osint-terminal
454 OSINT recon tools + server-side entity correlation & person sweeps. Keyless.
- 1.1.0
- Version
- remote
- Transport
- 200
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 200 tools scanned
- metadata: scanned
No findings.
Tools (200)
dns
DNS Records: A/AAAA/MX/NS/TXT/CNAME/SOA/CAA records
whois
WHOIS / RDAP: Registration, status, nameservers, DNSSEC
subdomains
Subdomains: Certificate-transparency subdomain discovery
tls
TLS Certificate: Live cert: issuer, validity, SANs, cipher
headers
HTTP / Security: Headers + security-header scorecard
wayback
Wayback Machine: Archive.org snapshot history
ipgeo
IP Geolocation: Geo, ISP, ASN, proxy/hosting flags
reversedns
Reverse DNS: PTR record / hostname
username
Username Hunter: Presence across 16 public sites
github
GitHub Recon: Profile, repos, languages
email
Email Intel: Gravatar, MX, disposable detection
internetdb
Shodan InternetDB: Open ports, CPEs, tags, known CVEs for a host
portscan
Port Scan: TCP connect scan: common + camera ports
camera
Camera Exposure: RTSP/ONVIF + camera-port exposure (per-target)
ipwhois
IP WHOIS / RDAP: Network owner, range, abuse contact
asn
ASN / BGP: ASN details or prefixes for an IP
reverseip
Reverse IP: Other domains sharing the host
dnsbl
DNS Blocklist: Spamhaus/Barracuda/SORBS/SpamCop check
tor
Tor Exit Check: Is the IP a known Tor exit node
cloud
Cloud Provider: AWS/GCP/Azure/etc. detection + hosting flag
emailsec
Email Security: SPF / DMARC / DKIM posture
robots
robots.txt: Disallowed paths + sitemaps
tech
Tech Fingerprint: CMS/framework/server detection
favicon
Favicon Hash: favicon md5/sha256 for pivoting
redirects
Redirect Tracer: Full HTTP redirect chain
certhistory
Cert History: crt.sh issuer timeline & counts
social
Social Links: Direct profile URLs across 20 platforms
mac
MAC Vendor: OUI → hardware vendor
crypto
Crypto Address: BTC/ETH balance & tx history
dorks
Search Dorks: Builds manual OSINT search links
urlscan
urlscan.io: Past scans, verdicts, infra (IP/ASN/server) for a site
greynoise
GreyNoise: Is the IP a known internet scanner — benign/malicious
typosquat
Typosquat Finder: Look-alike domains that currently resolve
securitytxt
security.txt: RFC 9116 disclosure policy & contacts
keybase
Keybase: Crypto identity + linked social proofs
phone
Phone Number: E.164 country/region (offline)
decode
Decoder: Auto base64/hex/URL-decode + refang
jwt
JWT Decoder: Header + claims (no signature verify)
hashid
Hash Identifier: Guess hash algorithm from length/charset
cidr
CIDR Calculator: Subnet calc: network, mask, host range, count (offline)
gitexposed
Exposed Files: .git/.env/backup exposure (per-target)
cors
CORS Check: Origin-reflection / wildcard misconfig
cookies
Cookie Audit: Secure/HttpOnly/SameSite flag review
dnssec
DNSSEC: Is the zone signed (AD flag + DNSKEY/DS)
pgp
PGP Key: Public key published on keys.openpgp.org
hackernews
Hacker News: Profile: karma, age, activity
gitlab
GitLab: Public user profile
dnsprop
DNS Propagation: Compare A records across Google/Cloudflare/Quad9
takeover
Subdomain Takeover: Dangling-CNAME takeover fingerprint check
sitemap
Sitemap: Fetch sitemap.xml + list URLs
waf
WAF / CDN: Detect WAF/CDN from headers & cookies
cve
CVE Lookup: CVE detail + CVSS (CIRCL, no key)
npm
npm Author: Packages published by an author
peers
ASN Peers: Upstream/downstream BGP neighbours
urlparse
URL Parse: Parse URL into components + query params
epoch
Epoch Time: Unix timestamp <-> UTC datetime
tlsscan
TLS Versions: Which SSL/TLS protocols the host accepts
revgeo
Reverse Geocode: lat,lon -> address (OSM Nominatim)
suntimes
Sun Times: Sunrise/sunset/twilight for a coordinate (UTC)
iban
IBAN Validate: ISO 13616 checksum + country/length (offline)
bin
Card BIN: Issuer/scheme/country from card BIN (binlist)
uuid
UUID Parser: Version/variant + v1 timestamp/MAC (offline)
isbn
ISBN Book: Book metadata (OpenLibrary) + checksum
txhash
Crypto Tx: BTC/ETH transaction detail (blockchair)
bluesky
Bluesky: AT Protocol public profile
chesscom
Chess.com: Public player profile + ratings
wikipedia
Wikipedia Summary: Wikipedia REST summary: extract, type, coords (no key)
httping
HTTP Ping: Reachability + response timing
links
Link Extractor: All links + external domains + emails on a page
pwstrength
Password Strength: Offline entropy/strength estimate
entropy
Shannon Entropy: Per-char entropy — flags secrets/keys
lobsters
Lobste.rs: Public user profile + karma
caa
CAA Records: Which CAs may issue certs for the domain
mtasts
MTA-STS: Inbound-mail TLS enforcement policy
bimi
BIMI: Brand-indicator (logo) DNS record
domainage
Domain Age: Days since registration (phishing signal)
luhn
Luhn Check: Validate card/IMEI Luhn checksum (offline)
pypi
PyPI Package: Python package metadata + links
crates
crates.io: Rust crate stats + downloads
rubygems
RubyGems: Ruby gem stats + downloads
packagist
Packagist: PHP/Composer package stats (vendor/pkg)
npmpkg
npm Package: npm package version, deps, maintainers
btcaddr
BTC Address: Bitcoin balance/tx via mempool.space
ethaddr
ETH Address: Ethereum balance/tx + contract flag
ghrepo
GitHub Repo: Stars/langs/license/activity (owner/repo)
ghgists
GitHub Gists: Public gists for a user
ghorg
GitHub Org: Public org profile
mastodon
Mastodon: Resolve user@instance via WebFinger
geohash
Geohash: lat,lon -> geohash (offline)
ipv6
IPv6 Validator: IPv6 parser, expander, classifier
transform
Text Transforms: rot13/base32/morse/reverse (offline)
cpfcnpj
CPF / CNPJ: Brazilian doc checksum (offline)
color
Color Parser: hex/rgb -> rgb/hsl + nearest name (offline)
doh
DoH Records: Uncommon DNS records (HTTPS/SVCB/TLSA/SRV/NAPTR…)
tlsa
DANE / TLSA: Certificate-pinning DANE records on :443
dnsverify
TXT Verifications: Which SaaS a domain is enrolled in (TXT tokens)
subbrute
Subdomain Brute: Resolve a common-subdomain wordlist (per-target)
hstspreload
HSTS Preload: Is the domain on the browser HSTS preload list
wpscan
WordPress Scan: WP version + author enum via REST (per-target)
wellknown
.well-known Scan: Which /.well-known/* resources exist
graphql
GraphQL Probe: Find GraphQL endpoint + introspection (per-target)
swagger
Swagger / OpenAPI: Exposed API docs at common paths (per-target)
s3buckets
Cloud Buckets: S3/GCS/Azure buckets named for the domain
httpmethods
HTTP Methods: Allowed methods + TRACE/risky-verb check
dirlisting
Directory Listing: Open directory-index exposure (per-target)
adstxt
ads.txt: Ad-tech sellers declared in ads.txt
feeds
RSS / Atom Feeds: Discover syndication feeds on a site
manifest
PWA Manifest: Web app manifest: name, icons, theme
wpplugin
WP Plugin Info: WordPress.org plugin version/install stats
abusecontact
Abuse Contact: Authoritative abuse email (RIPEstat finder)
asrank
AS Rank (CAIDA): Global ASN ranking + customer cone size
peeringdb
PeeringDB: Network type, traffic, IX/facility presence
rpki
RPKI / ROA: Route-origin validation for the covering prefix
ens
ENS Resolve: ENS name <-> ETH address + avatar
ethcontract
ETH Contract: Contract check + Sourcify verified source
osv
OSV Vulns: Known package vulns (OSV.dev). 'eco:name'
depsdev
deps.dev: Open-source insights: versions, default
gomod
Go Module: Go module latest version (module proxy)
nuget
NuGet: .NET package stats + downloads
maven
Maven Central: Java artifact: 'group:artifact' or name
hexpm
Hex.pm: Elixir/Erlang package downloads
cdnjs
cdnjs: Hosted JS library version + assets
npmdl
npm Downloads: npm download counts day/week/month
brew
Homebrew: Formula/cask version, deps, installs
pypistats
PyPI Downloads: PyPI recent download counts
devto
dev.to: Forem/dev.to public profile
medium
Medium: Author feed: recent post titles
orcid
ORCID: Researcher record (0000-000X-…)
codeberg
Codeberg: Codeberg/Gitea public user
wikidata
Wikidata Search: Search Wikidata entities by label (no key)
musicbrainz
MusicBrainz: Artist search: type, country, MBID
stackoverflow
Stack Overflow: SO/SE user search by display name
hashnode
Hashnode: Blogger profile: followers, posts
gravatarfull
Gravatar Profile: Full public Gravatar profile + linked accounts
osmuser
OpenStreetMap User: Contributor: last edit + changeset
feodo
Feodo C2: abuse.ch botnet C2 blocklist (key-free)
openphish
OpenPhish: Community phishing-URL feed membership
kev
CISA KEV: Is the CVE actively exploited (KEV catalog)
epss
EPSS Score: Exploitation probability (FIRST EPSS)
circlhash
Hash Lookup: Known-file lookup (CIRCL hashlookup)
weather
Weather: Current weather at a coordinate (Open-Meteo)
elevation
Elevation: Ground elevation in metres (Open-Meteo)
vin
VIN Decoder: NHTSA vPIC vehicle decode (make/model/plant)
lei
LEI Lookup: GLEIF legal-entity record by LEI code
orgname
Company → LEI: Fuzzy company-name search → candidate LEIs
cpe
CPE → CVEs: NVD: recent CVEs affecting a CPE 2.3 string
cvedetail
CVE Detail: Full CVE record (CVSS, refs) via CIRCL
port
Port Reference: Service + exposure notes for a port number
ssh
SSH Banner: Per-target SSH server banner / version
hostsearch
Host Search: Forward-DNS host enumeration for a domain
peeringnet
PeeringDB Net: Peering policy / traffic / IX presence for ASN
nearbywiki
Nearby Places: Wikipedia places near a coordinate
doi
DOI Resolver: Crossref publication metadata for a DOI
crossrefauthor
Crossref Author: Works by author/keyword (Crossref)
orcidworks
ORCID Works: Recent publications for an ORCID iD
isbnmeta
ISBN Metadata: Book title/authors/subjects (OpenLibrary)
sopostuser
StackOverflow User: SO profile + reputation by numeric id
breachsearch
Breach Catalog: Public HIBP breach metadata search
feodoips
Feodo C2 List: Is IP on abuse.ch Feodo botnet C2 list
urlscansearch
urlscan Archive: Public urlscan.io scan history for a domain
commoncrawl
Common Crawl: Captures of a domain in Common Crawl index
ipfull
IP Full Profile: Rich geo+ASN+proxy/mobile/hosting flags
geocode
Geocode: Place name → coordinates (OSM Nominatim)
revgeocode
Reverse Geocode: Coordinates → nearest address (OSM)
macvendorlookup
MAC Vendor: OUI → hardware vendor (macvendors.com)
dnsmx
MX (DoH): MX records via Google DNS-over-HTTPS
fxrate
FX Rates: Live exchange rates for a currency code
country
Country Profile: World Bank country profile by ISO code
wikidatasearch
Wikidata Search: Free-text → Wikidata entities
spdxlicense
SPDX License: SPDX license id → name + OSI status
gitignore
gitignore Template: GitHub .gitignore template for a language
ghcommits
GitHub Commits: Recent commits for owner/repo
ghpubkeys
GitHub SSH Keys: A user's public SSH keys (.keys)
ghkeysgpg
GitHub GPG Key: Whether a user publishes a GPG key
npmdownloads
npm Downloads: npm package download counts, last week + month (no key)
pypiproject
PyPI Project: PyPI version/license/links
dockerhub
Docker Hub Repo: Docker Hub repo pulls, stars, last update (no key)
httpstatus
HTTP Status: Explain an HTTP status code (offline)
useragent
UA Parser: Parse a User-Agent into OS/browser (offline)
asnprefixes
ASN Prefixes: All announced prefixes for an ASN (RIPEstat)
ripewhois
RIPE Network Info: Covering prefix + origin ASN (RIPEstat)
rdapip
RDAP IP: Authoritative RDAP record for an IP
isotime
Timestamp Convert: Parse/convert a timestamp (offline)
nvdcve
NVD CVE Detail: Full NVD record: CVSS, CWE, references
ghadvisory
GitHub Advisories: Security advisories for an ecosystem (pip/npm/…)
otxdomain
OTX Domain Rep: AlienVault OTX threat pulses for a domain
otxip
OTX IP Rep: AlienVault OTX threat pulses for an IP
hosthunt
Host Search: Forward-DNS host/subdomain map (HackerTarget)
ghlanguages
Repo Languages: Language byte-breakdown for owner/repo
githubsearch
GitHub Repo Search: Search GitHub repos by keyword
githubgists
GitHub Gists: A user's public gists
golangpkg
Go Module: Latest version of a Go module
rubygemrev
Gem Rev-Deps: Reverse dependencies of a RubyGem
cratedownloads
Crate Downloads: Download totals for a Rust crate
openalexwork
OpenAlex Work: Scholarly work: citations, concepts, OA
openalexauthor
OpenAlex Author: Author works count, h-index, institution
semanticscholar
Semantic Scholar: Paper TLDR, citations, influence
datacite
DataCite Search: Research datasets/DOIs by keyword
restcountry
Country Detail: Capital/region/income by name or ISO (World Bank)
wikisummary
Wikipedia Summary: Page extract/description for a topic