OSINT Tool Reviews

OSINT tool reviews written from each vendor's documentation, pricing pages and repositories: what the tool does, which data it draws on, what it costs, where it goes wrong and what to use instead. No scores, no affiliate links, no partnerships.

  • 30 reviews
  • Pricing checked on official pages
  • Limits and legal risks stated
  • No vendor affiliation
Short answer

These reviews cover username and email lookup tools, reconnaissance frameworks, internet-exposure search engines, link-analysis platforms, evidence capture and enterprise intelligence platforms. Each one is based on official documentation and pricing checked on the date shown, not on hands-on testing, and lists alternatives so you can compare.

All OSINT Tool Reviews

Open-source tools and commercial platforms, in one list. For a guide organized by investigation task, see the OSINT tools catalog.

Review

OSINT Industries

OSINT Industries reviewed from its official pages: search types, plans in GBP, free access, legal limits and alternatives.

Read more →
Review

Maltego

Maltego reviewed from official sources: link analysis, the free Community Edition, plans from €3,000 a year, limits and alternatives.

Read more →
Review

SpiderFoot

SpiderFoot reviewed from its repository and announcements: 200+ modules, MIT license, maintenance status, legal limits and alternatives.

Read more →
Review

WhatsMyName

The free, community-maintained username dataset behind whatsmyname.app: how its checks work, where they fail, and how to use them responsibly.

Read more →
Review

Maigret

The open-source username tool that parses profiles and searches recursively: what it adds over simple checkers, and the accuracy and privacy risks.

Read more →
Review

TheHarvester

Open-source recon tool that gathers emails, subdomains, hosts and names for a domain from public sources and APIs.

Read more →
Review

Sherlock

The open-source command-line tool that checks a username across 400+ sites: how detection works, its blind spots and when to use something else.

Read more →
Review

Epieos

Web-based reverse email and phone lookup: modules, free and paid plans, accuracy limits and GDPR questions, from vendor documentation.

Read more →
Review

Holehe

Free Python tool that checks whether an email is registered on 120+ sites: how it works, what it proves, maintenance and legal risks.

Read more →
Review

ShadowDragon

ShadowDragon Horizon and SocialNet reviewed: what the OSINT platform does, who buys it, pricing model, risks and alternatives.

Read more →
Review

Recon-ng

Open-source, modular reconnaissance framework with a Metasploit-style console, module marketplace and per-target workspaces.

Read more →
Review

Intelligence X

Intelligence X reviewed from its official pages: leak, darknet and archive search, plans from €2,500 a year, free tiers, legal limits.

Read more →
Review

Blackbird

The free command-line tool that runs WhatsMyName checks plus email lookups and an AI summary: what it does well and what to watch.

Read more →
Review

OSINT Combine

OSINT Combine review: the NexusXplore platform, training courses, free tools, the Kaseware merger, pricing signals and alternatives.

Read more →
Review

OSINT Dojo

OSINT Dojo reviewed as a learning resource: free ranks and badges, a large resource list, attack-surface diagrams and their limits.

Read more →
Review

Cognyte

Cognyte review: NEXYTE and the investigative analytics platform, who buys it, pricing, risks and how to get more from OSINT with it.

Read more →
Review

ShadowBroker

ShadowBroker, the self-hosted GitHub OSINT dashboard for flights, ships, satellites and cameras: features, data keys, license and legal limits.

Read more →
Review

Hunchly

Browser-based web capture tool that records, hashes and organizes every page an investigator visits, now part of Maltego.

Read more →
Review

Osiris

Osiris, the MIT-licensed OSINT dashboard for flights, satellites and CCTV: layers, recon toolkit, AI forecasts, costs and legal limits.

Read more →
Review

Opsis

Opsis, the web OSINT lookup service for usernames, emails and domains: features, pricing, data handling, terms and alternatives.

Read more →
Review

Liferaft

Liferaft review: the OSINT threat intelligence platform formerly marketed as Navigator, its features, pricing signals, the Securitas deal and alternatives.

Read more →
Review

Shodan and Censys

Search engines for internet-connected hosts, open ports, services and certificates, used for attack surface and threat research.

Read more →
Review

GHunt

Open-source Google account OSINT framework: modules, data returned, cookie-based login, account and terms risks, and alternatives.

Read more →
Review

Social Links

Social Links reviewed: SL Crimewall, SL API and the Maltego add-ons, data coverage, deployment, pricing model, risks and alternatives.

Read more →
Review

Babel Street (Babel X)

Babel X and Babel Street review: the multilingual risk intelligence platform, managed attribution, pricing signals, concerns and alternatives.

Read more →
Review

Skopenow

Skopenow reviewed: Workbench, Link Analysis, Grid and Pre-Check, data sources, FCRA limits, pricing evidence, risks and alternatives.

Read more →
Review

Pipl

Pipl reviewed: from people search engine to enterprise identity and fraud platform, Pipl Search API, FCRA limits, pricing evidence and alternatives.

Read more →
Review

Lampyre

Lampyre reviewed from its own documentation: Windows link-analysis client, web lookups, photon credits, pricing and data-source risks.

Read more →
Review

IntelBase

IntelBase reviewed from its own documentation: email and username lookups, breach and infostealer data, pricing, API and legal limits.

Read more →
Review

Osintgram

Open-source Instagram OSINT tool, rebuilt as a local web app: what it collects, data backends, Instagram terms, ban risk and legal limits.

Read more →

How We Write OSINT Tool Reviews

From primary sources, dated, with the limits and legal risks stated next to the features.

  • Primary sources first. Official sites, pricing pages, terms, repositories and package registries, linked on every page.
  • Dated. Prices and features change; every review says when it was checked.
  • No scores or rankings. The right tool depends on the task, the data you are allowed to process and your budget.
  • Limits included. False positives, coverage gaps, platform terms and data-protection risks are part of each review.

If you need a verified answer rather than a tool to learn, see our OSINT services or the OSINT investigations page.

Need the Answer, Not the Tool?

Send the question and the deadline. An analyst replies with a scope, a timeline and a fixed quote.

OSINT Tool Reviews: FAQ

I'm putting together a small OSINT toolkit for our fraud team on a limited budget — should I start with these tool reviews or with the catalog organized by investigation task?

Start with the catalog by task at /osint-tools/, which groups tools by what you need to find, such as emails, companies or domains, and shows free and paid options together. Then open the individual reviews for the shortlisted tools to check pricing, data sources, limits and legal risks before you buy or install anything.

Are these OSINT tool reviews sponsored or affiliated with any of the vendors, and how can I tell whether the information about pricing is still current?

No. OSINT-S has no affiliation, partnership or referral arrangement with any vendor reviewed, and we do not resell tools. Each review links to the official pricing page and shows the date it was checked. Prices and plans change often, so confirm on the vendor's site before buying.

We are a law firm and our IT team worries about installing open-source OSINT tools from GitHub on our network — do your reviews cover the security risks of running them?

Yes, where they apply. Reviews note the license, maintenance status and whether a tool needs logged-in sessions, API keys or cookies, and the free tools guide covers running unknown code safely, for example in an isolated virtual machine with a separate account. Your IT team should still review any tool before it touches client data.

If a tool can find someone's accounts or old passwords, is it legal for our company to use it, or could we get into trouble with data protection rules?

It depends on the purpose, the data and the jurisdiction. Under the GDPR and UK GDPR, public data is still personal data and processing needs a lawful basis that passes a balancing test. Some tools draw on breach data or break platform terms, which adds risk. Reviews flag these issues, but take legal advice before using such tools on real people.

Can you run one of these tools for us on a specific case instead of us buying a license and learning it ourselves?

We do not resell tools, but we can do the investigation. Email the question, the subject and the deadline to info@osint-s.com. An analyst chooses the sources and tools the case needs, verifies the findings and delivers a source-referenced report, with a fixed quote agreed before work starts.

Sources and Notes

Sources checked 10 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.

Related pages