Infrastructure Discovery

Tools for mapping networks, tracing domains, and identifying the systems behind online activity. Clear, reliable, and built for precise discovery.

crt.sh

Free

Certificate Transparency log search. Find all subdomains by looking up TLS certificates. Great for mapping web infrastructure.

URL: crt.sh
How to use:
  1. Go to crt.sh
  2. Enter domain name (e.g., example.com)
  3. Add % before domain for wildcard search (%example.com)
  4. Review all discovered subdomains and certificates

Certificate Transparency APIs

Free

Programmatic access to CT logs. Use SSLMate's certspotter API or Google's CT API to automate subdomain discovery.

RIPEstat

Free

RIPE NCC's data service. Look up IP addresses, ASNs, prefixes, and abuse contacts. Essential for network attribution.

Hurricane Electric BGP Toolkit

Free

BGP routing data and ASN relationships. See who peers with who, upstream providers, and network topology.

URL: bgp.he.net

Internet Archive Wayback Machine

Free

Historical snapshots of websites. See what a site looked like years ago. Recover deleted content, find old contact info, track changes.

Shodan

Freemium

Search engine for Internet-connected devices. Find exposed services, open ports, vulnerable systems. Free tier has limited searches.

URL: shodan.io

Robots.txt & Sitemap.xml

Free

Add /robots.txt or /sitemap.xml to any domain. Reveals hidden directories, admin panels, API endpoints that site owners don't want crawled.

Example: example.com/robots.txt or example.com/sitemap.xml

SecurityTrails

Freemium

Historical DNS records and subdomain discovery. Track domain changes over time. Free tier provides limited lookups per month.

DNSDumpster

Free

DNS reconnaissance and subdomain mapping. Generates visual network diagrams. No registration required.

ViewDNS

Free

Reverse DNS lookup, reverse WHOIS, and DNS history. Multiple DNS intelligence tools in one interface.

Censys

Freemium

Internet-wide scanning data. Certificate searches, device fingerprinting, and exposure mapping. More structured than Shodan for research.

AbuseIPDB

Free

IP address reputation database. Check if an IP has been reported for malicious activity. Community-driven threat intelligence.

IPinfo

Freemium

IP geolocation, ASN details, and company information. Clean API for programmatic lookups. Free tier available.

URL: ipinfo.io

GreyNoise

Freemium

Identifies internet background noise vs targeted attacks. Determines if IP scanning is mass scanning or targeted activity.

AlienVault OTX

Free

Open threat intelligence platform. Community-contributed indicators of compromise, malicious IPs, and threat data.

Pulsedive

Free

Threat intelligence search engine. Query IPs, domains, and URLs for threat indicators. Clean interface with API access.

BuiltWith

Freemium

Website technology profiler. Identifies frameworks, analytics, hosting providers, and tech stack. Free basic lookups, paid for historical data.

LeakIX

Free

Search engine for exposed databases, API keys, and configuration files. Scans the internet for data leaks and misconfigurations.

URL: leakix.net

BinaryEdge

Freemium

Internet scanner and data platform. Maps exposed services, vulnerabilities, and hosts. API access for automated queries.

Onyphe

Freemium

Cyber defense search engine. Collects data on exposed assets, threat intelligence, and internet infrastructure. Free tier available.

URL: onyphe.io

GrayHat Warfare

Free

Search engine for publicly exposed AWS S3 buckets. Find misconfigured cloud storage containing sensitive files and data.

Username & Identity Search

When you have a username, email, or handle and need to understand its footprint. These tools help you connect details efficiently and with accuracy.

UserSearch.io

Freemium
2000+ Platforms 3 Free Searches/Day

Searches across 2000+ platforms simultaneously. Includes social networks, forums, dating sites, and gaming communities. Designed for broad username reconnaissance.

Core Functions

  • Queries 2000+ platforms in a single search
  • Identifies social profiles, dating accounts, forum activity
  • Tracks gaming usernames and community handles
  • Export results for further analysis
  • Detects username variations and alternate spellings

WhatsMyName Web

Free
600+ Sites No Registration

Web-based username verification across 600+ sites. No registration required. Enter a username, receive structured results showing platform presence.

Core Functions

  • Verifies username presence on 600+ websites
  • No account creation needed
  • Real-time results as queries complete
  • Direct profile links provided
  • Open-source verification methods

Namechk

Free

Check username availability across social networks and domain names. Includes less common platforms.

What you can do:
  • Search major social media platforms
  • Check domain name availability
  • Find less common platform profiles
  • See availability at a glance with color coding
  • No rate limits or registration

Instant Username Search

Free

Lightning-fast username checking. Focuses on major platforms but updates frequently.

What you can do:
  • Get instant results for popular platforms
  • Clean, simple interface
  • Focus on actively maintained sites
  • Mobile-friendly design
  • Direct profile links for matches

Email Intelligence

Straightforward checks to verify whether an email is valid, active, or linked to any concerning activity. Clean results without unnecessary steps.

Epieos

Free

Email OSINT tool. Links email addresses to Google accounts, profile pictures, Google Maps reviews, and YouTube channels.

URL: epieos.com

Hunter.io

Freemium

Find professional email addresses by company name. Verify email deliverability. Free tier allows limited monthly searches.

URL: hunter.io

TrueCaller

Freemium

Reverse phone lookup. Identify spam callers, see caller ID info, and find who owns a phone number.

PhoneInfoga (CLI)

Free

Advanced phone number information gathering. Identifies country, carrier, line type, and scans for online footprints.

emailrep.io

Free

Email reputation lookup. Checks if an email address is associated with data breaches, disposable services, or suspicious activity.

Have I Been Pwned

Free

Check if an email or phone number appears in known data breaches. Maintained by Troy Hunt. API available for automated queries.

MXToolbox

Free

Email server diagnostics. SPF, DMARC, MX record lookups, blacklist checks, and DNS validation for email infrastructure.

RocketReach

Freemium

Contact intelligence platform. Find email addresses, phone numbers, and social profiles for professionals. Ideal for investigative research and contact discovery.

Spydialer

Free

Reverse phone, VOIP, address, name, and email lookup. Includes voicemail preview without calling the device. High accuracy for basic consumer-level OSINT.

How to use:
  1. Enter a name, phone number, address, or email.
  2. Run lookup.
  3. For numbers, click "Voicemail" to hear the carrier greeting without calling.

Command Line OSINT Tools

Sherlock

Free
400+ Networks Fast Scans

Command-line tool for username enumeration across 400+ social networks. Automated search with structured output. Commonly used for identity mapping.

Installation & Execution:

Environment: Mac Terminal / Linux Terminal / Windows CMD

git clone https://github.com/sherlock-project/sherlock.git cd sherlock pip install -r requirements.txt python sherlock username_here
Technical Note: Scans 400+ networks automatically. Average execution time: 60-120 seconds. Use the Copy button for quick command entry.

PhoneInfoga

Free

Advanced phone number information gathering tool. Scans international phone numbers to identify carrier, location, and online presence.

Installation & Usage:

Environment: Mac Terminal / Linux Terminal / Windows PowerShell

go install github.com/sundowndev/phoneinfoga/v2@latest phoneinfoga scan -n "+15551234567" phoneinfoga serve

theHarvester

Free

Gather emails, subdomains, IPs, and URLs from public sources. Uses search engines, PGP servers, and Shodan.

Installation & Usage:

Environment: Kali Linux / Ubuntu Terminal / Mac Terminal

git clone https://github.com/laramies/theHarvester cd theHarvester pip install -r requirements.txt python theHarvester.py -d example.com -b all

Maigret

Free

Collect dossier on a person by username. Checks 3000+ sites, extracts personal info from profiles.

Installation & Usage:

Environment: Python environment (Mac / Linux / Windows)

pip install maigret maigret john_doe maigret john_doe --pdf

Holehe

Free

Check if an email is used on different sites like Twitter, Instagram, Imgur without notifying the user.

Installation & Usage:

Environment: Python environment (Mac / Linux / Windows)

pip install holehe holehe johndoe@gmail.com holehe johndoe@gmail.com --only-used

Subfinder

Free

Subdomain discovery tool. Passive reconnaissance using certificate transparency, DNS, and search engines. Fast and reliable.

Installation & Usage:

Environment: Mac Terminal / Linux Terminal (Go required)

go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest subfinder -d example.com subfinder -d example.com -o output.txt

Amass

Free

In-depth DNS enumeration and network mapping. Active and passive subdomain discovery. Maintained by OWASP.

Installation & Usage:

Environment: Mac Terminal / Linux Terminal (Go required)

go install -v github.com/owasp-amass/amass/v4/...@master amass enum -d example.com amass enum -d example.com -o results.txt

Photon

Free

Fast web crawler designed for OSINT. Extracts URLs, emails, social media accounts, and files from websites.

Installation & Usage:

Environment: Python environment (Mac / Linux / Windows)

git clone https://github.com/s0md3v/Photon.git cd Photon pip install -r requirements.txt python photon.py -u https://example.com

ExifTool

Free

Read, write, and edit metadata in images, videos, PDFs. Extract GPS coordinates, camera info, timestamps, author names.

Installation & Usage:

Environment: Ubuntu / Kali Linux / Mac Terminal

sudo apt install exiftool exiftool filename.jpg exiftool -gps:all image.jpg

hashID

Free

Identify hash types. Determines what algorithm generated a hash string. Essential for password cracking and forensics.

Installation & Usage:

Environment: Python environment (Mac / Linux / Windows)

pip install hashid hashid examplehash hashid -m examplehash

Censys CLI

Freemium

Command-line interface for Censys internet scanning data. Query certificates, hosts, and services from the terminal.

Installation & Usage:

Environment: Python environment (Mac / Linux / Windows)

pip install censys censys config censys search "services.service_name: HTTP" censys view 8.8.8.8

Terminal Basics for Beginners

What's a Terminal?

The terminal (also called command line, command prompt, or shell) is a text-based interface where you type commands to control your computer. It looks intimidating but it's just another way to interact with your machine.

Opening the Terminal:

  • Mac: Press Cmd + Space, type "Terminal", hit Enter
  • Windows: Press Windows key, type "cmd" or "PowerShell", hit Enter
  • Linux: Press Ctrl + Alt + T (usually)

Basic Commands Everyone Should Know:

Environment: Mac Terminal / Linux Terminal / Windows CMD

pwd ls cd foldername cd .. clear

Installing Prerequisites:

Most CLI OSINT tools need Python and Git installed first:

Environment: Mac Terminal / Linux Terminal / Windows CMD

python --version git --version

Kali Linux Pre-installed Tools

Kali Linux comes with these OSINT tools already installed. If you're using Kali, you can skip the installation steps.

  • theHarvester - Just type: theharvester
  • Maltego - Pre-installed GUI tool
  • Nmap - Network scanning
  • Recon-ng - Web reconnaissance framework
  • SpiderFoot - Automated OSINT collection

Social Footprint Mapping

If a person exists online, these tools help surface the activity and patterns they leave behind. Structured, consistent, and easy to interpret.

Social Searcher

Freemium

Real-time social media search. Monitor mentions across Twitter, Facebook, Instagram, YouTube, Reddit, and more.

IntelX (Intelligence X)

Freemium

Search engine for data leaks, breaches, and the darknet. Paid subscription for unlimited searches and exports.

URL: intelx.io

Followerwonk

Freemium

Twitter analytics and search. Find people by bio keywords, compare followers, analyze activity patterns.

Twint

Free

Advanced Twitter scraping tool. Bypass API limits, scrape tweets, followers, following, likes without authentication.

Public Records & Registry Search

Direct access to government databases, court records, and official registries. No middleman data brokers. These are primary sources.

PACER (Federal Court Records)

Direct access to U.S. federal court documents, case filings, and dockets. Official government system. $0.10 per page, free up to $30 per quarter.

State Court Databases

Free

Most U.S. states maintain free searchable databases for criminal and civil cases. Search by name, case number, or party. Each state operates its own system.

Access: Search "[State Name] court records" or "[State Name] case search" to locate the official database.

National Sex Offender Registry

Free

Official U.S. government registry. Search registered sex offenders across all states. Includes photos, addresses, and conviction details.

URL: nsopw.gov

County Property Records

Free

Most counties provide free online access to property ownership records, tax assessments, and sale history. Direct access to assessor databases.

Access: Search "[County Name] property records" or "[County Name] assessor" to find the official database.

OpenCorporates

Free

World's largest open database of companies. Search 200+ million companies across jurisdictions. Track officers, filings, ownership.

State Corporate Registries

Free

Each U.S. state maintains official business entity databases. Search LLC registrations, corporation filings, and registered agent information.

Access: Search "[State Name] Secretary of State business search" to find the official corporate registry.

OSINT Industries

Freemium

Public data aggregation platform. Search phone numbers, emails, usernames across multiple open-source intelligence databases.

OpenSanctions

Free

Global sanctions database. Search politically exposed persons (PEPs), criminal watchlists, and anti-money laundering data from official sources worldwide.

Skopenow

Professional

Professional-grade OSINT and risk-analysis platform used by investigators to aggregate public data across multiple sources. Subscription-based investigative tool.

File & Metadata Analysis

Tools for uncovering the information stored inside documents, images, and other files. Organized, dependable extraction for investigative clarity.

ExifTool (Web)

Free

Read, write, and edit metadata in images, videos, PDFs. Extract GPS coordinates, camera info, timestamps, author names.

Why this matters: Metadata reveals when/where a photo was taken, what device created it, and sometimes who took it. Essential for verifying photo authenticity in alibis and fraud detection.

FOCA (Fingerprinting Organizations with Collected Archives)

Free

Crawl websites and extract metadata from Office documents, PDFs. Finds usernames, software versions, network paths.

Metadata2Go

Free

Online metadata viewer. Upload images, documents, or videos to extract hidden data. No installation required. Works in browser.

Deep Data & Hidden Footprint

Tools for discovering infrastructure details, technology stacks, and digital footprints not visible on the surface.

ZoomInfo

Business Only

B2B contact database. Company hierarchies, decision makers, direct dials. Enterprise pricing, expensive but comprehensive.

Hunter.io API

Freemium

Email finder and verification API. Domain search returns all public email addresses. Email pattern detection and deliverability checks.

API Endpoint Example:
curl "https://api.hunter.io/v2/domain-search?domain=example.com&api_key=YOUR_KEY"

Corporate Records & Research Funding

NIH RePORTER

Free

Search US government research funding. Find grants, principal investigators, institutions, publications, patents from NIH-funded research.

CORDIS (EU Research)

Free

European Commission research database. Find EU-funded projects, participants, publications, results from Framework Programmes.

ProQuest Dissertations & Theses

Access Varies

Largest collection of dissertations and theses. Free previews, full access through libraries. Find academic research by author or topic.

Municipal & County Records

Free

Search local government databases for property records, court filings, business licenses, permits. Every county has different online systems.

How to find: Google "[County Name] property records" or "[County Name] court records" to find official databases.

Code Repository Investigation

GitHub Advanced Search

Free

Search code, commits, issues, repos with advanced filters. Find API keys, credentials, personal info accidentally committed. Filter by date, language, user.

Power searches:
  • Find exposed API keys: filename:.env OPENAI_API_KEY
  • Search user's code: user:username password
  • Find specific file types: extension:py import requests

Archive Intelligence

Tools for accessing historical versions of web content, tracking changes, and recovering deleted information.

Archive.today

Free

Create permanent snapshots of web pages. Search for archived versions of deleted content. Captures complete pages including dynamic elements.

Memento Time Travel

Free

Search across multiple web archives simultaneously. Aggregates results from Internet Archive, Archive.today, and other archival services.

Browser Fingerprinting & Device Intelligence

Tools for analyzing browser characteristics, device information, and digital fingerprints left during online activity.

CreepJS

Free

Advanced browser fingerprinting detector. Analyzes canvas, WebGL, audio, fonts, and other fingerprint vectors. Open-source testing tool.

AmIUnique

Free

Check how unique your browser fingerprint is. Analyzes plugins, screen resolution, timezone, fonts, and other identifying characteristics.

DeviceInfo.me

Free

Displays detailed device and browser information. Shows what data websites can collect about your system and network.

Corporate Intelligence & SEC Filings

Direct access to official corporate registries, SEC filings, and business entity databases.

EDGAR SEC Filings

Free

U.S. Securities and Exchange Commission database. Access all public company filings, financial statements, and regulatory documents.

CrowdTangle

Restricted

Meta's social media analytics platform. Track public content performance across Facebook, Instagram, Reddit. Requires application and approval.

ICIJ Offshore Leaks Database

Free

International Consortium of Investigative Journalists database. Search Panama Papers, Paradise Papers, and other offshore leak investigations. Track shell companies and hidden wealth.

Vehicle & Property Lookup

VINCheck

Free

Free VIN lookup from NICB. Check if vehicle was reported stolen or has salvage title.

NHTSA VIN Decoder

Free

Official U.S. government VIN decoder. Identifies vehicle specifications, manufacturer details, and recall information. Direct access to NHTSA database.

Zillow Property Records

Free

Aggregates public property records from county assessors. Shows ownership history, sale prices, and tax assessments. Free access to most data.

URL: zillow.com

Video & Image Analysis

Google Reverse Image Search

Free

Find where images appear online. Track down original sources, find higher resolution versions, identify people and places.

TinEye

Free

Reverse image search with oldest and newest sorting. Find image modifications, track usage, locate sources.

URL: tineye.com

Yandex Image Search

Free

Russian search engine with excellent face recognition. Often finds results Google misses, especially for Eastern European content.

InVID/WeVerify

Free

Browser extension for video verification. Fragment videos, reverse image search frames, analyze metadata. Essential for journalists.

YouTube DataViewer

Free

Extract upload time, thumbnail images from YouTube videos for verification and reverse image searching.

Business Intelligence Tools

Maltego Community Edition

Free

Visual link analysis for OSINT investigations. Map relationships between people, companies, domains, IPs. Free version has limited transforms.

Crunchbase

Freemium

Startup and company information. Funding rounds, investors, key people, competitors. Free basic search, paid for exports.

LinkedIn Sales Navigator

Business Only

Advanced LinkedIn search and filtering. Boolean searches, company insights, org charts. Business subscription required.

Cached & Archived Content

Archive.is (archive.today)

Free

Create permanent snapshots of web pages. Search for archived versions of deleted content. Unlike Wayback Machine, captures complete pages.

URL: archive.is

CachedView

Free

Search multiple cache sources at once. Checks Google Cache, Wayback Machine, Archive.is from one interface.

Google Cache

Free

View Google's cached version of any page. Add "cache:" before URL or click dropdown next to search result.

Example: cache:example.com in Google search

AI-Powered Intelligence & Research Tools

AI-powered platforms designed for investigative research, multi-source analysis, and structured intelligence summaries.

Genspark

Free
Category: AI-Powered Intelligence & Research Tools

Genspark is an AI intelligence engine designed for investigative research. It performs multi-source analysis, generates structured and cited intelligence summaries, and supports OSINT workflows by aggregating data across platforms in real time.

OSINT Tips & Insider Techniques

DNS History & Passive DNS

Current DNS records only show where a domain points NOW. Passive DNS databases record historical changes. Use SecurityTrails or DNSDumpster to see:

  • Old IP addresses the domain used to point to
  • Other domains hosted on the same IP historically
  • Changes in hosting infrastructure over time
  • Potential shell companies or related domains

Why it works: People often move domains but leave traces. Historical DNS can reveal connections they thought were hidden.

Telegram OSINT

Telegram doesn't require phone numbers to search users. Key techniques:

  • Username search without @ symbol (direct chat links)
  • Group membership scraping via public group lists
  • Channel analysis for post patterns and engagement
  • Bot interactions reveal user IDs and activity

Tools: Use @username_to_id_bot to get numeric user IDs. Check recent message timestamps to see when someone's active.

LinkedIn Sales Navigator Boolean Tricks

Advanced Boolean search operators most people don't know:

title:(VP OR Director) AND company:Microsoft NOT title:Assistant school:"Stanford University" AND company:(Google OR Meta) AND title:Engineer profile_language:en AND location:"San Francisco Bay Area" AND past_company:Apple

Pro tip: Use parentheses for complex queries. Combine current_company and past_company to map career paths.

TikTok Username Enumeration

TikTok usernames can be changed but the profile URL numeric ID stays permanent. Finding someone who changed their username:

  1. Use Google dorking: site:tiktok.com "@oldusername"
  2. Check cached pages for the numeric ID in URL
  3. Navigate to tiktok.com/@username to get user ID from page source
  4. Profile ID never changes even when username does

Wireless Network Geolocation (WiGLE)

WiGLE database maps WiFi networks and their physical locations worldwide. If you have:

  • A WiFi network name (SSID)
  • A MAC address from WiFi scan
  • Bluetooth device addresses

You can find approximate physical location. Useful when investigating where photos were taken based on visible WiFi networks.

URL: wigle.net

Cached Page Analysis

Don't just look at cached pages. COMPARE them:

  • Use diff tools to see exactly what changed between snapshots
  • Deleted text often reveals what someone wants hidden
  • Compare Wayback Machine dates to significant events (lawsuits, scandals)
  • Check robots.txt history to see what they're blocking now vs before

Tool: CachedView pulls from multiple cache sources simultaneously.

Image Reverse Search Chaining

Don't just reverse search once. Chain your searches:

  1. Start with Google Reverse Image Search
  2. Take the OLDEST result and search that on Yandex
  3. Find different version? Search THAT on TinEye
  4. Download highest resolution found, search on Bing Visual
  5. Each engine has different databases and algorithms

Why it works: Original images propagate across the internet. Each search engine indexes different corners of the web.

Sock Puppet Account Best Practices

Creating believable fake accounts for investigation requires discipline:

  • Never mix: Use dedicated browser profiles, separate VPN, unique email
  • Age the account: Create weeks before using, add gradual activity
  • Steal legitimacy: Use real person's public info (with permission) or composite identities
  • Match the platform: Instagram needs photos, LinkedIn needs work history
  • Engagement pattern: Like/comment on unrelated content to build algorithmic trust

Warning: Check your jurisdiction's laws on digital impersonation.

Browser Fingerprinting Detection

Even with VPN/Tor, your browser has a unique fingerprint. Test and reduce it:

  • Test sites: amiunique.org, deviceinfo.me, browserleaks.com
  • What they see: Canvas fingerprint, WebGL, fonts, screen resolution, timezone
  • Mitigation: Use Tor Browser (best), Firefox with resistFingerprinting, or Brave's fingerprint randomization
  • Avoid: Browser extensions (they increase uniqueness), rare screen resolutions, custom fonts

Finding Real IPs Behind Cloudflare

Cloudflare hides origin servers. Techniques to find the real IP:

  • Subdomain scanning: mail.example.com often not behind Cloudflare
  • Historical DNS: Check SecurityTrails for pre-Cloudflare IPs
  • SSL certificates: Certificate Transparency logs show IPs that served the cert
  • Email headers: Send email to site contact, check X-Originating-IP header
  • Censys/Shodan: Search for unique page content, find servers serving it

Google Dorking for Exposed Data

Advanced Google search operators to find leaked information:

site:pastebin.com "password" "@company.com" filetype:pdf "confidential" site:target.com intitle:"index of" "parent directory" "config.php" inurl:"/admin/login.php" site:*.edu site:linkedin.com "email" "@target.com" AND "mobile"

Explanation: Combine operators to narrow down exposed files, login pages, directory listings, and contact info.

Email Pattern Discovery

Companies use predictable email formats. Once you know one email, you can guess others:

  1. Find one employee email (from signature, LinkedIn, company site)
  2. Identify pattern: firstname.lastname@, first.last@, flast@, firstnamel@
  3. Use Hunter.io or RocketReach to verify pattern
  4. Apply pattern to other employees from LinkedIn
  5. Verify deliverability without sending: use email verification APIs

Bonus: Email permutation tools like EmailHippo generate all possible formats.

Geolocation from Photos Without GPS

Even with GPS data stripped, photos reveal location through visual clues:

  • Architecture: Building styles specific to regions
  • Signage: Language, fonts, regulatory signs (speed limits, parking)
  • Vegetation: Plant species narrow down climate zones
  • Infrastructure: Power lines, road markings, license plates
  • Shadows: Sun angle indicates latitude and time of day

Tools: GeoGuessr skills transfer here. Cross-reference with Google Street View.

Audio Forensics for Verification

Audio files contain hidden metadata and forensic traces:

  • Metadata: ExifTool works on audio files too (recorder type, timestamps)
  • Background noise: Ambient sounds reveal location (traffic, birds, language)
  • Spectrograms: Visualize audio, sometimes hidden images in sound (steganography)
  • Voice comparison: Use Praat software for waveform/pitch analysis

Free tool: Audacity (spectrogram view) and Sonic Visualiser

Phone Number Intelligence

Phone numbers reveal more than you'd think:

  • Area code: Original registration location (even if portable)
  • Carrier lookup: Identifies VOIP vs real mobile numbers
  • HLR lookup: Home Location Register shows if number is active
  • WhatsApp check: Number registered? See profile pic and status
  • SignalHire/RocketReach: Reverse lookup to find associated person

CLI tool: PhoneInfoga automates most of this.

WHOIS History & Domain Relationships

Current WHOIS data is often privacy-protected. Historical WHOIS reveals original owners:

  • DomainTools: Historical WHOIS lookups (paid but sometimes free preview)
  • WHOXY: Search by registrant email to find all related domains
  • Reverse WHOIS: Find all domains registered by same person/org
  • Registrar patterns: Related sites often use same registrar/name server

Pastebin & Leaked Data Monitoring

Sensitive data gets dumped to paste sites regularly:

  • Pastebin, Ghostbin, Rentry: Search for company names, domains, emails
  • PasteLert: Set alerts for keywords appearing in new pastes
  • Dehashed/LeakCheck: Aggregated breach data search
  • IntelX: Darknet paste sites and forums

Google dork: site:pastebin.com "@targetdomain.com"

URL Shortener Resolution

Shortened URLs hide the destination. Expand them safely:

  • Add + to end: bit.ly/abc123+ shows preview page
  • Unshorten services: unshorten.me, urlex.org, checkshorturl.com
  • cURL command: curl -sI shortened-url | grep -i location
  • Browser extensions: Unshorten.link auto-expands on hover

Security tip: Never click shortened URLs directly. Always check destination first.

Cryptocurrency Blockchain Analysis

Crypto transactions are public. Track wallet activity:

  • Blockchain explorers: Etherscan (Ethereum), Blockchain.com (Bitcoin)
  • Wallet clustering: Group addresses by common ownership patterns
  • Exchange identification: Large wallets often belong to known exchanges
  • Transaction graphs: Visualize flow of funds between addresses

Tools: OXT.me (Bitcoin), Chainalysis Reactor (pro), GraphSense

Academic & Research Intelligence

Find someone's research, publications, collaborations:

  • Google Scholar: Publication history, citation count, co-authors
  • ORCID: Unique researcher ID, links all publications
  • ResearchGate: Social network for academics, often includes full-text papers
  • Semantic Scholar: AI-powered research paper search
  • Sci-Hub: Access paywalled papers (gray area legally)

About This Platform

This is a curated hub of OSINT tools organized for accuracy and ease of use. Everything is structured cleanly so you can find what you need without noise or clutter. Clear layout. Reliable resources. A straightforward space designed for real investigative workflows.