Censys
Censys is a search engine that allows computer scientists to ask questions about the devices and networks that compose the Internet by University of Michigan.
OffSec OSINT Pentest/RedTeam Tools
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
Censys is a search engine that allows computer scientists to ask questions about the devices and networks that compose the Internet by University of Michigan.
Shodan is a search engine that lets users search for various types of servers connected to the internet using a variety of filters. Some have also described it as a search engine of service banners, which are metadata that the server sends back to the client.
Search Exposed Internet assets, Malicious IP's.
ZoomEye is a freemium online tool aimed to help aid cybersecurity in the areas of reconnaissance and threat evaluation.
ONYPHE is an Attack Surface Management & Attack Surface Discovery solution built as a Cyber Defense Search Engine. We scan the entire Internet and Dark Web for exposed assets and crawl the links just like a Web search engine. Our data is searchable with a Web form or directly from our numerous APIs.
Attack surface database of the entire Internet. Search info by domain, ip, technology, host, tag, port, city and more.
Search engine for every domain and host available on the Internet (like Shodan and Censys): - search by IP, domain DNS-servers, whois info, certificates (with filtering by ports and protocols) - 2500 requests/month free; - API and python lib "netlas".
Cyberspace surveying and mapping system
Search engine for all public IPs on the Internet. Search by (for ex): html title, html meta tags and html keyword tags; whois city and country; ssl expired date; CVE id and MANY more
Synapsint is a 100% free service, the data that is presented for each search is the result of consulting different intelligence services, search engines, datasets, etc. You will find a lot of information related to a domain, a IP Address or to an ASN. Information like metatags, web site records,…
Scaling Network Scanning
Search engine indexing public information and an open reporting platform linked to the results
A partially free online tool that allows to collect search results from different search engines (Alexandria, Yahoo, Wikispecies, Yep, Wiby etc) and export them to JSON/TXT.
Data broker providing a Web search interface for discovering the email addresses and other organizational details of a company.
Find verified email addresses and automate email outreach.
Phonebook lists all domains, email addresses, or URLs for the given input domain. You are searching 121 billion records.
Find email addresses for given company.
A free tool to search for employees' emails by company domain. Partially free (only 25 emails can be viewed)
Find email addresses and phone numbers for professionals.
Email osint tool
Tool that provides valuable information on any email address
Analyses the company's mail format.
Email OSINT & Password breach hunting tool
Search emails from a domain through search engines
Gather emails, subdomains, hosts, employee names, open ports and banners from different public sources like search engines, PGP key servers and SHODAN computer database.
Find Verified Emails
email finder
person finder
Recursive recon engine and framework that can enumerate subdomains, DNS records, port scan, grab TLS certs, spider websites, and collect email addresses.
Toolkit of 51 modules (for collecting domain/IP information - cookie_brute, wappalyzer, sslcert, leakix, urlscan, wayback (full list in the picture)
Fast and powerfull to enumerate subdomains (50+ passive results ).
Passive subdomain continous monitoring tool
Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting
The OWASP Amass Project performs network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.
Gather emails, subdomains, hosts, employee names, open ports and banners from different public sources like search engines, PGP key servers and SHODAN computer database.
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
Chase subdomains by parsing the results of Google and Yandex search results
Enumerate directories, files, subdomains or parameters without leaving evidence on the target's serve
SubGPT looks at subdomains you have already discovered for a domain and uses BingGPT to find more.
Fast and customizable subdomain wordlist generator using DSL.
Recursive recon engine and framework that can enumerate subdomains, DNS records, port scan, grab TLS certs, spider websites, and collect email addresses.
securitytrails api
Historical and current WHOIS, historical and current DNS records, similar domains, certificate information and other domain and IP related API and tools.
Online versions of popular command line #osint tools: Amass, SubFinder, AssetFinder, GAU, DNSX
Phonebook lists all domains, email addresses, or URLs for the given input domain. You are searching 121 billion records.
Online network scanning tools including Nmap, subdomain finder, and more.
A subdomain finder is a tool used to find the subdomains of a given domain.
Discover hidden subdomains with unparalleled accuracy and speed
Simple #golang tool to fetch all known website URLs from: WayBackMachine, AlienVault's Open Threat Exchange, Common Crawl, URLScan
A command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact directl
A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.
a recon tool that allows searching on URLs that are exposed via shortener services
Search archived links to domain in Wayback Machine and Common Crawl (+ Urlscan and Alien Vault OTX).
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
Gather emails, subdomains, hosts, employee names, open ports and banners from different public sources like search engines, PGP key servers and SHODAN computer database.
Enumerate directories, files, subdomains or parameters without leaving evidence on the target's serve
Gathers links and analyses content
Tool that allows users to extract various personal information from a website.
Recursive recon engine and framework that can enumerate subdomains, DNS records, port scan, grab TLS certs, spider websites, and collect email addresses.
The tool extracts relevant information such as titles, URLs, and potential mentions of the query in the results.
Find any alphanumeric snippet, signature or keyword in the web pages HTML, JS and CSS code.
NerdyData will help you find which websites use certain SaaS technologies.
Search engine for @github, @gitlab, @bitbucket, @GoogleCode and other source code storages
Historical and current WHOIS, historical and current DNS records, similar domains, certificate information and other domain and IP related API and tools.
A partially free website research tool. Collects detailed information about IP, whois, ssl, dns, ports, threats reports, geolocation, cookies, metadata (fb app id etc). Make screenshots and many others
One step ahead of your adversary with high-fidelity, efficient and actionable cyber threat intelligence
Open Threat Exchange is the neighborhood watch of the global intelligence community. It enables private companies, independent security researchers, and government agencies to openly collaborate and share the latest information about emerging threats, attack methods, and malicious actors,…
Domain intelligence for DNS, WHOIS/RDAP, TLS, subdomains, reputation, redirects, and typosquatting.
A Free cybercrime intelligence toolset that can indicate if a specific APK package was compromised in an Infostealer malware attack.
The Hurricane Electric BGP Toolkit is free to use. Look up ASN from IP address
Quickly lookup updated information about specific Autonomous System Number (ASN), Organization, CIDR, or registered IP addresses (IPv4 and IPv6) among other relevant data
Reverse IP Lookup Find all sites hosted on a given server. Domain / IP. Reverse Whois Lookup Find domain names owned by an individual or company.
Historical and current WHOIS, historical and current DNS records, similar domains, certificate information and other domain and IP related API and tools.
NAPALM FTP Indexer lets you search and download files located on public FTP servers.
is a port scanner built with shodan.io's free API. It takes same command line arguments as Nmap and produces the same output which makes it a drop-in replacament for Nmap.
| #SemiOSINT
Automate Google Hacking Database scraping.
The Exploit Database is a CVE compliant archive of public exploits and corresponding vulnerable software, developed for use by penetration testers and vulnerability researchers.
Compiles Google dorks to search on LinkedIn, Dribbble, GitHub, Xing, StackOverflow, Twitter
Custom queries in Google
Maigret collect a dossier on a person by username only, checking for accounts on a huge number of sites and gathering all the available information from web pages.
API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites
Snoop Project One of the most promising OSINT tools to search for nicknames. Over 4000+ sites (THE BEST ONE)
Python library and CLI for accurately querying username and email usage on online platforms.
Recon-ng is a full-featured Web Reconnaissance framework written in Python. Recon-ng has a look and feel similar to the Metasploit Framework.
Online tool to get Google and Skype account information by email, phone number or nickname (free). + search for accounts in other services (paid).
Python tool for automated lookups on Spanish white pages (PaginasBlancas.es) to find phone numbers and addresses
+ Web Demo
Useful tool to track location or mobile number.
a service specifically designed to Track Mobile Number, Location on Google Map including information such as the owner's Name,Location,Country,Telecom provider.
Online tool to get Google and Skype account information by email, phone number or nickname (free). + search for accounts in other services (paid).
Reverse lookup search engine for email and phone numbers
free base of access points
Information gathering tool - OSINT.
Th3Inspector 🕵️ Best Tool For Information Gathering 🔎.
is the ultimate searching tool that is here to assist anyone looking for specific information through vast amounts of websites, search engines, and data collectors.
list of popular services that might be used in organizations. By having an account of the user - you can try to find entry points to the organization data. #semiosint
Repository with information related to Cloud Osint
awesome-selfhosted/awesome-selfhosted
A list of Free Software network services and web applications which can be hosted on your own servers
lissy93/awesome-privacy
🦄 A curated list of privacy & security-focused software and services
vavkamil/awesome-bugbounty-tools
A curated list of various bug bounty tools
ashishb/android-security-awesome
A collection of android security related resources
edoardottt/awesome-hacker-search-engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
qazbnm456/awesome-web-security
🐶 A curated list of Web Security materials and resources.