SpiderFoot OSINT Review: Open-Source Automation, Features and Alternatives

SpiderFoot OSINT automation takes one target, such as a domain, IP address, email or username, and runs it through more than 200 modules to collect what is publicly known about it. This review covers what the open-source tool does, how current it is, who owns it now and where it needs care.

  • MIT-licensed, written in Python
  • 200+ modules, 37 correlation rules
  • Web UI and command line
  • No affiliation with the vendor

Based on the official GitHub repository, release notes and vendor announcements, checked 10 October 2026. No scores, no affiliate links.

Short answer

SpiderFoot is a free, MIT-licensed OSINT automation tool written in Python. You give it a target and it queries 200+ modules, then flags notable findings with YAML correlation rules. It suits security teams mapping an organization's external exposure. The last tagged release is v4.0 from April 2022; the commercial SpiderFoot HX belongs to Intel 471 since 2022.

What Is SpiderFoot OSINT Automation?

An open-source reconnaissance tool that automates the collection of public data about a target and links the results.

SpiderFoot was created by Steve Micallef and is published on GitHub, where the repository describes it as MIT-licensed, written in Python 3, with over 200 modules, a web interface and a command-line mode (GitHub). It is also packaged in Kali Linux, which lists version 4.0 (Kali tools).

It can be used offensively, to see what an attacker would find before a penetration test, or defensively, to audit what an organization exposes. In our guide to OSINT tools it sits under domains and infrastructure.

Key Features: Modules, Correlations and Exports

Modules collect data, correlation rules flag what matters, and results export to CSV, JSON or GEXF for graph tools.

Collection

200+ modules

Most modules need no API key, and many that do have a free tier, according to the README.

Analysis

Correlation engine

Added to the open-source version in 4.0, with 37 predefined YAML rules and support for your own (release notes).

Interface

Web UI and CLI

An embedded web server for browsing scans, or fully command-line runs for scripting.

Export

CSV, JSON, GEXF

GEXF output opens in graph tools, so results can move into link analysis.

Tools

Integrated scanners

Version 4.0 added modules for tools such as Nuclei, nbtscan, TruffleHog and Wappalyzer.

Deploy

Docker and Tor

Dockerfiles for container deployment and Tor integration for dark web searches.

What SpiderFoot Scans: Targets and Data Sources

Ten target types, from IP ranges and domains to emails, phone numbers, usernames, names and Bitcoin addresses.

The README lists these target types: IP address, domain or subdomain, hostname, network subnet (CIDR), ASN, email address, phone number, username, person's name and Bitcoin address (GitHub). Sources range from DNS and certificate data to search engines, breach services and threat lists. Some, such as Shodan, Censys and Intelligence X, are marked as tiered APIs; Have I Been Pwned is marked commercial.

Coverage therefore depends on which API keys you add. A scan with no keys is useful for infrastructure; people-related findings get thin without paid sources.

SpiderFoot Pricing, License and SpiderFoot HX

The open-source tool is free under the MIT license; API keys for third-party sources may cost money, and the commercial HX edition's current availability is unclear.

EditionPriceStatus on 10 October 2026
SpiderFoot (open source)Free, MIT licenseOn GitHub; last tagged release v4.0
Third-party API keysFree tiers to paid plansSet by each data provider
SpiderFoot HX (cloud)Not publicStill promoted in the README; spiderfoot.net now redirects to Intel 471

Intel 471 announced the acquisition of SpiderFoot on 2 November 2022 and said it would integrate SpiderFoot's capabilities into its own platform; the founder joined as Vice President of Attack Surface Technology (Intel 471). We could not confirm a current public price or sign-up page for HX, so ask Intel 471 directly.

Installation and Maintenance Status

Install from the official GitHub repository or Kali package; the project still receives commits, but no tagged release has followed v4.0 from April 2022.

The README requires Python 3.7 or later and installs dependencies from requirements.txt; Dockerfiles are included. The v4.0 release, announced in April 2022, is still marked as the latest, and the release page shows 138 commits to master since then (release page). That means fixes land in the main branch without a new version number, so pin a commit and test before upgrading.

One supply-chain warning: the package named spiderfoot on PyPI is a placeholder that PyPI quarantined in September 2026, not the official project (PyPI). Do not install SpiderFoot by name from PyPI.

Who It Suits and Who It Does Not

It suits technical teams auditing their own exposure; it is a poor fit for non-technical users or people searches.

Good fitPoor fit
Security teams mapping their organization's attack surfaceUsers who need a finished report rather than raw scan data
Authorized penetration testers and red teams in the reconnaissance phaseBackground checks on individuals, which need a lawful process
Analysts who can run Python or Docker and manage API keysTeams that need vendor support and a release schedule

Limitations and Legal Risks of Automated OSINT Scans

Automated scans produce noise and false positives, some modules touch the target directly, and scanning assets you do not own needs authorization.

  • Active modules. Integrated tools such as Nuclei and nbtscan probe the target rather than only reading public data. Run them only against assets you own or are authorized in writing to test; unauthorized scanning can breach computer misuse laws and hosting terms.
  • Noise. Hundreds of modules return thousands of data points. Correlation rules help, but an analyst must still decide what is relevant and true.
  • Personal data. Email, name and phone scans collect personal data; under the GDPR you need a legitimate purpose and should keep only what you need.
  • Release cadence. No tagged release since 2022 means modules for changed APIs may break.

SpiderFoot Alternatives for OSINT Automation

Recon-ng and theHarvester are open-source alternatives; Maltego adds link analysis; Shodan and Censys provide internet-wide scan data.

Open source

Recon-ng

GPL-3.0 reconnaissance framework for web-based information gathering, built around modules (GitHub).

Recon-ng review →
Open source

theHarvester

Python tool that gathers hostnames, emails, IPs and URLs for a domain from search engines, certificate logs and DNS data (GitHub).

theHarvester review →
Link analysis

Maltego

Graph-based investigation platform with a free Community Edition and paid plans from €3,000 a year.

Maltego review →
Internet scans

Shodan and Censys

Search engines for internet-connected hosts and services, also available as SpiderFoot modules.

Shodan and Censys review →

Need the Answer, Not the Tool?

If you need a reviewed picture of your external exposure rather than raw scan output, an analyst-led review is the faster route.

A SpiderFoot scan lists what is out there; a security decision needs to know which findings matter and what to fix first. Our red team OSINT reconnaissance runs under written authorization, and an organizational OSINT exposure audit turns findings into a prioritized list. For a single site, see website and domain investigations.

Every report gets a senior analyst review, with a fixed quote after written scoping. See our OSINT services for the full range.

Get an External Exposure Review

Tell us your domains, the scope you are authorized to test and your deadline. We scope it in writing and quote a fixed fee.

SpiderFoot OSINT FAQ

Our IT manager suggested SpiderFoot OSINT scans to see what attackers can learn about our company — is it really free, and what does it need to run?

Yes, the open-source SpiderFoot is free under the MIT license. It needs Python 3.7 or later, or Docker, and runs from a web interface or the command line (GitHub). Many of its 200+ modules work without API keys, but richer results depend on third-party keys, some paid. Install it from the official GitHub repository or the Kali package, not from a package named spiderfoot on PyPI.

I read that SpiderFoot hasn't had a release since 2022 — is the open-source project still maintained, and is it safe to rely on for our security audits?

The latest tagged release is still v4.0 from April 2022, but the release page shows 138 commits to master since then, so work continues without new version numbers. For audits, pin a specific commit, test it in your environment and check that the modules you rely on still return data, since provider APIs change. Treat output as a starting point that an analyst reviews, not as an audit on its own.

What happened to SpiderFoot HX after the acquisition, and can my team still buy the hosted version instead of running the open-source tool ourselves?

Intel 471 announced its acquisition of SpiderFoot on 2 November 2022 and said it would fold SpiderFoot's capabilities into its own platform (Intel 471). The README still promotes SpiderFoot HX, but spiderfoot.net now redirects to Intel 471's site, and we could not find a public HX price or sign-up page. Ask Intel 471 sales whether HX is sold standalone or only within its products.

We're a pen testing firm — can we point SpiderFoot at a client's domains before the contract is signed, just to scope the job, or does that need authorization too?

Get written authorization first. Passive modules only read public sources, but SpiderFoot also integrates tools such as Nuclei and nbtscan that probe systems directly, and running those without permission can breach computer misuse laws and hosting terms. If you want a pre-contract view, limit the scan to passive modules and say so in your proposal; keep active testing for after the scope and rules of engagement are agreed.

Can I use SpiderFoot to look up a person's email or phone number for a background check on a job candidate, or should I use something else?

SpiderFoot can scan emails, phone numbers, usernames and names, but it is built for infrastructure reconnaissance, not people screening. Results are raw, need verification and collect personal data that the GDPR requires you to minimize. In the US, background checks used for hiring decisions fall under the FCRA when a consumer reporting agency prepares them. A screening process with consent and verification is the safer route.