OSINT tools
Molfar analysts use open-source intelligence tools to collect data from open sources. On this page, you will find an OSINT tools list that we offer for work. They are built on specific data search and analysis algorithms that help to quickly and easily collect information. OSINT online tools are divided into groups based on the search field and the type of data you need to get.
The learning of OSINT tools is part of the analyst's expertise: each new tool increases the researcher's skills in data collection. Sometimes, new OSINT software appears that provides access to previously closed or very fragmented information. A good analyst wants to be one of the first to know about it. Another common need is to replace old OSINT search tools with new ones. Experts generally do this to optimize and improve their work, or simply because their previous OSINT toolkit has stopped working.
All or almost all the created tools use common sources, meaning that most of the available tools are aggregators of open information. However, some tools contain unique data, such as FlightRadar24, an interactive map with real-time tracking of civilian and some military aircraft. Or MarineTraffic, a similar site for tracking the geolocation of ships.
These open-source intelligence tools are exceptions, as they reflect unique data, fragments of which are not freely available. Such tools are created and maintained by specialized teams as part of data openness programs, and simply need to be known and used.
What are the OSINT tools?
OSINT tools are a collection of websites, resources, applications, and software that an OSINT analyst can use to quickly obtain specified information from open sources. All OSINT apps or websites are divided into two groups according to the availability: public and custom.
Public OSINT software
It is services, programs and applications that are available to all Internet users by default. For example, a service for person search by nickname, WhatsMyName.
Custom OSINT software
It is specific tools created by experienced analysts for their own use. Custom search tool uses the same open sources, but usually has a very specialized function. For example: Molfar analysts created a custom OSINT tool to search for information about a person by name among job vacancies and CVs on job search sites.
According to statistics, most people have very low skills in collecting and analyzing information from open sources. Spreading the knowledge about open-source intelligence tools multiplies the chances of successful search. We recommend you regularly investing time and effort to studying the tools. For example, we have common chats within Molfar where we constantly share useful links and reviews of new products in the field of OSINT intelligence.
Who uses OSINT tools?
OSINT tools are mostly used by intelligence analysts who work with open sources of information. However, most tools are designed for a wide range of users.
Let's take a look at a rather dangerous for use service Getcontact (more on this in the next section), which shows how other people's numbers from your contact list are signed. This OSINT app was created to satisfy the interest of ordinary people, but it has found wide use in intelligence research. Getcontact is a great example of an OSINT tool that is used by a wide range of people.
Another example: Wayback Machine, a website created to research updates and history on a web page. The resource has not become widespread among ordinary users, but it is actively used in intelligence to obtain insights.
How OSINT tools work?
The tools simply collect open data according to certain designed algorithms. Open-source intelligence tools are very popular, so understanding the risks of using them is much more important than researching the internal architecture of the algorithms built. Let's talk about it.
We have already mentioned a dangerous (!) OSINT search tool called Getcontact. The main problem with such software is the conditions of data use. The service not only gives you the opportunity to see how the numbers in other people's contacts are signed, but also gives other people access to information from your phone book. This is a pretty strong vulnerability that users of the OSINT app voluntarily agree to accept.
Simply said, OSINT software can harm those using them. To stay safe, Molfar analysts recommend using a secure device and a secure account.
A secure device
A smartphone that does not contain any sensitive information. Sensitive information is data that, if leaked, could harm you or people related to you. For example: passwords, email or physical addresses, personal photos, etc. Some OSINT search tools may not collect sensitive information from the device directly, but due to internal vulnerabilities, they may be in the zone of potential hackers' access.
A secure account
This is an email address, phone number, and other data that does not reveal real information about you and people associated with you. If your security account is accessed, hackers cannot determine your age, gender, name, and other true information.
So, whatever OSINT tools you use, first of all, take care of your own safety. Otherwise, the collection and analysis of information can harm your privacy.
Are OSINT tools free to use?
Mostly, yes, the majority of tools are free or partially free. For example, the service for people's identity search X-Ray.contact. At first, users can search for information for free, but after completing trial searches, they will have to pay for the next ones.
According to statistics, most successful open-source intelligence tools are finally monetized. And then using the free version becomes ineffective. At the same time, according to Molfar analysts, paid versions of the OSINT software are really worth the money. The benefits of the data received are much greater compared to the cost of using the service. In addition, the monetization of the tool indicates that it is constantly being improved by the team that created it. This often guarantees that the chosen tool will not lose its relevancy for a long time.
Are OSINT tools legal?
Yes, completely legal! It is so since every OSINT app, resource or software is based on open sources. That is, information from open databases, registries, and websites.
OSINT tools are built on the use of publicly available data, but we still insist on following security rules when using them.
Customs declarations across 30 countries. Does not consolidate different spellings of companies into one profile. Searching in various spellings.
Online reading any language from pictures (OCR), there are up to 10 pages in the trial.
The list of offers from the main nets allows you to identify partners of any service.
Database of media by countries. It is also possible to sort by specific topics. One of the largest resources for news with magazines and newspapers from around the world. However, keyword search is not available here.
Software that allows you to view contact information on companies, as well as employees' contact information on LinkedIn profile. The free version after registration has 90 loans to view mail (1 loan - 1 mail).
AML/KYC Solution. Looking for a person's mention in the sanctions lists. Checks news by countries. Looking for world registers.
Online editor. Convenient when the photo shows an object (for example, the number of the machine), however, because of insufficient lighting, you cannot see the details. Changing the exposure or increasing sharpness, you can get the result.
Cards, diagrams, satellite photos, users photos. There is better resolution and fresh photos than Google in locations, but does not have the exact date of filming.
The service shows what technologies are used on the site (plugins, analytics, CMS, etc.), and it is also possible to view the list of sites from a given vertical. We use to find customers of technology. You can also analyze a separate technology site.
A search service that pulls results from Google and Yandex, categorizing the results into thematic folders (offices, LinkedIn, clients, revenue).
Extension for the browser. LinkedIn's employees are convenient for parsing.
Site with applications for repair permits, where you can find additional real estate information, such as a description of works, contractors. Registration for fake data.
Chrome extension. Monitoring of changes on pages. At the entrance? Page item (xpath, js), output? alert change.
Browses the browser window into 3 windows for simultaneous viewing from Google Services: satellite, maps and streets viewing.
A search engine that does not store user IP addresses and collects information.
Export of comments from posts: Facebook, Instagram, Twitter, Tiktok and more. Free 500 comments.
The search engine allows you to choose the resource where you will search (it is convenient to wait immediately for a list of social networks).
An image change tracking tool that allows you to analyze images using light spectrums. If an image lacks details during "error level analysis" (ELA), it can be assumed that it has been altered. It also allows you to obtain metadata.
Social networks and a person's name through mail. Works through Maltego.
Generates a face with a natural background. When keeping the browser, add .jpg extension. There are also many other generators on the site.
Finding a photo of a person from a base generated by a neural network, the ability to select filters on ethnic grounds.
A site that allows you to draw schemes. Most users use the free version, which is why their schemes are indexed by search engines.
Tracking information on a permanent basis. With the advent of new articles, mentions, etc., messages come.
Desktop version, available historical photos, objects are visible at different angles.
The service that can create cards based on data from files of different formats: .Gpx, .kml, .xml, .xls and others.
Tools tools, an analogue of Riskiq PassivTotal, does not require registration.
A tool that allows you to watch the comments on YT. There are filters by date, the number of likes and the number of answers to comments. You can search with the nickname of the comment.
Cards, diagrams, satellite photos, users photos. There is better resolution and fresh photos than Google in part of locations, but does not have the exact date of filming.
Mail by person's name/surname and company domain. Displays mail format. 100 requests/month.
The service that deletes the selected parts of the image and complements them with a neural network.
Web. It is more convenient than Octoparse. The free version does not bypass Loginwall.
Automatic collection of all available information. At the entrance you can give a domain, IP, mail, BTC-wallet, images, nickname, first and last name, phone, location, keyword to search for a file,
A convenient site to target Google search, you can specify the exact location and language.
Decompler of Android apps. For example, about the company that makes social games, you can see which SDK are installed in the application.
The platform shows keywords in any language and country. Some requests even see how popular they are, though the service is paid. You can look for keywords on Google, YouTube, Twitter, Instagram, Amazon, Ebay, Play Store, Bing.
Allows monitoring various communication frequencies in Kyiv, such as radio conversations of operators and patrols of a security firm. Enables recording with subsequent downloading. Works in Firefox and Internet Explorer, but may not play sound in other browsers.
Enhancing clarity, zooming. Registration using a fake email, 5 requests, up to 4x magnification.
Instructions for finding LinkedIn profiles by adding them to contacts through the Microsoft Outlook Online client.
Tool for building and analyzing relationships between entities and objects. It establishes connections between individuals, their contacts (email addresses, social media accounts, phone numbers, and addresses), companies, websites, elements of internet infrastructure (domain names, DNS records, IP addresses, network blocks), and metadata of documents.
Search for open FTP servers. Convenient because even if access to the server is already closed, page headers and file names remain indexed.
Allows finding archived copies of accounts using Telegram, Discord, Twitter, or Facebook IDs. Even if an account has been deleted, it can display photos and names.
Services that aggregate information about domains, networks, DNS, and IP. They are used to understand what other projects are hosted on the IP of a company's main website, whether they belong to the company, and so on. Myip.ms is convenient because it displays the history of IP changes.
App KPI dashboard. Allows viewing advertising campaigns and statistics related to them.
Swiss Army Knife plugin that allows downloading videos/images via links, breaks down videos frame by frame, checks for reposts on Twitter, automatically runs them through search engines like Google, Yandex, Tineye, and Baidu. Provides access to metadata in videos and images, checks for fakeness using ELA and various spectra, and enables zooming. Standard Twitter search functionality is also available.
Desktop. It is possible to create a detailed flowchart of actions. Can bypass loginwall.
The list of offers from the main nets allows you to identify partners of any service.
The list of offers from the main nets allows you to identify partners of any service.
Online editor. Convenient when the photo shows an object (for example, the car number), but because of insufficient lighting you cannot see the details. Changing the exposure or increasing sharpness, you can get the result.
OCR with limited functionality, reads files one page. Hebrew is supported.
Swiss knife to search for a picture: looking at Google, Yandex, Tineye and Bing at the same time. Download extensions, choose search engines? PKM by image? search; Similar Services: Search by Image and Image Search - are Baidu, no bing.
Searching on the indexed sites using technology similar to FindClone. The opening of the results is paid, but the photos themselves are visible and visible from what resource tightened.
Telegram bot for data lookup on individuals. Designed for the CIS region. Provides historical data from VK (VKontakte).
Finding human connections. Relsci also allows you to find a person/person and person/company.
Analogous to Forensically, it provides explanations for all filters, cases of fake photos. Also available as a plugin in InVID.
Domain, network, DNS, and IP information aggregation services. Used to understand what other projects are hosted on a company's main website's IP, whether they belong to the company, and more.
Mail by person's name/surname and company domain. Sometimes he finds personal mail and tightens social. networks. 10 requests for free.
To quickly switch between Google, Yandex, OpenStreet, Esri and Apple cards.
Extension for Google Chrome for quick search on Facebook, YouTube, Vimeo, Stackoverflow and others.
KPI mobile applications. At the entrance? Mobile app, on the way out? Download, DAU/Mau, advertisers, competitors, ASO.
Statistics on the number of websites using specific technologies. Used for client prospecting for a company providing those technologies. It can also analyze individual websites for their use of technologies.
Through the password recovery form, it is possible to obtain data such as email or phone number.
A paid, but the cheapest, virtual phone number service. It offers rare countries like Romania. A number is provided for rent for 20 minutes. We purchase the number, send an SMS, wait for 2 minutes, and then click the green checkmark to read the SMS. If no SMS is received, the rental fee is refunded to the account.
Browser extension. Finds email addresses of LinkedIn profiles. Allows displaying emails from the search form for 10 profiles without having to visit each profile individually.
Hashtag search engine. Retrieves results from social media platforms that contain the entered hashtag (displays photo previews instantly).
Integrates Graph Search functionality into Maltego (liking posts, tagged photos, tagged posts). Works as a standalone transform within Maltego.
OCR (Optical Character Recognition) for PDF files, suitable for working with large files.
Automatic collection of all available information. You provide a domain, IP, or email as input. It operates in different modes, with the full mode running for a couple of hours and gathering a significant amount of data, including some irrelevant information. There is also a passive mode that collects maximum information without making direct queries to the target. It allows exporting data to .csv format and building a graph of connections.
A website for viewing Instagram stories and posts without logging into any account. It also allows you to download stories.
Browser for safe surfing. Use users can maintain anonymity on the Internet when visiting sites, blogging, sending instant and postal messages, as well as when working with other applications.
A compilation of services for anonymous work: email, photos, SMS, and adding fake EXIF data to photos.
Searches by phone number, username, and full name in Russian. It has 39 databases.
VK parser, the obtained information can be downloaded to Maltego for graph construction.
Big Data platform. The platform includes "Russian Roots," a registry of companies related to the Russian Federation (RF) and the Republic of Belarus (RB) for verification (including mass verification) and identification of Russian connections. It also provides comprehensive profiles of companies and individual entrepreneurs (sole proprietors).
Google Chrome extension for reverse image search. After installing the extension, you can right-click on any image and select the search engine you want to use: Google, Yandex, Bing, Tineye, Baidu, Reddit. There is also an option to open the image in a separate editor and utilize custom tools such as a magnifying glass for zooming in on specific parts of the image, checking for Photoshop alterations, and viewing metadata.
A map with Wi-Fi hotspots marked and network names. If you don't know the exact address of a company, you can view the approximate area and find a hotspot with the name of the company/project.
Maps, diagrams, satellite photos, and user photos. Unofficial records about places and former owners are available. It offers higher resolution and more up-to-date photos compared to Google in certain locations, but the exact date of the photos is not provided.
The plugin for chrome. VPN. Quality - 50/50, 10 GB/month limit, but you can periodically find promotional codes to increase the number of traffic. You can also download the Desktop version on the site. Countries: US, CA, FR, DE, NL, NO, RO, CH, UK, HK.
Search from international and national research bases. The request can be entered in any language, including Russian. Filters are provided.
Data on Ukrainian legal entities. The main advantage is historical data on executives, founders and addresses, as well as finding ties and names. There are also financial indicators as ranges.
Services that aggregate information about domains, networks, DNS, IP. They are used to understand what other projects are placed on the IP main site of the company, whether they belong to the company, etc.