OSINT Tools: 10 Tools compared
The tools on this page do different parts of that job. Opsis, OSINT Industries, Sherlock, Maigret and WhatsMyName check a username, email address or phone number against many sites and return the accounts they find. Intelligence X and OSINTLeak search leaked data, stealer logs and darknet sources. Maltego and SpiderFoot connect many sources in one investigation, and SearchWebCode searches the source code of public websites.
Most of these tools are dual-use: the lookup that helps an investigator can also help someone stalk or harass. A match is a lead, not proof of who owns an account. Check each tool's terms of use, and the law where you work, before you search for a person. Opsis, for example, prohibits stalking, harassment, doxxing and employment, tenant or credit screening in its acceptable use policy.
10 OSINT Tools, side by side
Featured listings are paid placements.
| Tool | Deployment | Pricing model | Open source |
|---|---|---|---|
| Opsis OSINTFeatured | Cloud | Subscription | — |
| Intelligence X | Cloud | Free tier and annual subscription | — |
| Maigret | Self-hosted | Open source | Yes |
| Maltego | Cloud | Free tier and annual subscription with data credits | — |
| OSINT Industries | Cloud | Monthly subscription with search credits | — |
| OSINTLeak | Cloud | Freemium | — |
| SearchWebCode | Cloud | Pay per search or subscription | — |
| Sherlock | Self-hosted | Open source | Yes |
| SpiderFoot | Self-hosted | Open source | Yes |
| WhatsMyName | Cloud | Free and open data | Yes |
By use case
Our read on which firm suits which job. Editorial, not paid, and separate from the alphabetical listing below.
Username and email lookups without running your own tools
Opsis OSINT
Hosted search across about 1,100 modules for usernames and email addresses, plus domain WHOIS and DNS. A result only counts as a match when the source shows profile signals such as an avatar or display name. A REST API comes with the Pro plan; plans from $14.99 a month.
Cloud
Email, phone and username lookups for investigators
OSINT Industries
Searches an email address, phone number, username, name or crypto wallet and builds a profile of the linked accounts. Plans from £19 a month, with API access from £49.
Cloud
Link analysis across many data sources
Maltego
Maps people, organisations and infrastructure on a graph and pulls in data from partner integrations. Free Basic plan with the Community Edition; paid plans from €3,000 a year.
Cloud
Searching leaks, pastes and darknet sources
Intelligence X
Searches pastes, leaks, stealer logs, Tor and I2P sites and WHOIS records by selectors such as email, domain, IP and CIDR. Free tier; paid plans from €2,500 a year.
Cloud
Breach and stealer-log monitoring
OSINTLeak
Breach and stealer-log intelligence with multi-selector search, monitoring, an API and a Python client. Free community tier of 20 searches a day.
Cloud
Automated reconnaissance you host yourself
SpiderFoot
Open-source (MIT) tool that runs over 200 modules against a target and correlates the results, for threat intelligence and attack surface mapping.
Open source, Self-hosted
A free, scriptable username check
Sherlock
Open-source (MIT) command-line tool that checks a username across 400+ social networks and saves the accounts it finds.
Open source, Self-hosted
Turning a username into a report
Maigret
Open-source (MIT) tool that checks thousands of sites, follows links to other accounts, searches again with the usernames it discovers, and exports HTML or PDF reports.
Open source, Self-hosted
A maintained list of sites to check
WhatsMyName
Community dataset of 700+ sites (CC BY-SA 4.0) that other tools build on, with a free browser tool at whatsmyname.app.
Open source, Cloud
Finding every site that shares a script or tracking ID
SearchWebCode
Searches the HTML, JavaScript and CSS of about 131 million domains by exact string or regex. $0.05 a search or $10 a month.
Cloud
Opsis OSINT
OSINT platform searching usernames, emails and domains across public sources
Opsis OSINT is a hosted search platform for open-source intelligence. It takes a username, email address or domain, checks it against public sources in real time and returns the matching accounts with the profile data each source exposes, such as names, avatars, bios, follower counts and join dates. Opsis says it now runs about 1,100 modules: around 700 username platform lookups and 400 email enrichment modules, plus domain WHOIS and DNS tools. Its website still gives the earlier figure of 700+. A result only counts as a match when the source shows real profile signals, such as an avatar, display name or structured data. An HTTP 200 response on its own does not count. Premium searches, on the Basic plan and above, add 27 username platforms that need browser automation, including Facebook, Etsy and Crunchbase. The Pro plan adds a versioned REST API with synchronous, polling and streamed modes and a published OpenAPI schema. Opsis says it discards search results and keeps no database of people, and it logs each query with the account, timestamp and IP address for up to 90 days. The operator is Opsis LLC, a Minnesota limited liability company confirmed as active in the Minnesota Secretary of State registry. Its acceptable use policy permits licensed investigation, corporate due diligence, threat intelligence, law enforcement, journalism and academic research, and prohibits stalking, harassment, doxxing and FCRA, GLBA or DPPA-regulated screening.
Capabilities
- Username search across about 700 platform lookups, by Opsis's count
- Email search with about 400 enrichment modules, by Opsis's count
- Domain search with WHOIS, DNS and reverse WHOIS lookups
- Premium deep search adding 27 username platforms that need browser automation, including Facebook, Etsy and Crunchbase (Basic plan and above)
- Historical WHOIS records on domain reports, showing ownership changes over time
- Premium document metadata analysis on domain searches, where public files are accessible
- Match confirmation from profile signals such as avatar, display name or structured data
- Profile data returned where the source exposes it: names, avatars, bios, follower counts and join dates
- Results grouped by source category, with filters and live hit, miss and unavailable counts per module
- Saved Profiles for keeping findings across searches
- REST API (v1) with synchronous, polling and Server-Sent Events streaming modes (Pro plan)
- Published OpenAPI 3 schema, plus public health and capabilities endpoints that need no key
- Confidence score from 0.0 to 1.0 on each API result
- Suppression requests: people can ask for their own email or username to be refused in future searches, reviewed by a person within 30 days
- Query logging with account, query, timestamp and IP address, kept for up to 90 days
- Published acceptable use policy with enumerated prohibited uses
Sources
- Opsis OSINT product site
- Opsis LLC terms of service and acceptable use policy
- Opsis LLC privacy policy, including query logging
- Minnesota Secretary of State record for Opsis LLC, file number 1643670600029
- Opsis about page: data handling, team size and suppression requests
- Opsis FAQ: result retention and saved Profiles
- Opsis API reference (v1): endpoints, credits, rate limits and premium platforms
Intelligence X
OSINT ToolsThreat intelligence and security teams checking exposure in leaked data and darknet sources.
Intelligence X is a search engine and archive for information that has been leaked or published, searched by selectors such as email addresses, domains, IP addresses and CIDR ranges. Its sources include pastes, data leaks, stealer logs, Tor and I2P darknet sites, WHOIS records, Usenet and the public web, with several sources limited to paid accounts, and it keeps copies of what it indexes. It was founded in 2018 by Peter Kleissner and is based in Prague. A free tier is available, with paid plans for researchers, API use, identity monitoring portals and enterprises.
Maigret
OSINT ToolsInvestigators who want a free tool that turns a username into a report of linked accounts.
Maigret is an open-source (MIT) tool that collects a profile of a person from a username alone. Its project description says it checks about 6,000 websites. It extracts the information available on the profiles it finds, follows links to other accounts, and searches again recursively using any new usernames and IDs it discovers. Results can be filtered by site category and country and exported as HTML or PDF reports. It installs with pip, runs from a terminal or a web interface, and is also offered through a community Telegram bot.
Maltego
OSINT ToolsInvestigation and threat intelligence teams that need to connect many sources on one graph.
Maltego is an OSINT and investigations platform. Maltego Graph places entities such as people, organisations, email addresses, domains and IP addresses on a graph and links them, drawing data from integrated sources, while Maltego Search handles quick lookups for digital profiling. The product set also includes Monitor, Evidence, Data, Screen and Profile, and Hunchly for capturing web pages as evidence. Maltego Technologies is based in Munich and lists government, defence and national security, law enforcement, threat intelligence, banking and insurance among the industries it serves. A free Basic plan includes the Community Edition of Maltego Graph.
Opsis OSINT
OSINT ToolsInvestigators, journalists and small security teams who want username and email pivoting in a hosted interface or API, without installing and maintaining open-source tools such as Maigret or WhatsMyName.
Opsis OSINT is a hosted search platform for open-source intelligence. It takes a username, email address or domain, checks it against public sources in real time and returns the matching accounts with the profile data each source exposes, such as names, avatars, bios, follower counts and join dates. Opsis says it now runs about 1,100 modules: around 700 username platform lookups and 400 email enrichment modules, plus domain WHOIS and DNS tools. Its website still gives the earlier figure of 700+. A result only counts as a match when the source shows real profile signals, such as an avatar, display name or structured data. An HTTP 200 response on its own does not count. Premium searches, on the Basic plan and above, add 27 username platforms that need browser automation, including Facebook, Etsy and Crunchbase. The Pro plan adds a versioned REST API with synchronous, polling and streamed modes and a published OpenAPI schema. Opsis says it discards search results and keeps no database of people, and it logs each query with the account, timestamp and IP address for up to 90 days. The operator is Opsis LLC, a Minnesota limited liability company confirmed as active in the Minnesota Secretary of State registry. Its acceptable use policy permits licensed investigation, corporate due diligence, threat intelligence, law enforcement, journalism and academic research, and prohibits stalking, harassment, doxxing and FCRA, GLBA or DPPA-regulated screening.
OSINT Industries
OSINT ToolsInvestigators who need to pivot from an email address, phone number or username to linked accounts quickly.
OSINT Industries searches an email address, phone number, username, name or crypto wallet address and returns the accounts and public data linked to it, compiled into a profile of the subject. It is aimed at investigators in law enforcement, government, journalism, insurance and fraud, cyber security and legal work. Results are gathered at the time of each search. Published plans run from 30 to 300 searches a month, with API access from the Intermediate plan, and Enterprise adds team seats, SSO and a shared credit pool.
OSINTLeak
OSINT ToolsSecurity, threat intelligence and investigative teams that need to search and monitor breach and stealer-log data with API access.
OSINTLeak is a cloud-hosted breach intelligence platform whose page title describes it as a breach intelligence platform and stealer log search. It offers search across emails, usernames, phone numbers and other indicators with 17 or more search selectors, domain and IP intelligence, WHOIS, reverse image search and real-time monitoring, and it targets OSINT researchers, enterprises, governments and law enforcement. Pricing is published in US dollars from a free Community tier of 20 searches per day to a Developer tier at USD 250 per month with API access, and an Enterprise option from USD 6,500 per year. A Python client and command-line tool, pyosintleak, is published on GitHub and PyPI. The terms state the service is operated by BREACHGUARDS LLC, is available only to professional users, and that data is obtained from public and less public sources rather than purchased from threat actors; no address or jurisdiction is published. An opt-out page allows individuals to remove their email address from public search after verification.
SearchWebCode
OSINT ToolsThreat intelligence, OSINT and security research teams who need to find every site sharing a script, identifier or technology fingerprint.
SearchWebCode is a search engine for the source code of public websites. It indexes the HTML, JavaScript and CSS of about 131 million homepage domains and matches exact strings or regular expressions, returning every site that contains the match together with its full source. Security uses include finding sites that load a known-bad script or an outdated library, and linking sites that share a tracking or analytics ID; it is also used to map technology stacks. A signature library identifies common technologies by their fingerprints, and results can be filtered by domain and exported to CSV or read through an API.
Sherlock
OSINT ToolsAnalysts who want a free, scriptable first check of where a username is registered.
Sherlock is an open-source (MIT) command-line tool that checks whether a username is registered on more than 400 social networks and websites. It can search several usernames at once and saves the accounts it finds to text, CSV or Excel files, with options for proxies, timeouts and checking a single site. It installs with pipx, pip or uv, or runs in Docker. The project has been on GitHub since 2018.
SpiderFoot
OSINT ToolsSecurity teams that want automated reconnaissance and attack surface mapping on their own infrastructure.
SpiderFoot is an open-source (MIT) tool that automates OSINT collection for threat intelligence and for mapping an organisation's attack surface. Given a target such as a domain, IP address, email address or name, it runs over 200 modules against data sources and correlates the results, using a YAML-configurable correlation engine with 37 pre-defined rules. It runs as a self-hosted web application or from the command line, supports Docker deployment, can search the dark web through Tor, and can call other tools such as Nmap and DNSTwist. The project has been on GitHub since 2012.
WhatsMyName
OSINT ToolsAnyone who needs a quick, free username check, and developers who want a maintained list of sites to build on.
WhatsMyName is a community-maintained dataset of more than 700 websites and the rules for checking whether a username is registered on each, published under a Creative Commons BY-SA 4.0 licence. Other OSINT and digital-footprint tools build on it, and whatsmyname.app is a free browser-based tool built directly on the dataset that needs no installation. The project has been on GitHub since 2015.
Related guides
Other categories you might be evaluating alongside osint tools.
About this listing
OSINT Tools tools, compared on public information. The comparison table is ordered by reader upvotes, then A to Z, with paid Featured listings shown first and labelled; the full entries run A to Z. How we work →