Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
omnibus — The OSINT Omnibus (beta release) | Kitploit
Tools/GitHubGitHub/inquest/omnibus
Indicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)ReconnaissanceInformation GatheringThreat Intelligence
GitHubinquest/omnibus

omnibus

The OSINT Omnibus (beta release)

View Repository
35976186 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

OSINT Omnibus

  • Developed & maintained by InQuest
  • Release
  • Rawsec's CyberSecurity Inventory

Table of Contents

  • OSINT Omnibus
    • Omnibus
      • Documentation
      • Vocabulary
      • Running Omnibus
        • API Keys
      • Interactive Console
      • Artifacts
        • Overview
        • Creating & Managing Artifacts
      • Sessions
      • Modules
      • Machines
      • Reporting
      • Monitoring Modules

OSINT Omnibus

  • Developed & maintained by InQuest
  • Release
  • Rawsec's CyberSecurity Inventory

Omnibus

An Omnibus is defined as a volume containing several novels or other items previously published separately and that is exactly what the InQuest Omnibus project intends to be for Open Source Intelligence collection, research, and artifact management.

By providing an easy to use interactive command line application, users are able to create sessions to investigate various artifacts such as IP addresses, domain names, email addresses, usernames, file hashes, Bitcoin addresses, and more as we continue to expand.

This project has taken motivation from the greats that came before it such as SpiderFoot, Harpoon, and DataSploit. Much thanks to those great authors for contributing to the world of open source.

The application is written with Python 2.7 in mind and has been successfully tested on OSX and Ubuntu 16.04 environments.

This is a beta of the final application and as such there may be some bugs or other weirdness during usage. For the most part Omnibus is fully functional and can be used to begin OSINT investigation right away.

Contribution

Omnibus is built in a modular manner that allows the easy addition of OSINT data source modules and import/export modules. Each module per category is included in a single directory, and by adding a few lines of code, your module could be the next!

As the Wiki continues to grow, we will have full examples of how to write custom plugins.

If you happen to notice any bugs or other issues, please create an Issue and/or Pull Request. We would also love for community support in creating more modules and expanding the Omnibus use-cases. Forks and Pull Requests for new features are more than welcome!

Documentation

This README file serves as a quick overview of Omnibus and its features. Full documentation is available in the 'docs' folder of this repository.

Vocabulary

Before we begin we'll need to cover some terminology used by Omnibus.

  • Artifact:
    • An item to investigate
    • Artificats can be created in two ways:
      • Using the new command or by being discoverd through module execution
  • Session:
    • Cache of artifacts created after starting the Omnibus CLI
    • Each artifact in a session is given an ID to quickly identify and retrieve the artifact from the cache
    • Commands can be executed against an artifact either by providing it's name or it's corresponding session ID
  • Module:
    • Python script that performs some arbitirary OSINT task against an artifact

Running Omnibus

Starting up Omnibus for investigation is a simple as cloning this GitHub repository, installing the Python requirements using pip install -r requirements.txt and running python omnibus-cli.py.

Omnibus Shell - Main Startup Alt text

For a visual reference of the CLI, pictured above is the Omnibus console after a new session has been started, 2 artifacts have been added to a session, and the help menu is shown.

API Keys

You must set any API keys you'd like to use within modules inside the omnibus/etc/apikeys.json file. This file is a JSON ocument with placeholders for all the services which require API keys, and is only accessed by Omnibus on a per module basis to retrieve the exact API key a module needs to execute.

It should be noted that most of the services requiring API keys have free accounts and API keys. Some free accounts may have lower resource limits, but that hasn't been a problem during smaller daily investigations or testing the application.

A handy tip: Use the cat apikeys command to view which keys you do in fact have stored. If modules are failing or returning no results, check here first to ensure your API key is properly saved.

Interactive Console

When you first run the CLI, you'll be greeted by a help menu with some basic information. Omnibus tries to use commands that mimic some common Linux commands for familiarity and ease of use. For example, the command cat to show information about and artifact, rm to remove an artifact from the database, ls for view current session artifacts, and output redirection support for any command using the > character.

As an example of output redirection, if you wish to retrieve the details of an artifact named "inquest.net" saved to a JSON file on your local disk you'd simply run the command: cat inquest.net > inquest-report.json and there it would be! This feature also works with full file paths instead of relative paths.

The high level commands used in Omnibus most often are:

  • session
    • start a new session
  • new <artifact name>
    • create a new artifact for investigation
  • modules
    • display list of available modules
  • open <file path>
    • load a text file list of artifacts into Omnibus as artifacts
  • ls
    • show all active artifacts
  • rm
    • remove an artifact from the database
  • wipe
    • clear the current artifact session
  • cat <artifact name | session id>
    • view beautified JSON database records
  • <module name> <artifact name | session id>
    • run a module against an artifact to view & store the results
    • newly discovered artifacts from a modules executed are added as children to the original artifact and created in the database as their own new artifacts
  • <machine name> <artifact name | session id>
    • run all modules for an artifacts type against the specified artifact
    • all results are displayed in the output and stored to the database
    • provides an easy method to collect bulk information all at once

If you ever need a quick reference on the different commands available for different areas of the application there are sub-help menus for this exact purpose. Using these commands will show you only those commands available relevant to a specific area:

  • general
    • overall commands such as help, history, quit, set, clear, banner, etc.
  • artifacts
    • display commands specific to artifacts and their management
  • sessions
    • display helpful commands around managing sessions
  • modules
    • show a list of all available modules

Artifacts

Overview

Most cyber investigations begin with one or more technical indicators, such as an IP address, file hash or email address. After searching and analyzing, relationships begin to form and you can pivot through connected data points. These data points are called Artifacts within Omnibus and represent any item you wish to investigate.

Artifacts can be one of the following types:

  • IPv4 address
  • FQDN
  • Email Address
  • Bitcoin Address
  • File Hash (MD5, SHA1, SHA256, SHA512)
  • User Name
Download Tool