OSINT · 2026 edition

OSINT tools 2026,
sorted by the job

61 verified open-source intelligence tools across ten categories, from search and social media to breach data and OPSEC. Most free, each linked to source.

🧰 61 tools ✅ All verified 2026 🆓 Mostly free
2026 edition

61 OSINT tools, sorted by job

Open-source intelligence is the practice of collecting and analysing information from publicly available sources. This is the working toolkit, 61 tools across ten categories, that a modern OSINT investigation actually uses in 2026. Every one is verified and reachable, most are free, and each links straight to the source.

This is the quick-reference companion to the full OSINT guide, which walks through the techniques step by step. Bookmark this page for the tools; read the guide for how to chain them together.

⚖️
Use these legally and ethically

OSINT touches real people. Investigate only what you are authorised to, respect each platform's terms, and keep your own operational security tight. The last category exists for exactly that reason.

Category 01

01 Search & discovery

Search engine for internet-connected devices, ports and banners.
Web
TLS certificate and cloud-asset search; the modern complement to Shodan.
Web
Standing monitors that email you when a name or term appears.
Web
On-demand page snapshots that survive deletion.
Web
Category 02

02 Social media intelligence

Scrape X / Twitter timelines and search without the paid API.
CLI
Download Instagram posts, stories and metadata from the command line.
CLI
Reverse-lookup an email or phone to linked Google and social accounts.
Web
Enumerate employee names from LinkedIn to build email lists.
CLI
Category 03

03 Email & username

Check whether an email appears in known breaches.
Web
Find and verify corporate email address patterns.
Web
Pull public data tied to a Google account from an email.
CLI
Check a username across 2,500+ sites and build a report.
CLI
Web-based username enumeration across hundreds of platforms.
Web
List all emails, subdomains and URLs for a domain.
Web
Category 04

04 Domain & infrastructure

Certificate-transparency search to uncover subdomains.
Web
Fast passive subdomain enumeration.
CLI
OWASP in-depth attack-surface and DNS mapping.
CLI
Gather emails, hosts and subdomains from public sources.
CLI
Probe a list of hosts for live web servers and tech.
CLI
Free DNS recon and network mapping in the browser.
Web
Historical DNS and WHOIS records.
Web
A grab-bag of DNS, WHOIS and reverse-IP lookups.
Web
Fingerprint the technology stack of a website.
CLI
Identify frameworks and services from the browser.
Extension
Technology profile and history of any domain.
Web
Category 05

05 Dark web & breach data

Search engine for .onion sites on the Tor network.
Web
Search leaks, pastes and dark-web data by selector.
Web
Query breached credentials and exposed records.
Web
Check whether an email or domain appears in infostealer logs.
Web
Category 06

06 Crypto & blockchain

Attribute wallet addresses to real-world entities.
Web
Trace transactions and contracts on Ethereum.
Web
Multi-chain explorer with powerful filters.
Web
Follow Bitcoin transactions and addresses.
Web
Category 07

07 Geolocation & media verification

Reverse image search that finds where a photo first appeared.
Web
The strongest reverse image search for faces and places.
Web
Read and strip metadata from images, video and documents.
CLI
Inspect codec and container metadata of media files.
Free tool
Browser plugin for verifying and dissecting videos.
Extension
Estimate time and location from shadows in a photo.
Web
Historical satellite imagery for geolocation.
Web
Recent multispectral satellite imagery.
Web
Category 08

08 People & corporate records

The largest open database of company registrations and officers.
Web
Full-text search of Indian court judgments and law.
Web
Visual link analysis that maps relationships between entities.
Free tool
Open-source graph visualisation for large networks.
Free tool
Category 09

09 Threat intelligence & malware

The reference taxonomy of adversary tactics and techniques.
Web
Layer and annotate ATT&CK coverage.
Web
Multi-engine file, URL and hash reputation.
Web
Free automated malware sandbox reports.
Web
Interactive malware sandbox you drive in real time.
Web
Community threat-intelligence feeds and indicators.
Web
Free indicator-of-compromise database from abuse.ch.
Web
Repository of malware samples for research.
Web
Category 10

10 OPSEC, automation & reporting

Automate collection across 200+ modules from one target.
CLI
Modular recon framework with a Metasploit-style workflow.
CLI
Capture and timestamp every page you visit during an investigation.
Extension
Save a complete web page as one self-contained file.
Extension
Strip metadata from your own files before you share them.
CLI
See how identifiable your browser fingerprint is.
Web
Test exactly what your browser reveals about you.
Web
Confirm your VPN is not leaking DNS during an investigation.
Web
Section 07

07 OSINT tools FAQ

What are the best free OSINT tools in 2026?

For most investigations: Shodan and Censys for infrastructure, Maigret and WhatsMyName for usernames, HaveIBeenPwned and DeHashed for breach data, Yandex Images and ExifTool for media, and SpiderFoot to automate collection. All are free or have a free tier.

Is there an OSINT framework or handbook I can follow?

This list is organised the way an investigation flows, from search and social media through domains, breach data and media verification to reporting. Pair it with the step-by-step OSINT guide, which is the handbook to this toolbox.

Do I need to pay for OSINT tools?

No. The overwhelming majority here are free or open source. A few, such as SecurityTrails, IntelX and Maltego, gate their deepest data behind a paid tier, but every category has a capable free option.

What tools do OSINT investigators use for username searches?

Maigret and WhatsMyName check a single username across hundreds to thousands of sites. GHunt and Epieos pivot from an email to linked accounts, and Hunter.io finds corporate email patterns.

How do I stay anonymous while doing OSINT?

Separate your investigation identity from your real one, use a clean browser profile or VM, and verify you are not leaking with Am I Unique, BrowserLeaks and DNS Leak Test. Strip metadata from anything you publish with mat2.

Are these OSINT tools legal to use?

The tools are legal; how you use them is what matters. Collecting public information is generally lawful, but respect platform terms of service, privacy law in your jurisdiction, and the scope of any authorisation you are working under.