★ 61 OSINT tools, sorted by job
Open-source intelligence is the practice of collecting and analysing information from publicly available sources. This is the working toolkit, 61 tools across ten categories, that a modern OSINT investigation actually uses in 2026. Every one is verified and reachable, most are free, and each links straight to the source.
This is the quick-reference companion to the full OSINT guide, which walks through the techniques step by step. Bookmark this page for the tools; read the guide for how to chain them together.
OSINT touches real people. Investigate only what you are authorised to, respect each platform's terms, and keep your own operational security tight. The last category exists for exactly that reason.
01 Search & discovery
02 Social media intelligence
03 Email & username
04 Domain & infrastructure
05 Dark web & breach data
06 Crypto & blockchain
07 Geolocation & media verification
08 People & corporate records
09 Threat intelligence & malware
10 OPSEC, automation & reporting
07 OSINT tools FAQ
What are the best free OSINT tools in 2026?
For most investigations: Shodan and Censys for infrastructure, Maigret and WhatsMyName for usernames, HaveIBeenPwned and DeHashed for breach data, Yandex Images and ExifTool for media, and SpiderFoot to automate collection. All are free or have a free tier.
Is there an OSINT framework or handbook I can follow?
This list is organised the way an investigation flows, from search and social media through domains, breach data and media verification to reporting. Pair it with the step-by-step OSINT guide, which is the handbook to this toolbox.
Do I need to pay for OSINT tools?
No. The overwhelming majority here are free or open source. A few, such as SecurityTrails, IntelX and Maltego, gate their deepest data behind a paid tier, but every category has a capable free option.
What tools do OSINT investigators use for username searches?
Maigret and WhatsMyName check a single username across hundreds to thousands of sites. GHunt and Epieos pivot from an email to linked accounts, and Hunter.io finds corporate email patterns.
How do I stay anonymous while doing OSINT?
Separate your investigation identity from your real one, use a clean browser profile or VM, and verify you are not leaking with Am I Unique, BrowserLeaks and DNS Leak Test. Strip metadata from anything you publish with mat2.
Are these OSINT tools legal to use?
The tools are legal; how you use them is what matters. Collecting public information is generally lawful, but respect platform terms of service, privacy law in your jurisdiction, and the scope of any authorisation you are working under.