Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
awesome-osint-arsenal — OSINT & recon toolkit // 100+ tools, one-command installer, SOCMINT, GEOINT, network recon, dark web, forensics & more. | Kitploit
Tools/GitHubGitHub/rawfilejson/awesome-osint-arsenal
OSINT (Open Source Intelligence)ReconnaissanceForensicsInformation GatheringDigital ForensicsCTFPenetration TestingLearning & EducationRed TeamingCurated ResourcesLabs & Practice
GitHub
1.7k2621 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
rawfilejson/awesome-osint-arsenal

awesome-osint-arsenal

OSINT & recon toolkit // 100+ tools, one-command installer, SOCMINT, GEOINT, network recon, dark web, forensics & more.

View Repository
OSINT Arsenal

🔍 AWESOME OSINT ARSENAL

The Ultimate Open-Source Intelligence + Security Toolkit


Tools Categories Version Updated Stars


751+ tools · 50 categories · Multi-distro installers · Georgian OSINT · Termux support

The most comprehensive OSINT and security toolkit on the internet — every tool with installation instructions or a verified link.

Buy Me a Coffee


⚡ Get everything in one command

root@kitploit:~
git clone https://github.com/rawfilejson/awesome-osint-arsenal && cd awesome-osint-arsenal && sudo bash install.sh

🎯 Or pick just what you need

root@kitploit:~
sudo bash osint.sh        # 🔍 OSINT only (Sherlock, Maigret, Amass, …)
root@kitploit:~
sudo bash redteam.sh      # ⚔️  Red team (Sliver, BloodHound, Mimikatz, Nuclei, …)
root@kitploit:~
sudo bash blueteam.sh     # 🛡️  Blue team (Wazuh, Sigma, Suricata, Velociraptor, …)
root@kitploit:~
sudo bash forensics.sh    # 🔬 DFIR + RE (Volatility, Ghidra, radare2, …)
root@kitploit:~
sudo bash hardware.sh     # 🔌 Hardware + SDR (binwalk, hackrf, openocd, …)
root@kitploit:~
sudo bash labs.sh         # 🎓 Vulnerable apps for practice (DVWA, Juice Shop, …)
root@kitploit:~
bash termux.sh            # 📱 Android (Termux subset, no sudo needed)

Works on Kali, Debian, Ubuntu, Parrot, Mint, Pop!_OS (best — apt) Partial on Arch / Manjaro / Fedora / RHEL (auto-detected, falls back to git/pip/go) Termux subset on Android



[!IMPORTANT]

🙏 A note before you fork

This repo has 751 tools across 50 categories. Keeping that current — links, install commands, new tools every week — is a lot for one person.

If nobody helps, parts of this list will go stale. That's just real talk.

How you can help in 30 seconds:

  • ⭐ Star the repo (more stars = more contributors find it)
  • 🐛 Spotted a dead link? Open an issue, takes 1 minute
  • ☕ Buy me a coffee so weekends keep going to this
  • 📢 Share it — tweet, Discord, wherever the security crowd hangs out

If something's broken: don't just complain — open an issue or PR. That's how this stays useful.


[!WARNING] DISCLAIMER: This repository is for educational and authorized security research only. Always obtain written permission before testing systems you do not own. The authors are not responsible for any misuse of the tools or techniques listed here. See the full Legal Disclaimer at the bottom.


📋 Table of Contents

🔭 Reconnaissance & Discovery — click to expand
  1. Username & Social Media OSINT
  2. Email OSINT Tools
  3. Phone Number OSINT
  4. Domain & IP OSINT
  5. Geolocation & Maps OSINT
  6. Image & Video OSINT
  7. Facial Recognition & People Search
  8. Social Media Monitoring
💥 Data Breaches & Leaks — click to expand
  1. Data Breach & Leak Search Engines
  2. WikiLeaks, DDoSecrets & Whistleblower Platforms
  3. Password Cracking & Credential Tools
🕶️ Dark Web & Privacy — click to expand
  1. Dark Web Search Engines & Tools
  2. Anonymous & Privacy Tools
⚔️ Offensive Security (Authorized Testing Only) — click to expand
  1. Web Application OSINT & Scanning
  2. Social Engineering & Phishing
  3. Vulnerability Scanning & Exploitation
  4. Network & Wireless Tools
  5. Mobile Hacking & Phone Exploitation
🧠 Intelligence & Analysis — click to expand
  1. AI-Powered OSINT & Free AI Tools
  2. Financial & Corporate Intelligence
  3. Vehicle, Property & Public Records
  4. Metadata & Digital Forensics
👁️ Surveillance & Dorking — click to expand
  1. IP Camera & Webcam OSINT
  2. Google Dorking Bible
  3. Credential & Data Dorking
  4. IP Tracking & Geolocation Links
🌐 Community & Platforms — click to expand
  1. Telegram OSINT Bots & Channels
  2. Russian OSINT & Person Lookup Services
  3. Social Media Searcher Platforms
🧰 Toolkits & Frameworks — click to expand
  1. Termux Hacking Toolkit (Complete)
  2. Kali Linux OSINT Toolkit
  3. All-in-One Hacking Frameworks
  4. Wordlist Generation & Brute Force
🖥️ Hardware & Operating Systems — click to expand
  1. Hardware Hacking Tools
  2. OSINT Operating Systems
👨‍💻 Developer & Learning — click to expand
  1. OSINT APIs & Developer Tools
  2. Browser Extensions for OSINT
  3. OSINT Learning Resources
  4. Awesome OSINT GitHub Repos
⚡ Quick Reference — click to expand
  1. One-Click Install Scripts
  2. Top 50 Must-Have Tools
⚔️ Red Team & Blue Team — click to expand
  1. Red Team & Offensive Security
  2. Blue Team & Defensive Security
  3. Threat Intel Platforms
🔬 Forensics, Hardware & Training — click to expand
  1. Digital Forensics & Reverse Engineering
  2. Training, Labs & CTF
  3. Bug Bounty Platforms
📚 Knowledge & Curated Additions — click to expand
  1. Learning Resources
  2. Extra Tools (curated additions)
🇬🇪 Country-Specific OSINT — click to expand
  1. Georgian OSINT Arsenal

⚙️ Installation Guide

Quick install — Kali / Debian / Ubuntu / Parrot

root@kitploit:~
git clone https://github.com/rawfilejson/awesome-osint-arsenal
root@kitploit:~
cd awesome-osint-arsenal
root@kitploit:~
sudo bash install.sh

Pick a single stack

Other Linux distros

The installers auto-detect your package manager:

What every installer does

  • Detects your distro and uses the right package manager
  • Skips what's already installed (idempotent — safe to re-run)
  • Color output: 🟢 installed · 🟡 skipped · 🔴 failed
  • Logs failures to ~/osint-install-errors.log
  • Prints a summary at the end
  • Tools cloned via git go to /opt/osint-arsenal/ (or $HOME/osint-arsenal/ on Termux)

After install — add tools to your PATH

root@kitploit:~
echo 'export PATH="$PATH:/opt/osint-arsenal"' >> ~/.bashrc
root@kitploit:~
source ~/.bashrc

Tools installed via apt/pip/go install are already on your $PATH.


📊 Stats at a Glance

🛠️ Total Tools💻 CLI Tools📁 GitHub Repos🌐 Online Platforms🤖 AI Tools
751+165+

1. Username & Social Media OSINT

🎯 Find accounts, profiles, and digital footprints across hundreds of platforms.

Pro tip: Start with Sherlock for a quick sweep, then use Maigret for depth — it covers 3000+ sites.

💻 Sherlock — Install & Usage
root@kitploit:~
# Kali Linux / Ubuntu
pip install sherlock-project
sherlock "username"

# From GitHub source (always latest)
git clone https://github.com/sherlock-project/sherlock.git
cd sherlock
pip install -r requirements.txt
python3 sherlock "username"

# Search multiple usernames at once
sherlock user1 user2 user3
💻 Maigret — Install & Usage
root@kitploit:~
pip install maigret
maigret "username"

# From source
git clone https://github.com/soxoj/maigret.git
cd maigret
pip install -r requirements.txt
python3 -m maigret "username"

# Generate HTML report
maigret "username" --html

2. Email OSINT Tools

📧 Verify emails, find linked accounts, check breach exposure, and analyze headers.

Pro tip: Holehe is free and fast. h8mail is best for breach correlation when API keys are configured.

💻 h8mail — Install & Usage
root@kitploit:~
pip install h8mail

# Basic scan
h8mail -t "[email protected]"

# With API keys (unlocks more breach sources)
# Create config.ini with your API keys from HIBP, BreachDirectory, etc.
h8mail -t "[email protected]" -k config.ini

# Scan a list of emails
h8mail -t emails.txt

3. Phone Number OSINT

📱 Identify carriers, locations, registrations, and linked accounts from phone numbers.

Pro tip: PhoneInfoga is the gold standard CLI tool. GetContact reveals how a number is saved by others.

💻 PhoneInfoga — Install & Usage
root@kitploit:~
# Binary install (Kali Linux)
curl -sSL https://raw.githubusercontent.com/sundowndev/phoneinfoga/master/support/scripts/install | bash

# Open web UI at localhost:8080
phoneinfoga serve -p 8080

# Scan from CLI
phoneinfoga scan -n "+1234567890"

# pip install (alternative)
pip install phoneinfoga

4. Domain & IP OSINT

🌐 Enumerate subdomains, query DNS records, discover IP ranges, and map attack surfaces.

Pro tip: Run amass + subfinder together for maximum subdomain coverage, then pipe into httpx to check which hosts are live.

💻 Amass + Subfinder + HTTPx — Most effective recon combo
root@kitploit:~
# Step 1: Enumerate subdomains passively (fast)
subfinder -d example.com -o subs.txt

# Step 2: Deep active enumeration (slower but more complete)
amass enum -d example.com -o amass_subs.txt

# Step 3: Combine and deduplicate
cat subs.txt amass_subs.txt | sort -u > all_subs.txt

# Step 4: Check which subdomains are live
cat all_subs.txt | httpx -status-code -title -o live_subs.txt

# Step 5: Screenshot all live hosts
cat live_subs.txt | eyewitness --web -d screenshots/

5. Geolocation & Maps OSINT

🗺️ Geolocate images, analyze satellite data, and verify photo locations.

Pro tip: Combine SunCalc (shadow analysis) + ShadowMap + Mapillary for precision image geolocation.


6. Image & Video OSINT

🖼️ Extract metadata, reverse search images, verify authenticity, and detect AI-generated content.

Pro tip: Yandex reverse image search consistently outperforms Google for finding faces and locations.

💻 ExifTool — Install & Usage
root@kitploit:~
# Install
apt-get install libimage-exiftool-perl

# Basic metadata read
exiftool image.jpg

# Extract GPS coordinates specifically
exiftool -GPSLatitude -GPSLongitude image.jpg

# Strip ALL metadata (for privacy)
exiftool -all= image.jpg

# Show all metadata groups
exiftool -a -u -g1 image.jpg

# Batch process a whole folder
exiftool /path/to/images/

7. Facial Recognition & People Search

👤 Find people across the web using photos, names, or usernames.

⚠️ Warning: Facial recognition has serious privacy and legal implications. Use only with explicit authorization.


8. Social Media Monitoring

📡 Monitor, scrape, and investigate social media accounts and communities.

Pro tip: Combine Osintgram (Instagram) + Telepathy (Telegram) + snscrape (Twitter/X) for full platform coverage.


9. Data Breach & Leak Search Engines

💥 Check if credentials, emails, or phones have been exposed in data breaches.

Pro tip: HIBP is free and safe. DeHashed and LeakCheck offer the most data for paid tiers.

💻 Pwndb — Dark Web Breach Search (requires Tor)
root@kitploit:~
# Start Tor service first
sudo systemctl start tor

# Clone pwndb
git clone https://github.com/coj337/pwndb.git
cd pwndb

# Install requirements
pip install -r requirements.txt

# Search by email
python3 pwndb.py --target [email protected]

# The .onion address (open in Tor Browser)
# pwndb2am33lno4bq.onion

10. WikiLeaks, DDoSecrets & Whistleblower Platforms

📁 Archives of leaked government, corporate, and classified documents.


11. Password Cracking & Credential Tools

🔑 Tools for authorized password auditing and credential recovery on systems you own.

💻 Hashcat — Quick Reference
root@kitploit:~
# Install
apt install hashcat

# Crack MD5 hash with wordlist
hashcat -m 0 hash.txt /usr/share/wordlists/rockyou.txt

# Crack SHA-256 with rules
hashcat -m 1400 hash.txt wordlist.txt -r rules/best64.rule

# Common hash types:
# -m 0    = MD5
# -m 100  = SHA-1
# -m 1400 = SHA-256
# -m 1800 = SHA-512crypt (Linux)
# -m 1000 = NTLM (Windows)
# -m 2500 = WPA/WPA2 (Wi-Fi)

12. Dark Web Search Engines & Tools

🕶️ Search .onion sites, darknet markets, and hidden services.

Requires: Tor Browser or Tor service running on port 9050.

💻 Setting up Tor for dark web tools
root@kitploit:~
# Install Tor
sudo apt install tor proxychains4

# Start Tor service
sudo systemctl start tor
sudo systemctl enable tor

# Test Tor is working
curl --socks5 127.0.0.1:9050 https://check.torproject.org/api/ip

# Use proxychains with any tool
proxychains4 nmap -sT target.onion
proxychains4 curl http://example.onion

# Edit /etc/proxychains4.conf if needed
# Make sure this line is present: socks5 127.0.0.1 9050

13. Anonymous & Privacy Tools

🔒 Maintain anonymity during OSINT investigations and protect your identity.

Pro tip: Use Tails OS for investigations requiring full anonymity — it leaves zero trace on disk.


14. Web Application OSINT & Scanning

🕸️ Fingerprint web technologies, discover hidden directories, and crawl for endpoints.

Pro tip: Run Whatweb first to fingerprint, then Nikto for quick vulns, then Nuclei for deep scanning.


15. Social Engineering & Phishing

🎭 Phishing simulation frameworks for authorized red team engagements.

⚠️ For authorized penetration testing and security awareness training ONLY.

💻 Zphisher — Install & Usage
root@kitploit:~
git clone https://github.com/htr-tech/zphisher.git
cd zphisher
chmod +x zphisher.sh
bash zphisher.sh

# Select template from menu (Facebook, Google, Instagram, etc.)
# Tool generates a phishing URL with Cloudflare/Serveo tunnel
# Captured credentials are saved locally

16. Vulnerability Scanning & Exploitation

💣 Frameworks for finding and verifying vulnerabilities on authorized targets.

⚠️ Always have written permission before running any of these tools.


17. Network & Wireless Tools

📶 Analyze traffic, audit Wi-Fi networks, and perform MITM on authorized targets.


18. Mobile Hacking & Phone Exploitation

📲 Android/iOS security testing for authorized assessments.


19. AI-Powered OSINT & Free AI Tools

🤖 AI tools for automating research, analyzing images, and accelerating investigations.

Pro tip: Perplexity AI is excellent for OSINT research — it cites sources so you can verify everything.

AI-Powered OSINT Tools

Free AI Tools for OSINT Research


20. Financial & Corporate Intelligence

💰 Research companies, track crypto, and uncover financial relationships.


21. Vehicle, Property & Public Records

🚗 Access public records, vehicle history, property data, and court documents.


22. Metadata & Digital Forensics

🔬 Extract hidden data, recover deleted files, and analyze digital evidence.

Pro tip: CyberChef is a must-bookmark — it handles encoding, encryption, and data manipulation all in-browser.


23. IP Camera & Webcam OSINT

⚠️ WARNING: Accessing cameras without authorization is illegal everywhere. This section is for educational awareness only — to understand how exposed devices are found so you can protect them.

Shodan Searches for Exposed Cameras

Google Dorks for Camera Discovery


24. Google Dorking Bible

🔍 Advanced search operators for finding information that isn't easily discoverable.

Pro tip: Combine multiple operators for maximum precision. Always test in a private/incognito window.

Core Operators

High-Value OSINT Dorks

Dork Generator Tools


25. Credential & Data Dorking

🗄️ Advanced dorks for finding inadvertently exposed sensitive data on the web.


26. IP Tracking & Geolocation Links

📍 Tools for tracking IP addresses through crafted links.

⚠️ For authorized use only — e.g., tracking your own email campaigns or authorized phishing simulations.

💡 Trick: Mask a logger URL using the VK redirect: https://vk.com/away.php?to=YOUR_LOGGER_URL


27. Telegram OSINT Bots & Channels

💬 Telegram-based OSINT tools, bots, and intelligence communities.

OSINT Bots

OSINT Channels

Telegram Scraping Tools


28. Russian OSINT & Person Lookup Services

🇷🇺 Services widely used in Russian-speaking OSINT communities.

VK (VKontakte) OSINT


29. Social Media Searcher Platforms


30. Termux Hacking Toolkit (Complete)

📱 Full OSINT & security toolkit setup for Android via Termux.

Initial Setup

root@kitploit:~
# First-time Termux setup
pkg update -y && pkg upgrade -y
pkg install python python2 git wget curl nmap
pip install requests colorama
termux-setup-storage

Tool List

💻 One-command Termux installer
root@kitploit:~
pkg update -y && pkg upgrade -y && \
pkg install -y python git wget curl nmap hydra perl openssh php clang make openssl && \
pip install requests colorama sherlock-project maigret holehe h8mail && \
cd ~ && \
git clone https://github.com/htr-tech/zphisher && \
git clone https://github.com/Manisso/fsociety && \
git clone https://github.com/ultrasecurity/Storm-Breaker && \
git clone https://github.com/wishihab/userrecon && \
echo "Done! All tools installed."

31. Kali Linux OSINT Toolkit

🐉 Tools pre-installed on Kali, plus recommended additions.

Pre-installed on Kali

Quick Kali Setup (additional tools)

root@kitploit:~
# From this repo's installer (recommended — installs everything)
sudo bash install.sh

# Or add specific tools manually:
sudo apt update && sudo apt install -y \
  amass subfinder httpx nuclei gobuster feroxbuster \
  spiderfoot eyewitness phoneinfoga metagoofil

pip install maigret holehe h8mail socialscan social-analyzer \
  deepface face_recognition volatility3 telepathy

32. All-in-One Hacking Frameworks

🧰 Comprehensive frameworks that bundle dozens of tools under one roof.


33. Wordlist Generation & Brute Force

📖 Build custom wordlists or use proven collections.

Pro tip: CeWL is great for targeted attacks — it generates wordlists from the target's own website.

💻 Wordlist Quick Reference
root@kitploit:~
# Use RockYou (already in Kali)
/usr/share/wordlists/rockyou.txt.gz
gunzip /usr/share/wordlists/rockyou.txt.gz

# Generate a pattern-based wordlist with Crunch
# Format: crunch <min> <max> <charset>
crunch 8 10 abcdefghijklmnopqrstuvwxyz0123456789 -o wordlist.txt

# Generate custom wordlist from a target website
cewl https://example.com -m 6 -w cewl_wordlist.txt

# Profile-based wordlist (interview the target)
python3 cupp.py -i

34. Hardware Hacking Tools

🔧 Physical devices for authorized penetration testing and hardware security research.


35. OSINT Operating Systems

🖥️ Specialized operating systems built for security research, OSINT, and privacy.


36. OSINT APIs & Developer Tools

🔌 Programmatic access to OSINT data sources for building your own tools.


37. Browser Extensions for OSINT

🧩 Must-have browser extensions for every OSINT investigator.


38. OSINT Learning Resources

📚 The best resources for learning OSINT — from beginner to professional.

📺 YouTube Channels


39. Awesome OSINT GitHub Repos

⭐ The best curated OSINT resource lists on GitHub.


40. One-Click Install Scripts

🐉 Kali Linux — Full Arsenal

root@kitploit:~
# Option 1: Direct from this repo (one command)
curl -sL https://raw.githubusercontent.com/rawfilejson/awesome-osint-arsenal/main/install.sh | sudo bash

# Option 2: Clone first (recommended — inspect before running)
git clone https://github.com/rawfilejson/awesome-osint-arsenal.git
cd awesome-osint-arsenal
sudo bash install.sh

📱 Termux (Android)

root@kitploit:~
pkg update -y && pkg upgrade -y
pkg install -y python git wget curl nmap hydra perl openssh php clang make openssl
pip install requests colorama sherlock-project maigret holehe h8mail
cd ~ && git clone https://github.com/htr-tech/zphisher && git clone https://github.com/Manisso/fsociety

🔧 Manual Kali Snippet

root@kitploit:~
sudo apt update && sudo apt upgrade -y
sudo apt install -y git python3 python3-pip golang-go nmap wireshark \
  sqlmap hydra john hashcat aircrack-ng nikto dirb wpscan \
  theharvester maltego spiderfoot set exiftool masscan whatweb \
  gobuster feroxbuster wfuzz libimage-exiftool-perl binwalk \
  foremost bulk-extractor macchanger tor proxychains4

pip3 install sherlock-project maigret holehe h8mail socialscan \
  social-analyzer phoneinfoga snscrape instaloader deepface \
  face_recognition volatility3 blackbird-osint nexfil \
  socid-extractor osrframework telepathy twayback toutatis \
  dnstwist waybackpy trufflehog

cd /opt
sudo git clone https://github.com/Manisso/fsociety
sudo git clone https://github.com/Z4nzu/hackingtool
sudo git clone https://github.com/ultrasecurity/Storm-Breaker
sudo git clone https://github.com/htr-tech/zphisher
sudo git clone https://github.com/s0md3v/Orbit
sudo git clone https://github.com/s0md3v/Photon
sudo git clone https://github.com/danielmiessler/SecLists
sudo git clone https://github.com/lgandx/Responder
sudo git clone https://github.com/commixproject/commix
sudo git clone https://github.com/opsdisk/pagodo
sudo git clone https://github.com/RedSiege/EyeWitness

41. Top 50 Must-Have Tools (Quick Reference)


☕ Liked everything above? Section 42-50 just dropped — fuel the next batch:

Buy Me a Coffee


42. ⚔️ Red Team & Offensive Security

C2 frameworks, AD attacks, exploitation kits, post-exploitation. Authorized testing only.

Pro tip: Sliver and Havoc are the modern open-source Cobalt Strike alternatives — start there before paying.


43. 🛡️ Blue Team & Defensive Security

SIEM, EDR, network monitoring, detection engineering, IR.

Pro tip: Wazuh is your free Splunk replacement. Pair it with Sigma rules + Suricata for a full SOC stack on commodity hardware.


44. 🛰️ Threat Intel Platforms

CTI platforms — open-source and enterprise.

Pro tip: MISP is free and powerful. OpenCTI gives you a STIX2-native graph DB. Both run as Docker stacks.


45. 🔬 Digital Forensics & Reverse Engineering

Disk/memory forensics, malware reverse engineering, timeline tools, binary analysis.

Pro tip: Volatility 3 + Plaso (log2timeline) + KAPE = the modern DFIR triage stack. Ghidra > IDA Free for static analysis.


46. 🎓 Training, Labs & CTF

Hands-on practice — paid platforms and free local labs.

Pro tip: Free path: TryHackMe → PortSwigger Academy → HackTheBox retired boxes. Paid path: HTB Academy + OffSec PG.


47. 🎯 Bug Bounty Platforms

Where to actually earn money from your skills.

Pro tip: Start on Bugcrowd or YesWeHack public programs — easier triage and lower competition than HackerOne H1.


48. 📚 Learning Resources

Books, courses, blogs, YouTube channels, awesome lists.

Pro tip: IppSec.rocks indexes EVERY HackTheBox walkthrough — search any retired box and watch how a pro solves it.


49. ✨ Extra Tools (curated additions)

Tools added in v2.x — modern recon, archive lookups, niche services, research-grade pivots.

Pro tip: This section gets refreshed every release — check before you reach for an older tool.


50. 🇬🇪 Georgian OSINT Arsenal (500+ resources)


Read more

Download Tool
ScriptWhat it installsUse when
osint.shOSINT tools (Sherlock, Maigret, Amass, theHarvester, …)You only do recon / investigations
redteam.shSliver, BloodHound, Impacket, NetExec, Mimikatz, Nuclei, …Authorized pentesting / red team
blueteam.shWazuh, Sigma, Suricata, Velociraptor, Atomic Red Team, MITRE CALDERASOC / detection engineering
forensics.shVolatility 3, Ghidra, radare2, Plaso, CyberChef, …DFIR / malware analysis
hardware.shbinwalk, hackrf, openocd, GNU Radio, gqrx, …RF / IoT / firmware research
labs.shDVWA, Juice Shop, WebGoat (Docker)Local practice labs
termux.shAndroid-compatible subsetPhone-based recon
DistroManagerStatus
Kali / Debian / Ubuntu / Parrot / Mint / Pop!_OSapt✅ Best — primary target
Arch / Manjaro / EndeavourOSpacman🟡 Partial (apt-only tools skip cleanly)
Fedora / RHEL / Rocky / Almadnf🟡 Partial (apt-only tools skip cleanly)
Termux (Android)pkg✅ Subset only — use bash termux.sh
macOS / Windows—❌ Use a Kali VM or WSL2
117+
461+
25+
🕶️ Dark Web🇬🇪 Georgian OSINT💥 Breach Engines⚔️ Red Team🛡️ Blue Team
15+500+39+35+24+
🔬 Forensics🔌 Hardware🎓 Training🎯 Bug Bounty📂 Total Categories
16+16+21+12+50

Buy Me a Coffee

ToolDescriptionInstall / Link
SherlockFind usernames across 400+ social networkspip install sherlock-project
MaigretAdvanced Sherlock fork — 3000+ sitespip install maigret
NamechkUsername & domain availability checkernamechk.com
WhatsMyNameWeb-based username enumerationwhatsmyname.app
SnoopUsername search (Russian-focused)pip install snoop
UserReconBash-based username findergit clone https://github.com/wishihab/userrecon.git
BlackbirdFast username search toolpip install blackbird-osint
Social AnalyzerAPI-based social media profilerpip install social-analyzer
NExfilFind profiles by usernamepip install nexfil
Socid-extractorExtract info from web pagespip install socid-extractor
GitreconGitHub OSINT reconnaissancepip install gitrecon
OSRFrameworkUsername research frameworkpip install osrframework
HoleheCheck if email is registered on 120+ sitespip install holehe
socialscanCheck email/username availabilitypip install socialscan
InvestigoUsername checker (Go-based)go install github.com/tdh8316/investigo@latest
OSINT FrameworkVisual map of all OSINT toolsosintframework.com
CheckUserNamesCheck username across multiple platformscheckusernames.com
KnowEmUsername search on 500+ sitesknowem.com
Instant Username SearchReal-time username checkerinstantusername.com
Usersearch.orgFree social network searchusersearch.org
ToolDescriptionInstall / Link
h8mailEmail OSINT & breach huntingpip install h8mail
HoleheCheck email on 120+ sitespip install holehe
theHarvesterEmail & domain harvesterpip install theHarvester
EmailAnalyzerAnalyze suspicious .eml filesgit clone https://github.com/keraattin/EmailAnalyzer
ProwlEmail & domain reconnaissancegit clone https://github.com/nettitude/Prowl
EmailHeader-AnalyzerCLI email header parser + OSINTgit clone https://github.com/Giritharram/EmailHeader-Analyzer-CLI-Python
MailHeaderDetectiveEmail header forensicsgit clone https://github.com/akajhon/MailHeaderDetective
WhatMailEmail header analysis CLIgit clone https://github.com/z0m31en7/WhatMail
mailto_analyzerEmail exposure analysispip install mailto-analyzer
InfogaEmail OSINT gatheringgit clone https://github.com/m4ll0k/Infoga
Hunter.ioFind professional emailshunter.io
Phonebook.czEmail, domain & URL searchphonebook.cz
EmailRepEmail reputation lookupemailrep.io
EpieosGet info linked to emailepieos.com
GetNotifyEmail open tracking + geolocationgetnotify.com
Snov.ioEmail finder & verifiersnov.io
MXToolboxEmail header analysis & DNS checksmxtoolbox.com
SimpleLoginEmail alias service for OSINTsimplelogin.io
Email-CheckerEmail validation toolemail-checker.net
Voila NorbertFind anyone's emailvoilanorbert.com
ToolDescriptionInstall / Link
PhoneInfogaAdvanced phone number scannerpip install phoneinfoga
IgnorantCheck phone registrations on sitespip install ignorant
GetContactSee how number is saved by othersgetcontact.com
NumVerifyPhone number validation APInumverify.com
TruecallerCaller ID & spam lookuptruecaller.com
Sync.mePhone number lookupsync.me
CallerIDTestReverse phone lookupcalleridtest.com
SpyDialerFree reverse phone lookupspydialer.com
National Cellular DirectoryPhone owner lookupnationalcellulardirectory.com
TelPoiskRussian phone directorytelpoisk.com
NumLookupFree reverse phone lookupnumlookup.com
Hlr-LookupsHLR phone number lookuphlr-lookups.com
PhoneSploitADB-based phone exploitationgit clone https://github.com/aerosol-can/PhoneSploit
ToolDescriptionInstall / Link
AmassIn-depth DNS enumerationgo install github.com/owasp-amass/amass/v4/...@master
SubfinderFast passive subdomain discoverygo install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
dnsreconDNS enumerationpip install dnsrecon
Sublist3rSubdomain enumerationpip install sublist3r
crt.shCertificate transparency searchcrt.sh
ShodanInternet-connected device searchshodan.io
CensysInternet-wide scan searchcensys.io
Criminal IPAI-powered cyber threat intelligencecriminalip.io
VirusTotalDomain/IP/file analysisvirustotal.com
SecurityTrailsDNS & domain intelligencesecuritytrails.com
IPGeoLocationIP address geolocationgit clone https://github.com/maldevel/IPGeoLocation
NmapNetwork scanner & mapperapt install nmap
MasscanFastest internet port scannerapt install masscan
WHOIS.comWHOIS domain lookupwhois.com
ViewDNSMultiple DNS toolsviewdns.info
DNSDumpsterDNS reconnaissance & mappingdnsdumpster.com
RobtexDNS lookup visualizationrobtex.com
ARIN WHOISIP registration databasewhois.arin.net
BGP ToolkitBGP/ASN/IP intelligencebgp.he.net
urlscan.ioURL/domain analysis & screenshotsurlscan.io
AbuseIPDBIP address reputation databaseabuseipdb.com
Web-CheckAll-in-one website analysisweb-check.xyz
IPinfoIP address data & geolocationipinfo.io
DB-IPIP geolocation databasedb-ip.com
ToolDescriptionLink
Google Earth ProAdvanced satellite imageryearth.google.com
Overpass TurboOpenStreetMap data queryoverpass-turbo.eu
SunCalcSun position/time calculator from photossuncalc.org
GeoGuessrGeolocation training gamegeoguessr.com
Sentinel HubSatellite imagery accesssentinel-hub.com
FIRMSNASA fire/thermal hotspotsfirms.modaps.eosdis.nasa.gov
WikimapiaCollaborative world mapwikimapia.org
OpenStreetMapFree world mapopenstreetmap.org
GeoSpyAI-powered image geolocationgeospy.ai
MapillaryStreet-level imagerymapillary.com
MaxarCommercial satellite imagerymaxar.com
F4map3D interactive world mapdemo.f4map.com
Zoom EarthReal-time satellite & weatherzoom.earth
KartaViewStreet-level imagery (OpenStreetCam)kartaview.org
ShadowMapShadow analysis for time estimationshadowmap.org
Crime BrasilBrazil crime + accidents open data by neighborhood (bairro-level RS; municipal MG/RJ; PRF accidents)crimebrasil.com.br
ToolDescriptionInstall / Link
TinEyeReverse image searchtineye.com
Google Reverse ImageGoogle image searchimages.google.com
Yandex ImagesBest reverse image search for faces/placesyandex.com/images
ExifToolImage/document metadata extractionapt install libimage-exiftool-perl
FOCAMetadata extraction from documentsgithub.com/ElevenPaths/FOCA
InVIDVideo verification toolkitinvid-project.eu
FotoForensicsImage forensic analysis (ELA)fotoforensics.com
Fake Image DetectorAI-based fake image detectionfakeimagedetector.com
Search by ImageMulti-engine reverse image (browser ext)Chrome / Firefox extension
DepixRecover pixelated text from screenshotsgit clone https://github.com/beurtschipper/Depix
ForensicallyOnline image forensics suite29a.ch/photo-forensics
AI or NotDetect AI-generated imagesaiornot.com
Hive ModerationAI content detectionhivemoderation.com
IlluminartyAI image detectionilluminarty.ai
ToolDescriptionInstall / Link
FaceSeekAI-powered reverse face searchfaceseek.online
FaceCheck.IDFace recognition search enginefacecheck.id
PimEyesFace search engine from photospimeyes.com
Search4facesFace search in VK/OK social networkssearch4faces.com
face_recognitionPython face recognition librarypip install face_recognition
DeepFaceAI face analysis (age, gender, emotion)pip install deepface
ThatsThemFree people searchthatsthem.com
PiplDeep people search enginepipl.com
BeenVerifiedPeople search & background checkbeenverified.com
SpokeoPeople search aggregatorspokeo.com
FastPeopleSearchFree people finderfastpeoplesearch.com
WebMiiPeople search enginewebmii.com
OSINT IndustriesPeople search + social media lookuposint.industries
IDCrawlFree people search engineidcrawl.com
ToolDescriptionInstall / Link
OsintgramInstagram OSINT toolgit clone https://github.com/Datalux/Osintgram
InstaloaderInstagram data downloaderpip install instaloader
TwintTwitter OSINT (no API needed)pip install twint
snscrapeSocial media scraper (Twitter, Reddit, etc.)pip install snscrape
ToutatisInstagram OSINT by phone/emailpip install toutatis
TikTok ScraperTikTok data extractionnpm install -g tiktok-scraper
Reddit InvestigatorReddit user analysisreddit-user-analyser.netlify.app
socialscanSocial media presence checkerpip install socialscan
TelepathyTelegram OSINT analysispip install telepathy
TwaybackFind deleted tweetspip install twayback
XquikX/Twitter data API & MCP skillgithub.com
SocialBladeSocial media analyticssocialblade.com
Social-SearcherFree social media search enginesocial-searcher.com
MentionSocial media monitoringmention.com
BrandWatchSocial listening platformbrandwatch.com
ToolDescriptionTypeLink
Have I Been PwnedCheck email/phone in breaches🟢 Freehaveibeenpwned.com
DeHashedBreach search engine💰 Paiddehashed.com
LeakCheckEmail/username/phone breach search🟡 Freemiumleakcheck.net
Intelligence XSearch breaches, darknet, leaks💰 Paidintelx.io
BreachDirectoryFree breach search🟢 Freebreachdirectory.org
LeakPeekSearch leaked databases🟡 Freemiumleakpeek.com
SnusbaseBreach data search engine💰 Paidsnusbase.com
CheckLeakedLeak search engine (15B+ accounts)🟡 Freemiumcheckleaked.cc
DataBreach.comData breach lookup🟢 Freedatabreach.com
Hudson Rock CavalierInfostealer intelligence & breach data🟡 Freemiumhudsonrock.com
h8mailAutomated breach hunting CLI🟢 Freepip install h8mail
XposedOrNotBreach exposure check🟢 Freexposedornot.com
ScatteredSecretsBreach notification service🟡 Freemiumscatteredsecrets.com
The OSINT RackRansomware & data leak monitoring🟢 Freeosintrack.com
PwndbDark web breach database (Tor)🟢 FreeRequires Tor Browser
OsintCatEmail, username & phone breach lookup — fast results with real data🟡 Freemiumosintcat.net
PlatformDescriptionLink
WikiLeaksLeaked government & corporate documentswikileaks.org
DDoSecretsDistributed Denial of Secretsddosecrets.com
CryptomeDocuments archive since 1996cryptome.org
The InterceptInvestigative journalismtheintercept.com
SecureDropWhistleblower submission systemsecuredrop.org
ICIJ Offshore LeaksPanama Papers, Pandora Papersoffshoreleaks.icij.org
DocumentCloudPublic document researchdocumentcloud.org
Wayback MachineWeb archiveweb.archive.org
FBI VaultFBI electronic reading roomvault.fbi.gov
CIA Reading RoomDeclassified CIA documentscia.gov/readingroom
NSA DeclassifiedNSA declassified recordsnsa.gov
PACERUS federal court recordspacer.uscourts.gov
ToolDescriptionInstall / Link
HashcatAdvanced password recovery (GPU-accelerated)apt install hashcat
John the RipperClassic password crackerapt install john
HydraNetwork login brute-forcerapt install hydra
MedusaParallel brute-force toolapt install medusa
CeWLCustom wordlist generator from websiteapt install cewl
CrunchPattern-based wordlist generatorapt install crunch
RainbowCrackRainbow table crackerproject-rainbowcrack.com
OphcrackWindows password cracker (rainbow tables)ophcrack.sourceforge.io
LaZagneCredentials recovery tool (post-exploit)git clone https://github.com/AlessandroZ/LaZagne
MimikatzWindows credential dumpergit clone https://github.com/gentilkiwi/mimikatz
ResponderLLMNR/NBT-NS/MDNS poisonergit clone https://github.com/lgandx/Responder
ToolDescriptionLink / Onion Address
TorchOldest & largest dark web search enginexmh57jrknzkhv6y3ls3ubitzfqnkrwxhopf5aygthi7d6rplyvk3noyd.onion
HaystakDark web search with filteringhaystak5njsmn2hqkewecpaxetahtwhsbsa64jom2k22z5afxhnpxfid.onion
AhmiaClearnet dark web searchahmia.fi
DuckDuckGo OnionPrivate search on Torduckduckgogg42xjoc72x3sjasowoarfbgcmvfimaftt6twagswzczad.onion
PhobosDark web search enginephobosxilamwcg75xt22id7aywkzol6q6rfl2flipcqoc4e4ahima5id.onion
DarkSearchDark web search API (clearnet)darksearch.io
OnionScanScan & analyze .onion sitesgo install github.com/s-rah/onionscan@latest
Dark.failVerified dark web links directorydark.fail
OSINT-SPYOSINT tool with Tor supportgit clone https://github.com/SharadKumar97/OSINT-SPY
ToolDescriptionInstall / Link
Tor BrowserAnonymous web browsingtorproject.org
Tails OSAmnesic live OS (no trace)tails.boum.org
WhonixAnonymous OS via Tor (VM-based)whonix.org
ProtonVPNFree encrypted VPNprotonvpn.com
ProtonMailEncrypted emailproton.me
SignalEncrypted messagingsignal.org
OnionShareAnonymous file sharing via Toronionshare.org
AnonsurfAnonymize entire OS trafficgit clone https://github.com/Und3rf10w/kali-anonsurf
MAC ChangerChange/spoof MAC addressapt install macchanger
BleachBitDigital footprint cleanerbleachbit.org
VeraCryptDisk encryptionveracrypt.fr
KeePassXCOffline password managerkeepassxc.org
Mullvad VPNPrivacy VPN (no email needed)mullvad.net
Anon-SMSAnonymous SMS sendinggit clone https://github.com/HACK3RY2J/Anon-SMS.git
ToolDescriptionInstall / Link
NiktoWeb server vulnerability scannerapt install nikto
WPScanWordPress vulnerability scannergem install wpscan
WappalyzerTechnology profiler (browser ext)Browser Extension
WhatwebWeb technology identifierapt install whatweb
DirbWeb directory brute-forcerapt install dirb
GobusterURI/DNS brute-forcer (Go)go install github.com/OJ/gobuster/v3@latest
FeroxbusterFast recursive content discoveryapt install feroxbuster
HTTPxFast HTTP toolkit / probinggo install github.com/projectdiscovery/httpx/cmd/httpx@latest
KatanaWeb crawlergo install github.com/projectdiscovery/katana/cmd/katana@latest
LinkFinderDiscover endpoints in JavaScriptgit clone https://github.com/GerbenJavado/LinkFinder
PhotonWeb crawler for OSINT datagit clone https://github.com/s0md3v/Photon
WfuzzWeb fuzzerpip install wfuzz
ParamSpiderParameter discovery from web archivespip install paramspider
WebHackWeb hacking toolkitgit clone https://github.com/yan4ikyt/webhack
ToolDescriptionInstall / Link
SET (Social Engineering Toolkit)Complete SE frameworkapt install set
GophishEnterprise phishing simulation platformgetgophish.com
Zphisher30+ phishing templatesgit clone https://github.com/htr-tech/zphisher
NexPhisherMulti-platform phishing toolgit clone https://github.com/htr-tech/nexphisher
Storm-BreakerAccess webcam/mic/location (SE)git clone https://github.com/ultrasecurity/Storm-Breaker
Evilginx2Man-in-the-middle reverse proxygo install github.com/kgretzky/evilginx2@latest
ModlishkaReverse proxy phishing frameworkgo install github.com/drk1wi/Modlishka@latest
King PhisherPhishing campaign toolkitgithub.com/rsmusllp/king-phisher
SocialFishSocial media phishinggit clone https://github.com/UndeadSec/SocialFish
AdvPhishingAdvanced phishing toolgit clone https://github.com/Ignitetch/AdvPhishing
URLCADIZURL masking toolgit clone https://github.com/PerezMascato/URLCADIZ
ToolDescriptionInstall / Link
MetasploitIndustry-standard pen testing frameworkapt install metasploit-framework
NucleiTemplate-based fast vulnerability scannergo install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
SQLMapAutomated SQL injection toolapt install sqlmap
Burp SuiteWeb app security testing proxyportswigger.net/burp
OWASP ZAPOpen-source web app scannerzaproxy.org
OpenVASOpen-source vulnerability scannerapt install openvas
CommixCommand injection exploitergit clone https://github.com/commixproject/commix
GoldenEyeHTTP DoS tool (authorized load testing)git clone https://github.com/jseidl/GoldenEye
ExploitDBExploit database (searchsploit)exploit-db.com
Criminal IPVulnerability & CVE searchcriminalip.io
ToolDescriptionInstall / Link
WiresharkNetwork protocol analyzerapt install wireshark
Aircrack-ngWi-Fi security auditing suiteapt install aircrack-ng
KismetWireless network detector & snifferapt install kismet
BettercapMITM framework (ARP, DNS, HTTP)apt install bettercap
EttercapMITM attack suiteapt install ettercap-common
WifiteAutomated Wi-Fi auditing toolapt install wifite
ReaverWPS brute force toolapt install reaver
Fern Wifi CrackerGUI-based Wi-Fi audit toolapt install fern-wifi-cracker
FluxionWi-Fi social engineering (evil twin)git clone https://github.com/FluxionNetwork/fluxion
hcxtoolsWi-Fi packet capture conversionapt install hcxtools
NetcatThe TCP/IP swiss army knifeapt install netcat-openbsd
tcpdumpCommand-line packet analyzerapt install tcpdump
ToolDescriptionInstall / Link
PhoneSploitADB-based phone exploitationgit clone https://github.com/aerosol-can/PhoneSploit
AhMyth Android RATAndroid remote access toolgit clone https://github.com/AhMyth/AhMyth-Android-RAT
ApktoolAndroid APK decompiler/rebuilderapt install apktool
jadxAndroid APK decompiler (GUI)apt install jadx
FridaDynamic instrumentation toolkitpip install frida-tools
ObjectionRuntime mobile explorationpip install objection
MobSFMobile Security Framework (static+dynamic)github.com/MobSF/Mobile-Security-Framework-MobSF
MSFPCMSF payload creatorgit clone https://github.com/g0tmi1k/msfpc
ToolDescriptionInstall / Link
GeoSpyAI geolocation from imagesgeospy.ai
DeepFaceFace analysis (age, gender, emotion)pip install deepface
face_recognitionPython face recognition librarypip install face_recognition
OpenCVComputer vision librarypip install opencv-python
ReconAIzerAI-enhanced Burp Suite extensiongithub.com/hisxo/ReconAIzer
AI or NotDetect AI-generated contentaiornot.com
HARPA AIAI browser agent for OSINTharpa.ai
ToolDescriptionFree TierLink
ClaudeBest for reasoning & analysis✅ Free tierclaude.ai
ChatGPTOpenAI's AI assistant✅ GPT-4o minichat.openai.com
Perplexity AIAI search with cited sources✅ 5 Pro/dayperplexity.ai
Google GeminiGoogle AI with web search✅ Freegemini.google.com
DeepSeekOpen-source, strong reasoning✅ Freechat.deepseek.com
GrokReal-time X/Twitter data✅ Free on Xx.com/grok
Microsoft CopilotAI with Bing search integration✅ Freecopilot.microsoft.com
NotebookLMGoogle's document analysis AI✅ Freenotebooklm.google.com
PhindAI search for developers✅ Freephind.com
HuggingChatOpen-source AI chat✅ Freehuggingface.co/chat
ToolDescriptionLink
OpenCorporatesGlobal corporate databaseopencorporates.com
ICIJ Offshore LeaksPanama/Pandora/Paradise Papersoffshoreleaks.icij.org
SEC EDGARUS company filingssec.gov/edgar
Companies House (UK)UK company registerbeta.companieshouse.gov.uk
Aleph (OCCRP)Global corporate & public recordsaleph.occrp.org
OrbitBitcoin address investigatorgit clone https://github.com/s0md3v/Orbit
Blockchain.comBitcoin explorerblockchain.com/explorer
EtherscanEthereum blockchain exploreretherscan.io
BinCheckBank card BIN lookupbincheck.io
CrunchbaseCompany/startup databasecrunchbase.com
LEI SearchLegal Entity Identifier lookupsearch.gleif.org
Tool/ServiceDescriptionLink
FAXVINFree VIN decoderfaxvin.com
AutoCheckVehicle history reportsautocheck.com
NICB VINCheckStolen vehicle checknicb.org/vincheck
PACERUS federal court recordspacer.uscourts.gov
ZillowProperty records & estimateszillow.com
Who Owns WhatNYC landlord portfolio lookupwhoownswhat.justfix.org
FOIA.govFreedom of Information Act portalfoia.gov
Court ListenerFree US court opinion searchcourtlistener.com
ToolDescriptionInstall / Link
AutopsyFull digital forensics platformautopsy.com
VolatilityMemory forensics frameworkpip install volatility3
WiresharkNetwork packet analysisapt install wireshark
BinwalkFirmware analysis & extractionapt install binwalk
ForemostFile carving (recover deleted files)apt install foremost
Bulk ExtractorExtract features from disk imagesapt install bulk-extractor
ExifToolComplete metadata extractionapt install libimage-exiftool-perl
MetagoofilDocument metadata harvesterpip install metagoofil
CyberChefData analysis swiss army knifegchq.github.io/CyberChef
ScalpelFile carving toolapt install scalpel
Search QueryWhat It Finds
screenshot.label:webcamWebcams indexed by Shodan
port:554 has_screenshot:trueRTSP cameras with screenshots
Server: yawcamYawcam webcams
webcamXPWebcamXP servers
port:8080 title:"Blue Iris"Blue Iris CCTV
port:37777 "DVR"Dahua DVR systems
port:80 title:"DVR"Web-accessible DVR
Google DorkTarget
inurl:"viewerframe?mode="Axis network cameras
intitle:"webcamXP 5"WebcamXP 5 servers
inurl:"videostream.cgi"CGI video streams
intitle:"Live View / - AXIS"AXIS cameras
inurl:/view/view.shtmlMobotix cameras
OperatorDescriptionExample
site:Search within a domainsite:example.com admin
inurl:Search in URL pathinurl:admin login
intitle:Search in page titleintitle:"index of" passwords
intext:Search in page bodyintext:"username" "password"
filetype:Search by file typefiletype:pdf "confidential"
ext:Search by extensionext:sql "dump"
cache:View Google's cached versioncache:example.com
allintext:All terms in page bodyallintext:username password email
PurposeGoogle Dork
Exposed passwordsintitle:"index of" "passwords.txt"
SQL database dumpsfiletype:sql "CREATE TABLE" "INSERT INTO"
Config filesext:conf OR ext:cnf "password"
Exposed .env filesintitle:"index of" ".env"
Open FTP serversintitle:"index of" inurl:ftp
Exposed git reposintitle:"index of" ".git"
SSH private keysfiletype:pem "PRIVATE KEY"
phpinfo pagesext:php intitle:phpinfo
Exposed log filesfiletype:log "password" OR "username"
ToolLink
DorkSearchdorksearch.com
Google Hacking DB (GHDB)exploit-db.com/google-hacking-database
Pagodogit clone https://github.com/opsdisk/pagodo
GooFuzzgit clone https://github.com/m3n0sd0n4ld/GooFuzz
PurposeGoogle Dork
Gmail in spreadsheetsallintext:"@gmail.com" "password" filetype:xlsx
Exposed credentials in CSVfiletype:csv "email" "password"
Pastebin credential dumpsfiletype:txt "username" "password" site:pastebin.com
Database dumpsfiletype:sql "INSERT INTO" "password" "email"
Config files with API keysfiletype:env "DB_PASSWORD" OR "API_KEY" OR "SECRET"
Exposed .htpasswdfiletype:htpasswd htpasswd
phpMyAdmin without authinurl:phpmyadmin/index.php intitle:"phpMyAdmin"
Exposed Jenkinsintitle:"Dashboard [Jenkins]" inurl:"/login"
AWS keys exposedfiletype:pem "AKIA" OR "ASIA"
GitHub secretssite:github.com "API_KEY" OR "api_secret" filetype:env
ToolDescriptionLink
GrabifyIP grabber & URL shortenergrabify.link
IPLoggerIP logging URL shorteneriplogger.org
Canary TokensTracking tokens (URL, email, DNS, files)canarytokens.org
GetNotifyEmail open tracking + geolocationgetnotify.com
IPinfoIP address data APIipinfo.io
IP-APIIP geolocation APIip-api.com
MaxMind GeoIPIP geolocation databasemaxmind.com
BotDescriptionHandle
Eye of God (Glaz Boga)Person lookup by phone/email/photo/VK@glazzz_rus_bot
@No_BlackMail_botSearch email by phone number@No_BlackMail_bot
@OverSerchBotMulti-search OSINT bot@OverSerchBot
GetContact BotPhone number caller ID@getcontact_real_bot
Quick OSINTFast person lookup@Quick_OSINT_bot
@CreationDateBotCheck Telegram account creation date@creationdatebot
@SangMataBotCheck username history of TG accounts@SangMataInfo_bot
ChannelContentLink
@overbafer1Hacking & cybersecurityt.me/overbafer1
@Social_engineeringSocial engineering techniquest.me/Social_engineering
@cyberbezopasnoCybersecurity news & toolst.me/cyberbezopasno
@OSINT_groupOSINT communityt.me/OSINT_group
ToolDescriptionInstall
TelepathyTelegram OSINT analysispip install telepathy
TelethonPython Telegram API librarypip install telethon
TeleGram-OSINTerTelegram profile investigationgit clone https://github.com/Alb-310/TeleGram-OSINTer
#ServiceDescriptionLink
1FNS (Tax Service)Get INN number, check tax debtsservice.nalog.ru
2TelPoiskPhone directory — address by nametelpoisk.com
3GetContactSee how number is saved by othersgetcontact.com
4Eye of GodPerson lookup by phone/email/photo@glazzz_rus_bot
5Search4facesFace search in VK & OKsearch4faces.com
6GetNotifyEmail tracking + geolocationgetnotify.com
7BinCheckCard BIN lookup (bank, region)bincheck.io
PurposeTool/URL
Registration dataregvk.com
FOAF datahttps://vk.com/foaf.php?id=USER_ID
VK page archivevk.watch/ID/profile
Activity trackingnebaz.ru
VK tools220vk.com
ToolDescriptionFree?Link
Social SearcherReal-time social media search✅ Yessocial-searcher.com
Social MentionSocial media aggregator✅ Yessocialmention.com
Google AlertsFree web monitoring✅ Freegoogle.com/alerts
Who Posted WhatFacebook keyword search✅ Freewhopostedwhat.com
MentionSocial media & web monitoring🟡 Freemiummention.com
TalkwalkerSocial listening & analytics💰 Paidtalkwalker.com
BrandWatchSocial intelligence platform💰 Paidbrandwatch.com
HootsuiteSocial media management🟡 Freemiumhootsuite.com
#ToolPurposeInstall
1SherlockUsername OSINTpip install sherlock-project
2MaigretUsername OSINT (3000+ sites)pip install maigret
3h8mailEmail breach huntingpip install h8mail
4ZphisherPhishing (30+ templates)git clone https://github.com/htr-tech/zphisher
5NexPhisherAdvanced phishinggit clone https://github.com/htr-tech/nexphisher
6Storm-BreakerCamera/Mic/Location SEgit clone https://github.com/ultrasecurity/Storm-Breaker
7UserReconUsername searchgit clone https://github.com/wishihab/userrecon
8IPGeoLocationIP geolocationgit clone https://github.com/maldevel/IPGeoLocation
9OrbitBitcoin address searchgit clone https://github.com/s0md3v/Orbit
10NmapNetwork scannerpkg install nmap
11HydraLogin brute forcepkg install hydra
12PhoneSploitPhone exploitation via ADBgit clone https://github.com/aerosol-can/PhoneSploit
13fsocietyAll-in-one hacking packgit clone https://github.com/Manisso/fsociety
ToolCategoryCommand
NmapNetwork scanningnmap
WiresharkPacket analysiswireshark
MetasploitExploitationmsfconsole
SQLMapSQL injectionsqlmap
HydraBrute forcehydra
John the RipperPassword crackingjohn
HashcatGPU password crackinghashcat
Aircrack-ngWi-Fi crackingaircrack-ng
NiktoWeb scannernikto
DirbDirectory brute forcedirb
WPScanWordPress scannerwpscan
theHarvesterEmail/subdomain OSINTtheHarvester
MaltegoVisual link analysismaltego
Recon-ngWeb recon frameworkrecon-ng
SETSocial engineering toolkitsetoolkit
Burp SuiteWeb proxyburpsuite
FrameworkDescriptionInstall
fsocietyMr. Robot-inspired hacking packgit clone https://github.com/Manisso/fsociety
HackingtoolAll-in-one tool (100+ categories)git clone https://github.com/Z4nzu/hackingtool
SpiderFootOSINT automation platformpip install spiderfoot
MaltegoVisual OSINT & link analysisPre-installed in Kali
Recon-ngModule-based recon frameworkpip install recon-ng
Lazy ScriptAutomated pentest helpergit clone https://github.com/arismelachroinos/lscript
osmedeusFull automated recon workflowgit clone https://github.com/j3ssie/osmedeus
ToolDescriptionInstall
CrunchPattern-based wordlist generatorapt install crunch
CeWLCustom wordlist from any websiteapt install cewl
CuppProfile-based wordlist generatorgit clone https://github.com/Mebus/cupp
SecListsThe ultimate security wordlist collectiongit clone https://github.com/danielmiessler/SecLists
RockYouClassic leaked password listPre-installed in Kali (/usr/share/wordlists/)
WeakpassMassive wordlist collectionweakpass.com
DeviceDescriptionPrice
Flipper ZeroMulti-tool: RFID, NFC, IR, Sub-GHz, BadUSB~$170
HackRF OneSoftware-defined radio (1MHz–6GHz)~$300
Proxmark3RFID/NFC research & cloning tool~$60–300
WiFi PineappleWi-Fi auditing & rogue AP platform~$100–300
USB Rubber DuckyUSB keystroke injection device~$80
Bash BunnyMulti-function USB attack platform~$120
LAN TurtleCovert network access & MITM~$60
RTL-SDRBudget software-defined radio dongle~$25
Alfa AWUS036ACHLong-range dual-band Wi-Fi adapter~$50
O.MG CableUSB cable with embedded implant~$120
OSFocusLink
Kali LinuxPenetration testing (600+ tools)kali.org
Parrot OSSecurity & privacyparrotsec.org
TailsPrivacy & anonymity (amnesic)tails.boum.org
WhonixAnonymous OS via Torwhonix.org
CSI LinuxOSINT & forensics focusedcsilinux.com
Trace Labs OSINT VMOSINT-specific VMtracelabs.org
BlackArch2800+ security toolsblackarch.org
SIFT WorkstationSANS digital forensicsdigital-forensics.sans.org
REMnuxMalware analysisremnux.org
Qubes OSSecurity via compartmentalizationqubes-os.org
CommandoVMWindows pentest VMgithub.com/mandiant/commando-vm
APIDescriptionLink
Shodan APIIoT/device searchdeveloper.shodan.io
VirusTotal APIFile/URL analysisdevelopers.virustotal.com
Hunter.io APIEmail discoveryhunter.io/api
Have I Been Pwned APIBreach checkhaveibeenpwned.com/API
IPinfo APIIP geolocationipinfo.io/developers
Censys APIInternet scanningsearch.censys.io/api
GitHub APIRepository/user dataapi.github.com
Dehashed APIBreach data searchdehashed.com/docs
urlscan.io APIURL analysisurlscan.io/docs/api
AbuseIPDB APIIP reputationabuseipdb.com/api
Google Custom Search APIProgrammable searchdevelopers.google.com/custom-search
WhoisXML APIDomain intelligencewhoisxmlapi.com
Criminal IP APIThreat intelligencecriminalip.io/developer
ExtensionDescriptionBrowser
Search by ImageMulti-engine reverse image searchChrome / Firefox
WappalyzerTechnology stack detectorChrome / Firefox
ShodanServer info on any websiteChrome / Firefox
Wayback MachineView archived pages instantlyChrome / Firefox
EXIF ViewerView image metadataChrome / Firefox
User-Agent SwitcherChange browser identityChrome / Firefox
FoxyProxyProxy managementChrome / Firefox
HunchlyOSINT web capture & case managerChrome
InVID/WeVerifyVideo/image verificationChrome / Firefox
SingleFileSave complete web pagesChrome / Firefox
ResourceTypeLink
OSINT FrameworkInteractive tool directoryosintframework.com
IntelTechniquesMichael Bazzell's resources & podcastinteltechniques.com
BellingcatOSINT investigative journalismbellingcat.com
Trace LabsOSINT for missing persons CTFstracelabs.org
OSINT Curious ProjectCommunity & trainingosintcurio.us
Sector035 Week in OSINTWeekly OSINT newslettersector035.nl
OSINT DojoTraining platform & challengesosintdojo.com
CTF TimeHands-on CTF competitionsctftime.org
GIJNGlobal Investigative Journalism Networkgijn.org
SANS OSINTProfessional cyber trainingsans.org
ChannelFocus
John HammondCybersecurity & CTFs
The Cyber MentorEthical hacking
David BombalNetworking & security
NetworkChuckCybersecurity tutorials
HackerSploitPenetration testing
Null ByteHacking tutorials
13CubedDFIR & forensics
RepositoryStarsLink
jivoi/awesome-osint20k+github.com/jivoi/awesome-osint
danielmiessler/SecLists55k+github.com/danielmiessler/SecLists
Z4nzu/hackingtool40k+github.com/Z4nzu/hackingtool
cipher387/osint_stuff_tool_collection6k+github.com/cipher387/osint_stuff_tool_collection
Manisso/fsociety10k+github.com/Manisso/fsociety
sinwindie/OSINT3k+github.com/sinwindie/OSINT
Astrosp/Awesome-OSINT-For-Everything2k+github.com/Astrosp/Awesome-OSINT-For-Everything
tracelabs/awesome-osint1k+github.com/tracelabs/awesome-osint
#ToolCategoryInstall
1SherlockUsername OSINTpip install sherlock-project
2MaigretUsername OSINT (3000+ sites)pip install maigret
3h8mailEmail breach huntingpip install h8mail
4HoleheEmail registration checkpip install holehe
5theHarvesterDomain/email reconapt install theharvester
6PhoneInfogaPhone number OSINTSee install guide
7NmapNetwork scanningapt install nmap
8AmassDNS enumerationgo install ...amass@master
9SubfinderSubdomain discoverygo install ...subfinder@latest
10NucleiVulnerability scanninggo install ...nuclei@latest
11SQLMapSQL injectionapt install sqlmap
12MetasploitExploitation frameworkapt install metasploit-framework
13HashcatPassword cracking (GPU)apt install hashcat
14HydraLogin brute forceapt install hydra
15WiresharkNetwork analysisapt install wireshark
16Aircrack-ngWi-Fi securityapt install aircrack-ng
17Burp SuiteWeb proxy/testingportswigger.net
18SpiderFootOSINT automationpip install spiderfoot
19MaltegoVisual link analysisPre-installed in Kali
20Recon-ngRecon frameworkpip install recon-ng
21PimEyesFace search enginepimeyes.com
22ShodanIoT device searchshodan.io
23CensysInternet scanningcensys.io
24ZphisherPhishing toolgit clone .../zphisher
25Storm-BreakerCamera/mic SE toolgit clone .../Storm-Breaker
26ExifToolImage metadataapt install libimage-exiftool-perl
27AutopsyDigital forensicsautopsy.com
28VolatilityMemory forensicspip install volatility3
29Tor BrowserAnonymous browsingtorproject.org
30DeHashedBreach search enginedehashed.com
31Have I Been PwnedBreach checkerhaveibeenpwned.com
32fsocietyAll-in-one frameworkgit clone .../fsociety
33Hackingtool100+ tools in onegit clone .../hackingtool
34SecListsSecurity wordlistsgit clone .../SecLists
35OsintgramInstagram OSINTgit clone .../Osintgram
36VirusTotalMalware/file analysisvirustotal.com
37Canary TokensIP tracking tokenscanarytokens.org
38CyberChefData analysis toolgchq.github.io/CyberChef
39DeepFaceAI face analysispip install deepface
40dnsreconDNS enumerationpip install dnsrecon
41GobusterDirectory brute-forcego install ...gobuster@latest
42HTTPxHTTP probinggo install ...httpx@latest
43EyeWitnessWeb screenshotsgit clone .../EyeWitness
44ResponderLLMNR/NBT-NS poisonergit clone .../Responder
45BettercapMITM frameworkapt install bettercap
46PhotonWeb OSINT crawlergit clone .../Photon
47Perplexity AIAI research assistantperplexity.ai
48GeoSpyAI image geolocationgeospy.ai
49osmedeusFull recon workflowgit clone .../osmedeus
50trufflehogGit secret scannerpip install trufflehog
ToolDescriptionInstall / Link
AD Attack & DefenseComprehensive Active Directory attack referencegit clone https://github.com/infosecn1nja/AD-Attack-Defense.git
ArjunHTTP parameter discovery suitepip3 install arjun
BloodHoundAD attack-path graph analysisgit clone https://github.com/BloodHoundAD/BloodHound.git
BloodHound CECommunity Edition of BloodHound — modernized stackdocker pull specterops/bloodhound:latest
Brute Ratel C4Premium C2 with strong AV/EDR evasionbruteratel.com
CertipyActive Directory Certificate Services enumeration and abusepip3 install certipy-ad
Cobalt StrikePremium adversary simulation / red team frameworkcobaltstrike.com
CrackMapExecPost-exploitation tool for AD networkspip3 install crackmapexec
CRLFuzzFast CRLF-injection scanner in Gogo install github.com/dwisiswant0/crlfuzz/cmd/crlfuzz@latest
DalfoxFast, intelligent XSS scannergo install github.com/hahwul/dalfox/v2@latest
Evil-WinRMUltimate WinRM shell for hacking/pentestingapt install evil-winrm
GhauriAdvanced cross-platform tool to detect/exploit SQLigit clone https://github.com/r0oth3x49/ghauri.git
GxssTest parameters for cross-site scripting reflectiongo install github.com/KathanP19/Gxss@latest
HackTricksPentesting / hacking knowledge base by carlospolopbook.hacktricks.xyz
HavocModern, malleable post-exploitation C2 frameworkgit clone https://github.com/HavocFramework/Havoc.git
ImpacketPython classes for working with network protocols (Windows attacks)pip3 install impacket
KerbruteTool for performing Kerberos pre-auth bruteforcinggo install github.com/ropnop/kerbrute@latest
kiterunnerContextual content-discovery for modern API endpointsgo install github.com/assetnote/kiterunner/cmd/kr@latest
MerlinCross-platform HTTP/2 post-exploitation server and agent in Gogo install github.com/Ne0nd0g/merlin@latest
Metasploit FrameworkIndustry-standard exploitation framework with 2000+ modulesapt install metasploit-framework
MythicCross-platform, post-exploit, multi-user red team frameworkgit clone https://github.com/its-a-feature/Mythic.git
NetExec (nxc)CrackMapExec maintained successor — AD network exploitationpip3 install git+https://github.com/Pennyw0rth/NetExec
NighthawkPremium evasive C2 by MDSec (Cobalt Strike alt)mdsec.co.uk
NoSQLMapAutomated NoSQL database enumeration and exploitationgit clone https://github.com/codingo/NoSQLMap.git
Nuclei TemplatesCommunity-curated templates for Nucleigit clone https://github.com/projectdiscovery/nuclei-templates.git
ParamMiner (Burp ext)Discover hidden, unlinked HTTP parameters in Burpgit clone https://github.com/PortSwigger/param-miner.git
PayloadsAllTheThingsWeb app pentest payloads, bypasses, and methodologygit clone https://github.com/swisskyrepo/PayloadsAllTheThings.git
PetitPotamPoC tool to coerce Windows hosts to authenticate to attackergit clone https://github.com/topotam/PetitPotam.git
PowerShell EmpirePost-exploitation framework with PS-based agentsgit clone https://github.com/BC-SECURITY/Empire.git
RubeusC# toolset for raw Kerberos interaction and abusegit clone https://github.com/GhostPack/Rubeus.git
SharpHoundC# data collector for BloodHoundgit clone https://github.com/BloodHoundAD/SharpHound.git
SliverOpen-source adversary emulation/red-team framework (Cobalt Strike alt)go install github.com/bishopfox/sliver/server@latest
SSRFmapAutomated SSRF detection and exploitation frameworkgit clone https://github.com/swisskyrepo/SSRFmap.git
VillainHigh-level stage 0/1 C2 framework for handling sibling agentsgit clone https://github.com/t3l3machus/Villain.git
XSStrikeAdvanced XSS scanner with crawler and payload generatorgit clone https://github.com/s0md3v/XSStrike.git
ToolDescriptionInstall / Link
Atomic Red TeamLibrary of small detection-test scripts mapped to MITRE ATT&CKgit clone https://github.com/redcanaryco/atomic-red-team.git
ChainsawHunt threats in Windows event logs — fast forensicsgit clone https://github.com/WithSecureLabs/chainsaw.git
Cortex (TheHive)Observable analysis and active response enginedocker pull thehiveproject/cortex:latest
Elastic Stack (ELK)Elasticsearch + Logstash + Kibana — log analyticsdocker pull docker.elastic.co/elasticsearch/elasticsearch:latest
FalcoCloud-native runtime securitygit clone https://github.com/falcosecurity/falco.git
GraylogOpen-source log management / SIEMdocker pull graylog/graylog:latest
HayabusaWindows event log fast forensics timeline generatorgit clone https://github.com/Yamato-Security/hayabusa.git
LokiSimple IOC and YARA scanner by Florian Rothgit clone https://github.com/Neo23x0/Loki.git
MITRE ATT&CKAdversary tactics, techniques, and procedures knowledge baseattack.mitre.org
MITRE CALDERACyber adversary emulation platformgit clone https://github.com/mitre/caldera.git
MITRE D3FENDDefensive countermeasure knowledge graphd3fend.mitre.org
osquerySQL-powered OS instrumentation/monitoring/analyticsapt install osquery
RITAReal Intelligence Threat Analytics — beaconing/long-conn detectiongit clone https://github.com/activecm/rita.git
Security OnionLinux distro for threat hunting, monitoring, and log managementsecurityonionsolutions.com
SigmaGeneric signature format for SIEM detectionsgit clone https://github.com/SigmaHQ/sigma.git
sigma-cliConvert Sigma rules to native SIEM queriespip3 install sigma-cli
SnortOpen-source intrusion-prevention/detection systemapt install snort
SuricataHigh-perf network IDS / IPS / NSMapt install suricata
TheHiveScalable, free, open-source case management for SOCsdocker pull strangebee/thehive:latest
TraceeRuntime security and forensics using eBPF (Aqua)git clone https://github.com/aquasecurity/tracee.git
VelociraptorEndpoint visibility and digital forensics — query-drivengit clone https://github.com/Velocidex/velociraptor.git
Velociraptor ServerCentralized server for Velociraptor agentsdocs.velociraptor.app
WazuhOpen-source XDR / SIEM platformgit clone https://github.com/wazuh/wazuh.git
Zeek (Bro)Powerful network analysis framework for security monitoringapt install zeek
ToolDescriptionInstall / Link
Anomali ThreatStreamEnterprise threat intel aggregation platformanomali.com
CrowdStrike Falcon IntelligencePremium adversary intel from CrowdStrikecrowdstrike.com
Digital Shadows SearchLightBrand protection + dark web monitoring (now ReliaQuest GreyMatter DRP)reliaquest.com
EclecticIQ Intelligence CenterSTIX/TAXII-native threat intel platformeclecticiq.com
FlashpointBusiness risk intel from criminal forums and dark webflashpoint.io
Intel471Premium adversary intelligence and underground monitoring platformintel471.com
IntSightsExternal threat protection and intel (now part of Rapid7)intsights.com
KELACybercrime intelligence and dark-web monitoringkelacyber.com
Mandiant AdvantageThreat intel from Google's Mandiant teammandiant.com
OpenCTIOpen-source CTI platform structured around STIX2docker pull opencti/platform
SOCRadarExtended threat intel — attack surface + dark web + brandsocradar.io
ThreatConnectThreat intel platform combining intel and SOARthreatconnect.com
ThreatQThreat intel platform for SOCsthreatq.com
YetiOpen distributed threat intelligence platformgit clone https://github.com/yeti-platform/yeti.git
ToolDescriptionInstall / Link
Binary NinjaModern reverse engineering platform with APIbinary.ninja
CutterGUI for radare2/rizin reverse-engineeringgit clone https://github.com/rizinorg/cutter.git
DissectFox-IT framework for fast forensic image analysispip3 install dissect
Eric Zimmerman's ToolsSuite of free Windows DFIR utilitiesericzimmerman.github.io
FTK ImagerForensic disk imaging tool by AccessDataexterro.com
GhidraNSA's open-source software reverse engineering suitegit clone https://github.com/NationalSecurityAgency/ghidra.git
IDA FreeFree version of IDA disassembler/decompilerhex-rays.com
KAPEKroll Artifact Parser and Extractor — fast triage collectionkroll.com
PhotoRecFile data recovery — focuses on multimediaapt install testdisk
Plaso (log2timeline)Super-timeline creation from forensic artifactspip3 install plaso
radare2Reverse engineering frameworkapt install radare2
RegRipperOpen-source Windows registry parsing toolgit clone https://github.com/keydet89/RegRipper3.0.git
RekallMemory forensics tooling (legacy fork of Volatility)pip3 install rekall
rizinModern fork of radare2 with cleaner APIgit clone https://github.com/rizinorg/rizin.git
The Sleuth KitLibrary and CLI tools for forensic disk analysisapt install sleuthkit
Volatility 3Memory forensics frameworkpip3 install volatility3
ToolDescriptionInstall / Link
BugBountyHunterWeb hacking training and labsbugbountyhunter.com
CTFtimeCalendar of upcoming and past CTF eventsctftime.org
CybraryFree + paid cybersecurity coursescybrary.it
DVWADamn Vulnerable Web Application — classic appsec labgit clone https://github.com/digininja/DVWA.git
Hack The BoxOnline pentesting labs and CTFshackthebox.com
Hacker101Free HackerOne course library and CTFhacker101.com
Immersive LabsCyber skills platform with hands-on exercisesimmersivelabs.com
MetasploitableIntentionally vulnerable Linux VM for Metasploit practicedocs.rapid7.com
OffSec Proving GroundsOSCP-style training labs by Offensive Securityoffsec.com
OverTheWire WargamesFree wargames for learning offensive security from scratchoverthewire.org
OWASP Juice ShopModern, intentionally insecure web app — covers OWASP Top 10docker pull bkimminich/juice-shop
OWASP WebGoatDeliberately insecure Java-based web app for trainingdocker pull webgoat/webgoat
PentesterLabHands-on web-app pentesting trainingpentesterlab.com
picoCTFFree CTF and learning platform built by CMUpicoctf.org
PortSwigger Web Security AcademyFree, world-class web security training (by Burp Suite team)portswigger.net
pwn.collegeFree college-level cybersecurity education from ASUpwn.college
PwnedHubIntentionally-vulnerable web app for hands-on appsec traininggit clone https://github.com/practisec/pwnedhub.git
Root-Me500+ challenges and 100+ virtual labsroot-me.org
TryHackMeBeginner-friendly cybersecurity training platformtryhackme.com
VulnHubFree downloadable vulnerable VMs for offline practicevulnhub.com
VulnYXOnline platform with vulnerable boxes (free + premium)vulnyx.com
ToolDescriptionInstall / Link
BugbaseIndian-origin bug-bounty + vulnerability disclosure platformbugbase.ai
BugcrowdCrowdsourced security platform — bug bounty + pentestingbugcrowd.com
Disclose.ioStandardized vulnerability-disclosure language and toolsdisclose.io
HackerOneLargest bug-bounty platform — public and private programshackerone.com
HackTrophyEuropean bug-bounty platformhacktrophy.com
ImmunefiWeb3 / crypto-focused bug bounty platformimmunefi.com
IntigritiEuropean bug-bounty platform with fast triageintigriti.com
Open Bug BountyFree coordinated-disclosure platformopenbugbounty.org
Public Bug Bounty Programs (chaos)ProjectDiscovery's free BBH program listchaos.projectdiscovery.io
SynackCrowdsourced + vetted-researcher pentesting platformsynack.com
YesWeHackEuropean-based bug-bounty and VDP platformyeswehack.com
ZerodiumPremium 0day acquisition platformzerodium.com
ToolDescriptionInstall / Link
0xdf hacks stuffHTB writeups and pentesting writeups0xdf.gitlab.io
awesome-hacking-resourcesBeginner-friendly hacking learning resourcesgithub.com
awesome-incident-responseCurated list of IR tools and resourcesgithub.com
awesome-malware-analysisCurated list of malware-analysis toolsgithub.com
awesome-pentestMassive curated list of pentesting tools and resourcesgithub.com
Bellingcat's Online Investigations ToolkitBellingcat-curated tools and methodology guidebellingcat.com
BTFM: Blue Team Field ManualConcise blue-team incident response referenceamazon.com
Hacking: The Art of Exploitation (book)Classic by Jon Erickson — low-level attack fundamentalsnostarch.com
IppSec.rocksIndexed walkthroughs of HackTheBox machines (video)ippsec.rocks
John HammondCybersecurity YouTube — CTFs, malware, walkthroughsyoutube.com
Linux for OSINT (cipher387)21-day Linux-for-OSINT course (free)git clone https://github.com/cipher387/linux-for-OSINT-21-days.git
LiveOverflowHacking and security YouTube — deep technical contentyoutube.com
NahamSecBug bounty and offensive security YouTube contentyoutube.com
Netlas CookbookFree OSINT automation cookbookacademy.netlas.io
OSINT CuriousCommunity blog, podcast, and learning resourcesosintcurio.us
OSINT TechniquesMichael Bazzell's resources, books, and search toolsinteltechniques.com
Python for OSINT (cipher387)21-day Python-for-OSINT course (free)git clone https://github.com/cipher387/python-for-OSINT-21-days.git
Real-World Bug Hunting (book)Peter Yaworski — bug bounty methodology and real reportsnostarch.com
RTFM: Red Team Field ManualConcise red-team command referenceamazon.com
The Web Application Hacker's Handbook (book)Stuttard & Pinto — appsec bibleamazon.com
ToolDescriptionInstall / Link
abuse.ch HuntingHunt across all abuse.ch malware platforms with one queryhunting.abuse.ch
Aleph Open SearchDark-web search engine by Aleph Networksopen-search.aleph-networks.eu
Aletheia (image forensics)Detect manipulated/AI-generated imagesaletheia.ai
altdnsGenerates permutations, alterations and mutations of subdomainspip3 install py-altdns
anewAppend lines from stdin to a file only if not already therego install github.com/tomnomnom/anew@latest
ANY.RUNInteractive online malware sandboxany.run
Apollo.ioB2B phone/email finder — 1200 free credits/yrapollo.io
APT Groups and OperationsSpreadsheet of threat actors, sponsoring countries, TTPsdocs.google.com
AquatoneVisual inspection of websites across hosts (HTTP screenshots, attack-surface flyovers)go install github.com/michenriksen/aquatone@latest
Archive.todayWeb archive — saves snapshots even when robots.txt blocks Waybackarchive.ph
Arctic ShiftTool for accessing large dumps of Reddit data via API/webgit clone https://github.com/ArthurHeitmann/arctic_shift.git
Arkham IntelligenceOn-chain intel — labels, entities, historical flowsarkhamintelligence.com
assetfinderFind domains and subdomains related to a given domaingo install github.com/tomnomnom/assetfinder@latest
AutoReconMulti-threaded network reconnaissance and enumeration frameworkpip3 install git+https://github.com/Tib3rius/AutoRecon.git
AxiomDynamic infra framework for parallel cloud-based recongit clone https://github.com/pry0cc/axiom.git
BackgroundChecks.comBackground check aggregator (BeenVerified family)backgroundchecks.com
BaiduMajor Chinese search engine — essential for China-focused OSINTbaidu.com
BeVigilSearch subdomains, URLs, parameters from mobile applicationsbevigil.com
BGP.toolsModern BGP toolkit for network reconnaissancebgp.tools
BinaryEdgeCyber risk and attack-surface intelligencebinaryedge.io
BitqueryBlockchain data APIs for on-chain investigationbitquery.io
Black Book OnlineFree nationwide directory of public-record lookupsblackbookonline.info
BlackEye32+ phishing template builder for credential capture (lab-only)git clone https://github.com/An0nUD4Y/blackeye.git
Brave BrowserPrivacy-focused browser with built-in Tor/IPFS supportbrave.com
Brave SearchIndependent, transparent, ad-free search enginesearch.brave.com
BreachForums StatusStatus tracking for the rotating BreachForums mirrorsbreachforums.cx
BreadcrumbsFree crypto investigation platform — visualize transaction flowsbreadcrumbs.app
BrightCloud Threat IntelligenceURL/IP/threat reputation databasebrightcloud.com
BrightCloud URL/IP LookupReputation, category, and threat checks for URLs/IPsbrightcloud.com
BscScanBinance Smart Chain explorer — same UX as Etherscanbscscan.com
CachedViewView Google/Bing/Yandex cached versions of any pagecachedview.com
CastrickFind social media accounts via email, username, phonecastrickclues.com
Censys CLIOfficial Python wrapper and CLI for Censyspip3 install censys
CertKit Certificate SearchFast search for public SSL/TLS certificate recordscertkit.io
ChainabusePublic crypto-scam reporting databasechainabuse.com
Chainalysis ReactorPremium blockchain investigation platformchainalysis.com
CheckUserSearch username across multiple social networkscheckuser.vercel.app
CIRCL HashlookupFree public hashlookup for known software filescircl.lu
Cisco Talos IntelligenceIP and Domain Reputation Center for real-time detectiontalosintelligence.com
Clearbit ConnectEmail finder browser extension with company dataconnect.clearbit.com
Cloudflare RadarInternet traffic patterns, attacks, technology trendsradar.cloudflare.com
ClustrmapsFind people and address informationclustrmaps.com
Commander SearchBoolean search builder for OSINT investigatorscommandersearch.com
Constella IntelligenceIdentity threat intel from breaches and dark webconstellaintelligence.com
ContactOutFind emails and phones for 300M+ professionalscontactout.com
CredenShowIdentify your compromised credentials before others docredenshow.com
CrossLinkedLinkedIn enumeration — generate username lists from LinkedIn profilespip3 install crosslinked
DBpediaStructured Wikipedia data — SPARQL endpointdbpedia.org
Digital Footprint CheckFree username check on hundreds of sitesdigitalfootprintcheck.com
dirsearchWeb path scanner — advanced wordlist-based directory bruteforcepip3 install dirsearch
Discord LookupLook up Discord user info via IDdiscordlookup.com
DiscordHistorySearch public Discord servers and messagesdisboard.org
DNS HistoryHistorical DNS records lookupdnshistory.org
DocumentCloudPlatform for analyzing, annotating, publishing documentsdocumentcloud.org
DomainEye Reverse WHOISSearch domains by registrant datadomaineye.com
dork-cliRun Google dorks from the command linegit clone https://github.com/jgor/dork-cli.git
DorkGeniusAI-powered search query generator for Google, Bing, DuckDuckGodorkgenius.com
DorkyOnline dork builder for Google/Bing/DuckDuckGodorky.io
Dune AnalyticsSQL queries over indexed blockchain datadune.com
EllipticCrypto financial-crime detection and investigationelliptic.co
EmailRep.ioFree email reputation API by Sublime Securityemailrep.io
Epieos ToolsReverse-lookup email/phone for Google profile datatools.epieos.com
Epstein ExposedSearchable database of 2M+ DOJ Epstein case docs and network graphsepsteinexposed.com
ETDA APT GroupsSearch threat-actor groups and their toolsapt.etda.or.th
etherscan-pyPython wrapper for Etherscan APIpip3 install etherscan-python
ExportDataHistorical tweet, follower, and trend export toolexportdata.io
FamilyTreeNowFree genealogy search — addresses, phones, emailsfamilytreenow.com
ffufFast Go-based web fuzzer — directory, parameter, vhost discoverygo install github.com/ffuf/ffuf/v2@latest
Filesec.ioCatalog of malicious file extensions, risks, OS-level mitigationsfilesec.io
FindomainCross-platform subdomain enumerator with monitoring featuresgit clone https://github.com/Findomain/Findomain.git
FlickrPhoto-sharing — geosearch + license + camera EXIF intactflickr.com
Foller.meTwitter analytics — bio, languages, hashtags, mentionsfoller.me
Forensically BetaOnline image forensics — clone detection, level sweep29a.ch
FullContactIdentity-resolution API and person enrichmentfullcontact.com
gau (getallurls)Fetch URLs from AlienVault OTX, Wayback, Common Crawl, URLScango install github.com/lc/gau/v2/cmd/gau@latest
GeocreepyGeolocation aggregator — pulls geotagged posts across networksgeocreepy.com
GeoHintsBrowser-based satellite/streetview geolocation training & investigationgeohints.com
GeoSpy ProPremium AI image geolocation by Graylarkgeospy.ai
Get-Metadata.comOnline EXIF extractor — handles .DOCX/.PDF tooget-metadata.com
gfWrapper around grep with patterns for bug-bounty workflowgo install github.com/tomnomnom/gf@latest
GhiroAutomated digital image forensicsgetghiro.org
git-houndFind sensitive data exposed via GitHub code searchgo install github.com/tillson/git-hound@latest
github_monitorReal-time tracking of GitHub user activity and repo changesgit clone https://github.com/misiektoja/github_monitor.git
gitleaksDetect secrets, credentials, and API keys in git reposgo install github.com/gitleaks/gitleaks/v8@latest
Google Guide Advanced OperatorsReference for Google search operatorsgoogleguide.com
Google Hacking Database (GHDB)Index of dorks for finding publicly exposed infoexploit-db.com
GoSpiderFast Go web spider for crawling/auditgo install github.com/jaeles-project/gospider@latest
gowitnessModern Go-based web screenshot utility (Aquatone successor)go install github.com/sensepost/gowitness@latest
GrayhatWarfareIndex of open Amazon S3 buckets — find exposed cloud datagrayhatwarfare.com
GreyNoise CLICommand-line tool for GreyNoise mass-scanner intelpip3 install greynoise
GreyNoise VisualizerTells you which IPs are noise vs targeted threatsviz.greynoise.io
hakrawlerFast Go web crawler for endpoint and asset discoverygo install github.com/hakluke/hakrawler@latest
Hatching TriageModern malware sandbox with kernel-level monitoringtria.ge
haveibeenzuckeredCheck if a phone number is in the 533M Facebook breachhaveibeenzuckered.com
HIB RansomedCheck if your data has been leaked by ransomware groupshaveibeenransom.com
httprobeTake a list of domains and probe for working HTTP/HTTPSgo install github.com/tomnomnom/httprobe@latest
Hudson RockFree infostealer-compromise check tools (domain/email/IP)hudsonrock.com
Hybrid AnalysisFree advanced malware analysis service by CrowdStrikehybrid-analysis.com
IKnowYour.DadData breach search engineiknowyour.dad
ImgurImage hosting — meme tracing and reverse searchimgur.com
instagram_monitorReal-time tracking of Instagram users with email alerts and CSV logsgit clone https://github.com/misiektoja/instagram_monitor.git
Intelligence X (intelx.io)Selective archive search — emails, leaks, paste sites, dark-webintelx.io
InterlaceEasily turn single-threaded CLI apps into multi-threaded jobsgit clone https://github.com/codingo/Interlace.git
Joe SandboxDeep automated malware analysis (free tier)joesandbox.com
JSFinderFind JS files referenced from a URL — endpoints / API pathsgit clone https://github.com/Threezh1/JSFinder.git
Kagi SearchPremium privacy-respecting search engine, no ads, no trackingkagi.com
knockDomain knock — security testing via DNSgit clone https://github.com/guelfoweb/knock.git
KnockpySubdomain enumeration scan with virtual host discoverypip3 install knock-subdomains
linkedin2usernameGenerate usernames from a target's LinkedIn employeesgit clone https://github.com/initstring/linkedin2username.git
LinkedInDumperDump/scrape company employees from LinkedIn APIgit clone https://github.com/l4rm4nd/LinkedInDumper.git
MalpediaThreat-actor groups, malware families, and analysis by Fraunhofermalpedia.caad.fkie.fraunhofer.de
MalShareFree malware sample repository for researchersmalshare.com
massdnsHigh-performance DNS stub resolver for bulk lookupsgit clone https://github.com/blechschmidt/massdns.git
megFetch many paths for many hosts without floodinggo install github.com/tomnomnom/meg@latest
Memento Time TravelFederated search across multiple web archivestimetravel.mementoweb.org
Metadata2GoFree online metadata extractor for any filemetadata2go.com
MetaDefender CloudMulti-engine file/URL/IP scanning by OPSWATmetadefender.com
MetaSleuthFree + paid crypto transaction tracing toolmetasleuth.io
MISP GalaxyAdversary group identification used by SOCs/ISACsmisp-galaxy.org
MitakaBrowser extension for OSINT — extract IoCs from highlighted textgit clone https://github.com/ninoseki/mitaka.git
Mnemonic Passive DNSFree passive-DNS query toolpassivedns.mnemonic.no
MojeekIndependent search engine that doesn't track usersmojeek.com
Mylnikov GeolocationBSSID/Wi-Fi MAC to coordinates lookupmylnikov.org
NaabuFast Go-based port scanner from ProjectDiscoverygo install github.com/projectdiscovery/naabu/v2/cmd/naabu@latest
Name CheckrCheck domain and username across many platformsnamecheckr.com
Name CheckupCheck username availability across social medianamecheckup.com
NameKetchupCheck domain + username on popular social medianameketchup.com
NaverSouth Korean search engine — local content not on Googlenaver.com
NerdyDataSearch engine for source code across the public webnerdydata.com
Netcraft Site ReportWeb technology, hosting history, takedown servicesitereport.netcraft.com
OblivionOSINT frameworkgit clone https://github.com/loseys/Oblivion.git
ODINSearch hosts, CVEs, exposed buckets — 10 free searches/daysearch.odin.io
Offshore Leaks DatabasePanama/Pandora/Paradise Papers searchable databaseoffshoreleaks.icij.org
OnionLand SearchSearch engine for dark-web contentonionlandsearchengine.com
Open-Source Intelligence (Reverse Image)Yandex/Bing/TinEye combined reverse-image searchoosint.com
OpenCellIDLargest public database of cell-tower IDsopencellid.org
opencorporates-cliCommand-line client for OpenCorporates APIpip3 install opencorporates
OpenPhishLive phishing URL feedopenphish.com
OpenRailwayMapWorldwide rail network map — rolling stock, infrastructure, signalsopenrailwaymap.org
OpenSanctionsConsolidated database of sanctioned entities across 200+ sourcesopensanctions.org
OXT (OpenXt)Bitcoin transaction graph explorer with clusteringoxt.me
PassiveTotal (RiskIQ)Passive DNS, WHOIS, SSL cert pivots — now Microsoft Defender TIcommunity.riskiq.com
PeekalinkPreview any URL — title, description, screenshot via APIpeekalink.io
PhishStatsLive phishing intelligence feed and searchphishstats.info
PhishTankAnti-phishing community — verified phishing URLsphishtank.org
Picarta.aiAI-powered photo geolocation predictorpicarta.ai
PinterestVisual search engine — alternate reverse-image sourcepinterest.com
PolygonScanPolygon (Matic) blockchain explorerpolygonscan.com
Predicta SearchSearch social accounts by email or phonepredictasearch.com
Public Transport Maps20+ online public transport maps by countrycipher387.github.io
PublicWWWSearch the web's source code (HTML/JS/CSS) for snippets, trackers, scriptspublicwww.com
PullPushIndex/retrieval service for Reddit (incl. deleted content)pullpush.io
Pushshift APIHistorical Reddit data — posts, comments, metadatapushshift.io
Quake (360.cn)Chinese internet asset search enginequake.360.net
RECAP ArchivePublic archive of PACER court documentscourtlistener.com
reconFTWFull-suite domain recon — subdomain enum, port scan, vuln scan in one pipelinegit clone https://github.com/six2dez/reconftw.git
RedditMetisReddit user analysis — summary, top posts, activity statsredditmetis.com
RedditSearch.ioSearch archived Reddit content via Pushshift mirrorredditsearch.io
Revealer.ccDiscord-based account-checker & breach lookuprevealer.cc
RocketReachFind professional emails/phones for 700M+ profilesrocketreach.co
RustScanModern port scanner — finds open ports, then pipes to Nmapgit clone https://github.com/RustScan/RustScan.git
ScamAdviserCheck website trustworthiness scoresscamadviser.com
ScribdSearch for documents, presentations, sheet music, ebooksscribd.com
searchcodeSearch 75+ billion lines of public source code across GitHub/GitLab/Bitbucketsearchcode.com
SeekerGeolocation by phishing — collects precise GPS via WebRTC + browser geolocationgit clone https://github.com/thewhiteh4t/seeker.git
Shadowserver DashboardGlobal statistics on cyber threats by Shadowserver Foundationdashboard.shadowserver.org
SherloqOpen-source image forensics toolsetgit clone https://github.com/GuidoBartoli/sherloq.git
Shodan CLIOfficial Shodan command-line clientpip3 install shodan
SlideShareSearch public PowerPoint/PDF presentationsslideshare.net
smapDrop-in replacement for nmap powered by shodan.iogo install github.com/s0md3v/smap/cmd/smap@latest
Snusbase APIAPI access to breach data (premium)snusbase.com
SourceGraphSearch code from millions of open-source repossourcegraph.com
SpyCloudAccount-takeover prevention + identity exposure dataspycloud.com
StartpagePrivacy-focused search — Google results with no trackingstartpage.com
StealSeekSearch engine for finding and analyzing data breachesstealseek.io
SubredditStatsSubreddit user-overlap, growth, top postssubredditstats.com
TelegagoGoogle CSE for finding public/private Telegram channelscse.google.com
Telegram Nearby MapFind positions of nearby Telegram users via OSMgit clone https://github.com/tejado/telegram-nearby-map.git
Telegram Search (lyzem.com)Search public Telegram messages and channelslyzem.com
TelemetrTelegram channel/group analyticstelemetr.io
TelereconReconnaissance framework for investigating Telegramgit clone https://github.com/sockysec/Telerecon.git
TeletegTelegram search engine — 10 free resultsteleteg.com
TGStatTelegram channel analytics — post stats, audience overlaptgstat.com
The Hidden WikiCurated directory of dark-web sites (mirror-dependent)thehiddenwiki.org
the-endorserMap LinkedIn endorsements/skills to draw out person relationshipsgit clone https://github.com/eth0izzle/the-endorser.git
TikTok Finder CountryFree OSINT lookup for TikTok account country/languagetiktokfindercountry.xyz
TorghostNGAnonymize all OS traffic via Tor (Linux)git clone https://github.com/githacktools/TorghostNG.git
TOsintExtract info from Telegram bots and channelsgit clone https://github.com/drego85/tosint.git
TraceSearch usernames, emails, phones across 600+ platforms with risk scoringtrace.manus.space
Transit Visualisation ClientReal-time public transport across 700+ citiestracker.geops.ch
Trends24Twitter trends history per countrytrends24.in
TRM LabsCrypto compliance and investigation platformtrmlabs.com
TweetBinderTwitter/X analytics dashboardstweetbinder.com
Twitch SearchSearch live streams by category, language, viewer counttwitch.tv
TwiteurTwitter/X advanced search wrapper — geo, date, sentimenttwiteur.com
U-FindReddit user comment / submission scraperu-find.com
uncoverProjectDiscovery — quickly find exposed hosts via Shodan/Censys/Fofago install github.com/projectdiscovery/uncover/cmd/uncover@latest
URLCrazyGenerate domain typos and check availability/registrationgit clone https://github.com/urbanadventurer/urlcrazy.git
URLhaus (abuse.ch)Database of malicious URLs used for malware distributionurlhaus.abuse.ch
User-SearcherSearch a username across 2000+ websitesuser-searcher.com
Vehicle Number Search ToolboxSearch 14 country license plates from one pagecipher387.github.io
VenacusSearch for your data breaches and get notified when compromisedvenacus.com
Vigilante.pwIndex of dumped databases (educational)vigilante.pw
VMRay AnalyzerMalware sandbox analysis platformvmray.com
WalletExplorerSmart bitcoin block explorer — clusters addresses by entitywalletexplorer.com
waybackurlsFetch all URLs the Wayback Machine knows about a domaingo install github.com/tomnomnom/waybackurls@latest
WhoisologyReverse WHOIS — find domains by registrantwhoisology.com
WhoxyWHOIS lookup with reverse-WHOIS, history, and bulk APIwhoxy.com
WikidataWikipedia's structured-data backbone — query via SPARQLwikidata.org
WikipediaFree encyclopedia — start of every people/place investigationen.wikipedia.org
WorldLicensePlatesGraphic index of license plates by countryworldlicenseplates.com
XeuleDocFetch info on Google Docs/Sheets/Slides/Drawings without authpip3 install xeuledoc
YandexRussian search engine — strong reverse-image and Cyrillic supportyandex.com
YARAifyCollaborative YARA engine for open threat intel via file pattern matchingyaraify.abuse.ch
YumpuDocument publishing — sometimes leaks via searchyumpu.com
ZeroBounceEmail validation and deliverability servicezerobounce.net
ZoomEye CLICommand-line interface for ZoomEye internet asset searchpip3 install zoomeye