Open Source Intelligence Tools
Open source intelligence tools collect and correlate public endpoints, DNS records, certificate logs, code leaks, and organizational assets to map external attack surfaces.
| Tool | License | Platforms | Pricing | Action |
|---|---|---|---|---|
| Amass | Apache-2.0 | Linux, macOS, Windows, BSD | Open Source | Profile→ |
| Censys | Proprietary | Web | Freemium | Profile→ |
| httpx | MIT | Linux, Windows, macOS | Open Source | Profile→ |
| katana | MIT | Linux, Windows, macOS | Open Source | Profile→ |
| Maltego | Proprietary | Windows, Linux, macOS | Free / Commercial | Profile→ |
| OSINT Framework | MIT | Web | Open Source | Profile→ |
| Photon | GPL-3.0-only | Linux, macOS, Windows | Open Source | Profile→ |
| Recon-ng | GPL-3.0-or-later | Linux, macOS, Windows | Open Source | Profile→ |
| Sherlock | MIT | Linux, macOS, Windows | Open Source | Profile→ |
| Shodan | Proprietary (service); MIT (Python client) | Web, Linux, macOS, Windows | Freemium | Profile→ |
| SpiderFoot | MIT | Linux, macOS, Windows | Free / Commercial | Profile→ |
| subfinder | MIT | Linux, macOS, Windows | Open Source | Profile→ |
| theHarvester | GPL-2.0-only | Linux, macOS, Windows | Open Source | Profile→ |
Tools in Open Source Intelligence Tools
Amass
Open SourceOWASP attack-surface discovery framework written in Go that discovers external assets through DNS enumeration and OSINT, licensed under Apache-2.0.
Censys
FreemiumInternet scan and host reconnaissance platform that maps exposed services, certificates, and infrastructure across the global web.
httpx
Open SourceFast HTTP toolkit that probes services, captures response metadata, and fingerprints technologies to verify external attack surfaces.
katana
Open SourceConfigurable web crawler that discovers endpoints and content in standard and headless modes to map attack surfaces and catalog applications.
Maltego
Free / CommercialVisual link-analysis and OSINT platform that maps relationships between domains, people, and infrastructure through transforms and data integrations.
OSINT Framework
Open SourceCurated browser-based index of free OSINT tools and resources, organized by research task for username, email, domain, and records work.
Photon
Open SourcePython web crawler for OSINT that extracts URLs, emails, social handles, files, secrets, and subdomains from a target website in a single run.
Recon-ng
Open SourceFull-featured, modular web-reconnaissance framework with a Metasploit-style CLI, SQLite workspaces, and a marketplace, licensed under GPL-3.0-or-later.
Sherlock
Open SourcePython command-line tool that searches a username across more than 400 social networks and returns links to matching public profiles.
Shodan
FreemiumSearch engine for Internet-connected devices that indexes service banners, open ports, and exposed assets across public IP space.
SpiderFoot
Free / CommercialOpen-source OSINT automation tool with 200+ modules and a web UI that gathers and correlates data on domains, IPs, emails, and users.
subfinder
Open SourceGo-based passive subdomain enumeration tool that aggregates online data sources to map an organization's external DNS footprint.
theHarvester
Open SourceLightweight, passive OSINT harvester that collects emails, subdomains, IPs, URLs, and names from public sources for authorized reconnaissance.
Frequently Asked Questions
What is Open Source Intelligence Tools?→
Open source intelligence tools collect and correlate public endpoints, DNS records, certificate logs, code leaks, and organizational assets to map external attack surfaces.
What topics does the Open Source Intelligence Tools category cover?→
Passive Subdomain Enumeration, External Attack Surface Discovery, Certificate Transparency Auditing, Public Identity Reconnaissance, Multi-Source OSINT Frameworks
About Open Source Intelligence Tools
Open source intelligence (OSINT) tools collect and correlate publicly available data to map an organization's external attack surface. The category includes subdomain enumeration tools like Amass and Subfinder that discover hosts through certificate transparency logs, DNS records, and search engine scraping. Attack surface discovery platforms like Shodan and Censys index internet-connected devices, letting analysts find exposed services and open ports across their IP ranges. Recon frameworks like Recon-ng and SpiderFoot automate multi-source enumeration, combining DNS, WHOIS, certificate, and social media data into structured results. People and identity reconnaissance tools like Sherlock and theHarvester find email addresses, usernames, and social media profiles associated with a target organization. The category serves both offensive and defensive use cases. Offensive teams use OSINT during authorized assessments to identify entry points before active testing. Defensive teams use the same tools to monitor their own exposure, finding leaked credentials, accidentally exposed services, and shadow IT before attackers do. Most OSINT tools are open source and rely on public data sources, though commercial platforms like Shodan and Maltego offer paid tiers with broader data access and visualization.
Covered Topics & Disciplines
Related Security Categories
Intercepting HTTP proxies, security assessment toolkits, and network exploitation frameworks.
Phishing campaign platforms, security awareness testing tools, and credential harvesting simulators.
Threat intelligence platforms, IOC sharing communities, and STIX/TAXII tooling for collecting and distributing threat data.