Skip to main content

Open Source Intelligence Tools

Open source intelligence tools collect and correlate public endpoints, DNS records, certificate logs, code leaks, and organizational assets to map external attack surfaces.

13 Tools Cataloged
ToolLicensePlatformsPricingAction
AmassApache-2.0Linux, macOS, Windows, BSDOpen SourceProfile
CensysProprietaryWebFreemiumProfile
httpxMITLinux, Windows, macOSOpen SourceProfile
katanaMITLinux, Windows, macOSOpen SourceProfile
MaltegoProprietaryWindows, Linux, macOSFree / CommercialProfile
OSINT FrameworkMITWebOpen SourceProfile
PhotonGPL-3.0-onlyLinux, macOS, WindowsOpen SourceProfile
Recon-ngGPL-3.0-or-laterLinux, macOS, WindowsOpen SourceProfile
SherlockMITLinux, macOS, WindowsOpen SourceProfile
ShodanProprietary (service); MIT (Python client)Web, Linux, macOS, WindowsFreemiumProfile
SpiderFootMITLinux, macOS, WindowsFree / CommercialProfile
subfinderMITLinux, macOS, WindowsOpen SourceProfile
theHarvesterGPL-2.0-onlyLinux, macOS, WindowsOpen SourceProfile

Tools in Open Source Intelligence Tools

Amass

Open Source

OWASP attack-surface discovery framework written in Go that discovers external assets through DNS enumeration and OSINT, licensed under Apache-2.0.

LicenseApache-2.0
PlatformLinux, macOS, Windows, BSD

Censys

Freemium

Internet scan and host reconnaissance platform that maps exposed services, certificates, and infrastructure across the global web.

LicenseProprietary
PlatformWeb

httpx

Open Source

Fast HTTP toolkit that probes services, captures response metadata, and fingerprints technologies to verify external attack surfaces.

LicenseMIT
PlatformLinux, Windows, macOS

katana

Open Source

Configurable web crawler that discovers endpoints and content in standard and headless modes to map attack surfaces and catalog applications.

LicenseMIT
PlatformLinux, Windows, macOS

Maltego

Free / Commercial

Visual link-analysis and OSINT platform that maps relationships between domains, people, and infrastructure through transforms and data integrations.

LicenseProprietary
PlatformWindows, Linux, macOS

OSINT Framework

Open Source

Curated browser-based index of free OSINT tools and resources, organized by research task for username, email, domain, and records work.

LicenseMIT
PlatformWeb

Photon

Open Source

Python web crawler for OSINT that extracts URLs, emails, social handles, files, secrets, and subdomains from a target website in a single run.

LicenseGPL-3.0-only
PlatformLinux, macOS, Windows

Recon-ng

Open Source

Full-featured, modular web-reconnaissance framework with a Metasploit-style CLI, SQLite workspaces, and a marketplace, licensed under GPL-3.0-or-later.

LicenseGPL-3.0-or-later
PlatformLinux, macOS, Windows

Sherlock

Open Source

Python command-line tool that searches a username across more than 400 social networks and returns links to matching public profiles.

LicenseMIT
PlatformLinux, macOS, Windows

Shodan

Freemium

Search engine for Internet-connected devices that indexes service banners, open ports, and exposed assets across public IP space.

LicenseProprietary (service); MIT (Python client)
PlatformWeb, Linux, macOS, Windows

SpiderFoot

Free / Commercial

Open-source OSINT automation tool with 200+ modules and a web UI that gathers and correlates data on domains, IPs, emails, and users.

LicenseMIT
PlatformLinux, macOS, Windows

subfinder

Open Source

Go-based passive subdomain enumeration tool that aggregates online data sources to map an organization's external DNS footprint.

LicenseMIT
PlatformLinux, macOS, Windows

theHarvester

Open Source

Lightweight, passive OSINT harvester that collects emails, subdomains, IPs, URLs, and names from public sources for authorized reconnaissance.

LicenseGPL-2.0-only
PlatformLinux, macOS, Windows

Frequently Asked Questions

What is Open Source Intelligence Tools?

Open source intelligence tools collect and correlate public endpoints, DNS records, certificate logs, code leaks, and organizational assets to map external attack surfaces.

What topics does the Open Source Intelligence Tools category cover?

Passive Subdomain Enumeration, External Attack Surface Discovery, Certificate Transparency Auditing, Public Identity Reconnaissance, Multi-Source OSINT Frameworks

About Open Source Intelligence Tools

Open source intelligence (OSINT) tools collect and correlate publicly available data to map an organization's external attack surface. The category includes subdomain enumeration tools like Amass and Subfinder that discover hosts through certificate transparency logs, DNS records, and search engine scraping. Attack surface discovery platforms like Shodan and Censys index internet-connected devices, letting analysts find exposed services and open ports across their IP ranges. Recon frameworks like Recon-ng and SpiderFoot automate multi-source enumeration, combining DNS, WHOIS, certificate, and social media data into structured results. People and identity reconnaissance tools like Sherlock and theHarvester find email addresses, usernames, and social media profiles associated with a target organization. The category serves both offensive and defensive use cases. Offensive teams use OSINT during authorized assessments to identify entry points before active testing. Defensive teams use the same tools to monitor their own exposure, finding leaked credentials, accidentally exposed services, and shadow IT before attackers do. Most OSINT tools are open source and rely on public data sources, though commercial platforms like Shodan and Maltego offer paid tiers with broader data access and visualization.

Covered Topics & Disciplines

Passive Subdomain EnumerationExternal Attack Surface DiscoveryCertificate Transparency AuditingPublic Identity ReconnaissanceMulti-Source OSINT Frameworks