21 Best Free OSINT Tools for Cyber Investigations

There are plenty of free or almost-free OSINT tools you can find online — ChatGPT can provide you with quite a list. But, as often happens with ChatGPT, some of those tools simply don’t exist, some don’t work anymore, and some provide low-quality data. 

In this post, we have collected several OSINT tools that actually work quite well for different digital research and information gathering purposes, grouped according to their primary use cases. All of these tools could be very handy for different tasks such as cybercrime investigation, threat hunting, offensive cybersecurity exercises, and more.

Note that the tools on this list are mostly for investigating and mapping internet infrastructure and working with indicators of compromise (IoCs), such as network and host artifacts, domain names, IP addresses, and hash values. For tools that look into people, entities, and their internet presence, we suggest that you take a look at Bellingcat’s OSINT toolkit, even though some of the tools mentioned below can help with that as well.

OSINT Toolboxes

1. Maltego

Maltego is a multipurpose OSINT pivot engine and a visual investigation platform for connection mapping, widely used by law enforcement agencies and cybersecurity investigators. It takes “entities,” such as people, organizations, domains, or IP addresses and uses “transforms” to gather related information and present it in an interactive graph. 

Maltego screenshot
Image source: https://docs.maltego.com/en/support/solutions/articles/15000008836-panning-and-zooming#zooming-0-1

Maltego’s key features include:

  • “Transforms” — automated search queries that fetch data from open data sources and APIs.
  • Various entities or data points that can be linked and analyzed.
  • Visual link analysis in an interactive graph, limited to 24 results per “transform” for free accounts.
  • Preconfigured sets of transforms called “machines” that automate common investigation workflows.
  • Prebuilt connectors that enable you to integrate with more than 100 data sources, with limited access for free accounts.

Maltego is not completely free, but it has a free tier called Basic, that provides you with core features and a couple of hundred credits per month to use the powerful engine for occasional small OSINT investigations.

What can you do with Maltego?

  • Cybercrime investigations: Link a known email address to related domains, social profiles, and network infrastructure using automated transforms.
  • Threat actor attribution: Uncover connections between seemingly unrelated domains, IPs, and registrant details.
  • Corporate due diligence: Spot hidden relationships between business entities, executives, and web assets to detect shell companies or suspicious affiliations during a background investigation.

2. SpiderFoot

SpiderFoot is an OSINT automation tool for threat intelligence and attack surface mapping. You can gather and correlate information from over 200 data sources (some open, some paid) about targets like domain names, subdomains, IP addresses, personal or company names, email addresses, subnets, Bitcoin addresses, social media platform accounts, and usernames.

SpiderFoot Screenshot
Image source: https://medium.com/@micallst/lessons-learned-from-my-10-year-open-source-project-4a4c8c2b4f64

Among SpiderFoot’s key features are:

  • More than 200 modules or integrations that either don’t require API keys or have free tiers.
  • Both a web-based GUI and a command-line interface.
  • Modules that search the Tor network (dark web) for mentions of targets.

SpiderFoot is available on GitHub for free. Or rather, there’s a version that hasn’t received updates for three years and with more than two dozen pull requests awaiting acceptance and over a hundred issues awaiting triage. That probably has something to do with the fact that SpiderFoot was acquired by Intel 471 in 2022. The terms of the deal were not disclosed, but seemingly, since then, the open-source part of the project has been abandoned. However, there is a fork that seems to be actively maintained as of the time of writing.

What can you do with SpiderFoot?

  • Attack surface mapping: Automatically enumerate subdomains, exposed email addresses, open ports, and leaked credentials tied to a target organization.
  • Phishing investigations: Discover related infrastructure behind a suspected phishing campaign, including connected domains, hosting providers, and threat intelligence hits.
  • Dark web monitoring: Detect mentions of a target domain or email address on dark web forums and marketplaces.

3. OSINT Framework

OSINT Framework was developed to help users find free OSINT tools, public sources, and resources, although some data sources might still require registration or provide more data for a fee. It’s not strictly a toolbox that allows you to pivot off a data point, but more of a directory of resources from which you can find more information about a target data point. 

OSINT Framework Screenshot
OSINT Framework screenshot

The key features of the OSINT Framework are:

  • It is very organized, with the list of tools presented as a tree-like structure based on the type of information you already have and want to pivot off.
  • It prioritizes free or open-source tools.
  • OSINT Framework is maintained by the OSINT community, so the listed resources are likely updated.

OSINT Framework is completely free and open-source, with its source code available on GitHub under the MIT license. The project seems to be actively maintained, with the latest pull request merged less than a month ago.

Warning: Reddit users have complained that they’ve landed on malicious websites upon trying to use some of the tools listed in the OSINT Framework. While the Framework maintainers are likely not to blame and this is the problem of all large free tool catalogues, we suggest that you exercise caution while using it.

What can you do with OSINT Framework?

  • Investigation starting point: Find the right tool for a specific data type, such as email addresses, usernames, IP addresses, or phone numbers.
  • Tool discovery: Find free resources for less-common investigation types, such as cryptocurrency tracing, dark web research, or vehicle identification.

4. Domain Research Suite

Domain Research Suite by WhoisXML API is a web-based investigation platform that provides cyber investigators and security analysts with a centralized 10-in-1 toolkit for domain analysis and current or historical domain events. It allows users to pivot from a single data point — such as a registrant’s email address, IP address, or brand name — to investigate domains, uncover related assets, and track threat actors.

Domain Research Suite screenshot

Domain Research Suite includes these specialized tools:

Search toolsMonitoring tools
Reverse WHOIS Search
WHOIS History Search
WHOIS Search
Reverse DNS Search
Domain Availability Check
Domains & Subdomains Discovery
Domain Info Search
Domain Monitor
Registrant Monitor
Brand Monitor

The platform’s main features are:

  • Access to billions of records through specialized tools to connect the dots between seemingly unrelated domains.
  • Access to historical WHOIS records that may reveal ownership information and other details from before privacy redaction, helping investigators build fuller domain-registration timelines where such data is available.
  • The ability to track domain registration changes and receive automated alerts for typosquatting, brand infringement, or infrastructure updates.
  • A user-friendly interface that allows investigators to effortlessly organize their findings and download comprehensive reports.

While Domain Research Suite is a commercial product, new users can create a free account to receive complimentary credits, allowing them to test the platform and perform initial OSINT investigations at no cost.

What can you do with the Domain Research Suite?

  • Phishing investigations: Pivot from a suspicious registrant email address to uncover all domains registered by the same actor.
  • Typosquatting detection: Discover newly registered domains that mimic a brand name and set up alerts to catch new lookalike domains a few hours after they are registered.
  • Attacker profiling: Trace historical WHOIS records to reconstruct a timeline of a threat actor’s domain registration activity, including historical details that may predate GDPR-era privacy redactions, where available.

5. Jake AI

Jake AI is WhoisXML API’s cloud-based Domain Intelligence AI Assistant that works much like the aforementioned MCP Server, but without the need to install anything — it has a web-based GUI and runs an LLM and the MCP server under the hood. 

All you need is your API key, and you can start using Jake AI, doing OSINT investigations, external attack surface discovery, and threat infrastructure mapping, among other things.  

Jake AI: WhoisXML API's domain intelligence assistant screenshot

Jake AI connects to 17 different APIs and has the following key features:

  • It can combine multiple APIs to answer complex questions.
  • Jake AI can do bulk lookups, so you can investigate up to 10 IP addresses or domain names all at once.
  • Setup is as easy as 1-2-3: Request access here, log in, and plug in your API key (existing WhoisXML API customers can use their API keys, while new users can sign up to get some free API credits)!
  • It gives you access to 17 WhoisXML API tools and billions of WHOIS, IP, DNS, and threat-intelligence data points.

WhoisXML API also offers an MCP server to connect the LLM of your choice to the APIs, if you prefer Claude, ChatGPT, or some other platform to Jake AI’s built-in model.

What can you do with Jake AI?

  • Threat infrastructure mapping: Ask natural language questions to correlate data across WHOIS, DNS, and threat intelligence databases.
  • Bulk IoC investigation: Investigate multiple IP addresses or domain names in one workflow, speeding up triage during incident response.
  • Guided OSINT workflow: Use the AI assistant to perform complex, multi-step investigations without having to manually switch between 17 different APIs.

Search Engines

1. Ahmia.fi 

Ahmia.fi is a search engine designed to index and search hidden services on the Tor network. It allows investigators to find find dark web content and .onion sites without having to manually browse the Tor network. 

Ahmia.fi screenshot
Image source: a screenshot of Ahmia.fi done by the author

Its key features are:

  • It’s dark-web-specific but accessible via your regular web browser.
  • There’s a time filter that allows you to limit search results to entries added in the previous day, week, or month.
  • It filters out potentially illegal content.

Ahmia.fi is free to use. If someone wants to contribute to the project, it’s available on GitHub under BSD-3-Clause license.

What can you do with Ahmia.fi?

  • Dark web monitoring: Search for keywords, email addresses, or brand names mentioned across .onion sites without needing to manually browse the Tor network.
  • Dark-web discovery: Find indexed .onion sites by keyword without relying only on manually curated .onion directories.

2. Intelligence X

Intelligence X specializes in searching for online information in places not typically indexed by regular search engines, such as the darknet, document-sharing platforms, WHOIS databases, and public data leaks for email addresses, domains, URLs, IP addresses, CIDRs, Bitcoin addresses, IPFS hashes, and many other data points.

Intelligence X OSINT tool

Some of Intelligence X’s features include:

  • A broader scope than other search engines since it searches several sources.
  • Searches current data but also archives historical data.
  • Supports a diverse range of input types.
  • Advanced search filters by date, media type, certain countries, specific TLDs, and other categories.

Intelligence X is a commercial product, but it offers as many as four different free tiers. They are, of course, severely limited compared to paid ones, but they still do the job.

What can you do with Intelligence X? 

  • Data breach research: Search for email addresses or domains exposed in past data leaks and public breach datasets to assess whether sensitive information from your organization is in circulation.
  • Dark web intelligence: Find archived or indexed content from dark web forums, paste sites, and document-sharing platforms that standard search engines do not index.
  • Financial crime investigations: Look up Bitcoin addresses to find related mentions across multiple sources and historical archives.

3. Shodan

Shodan is a search engine for internet-connected devices that can be used for scanning IP addresses to find exposed services, industrial control systems, webcams, and other network devices. 

Shodan screenshot

Shodan’s key features include the following:

  • The tool’s search is device-centric, unlike other search engines that index websites.
  • It displays service banners (metadata about running software or hardware), which often reveal version numbers, vulnerabilities, and misconfigurations.
  • It allows you to filter results based on location, metadata, hostname, ISP, operating system, and other parameters.

While Shodan offers commercial price plans and doesn’t have a free plan, it still allows users to perform basic searches without requiring them to log in.

What can you do with Shodan?

  • Exposed asset discovery: Identify internet-facing services within an organization’s IP ranges that are running outdated software versions or have open ports that should not be publicly accessible.
  • Threat hunting: Search for IP addresses or services that match the configuration fingerprints of known threat actor infrastructure, using banner data and metadata to identify malicious hosts.

4. Censys Search

Censys’ search engine allows you to scan certificates and hosts (IP address, domain name, or protocol), which helps identify misconfigurations in web servers, databases, and other internet-facing systems. 

Censys Search screenshot

Among its key features are:

  • Offers detailed information on SSL/TLS certificates, but you need to create an account to access other details like historical changes, WHOIS information, and connected domains.
  • Identifies the software, versions, and protocols running on exposed ports.
  • Performs broad and deep scans of the entire IPv4 space, often discovering different sets of exposed services and devices compared to other scanners.

Censys Search is a commercial product, but it allows you to perform some searches without having an account at all and offers additional information on the free plan. 

What can you do with Censys Search?

  • Certificate pivoting: Find all domains sharing a specific SSL/TLS certificate to identify additional infrastructure tied to it, getting additional leads in threat actor attribution.
  • Misconfiguration detection: Identify exposed databases, open Redis or Elasticsearch instances, and misconfigured web servers across the entire IPv4 space before attackers exploit them.

Infrastructure Analysis Tools 

1. BuiltWith 

BuiltWith is a website analysis tool that identifies the technologies used to build and run any given website. It uncovers everything from content management systems (CMS) and e-commerce platforms to analytics tools, hosting providers, and advertising networks. 

Builtwith screenshot

BuiltWith’s features include:

  • A database with more than 117,000 web technologies.
  • Tracking the historical usage of technologies on a website.
  • Integrations with several third-party vendors, although most are sales- and marketing-related.

BuiltWith is a commercial tool, but individual website lookups are free and don’t even require registration. The paid plans allow you to get lists of websites built using a certain technology. 

What can you do with BuiltWith?

  • Phishing site analysis: Identify the CMS, hosting provider, CDN, analytics tags, tracking scripts, JavaScript libraries, and other technologies used by a suspected phishing site. Analysts can compare the stack against legitimate infrastructure, find reusable fingerprints, and cluster related suspicious sites for further investigation.
  • Competitive intelligence: Profile a competitor’s full technology stack, including their CDN, e-commerce platform, and analytics tools, to inform infrastructure planning or market research.

2. Netcraft’s Site Report

Netcraft’s Site Report provides a detailed security and technology overview of any website, leveraging Netcraft’s internet data mining and cybercrime monitoring capabilities. It lets investigators see that website’s hosting information, site popularity, network details, and various security-related configurations, including SSL/TLS, SPF, and DMARC records.

Netcraft's Site Report screenshot

Its key features are:

  • Netcraft’s Site Report includes critical security aspects like SSL/TLS certificate details, HTTP security headers (e.g., X-Frame-Options, CSP), and email authentication records (SPF, DMARC).
  • The site report provides context related to the site’s hosting, age, and reputation, which can indicate phishing or malicious intent.
  • It tracks changes in a website’s hosting provider, IP address, and nameservers over time.
  • An option to report a suspicious website that is easily accessible from the site report page. 

Netcraft’s Site Report is completely free. Netcraft also offers paid products that allow users to find similar websites.

What can you do with Netcraft’s Site Report?

  • Phishing verification: Check a suspicious domain’s hosting provider, IP/network information, site technology, trackers, and historical infrastructure signals to assess whether it may be a newly created or suspicious site impersonating a legitimate brand.
  • Security configuration review: Inspect a site’s SSL certificate details, HTTP security headers, SPF, and DMARC as part of a security audit or vendor assessment.

3. urlscan.io

urlscan.io is a web-scanning and analysis platform that lets investigators submit URLs and inspect how a website behaves when loaded in a browser-like environment. It shows the infrastructure touched when the page loads, including the final domain, IP address, autonomous system numbers (ASN), country, PTR record, server header, redirects, TLS details, requested resources, contacted domains/IPs, hashes, screenshots, and DOM data.

urlscan.io screenshot
Image source: A screenshot of a scan from https://urlscan.io/result/019eba09-0277-71cb-9860-ef4125b265b5/

urlscan.io’s key features include:

  • Public, unlisted, or private scans.
  • Search capabilities that allow users to run search queries against existing scans by domains, IP addresses, ASN, hashes, and other attributes.
  • API access for submitting URLs, retrieving scan results, and searching existing scan data.

urlscan.io offers free web scanning and API access with usage limits. Paid plans add higher limits and additional threat hunting, monitoring, phishing feed, similarity search, and advanced search capabilities.

What can you do with urlscan.io? 

  • Phishing URL analysis: Submit a suspected phishing link to see every domain, IP address, and resource it contacts when loaded.
  • Malware delivery chain mapping: Identify JavaScript redirects, external scripts, and resources loaded by a malicious page to map the full delivery chain behind a malware distribution campaign.

Threat Intelligence Tools

1. LevelBlue’s Open Threat Exchange (OTX)

OTX (previously AlienVault’s OTX, but now under AT&T’s cybersecurity division called LevelBlue) is a free, community-powered threat intelligence sharing platform where security professionals collaborate to share information about the latest security threats. You can find information about indicators of compromise (IoCs), malware families, and adversaries, as well as browse threat intelligence by industry.

Alienvault OTX screenshot

Its key features are:

  • Threat intelligence is organized into “Pulses,” which are curated lists of IoCs with a summary of a specific threat, its impact, and the targeted software.
  • OTX allows users to automatically integrate shared IoCs into their security infrastructure (e.g., SIEMs, firewalls) via APIs.
  • It supports a wide range of IoC types, including IP addresses, domains, URLs, file hashes (MD5, SHA-1, SHA-256), and email addresses.

Unlike many commercial threat intelligence feeds, OTX provides free and open access to a wealth of real-time threat data.

What can you do with AlienVault OTX? 

  • IoC enrichment: Look up a suspicious IP address, domain, or file hash to surface associated threat intelligence pulses, malware families, and attack campaigns contributed by the global security community.
  • Incident response: Cross-reference IoCs discovered during a breach against OTX pulses to get immediate context, attribution clues, and target systems.
  • Threat feed integration: Use the OTX API to pull curated IoC lists directly into a SIEM, firewall, or EDR platform for automated detection and blocking.

2. WhoisXML API’s Threat Intelligence API 

The Threat Intelligence API allows investigators to find cybersecurity intelligence and threat information about any domain, URL, IP address, CIDR number, or hash. It also accepts wildcard queries, allowing you to see if any IoC uses the search term.

WhoisXML API's Threat Intelligence API

The key features of WhoisXML API’s Threat Intelligence API are:

  • Seamless integration since query responses come in standardized XML and JSON formats.
  • Various data sources, including honeypots, server logs, OSINT data sources, and ISP abuse reports.
  • Covers several types of threats, including cyberattacks, botnet usage, C&C, malware, phishing, spamming, Tor usage, and suspicious activities.
  • Supports several IoC types, such as domain, URL, IP address, CIDR, and hash.

Like most of WhoisXML API’s tools, the Threat Intelligence API is not entirely free, but offers a certain free monthly credit allowance that the user can employ to try it out (and enough to support small-scale investigations).

What can you do with the Threat Intelligence API? 

  • IoC validation: Verify whether a domain, IP address, or file hash is flagged across multiple threat intelligence feeds before acting on a security alert, reducing false positives.
  • Phishing detection: Run domains and URLs extracted from suspicious emails through the API to check for known phishing infrastructure.
  • Botnet C2 identification: Investigate IP addresses for known associations with botnet command-and-control (C2) activity, spamming, or Tor exit node usage.

3. VirusTotal

VirusTotal is a free online service that analyzes suspicious files, URLs, domains, and IP addresses against more than 70 antivirus scanners and threat intelligence blacklisting services. Users can just scan a suspicious resource to see if any of the threat engines have reported it to be malicious.

VirusTotal screenshot

Its key features are:

  • Allows registered users to comment on indicators and share valuable context that enriches the analysis for other users and helps identify false positives or negatives.
  • Its relationship graph enables users to visualize the connections between files, URLs, domains, and IP addresses.
  • Aside from threat detection, VirusTotal provides WHOIS registration data and Google search results.

VirusTotal is free to use for basic web analysis and even offers free API access, but with some severe limitations. There are also premium/enterprise features, such as higher-volume enrichment and YARA-based hunting.

What can you do with VirusTotal? 

  • Malware file analysis: Upload a suspicious executable to scan it against multiple antivirus engines simultaneously and enrich it with detection names, file metadata, known malware-family labels, static indicators, and behavioral observations without executing the file locally.
  • URL and domain reputation: Check whether a URL or domain is blacklisted by threat intelligence services before clicking on a link or allowing it through a network filter.
  • Relationship mapping: Use VirusTotal’s graph feature to trace connections between malware samples, related domains, and IP addresses.

4. GreyNoise

GreyNoise is a threat intelligence platform that helps analysts understand whether an IP address is part of internet-wide scanning, exploitation, bot activity, or other noise that commonly hits internet-facing systems. Its free community edition allows users to perform IP lookups that show whether an address has been observed scanning the internet or appears in GreyNoise’s dataset of known business services.

Greynoise screenshot
Image source: Sample of an IP lookup on GreyNoise Community Edition

GreyNoise’s key features include:

  • IP classification labels, such as benign, malicious, or unknown, depending on available context.
  • Infrastructure context, including organization, ASN, country, region, city, domain, carrier, datacenter, rDNS, and rDNS parent when available.
  • Trends, Today, Tags, and Analysis sections for exploring broader internet scanning, exploitation activity, and digital security risks.

GreyNoise is a commercial product, but it offers a free community tier for basic IP lookups. Free/community usage is limited, while paid plans provide broader access, higher-volume lookups, deeper context, integrations, feeds, and additional investigation features.

What can you do with GreyNoise? 

  • Alert triage: Determine whether an IP that triggered a security alert is part of routine internet background scanning, helping analysts quickly separate opportunistic noise from targeted attacks.
  • Threat hunting: Identify IP addresses that are actively exploiting known vulnerabilities or scanning for specific services.

Domain Intelligence Tools

1. WhoisXML API’s WHOIS History 

WhoisXML API’s WHOIS History provides access to billions of historical WHOIS records for domains, which allows investigators to track ownership changes, registration details, and contact information over time. 

WhoisXML API's Whois History screenshot

WhoisXML API’s WHOIS History standout features include:

  • Multiple data consumption models, including via API, web-based lookup tool, and a full database.
  • For older websites, the tool gives access to WHOIS records from before the GDPR implementation that led to widespread redaction of registrant information, often allowing users to find website owner contact information. 
  • The database is updated daily, ensuring that the information includes the latest records.
  • It’s easy to integrate into workflows thanks to  standardized JSON and XML output formats.

WHOIS History is a commercial product, but 500 free API credits are available upon signup.

What can you do with WHOIS History? 

  • Domain attribution: Retrieve historical registrant contact details from before the GDPR-era privacy redaction to identify who originally registered a domain.
  • Threat actor tracking: Monitor ownership changes across a domain’s registration history to spot when it switched hands to a known malicious actor or was re-registered after expiry.
  • Fraud investigation: Trace the full registration timeline of a fraudulent website to build a chronological attacker profile and connect the domain to related assets.

2. WhoisXML API’s DNS History

WhoisXML API’s DNS history products include the DNS Chronicle API, a web-based lookup tool, and a DNS database download. They enable investigators to perform both forward and reverse historical DNS searches. Forward lookups allow users to access a log of past DNS configurations for a given domain, including changes to IP addresses, nameservers, mail servers, and other DNS records (some record types are only available in the database download option). Reverse DNS searches for an IP address return a list of all connected FQDNs. 

WhoisXML API's DNS History screenshot

DNS Chronicle’s key features are:

  • Provides access to hundreds of billions of historical DNS records.
  • Offers a detailed timeline of a domain’s DNS activity, arranged in chronological order.
  • Aggregates passive DNS data, which is collected from sensors worldwide, and records DNS resolutions over time.
  • Like WHOIS History, WhoisXML API offers flexible DNS history access via API integration or database downloads.

Like with other WhoisXML API tools, DNS Chronicle is commercial, but 500 free API credits are available upon signup and can be used both for web lookups and API access.

What can you do with DNS History? 

  • IP-to-domain pivoting: Find all domains that historically resolved to a suspicious IP address to identify co-hosted infrastructure and uncover additional assets tied to the same operator.
  • Threat infrastructure timeline: Reconstruct how a threat actor’s domain DNS configuration changed over time, including IP address hops and changes to nameservers and mail servers, to follow their operational trail.
  • C2 tracking: Use historical DNS records to map the full C2 infrastructure behind a malware campaign, tracing how domains and IPs were rotated to evade detection.

3. WhoisXML API’s IP Geolocation API

IP Geolocation API is also a product of WhoisXML API, which adds geographical and network context to any given IPv4 or IPv6 address, including its country, region, city, postal code, precise coordinates, and time zone. It also reveals information about the internet service provider (ISP), autonomous system (AS) details, and associated domain names for that IP address.

WhoisXML API's IP Geolocation lookup screenshot

Its key features include:

  • 99.5% IP address coverage for both IPv4 and IPv6, across hundreds of thousands of unique locations worldwide.
  • Provides very specific location data, including latitude, longitude, and postal codes, not just country or city.
  • There’s an option to include up to five domain names associated with the target IP address.

You automatically get a free subscription plan limited to 1,000 queries after signing up.

What can you do with the IP Geolocation API? 

  • Fraud detection: Compare a user’s claimed location against their IP address’s estimated country, region, and city to flag account takeover attempts or transactions made from unexpected locations.
  • Alert enrichment: Add geographic, ISP, and autonomous system context to suspicious IP addresses surfaced in SIEM alerts or server logs.
  • Access log analysis: Enrich large volumes of IP addresses from web server logs with location and network data to identify patterns, such as traffic spikes from unusual regions or ASNs.

4. OWASP Amass 

OWASP Amass is an open-source attack surface mapping and external asset discovery framework. It helps investigators discover domains, subdomains, related infrastructure, and other connected assets using open-source intelligence gathering and reconnaissance techniques.

OWASP Amass graph screenshot
Image source: https://github.com/owasp-amass/amass

Amass’s key features include:

  • Automated external asset discovery across domains and related infrastructure.
  • Subdomain enumeration using OSINT sources and, when configured, active reconnaissance techniques.
  • Network mapping that helps reveal relationships between discovered assets.
  • An asset database and Open Asset Model designed to store findings and support long-term attack surface tracking.
  • Flexible deployment through source builds, Homebrew, Docker, or Docker Compose.

Amass is free and open-source. The OWASP Amass Project is free to use under the Apache 2.0 License.

What can you do with Amass? 

  • Subdomain enumeration: Discover all subdomains of a target domain as part of a penetration test or external attack surface assessment.
  • Asset inventory: Map all internet-facing infrastructure owned by an organization.
  • Threat research: Identify additional domains and IP ranges associated with a known threat actor’s infrastructure by pivoting off known indicators using open-source intelligence techniques.

5. Archive.today

Archive.today (accessible through archive.is, archive.ph, and several other domain aliases) is a web archiving service that lets users capture and retrieve snapshots of web pages. For OSINT investigations, it can be useful for preserving pages that may change, disappear, or become unavailable during an investigation. It can also be used to check previously saved snapshots. 

archive.today screenshot, retrieving WhoisXML API's website from 13 years ago
This is how WhoisXML API’s website looked 13 years ago, reproduced by archive.today. Image source: https://archive.is/2FYqT

Archive.today’s key features include:

  • Supports different search methods — search by host, exact URL, URL prefix, or wildcard subdomain (*.medium.com). 
  • Short links to archived records that can be shared in reports or investigation notes.
  • Oldest and newest snapshot previews with timestamps.

Archive.today is free to use.

Warning: In January 2026, archive.today was found to have embedded code in its pages that used visitors’ browsers to perform a distributed denial-of-service (DDoS) attack against a third-party blog. The service was also found to have altered past archived snapshots. As a result, Wikipedia banned archive.today from use as a reference source in February 2026. Exercise caution when relying on archive.today snapshots as evidence, as their integrity cannot be guaranteed.

What can you do with Archive.today? 

  • Evidence preservation: Capture timestamped snapshots of web pages that may be modified or taken down during an investigation.
  • Historical comparison: Retrieve older snapshots of a website to identify changes in content, ownership statements, or page structure that may indicate a domain was repurposed for malicious activity.

Conclusion

Open source intelligence tools are an essential part of any investigator’s toolkit — whether you’re working in cybersecurity, law enforcement, digital forensics, digital research, threat hunting, or just having fun as a wanna-be FBI agent. While there’s no shortage of OSINT tools online, finding ones that are reliable, regularly updated, and truly useful can be a challenge. That’s why we focused this list on tools that work and deliver value, whether you’re tracking domain ownership, analyzing infrastructure, mapping threat data, or scanning the deep web.

Many of these tools offer free tiers that are generous enough to support small-scale investigations. Paired together, they can help build a clearer picture of online security threats, suspicious infrastructure, and digital footprints—without the need for expensive software licenses. As always, remember to validate findings, respect privacy laws, and use OSINT responsibly.

Changelog

June 2026:

  • Added: GreyNoise, Archive.today, Amass, urlscan.io, Domain Research Suite
  • Updated: tool descriptions
  • Removed: WhoisXML API’s subdomain discovery, WhoisXML API’s MCP server

July 2025:

  •  first published

Try our WhoisXML API for free

Get Started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.

Contact Us

White Paper Download

Please complete the form below to download the required file:

Your business email will be validated while the request is being processed. This may take time.