outside help when cases are occasional, high-stakes or cross-border, or when nobody has time to verify results. Licenses pay off only with trained analysts who use them every week. With OSINT-S, focused checks start from 10 business days, comprehensive work takes up to about a month, and each engagement has a fixed quote after written scoping.
Sources and Notes
- ODNI: IC OSINT Strategy 2024–2026
- Sherlock repository (GitHub)
- Maigret repository (GitHub)
- Opsis: plans
- OSINT Industries: pricing
- Holehe on PyPI
- GHunt repository (GitHub)
- PhoneInfoga repository (GitHub)
- Epieos: pricing
- Have I Been Pwned: subscriptions
- GOV.UK: get information about a company
- SEC: EDGAR full-text search
- ICIJ Offshore Leaks Database
- OpenCorporates: plans and pricing
- OpenSanctions: licensing
- OSINT Combine: NexusXplore
- Babel Street: platform
- Shodan: pricing
- Censys: pricing
- theHarvester repository (GitHub)
- SpiderFoot repository (GitHub)
- urlscan.io: pricing
- TinEye: search limits
- WeVerify: InVID-WeVerify verification plugin
- Social Links: products
- ShadowDragon: Horizon platform
- Osintgram repository (GitHub)
- Intelligence X: product and pricing
- Liferaft: platform
- Maltego: pricing
- Lampyre: pricing
- Gephi
- Hunchly: pricing
- Webrecorder: ArchiveWeb.page
- Google Alerts
- ShadowBroker repository (GitHub)
- Bellingcat: Online Investigations Toolkit
- OHCHR: Berkeley Protocol on Digital Open Source Investigations
- GDPR Article 14
- FTC: using consumer reports, what employers need to know
- ICO and partners: joint statement on data scraping (2023)
Sources checked 10 October 2026. Tool descriptions, licenses and prices are as published by the vendor or repository on that date. OSINT-S has not run independent tests of these tools, has no affiliation with any vendor and does not resell tools. This page is a catalog, not a ranking.
Social Media Investigation Tools
Commercial social media platforms search, collect and chart public posts and accounts at scale; free scripts exist but often depend on logged-in scraping.
Caution. Platforms restrict automated collection in their terms, and data protection regulators have told social media companies and scrapers that publicly accessible personal data is still protected (joint statement on data scraping, 2023). Do not create fake profiles to see private content. Our social media investigations work only with lawfully accessible material.