OSINT Tools: Free and Paid Tools by Investigation Task

OSINT tools are the search engines, scripts, databases and platforms investigators use to collect and verify publicly available information. This catalog groups them by the job you need done, from a username or an email address to a company, a domain, a photo or a leak, and shows what is free, what is paid and where the legal limits sit.

  • Grouped by investigation task
  • Free and paid options side by side
  • Prices and licenses checked 10 October 2026
  • Legal and OPSEC cautions for each task

This is a catalog, not a ranking. It is based on vendor documentation, official pricing pages and public repositories, checked on 10 October 2026. OSINT-S has no affiliation with any vendor listed and does not resell tools.

Short answer

OSINT tools fall into ten task groups: people and usernames, emails and phones, companies and ownership, domains and infrastructure, images and geolocation, social media, dark web and leaks, link analysis, capture and evidence, and monitoring. No single tool covers all of them. Most investigators combine free open-source scripts and public registries with one or two paid platforms, then verify every result by hand.

What Are OSINT Tools?

Software and services that find, collect, organize or preserve publicly and commercially available information so an analyst can answer a specific question.

The US intelligence community defines open-source intelligence as intelligence derived exclusively from publicly or commercially available information that addresses specific requirements (IC OSINT Strategy 2024–2026). The tools are the collection and analysis layer under that definition. They do not decide what is relevant, true or lawful to use; the analyst does.

In practice, OSINT investigation tools come in five forms: lookup scripts that check one identifier against hundreds of sites, public registries and databases, recon frameworks that chain data sources, commercial platforms with licensed data and sales-led pricing, and analysis and capture software for link charts, evidence and alerts.

Tool directories such as the OSINT Framework and Bellingcat's Online Investigations Toolkit list hundreds of resources. This page is narrower: a working OSINT toolkit by task, with representative tools in each group and links to our individual reviews in the OSINT tool reviews hub. If you only want zero-cost options, see the separate guide to free OSINT tools.

OSINT Tools List at a Glance

Ten investigation tasks, each with free and paid options; the right mix depends on the question, the jurisdiction and how the result will be used.

TaskFree or open-source examplesPaid examples
People and usernamesSherlock, Maigret, WhatsMyName, BlackbirdOSINT Industries, Opsis, Pipl, Skopenow
Emails and phonesHolehe, GHunt, PhoneInfoga, Epieos free planOSINT Industries, Epieos Osinter
Companies and ownershipCompanies House, SEC EDGAR, ICIJ Offshore Leaks, OpenSanctions (non-commercial)OpenCorporates API, OSINT Combine, Babel Street
Domains and infrastructuretheHarvester, SpiderFoot, Recon-ng, Shodan and Censys free tiersShodan and Censys paid plans, urlscan.io
Images and geolocationTinEye (non-commercial), InVID-WeVerify, ExifTool, Copernicus BrowserTinEye API
Social mediaOsintgram (with serious caveats)Social Links, ShadowDragon, Babel Street, OSINT Combine
Dark web and leaksAhmia, Have I Been Pwned search, Intelligence X free tierIntelligence X, Liferaft
Link analysisGephi, Maltego BasicMaltego, Lampyre, ShadowDragon Horizon, Cognyte
Capture and evidenceArchiveWeb.page, Auto Archiver, Wayback MachineHunchly, Maltego Evidence
Monitoring and alertsGoogle Alerts, changedetection.io, ShadowBroker, OsirisLiferaft, ShadowDragon Horizon Monitor, Maltego Monitor

People and Username Search Tools

Username tools check whether a handle exists on hundreds of sites; people-search platforms add licensed records and identity resolution, at a price.

People often reuse a handle across sites. Username checkers query each site and report where a profile appears to exist; paid platforms resolve emails, phones and names into one identity using data free scripts cannot reach.

ToolWhat it doesCost model (checked 10 October 2026)
SherlockCommand-line search for one username across 400+ social networks (repository)Free, MIT license
MaigretChecks 3,000+ sites (500 by default), searches recursively and exports reports (repository)Free, MIT license
WhatsMyNameCommunity dataset of 700+ sites with a free web interface (repository)Free, CC BY-SA 4.0 data
BlackbirdUsername and email account search built on WhatsMyName data (repository)Free, Python
OpsisWeb platform for username, email and domain lookups (Opsis)$14.99 to $49.99 a month for 25 to 150 searches
OSINT IndustriesEmail, phone, username, name and crypto wallet searches (pricing)£19 to £99 a month; no free plan

Enterprise identity platforms such as Pipl (identity resolution for fraud and investigations teams, pricing not public) and Skopenow (entity reports and link analysis for qualified organizations, free trial, pricing via sales) sit at the top of this category.

Caution. A matching username is a lead, not an identity. Common handles produce false positives, and a missing result does not prove an account does not exist. If the search supports a hiring or tenancy decision in the US, consumer reporting rules may apply (see legal limits). For a verified answer, see our username investigation service.

Email and Phone Number Lookup Tools

Email and phone tools show which services an identifier is registered with and whether it appears in known breaches; results are signals that need corroboration.

ToolWhat it doesCost model (checked 10 October 2026)
HoleheChecks whether an email is registered on sites via password-recovery flows; last PyPI release July 2022 (PyPI)Free, GPL-3.0
GHuntGoogle account framework that logs in with your own Google session cookies (repository)Free, AGPL-3.0
EpieosEmail and phone lookups; the free Member plan has limited modules and a heavy watermark (pricing)Free plan; Osinter €29.99 a month
PhoneInfogaInformation-gathering framework for phone numbers; the README says it is stable but unmaintained (repository)Free, GPL-3.0
Have I Been PwnedShows which known breaches include an email address (subscription page)Free browser search; API from $52.68 a year

OSINT Industries, listed above, is the common paid option for email and phone pivots. Caution. Tools that probe password-recovery pages or reuse your logged-in session interact with live services, so platform terms and rate limits apply, and the session belongs to you. Never use a client's or subject's credentials. Our email address and phone number investigations explain what a verified check covers.

Company, Ownership and Sanctions Research Tools

Official registries and open datasets are the backbone of company research; paid tools add coverage, history, matching and alerts.

ToolWhat it doesCost model (checked 10 October 2026)
Companies House (UK)Company details, current and resigned officers, filed documents, charges and insolvency information (GOV.UK)Free to search
SEC EDGAR full-text searchFull text of US electronic filings since 2001 (SEC)Free public tool
ICIJ Offshore Leaks DatabaseMore than 810,000 offshore companies, foundations and trusts from five leak investigations (ICIJ)Free, open license with attribution
OpenCorporatesCompany records from 140+ jurisdictions; free at-scale access on request for journalists, NGOs and universities (pricing)API from £2,250 a year
OpenSanctionsConsolidated sanctions, PEP and watchlist data under CC BY-NC 4.0 (licensing)Free for non-commercial use; commercial license quoted
OSINT CombineNexusXplore platform with company data, sanctions search and other modules (OSINT Combine)Pricing not public

Commercial risk platforms such as Babel Street add multilingual identity matching and vendor risk intelligence (Babel Street). Caution. Registry coverage and ownership disclosure vary widely by country, and a name in a leak database is not evidence of wrongdoing. Commercial use of non-commercial datasets breaches their license. For ownership questions that registries do not answer, see company investigations and due diligence.

OSINT Tools for Domains and Internet Infrastructure

Domain and infrastructure tools map subdomains, hosts, certificates, exposed services and page behavior, mostly through passive lookups.

ToolWhat it doesCost model (checked 10 October 2026)
Shodan and CensysSearch engines for internet-connected devices. Every Shodan account gets a free API plan; membership is $49 once and monthly plans run $69 to $1,099 (Shodan). Censys offers a free account and sales-led plans, with credit packs from $100 (Censys)Free tiers; paid plans
theHarvesterCollects emails, subdomains and hosts from search engines, certificate transparency logs, DNS datasets and code repositories; many sources need API keys (repository)Free, GPL-2.0
SpiderFootAutomates collection for threat intelligence and attack surface mapping with 200+ modules; a managed edition, SpiderFoot HX, also exists (repository)Free, MIT; HX paid
Recon-ngModular framework for web-based reconnaissance (repository)Free, GPL-3.0
urlscan.ioScans and records what a URL loads; the free API plan allows 5,000 public scans a day (pricing)Free API plan; paid from $5,000 a year

Caution. Passive lookups read data others have already collected. Active scanning or vulnerability testing of systems you do not own requires written authorization. Public urlscan.io scans are visible to anyone, so never submit a URL that reveals your client or case. Related services: website and domain investigations and red team OSINT reconnaissance.

Image Verification and Geolocation Tools

Reverse image search, metadata readers, video verification plugins and satellite imagery let an analyst test where and when a photo or video was taken.

ToolWhat it doesCost model (checked 10 October 2026)
TinEyeReverse image search; free non-commercial use is limited to 100 searches a day and 300 a week (TinEye help)Free for non-commercial use; commercial use via API
InVID-WeVerify pluginBrowser extension maintained by AFP Medialab with forensic filters, similarity search and OCR; some advanced tools are reserved for registered journalists and fact-checkers (WeVerify)Free download
ExifToolReads and writes EXIF, GPS, IPTC and XMP metadata in many file types; version 13.59 was released 27 May 2026 (ExifTool)Free software
Copernicus BrowserView, compare and download Sentinel satellite imagery (Copernicus Data Space)Free for individual use

Caution. Uploading a sensitive image to an online service shares it with that service. Face-search services raise separate privacy and biometric-data issues and are outside this catalog. When an image is evidence in a dispute or a news decision, see geolocation verification and image and video verification.

Social Media Investigation Tools

Commercial social media platforms search, collect and chart public posts and accounts at scale; free scripts exist but often depend on logged-in scraping.

ToolWhat it doesCost model (checked 10 October 2026)
Social LinksSL Professional for Maltego, the SL Crimewall investigation platform and an API for in-house systems (Social Links)Pricing via sales
ShadowDragonHorizon platform with identity triage, link analysis and monitoring modules, plus the SocialNet API (ShadowDragon)Pricing not public
Babel StreetMultilingual data and AI-assisted analysis, with a managed attribution option for sensitive research (Babel Street)Pricing not public; demo or trial on request
OSINT CombineNexusXplore includes a Rich Social Media module alongside company, domain and dark web modules (OSINT Combine)Pricing not public
OsintgramInteractive shell for analyzing Instagram accounts; the README labels it for educational purposes and advises against using your primary account (repository)Free, GPL-3.0

Caution. Platforms restrict automated collection in their terms, and data protection regulators have told social media companies and scrapers that publicly accessible personal data is still protected (joint statement on data scraping, 2023). Do not create fake profiles to see private content. Our social media investigations work only with lawfully accessible material.

Dark Web and Data Leak Search Tools

Leak and dark web search tools index paste sites, breach data and Tor services so you can see whether an identifier or company has been exposed.

ToolWhat it doesCost model (checked 10 October 2026)
Intelligence XSearches paste sites, darknet services on Tor and I2P, data leaks, WHOIS data and the public web by selector. Two searches a day without login, 50 a day with a free account; Researcher €2,500 and Enterprise €20,000 a year (pricing)Free tier; paid plans
Have I Been PwnedBreach exposure for an email address (subscription page)Free browser search; paid API
AhmiaSearch engine for Tor onion services; free and open source, with a blocklist for abuse material (Ahmia)Free
LiferaftThreat monitoring platform drawing on social media, surface, deep and dark web sources, with alerts and case dossiers (Liferaft)Pricing not public

Caution. Never buy stolen data or log in with leaked credentials. Minimize and secure any leaked personal data you handle, and expect malware and scams on dark web sites. For ongoing coverage see dark web monitoring and leaked credential monitoring.

Web Capture and Evidence Preservation Tools

Capture tools save what you saw, with the URL, time and page content, so a finding can be checked and defended after the page changes or disappears.

ToolWhat it doesCost model (checked 10 October 2026)
HunchlyCaptures every page you visit during an investigation, with metadata, stored on your own computer; Classic costs $169 or €149 a year after a 30-day trial (pricing). Maltego Entry and higher plans include itPaid, free trial
ArchiveWeb.pageWebrecorder's Chromium extension and desktop app that archive pages as you browse and export WARC or WACZ files (Webrecorder)Free, AGPL-3.0
Auto ArchiverBellingcat's open-source tool for archiving online posts and media in bulk; version 1.2.9 was released 1 September 2026 (PyPI)Free, MIT
Wayback MachineSave Page Now stores a single page in the Internet Archive and lets anyone view it later (Internet Archive help)Free

The Berkeley Protocol on Digital Open Source Investigations sets out preservation and documentation practices used by international investigators. When captured posts may go to court, see social media evidence capture.

OSINT Monitoring and Alerting Tools

Monitoring tools repeat searches on a schedule and alert you to new mentions, page changes or events, from free alerts to analyst-grade platforms.

ToolWhat it doesCost model (checked 10 October 2026)
changedetection.ioSelf-hosted monitoring of web page changes; version 0.60.8 released 28 September 2026 (PyPI)Free, Apache 2.0; hosted option
ShadowBrokerSelf-hosted map dashboard with 40+ public data layers such as aircraft, ships, earthquakes and fires (repository)Free, AGPL-3.0
OsirisOpen-source situational awareness dashboard combining flight tracking, seismic data, news and a recon toolkit (repository)Free, MIT
LiferaftThreat monitoring with custom alerts for protective intelligence teams (Liferaft)Pricing not public

ShadowDragon Horizon Monitor and Maltego Monitor (Enterprise plan) also fit here. Caution. The recon toolkits bundled with some dashboards can scan ports and vulnerabilities; use them only on systems you are authorized to test. For alerts reviewed by analysts, see OSINT monitoring.

How to Choose OSINT Investigation Tools

Start from the question and the jurisdiction, then compare coverage, total cost, maintenance and data handling before you buy anything.

  1. Write the question firstOwnership questions need registries and sanctions data; account attribution needs username, email and social tools.
  2. Check coverage for your jurisdictionsAsk vendors which countries and platforms they cover, and test known cases during a trial.
  3. Count the full costAdd credits, seats, API add-ons and analyst time; a free script that needs a day of fixes is not free.
  4. Check maintenanceCheck the last release and open issues; scripts break quietly when sites change.
  5. Read the terms and data handlingConfirm where searches and results are stored, whether commercial use is allowed and what the license requires.

Building an OSINT Workflow, Step by Step

Good workflows move from requirements to collection, verification, capture, analysis and a sourced report, with one tool per job.

  1. Set requirements and a lawful purposeRecord what you need to know, why, and your legal basis.
  2. Prepare a clean environmentUse a dedicated browser profile or virtual machine and turn on capture before you start.
  3. Collect broadly, then narrowRun identifier lookups and registry searches, then follow only the leads that answer the question.
  4. Verify with a second sourceConfirm each key finding through an independent source.
  5. Capture and logSave pages, timestamps and URLs as you go, with notes on how each item was found.
  6. Analyze connectionsChart people, companies and accounts, marking confirmed and inferred links.
  7. Report with sourcesState findings, confidence and limits, and cite every source so a reader can check the work.

OPSEC Basics for Online Investigators

Keep your identity, your client and your case out of the tools you use, and assume every lookup leaves a trace somewhere.

  • Separate identities. Never research from personal social accounts. Some platforms show profile visitors, and logged-in tools act as you.
  • Mind what online tools keep. Search terms, images and URLs may be stored or published by the service.
  • Isolate unknown code. Run community scripts in a virtual machine or container, installed from the official repository.
  • Protect the results. Encrypt case files, restrict access and delete what you no longer need.
  • Use managed attribution where the risk justifies it. Commercial platforms offer it for sensitive research; a VPN alone does not hide behavior patterns.

When to Hire Investigators Instead of Buying Tools

Hire help when the stakes are high, the subject spans several countries, the result must stand up in court or nobody has time to verify what tools produce.

Tools collect; people verify and decide. A team that runs one investigation a quarter rarely recovers the cost of licenses, training and upkeep. Outsourcing makes sense when a deal, a hire, a dispute or a threat depends on the answer and false positives would be expensive.

OSINT-S uses many of the tools above alongside licensed sources and manual research, with a senior analyst review before reporting. Focused checks start from 10 business days, comprehensive work can take up to about a month, and urgent delivery carries a 50% surcharge. Each engagement has a fixed quote after written scoping. Compare OSINT investigations, hiring an OSINT investigator and working with an OSINT agency, or see all of our OSINT services.

Need the Answer, Not Another Tool?

Tell us the question, the subject and the deadline. We scope it in writing, run the checks lawfully and return a sourced report.

OSINT Tools FAQ

I'm putting together a list of OSINT tools for a new three-person corporate investigations team — which ones should we start with, and roughly what should we budget for the first year?

Start with free registries and open-source scripts for each task, then add capture software and one or two paid platforms that match your usual cases. On 10 October 2026, Hunchly Classic cost $169 a year, OSINT Industries £19 to £99 a month, and Maltego ran from a free Basic plan to €7,500 a year for Professional. Budget for analyst training and time too; that is where most of the cost sits.

I keep seeing people argue about which OSINT tool is the best for 2026 — is there actually one tool that does everything, or do investigators always end up combining several?

No single tool covers every task, so investigators combine several. Username scripts, company registries, infrastructure search engines, reverse image search, capture software and link analysis each solve a different part of a case. Commercial platforms bundle more data but still leave gaps by country and platform. Pick tools by the question, not by popularity, and verify key findings with a second source.

I found a Python OSINT tool on GitHub that claims to find every account linked to an email address — is it safe to run on my work laptop, and can I trust what it reports?

Run it in an isolated virtual machine or container, not on your work laptop, and treat its output as leads. Install only from the official repository, check the last release date and open issues, and keep API keys out of shared folders. Tools that test password-recovery pages return false positives when sites change; Holehe's last PyPI release dates from July 2022. Confirm each account through a second source.

Our compliance team wants to screen counterparties for sanctions and adverse media with free OSINT tools — can open datasets replace a commercial screening database, or would we be taking a regulatory risk?

Open datasets help with research but rarely replace a commercial screening system for regulated onboarding. OpenSanctions data is licensed CC BY-NC 4.0, so commercial use needs a paid license, and free tools lack audit trails, tuned name matching and ongoing alerts. Use registries, leak databases and sanctions data to investigate hits and complex ownership, and document the process for your regulator.

I'm an HR manager and want to run a job candidate's username through a few search tools to see their online presence — are there legal limits I need to know about before I start?

Yes. In the US, information compiled by a third party for hiring decisions can be a consumer report under the Fair Credit Reporting Act, which requires disclosure, written authorization and adverse action notices. Under the GDPR you need a lawful basis and must generally inform the candidate. Username matches also produce false positives. Keep checks job-relevant and documented, or use a compliant background screening process.

We're a law firm and might have to put social media posts and web pages in front of a court — which tools help us capture them in a way that will hold up later?

Use capture tools that record the URL, time and full page content, and log how each item was found. Hunchly saves every page visited with metadata, ArchiveWeb.page exports WARC and WACZ archives, and Bellingcat's Auto Archiver preserves posts and media in bulk. The Berkeley Protocol describes preservation practices used by international investigators. Check authentication rules in your jurisdiction with your litigation team.

Our security team uses Shodan and a few recon scripts — is it legal for us to look up our suppliers' infrastructure with OSINT tools, or do we need their permission first?

Passive lookups in Shodan, Censys or certificate transparency logs read data that has already been collected and are generally used without the supplier's permission. Port scanning, vulnerability testing or login attempts against systems you do not own need written authorization. Agree the scope with the supplier, or stay with passive sources and share findings responsibly.

How do I keep my own identity hidden while using OSINT investigation tools, so the person or company I'm researching doesn't notice that I'm looking into them?

Separate your research identity from your personal one. Use a dedicated browser profile or virtual machine, never log in with personal accounts, and remember that some platforms show who viewed a profile. Check what online tools publish: public urlscan.io scans are visible to anyone. For sensitive work, managed attribution hides more than a VPN alone.

We bought an expensive link analysis license last year but nobody on the team has time to use it — when does it make more sense to hire an outside OSINT team instead of buying more tools?

Hire outside help when cases are occasional, high-stakes or cross-border, or when nobody has time to verify results. Licenses pay off only with trained analysts who use them every week. With OSINT-S, focused checks start from 10 business days, comprehensive work takes up to about a month, and each engagement has a fixed quote after written scoping.

Sources and Notes

Sources checked 10 October 2026. Tool descriptions, licenses and prices are as published by the vendor or repository on that date. OSINT-S has not run independent tests of these tools, has no affiliation with any vendor and does not resell tools. This page is a catalog, not a ranking.

Related pages