SpiderFoot vs Intelligence X
SpiderFoot
SpiderFoot is an open-source (MIT) tool that automates OSINT collection for threat intelligence and for mapping an organisation's attack surface. Given a target such as a domain, IP address, email address or name, it runs over 200 modules against data sources and correlates the results, using a YAML-configurable correlation engine with 37 pre-defined rules. It runs as a self-hosted web application or from the command line, supports Docker deployment, can search the dark web through Tor, and can call other tools such as Nmap and DNSTwist. The project has been on GitHub since 2012.
Pros
- Free and open source under the MIT licence
- Broad automated collection from one scan
- Self-hosted, so scan data stays on your own infrastructure
Things to check
- Self-hosted: you install, run and maintain it
Pricing: Free and open source (MIT).
Intelligence X
Intelligence X is a search engine and archive for information that has been leaked or published, searched by selectors such as email addresses, domains, IP addresses and CIDR ranges. Its sources include pastes, data leaks, stealer logs, Tor and I2P darknet sites, WHOIS records, Usenet and the public web, with several sources limited to paid accounts, and it keeps copies of what it indexes. It was founded in 2018 by Peter Kleissner and is based in Prague. A free tier is available, with paid plans for researchers, API use, identity monitoring portals and enterprises.
Pros
- Covers darknet, leak and stealer-log sources in one search
- Free tier for basic searches
- Published annual prices
Things to check
- Most darknet and leak sources need a paid plan
- Paid plans start at €2,500 a year
Pricing: Free tier. Researcher €2,500/year, API €7,000/year, Identity Portal €10,000/year, Enterprise €20,000/year.