
Passive OSINT triage console for email, username, domain, IP, and crypto wallet reconnaissance. Features case management, curated resource links, and exportable reports for defensive research.
Open-Source Recon Console
Built for Hunters, Not Browsers.
OSINT Menace is a Defensive Thinking Project.
OSINT Menace is a Dockerized Python web application for passive, case-driven OSINT triage. It gives analysts a simple cyberpunk-styled interface for running common open-source pivots, reviewing results, saving only the useful findings to cases, and exporting polished reports.
The tool is designed for defensive research, digital footprint review, investigation note-taking, and authorized security work. It favors passive lookups, generated source links, public records pivots, DNS/RDAP information, certificate transparency, wallet explorers, and analyst-controlled case management.
This is an early local build intended to grow into a fuller site later. The current version is useful as a local analyst console and Docker-hosted prototype.
data/cases.OSINT Menace is intentionally conservative by default.
Included by default:
Excluded by default:
Auto mode accepts mixed targets separated by new lines, commas, or semicolons. It detects likely target types and runs the matching modules.
Examples:
[email protected]
John P. Smith
example.com
1.1.1.1
0x0000000000000000000000000000000000000000
Email searches include:
Username searches include:
{username}.Phone searches include:
Signal and Life360 account discovery are intentionally not automated.
Full-name searches include:
Domain searches include:
IP searches include:
Wallet searches include:
Cases are the working folders for an investigation. They are stored in:
data/cases/
The case workflow supports:
Each case can be exported in three formats:
JSON: machine-readable case data.Markdown: lightweight report text.HTML Report: styled final report page with metadata, summaries, findings, links, notes, and print support.The /osint-links page includes a curated set of OSINT categories and links derived from:
https://start.me/p/L1rEYQ/osint4all
Credit is shown at the bottom of the OSINT Links page. The local catalog is stored at:
data/catalog/osint_links.json
The default catalog excludes obviously unsafe identity-generation, onion mirror, and scraped-data entries.
Health check:
curl http://localhost:8088/health
Run a search:
curl -sS http://localhost:8088/api/search \
-H 'Content-Type: application/json' \
-d '{"search_type":"auto","query":"[email protected]\nexampleuser\nexample.com"}'
Supported search_type values:
auto
email
username
phone
name
domain
ip
wallet
.
├── app.py # Flask routes, case management, reports, API
├── osint_tool.py # Passive OSINT modules and helper functions
├── Dockerfile # Python/Gunicorn container
├── docker-compose.yml # Local service definition
├── requirements.txt # Python dependencies
├── INSTALL.md # Installation and operations guide
├── README.md # Product and developer overview
├── data/
│ ├── cases/ # Saved case JSON files
│ └── catalog/ # OSINT Links catalog
├── reference_scripts/ # Optional local reference notes/archives
├── static/
│ └── styles.css # Cyberpunk UI styling
└── templates/ # Flask/Jinja HTML templates
The following GitHub projects were reviewed as reference material for workflow ideas, target categories, UI/reporting concepts, defensive boundaries, or passive pivot patterns. OSINT Menace does not present these credits inside run results, but they are documented here for attribution and project history.