
maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites

🕵️♂️ Collect a dossier on a person by username from 3000+ sites

Abusing Certificate Transparency logs for getting HTTPS websites subdomains.

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain…

An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and…

🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.

XRay is a tool for recon, mapping and OSINT gathering from public networks.

AI-powered threat intelligence platform for automated CVE/ransomware monitoring, domain surveillance, data leak detection, and incident response with…

Build interactive map of cameras from Shodan

Shodan-powered tool to discover real IP addresses behind Cloudflare by hashing favicon icons using MurmurHash3, enabling origin server identification…

Real-time geospatial OSINT platform aggregating flight, vessel, and satellite data with dark web search, social media dorking, and AI-powered…

⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.

Extract subdomains from SSL certificates in HTTPS sites.

Get related domains / subdomains by looking at Google Analytics IDs

Twitter Back From The Dead looks in a user tweets history for domain names that are available for registration

Opinionated organisation-centric OSINT footprinting inspired from recon-ng and Maltego