Skip to content
Osintpro

OSINT Tools for Authorized Investigations

Run a scoped sweep across public sources and get findings that carry their own evidence: the raw record, the source endpoint, and the UTC moment it was retrieved.

  • Passive collection only.
  • Public sources.
  • Domains only, never a person.
  • Your case data stays yours.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

Where the day actually goes

Collection is the easy part. Three things break afterwards.

The screenshot will not hold up.

A screenshot has no retrieval time, no source endpoint and no proof the record said that when you looked. DNS answers, registrant data and certificates all change. The first question anyone asks is where this came from and when, and a screenshot cannot answer it.

The write-up costs more than the collection.

Collecting takes minutes per source. Turning eight tabs of output into something a non-technical stakeholder can act on takes hours, every case, forever, and it is done by the most expensive person on the team.

Nobody wrote down the scope.

Nothing in the usual toolchain records what you were authorized to look at. The same tool that does vendor due diligence does stalking, and the only thing separating them is an intent nobody ever put in writing. That is why OSINT tooling stalls in procurement.

Scope in, evidence out

A finding is not a sentence. It is a sentence plus its record.

Every line Osintpro emits carries four things, and it will not emit a line that is missing any of them. That constraint is the product. It is also why a finding from this tool can be handed to a reviewer who was not in the room.

  • 1

    Severity. What it means for the decision in front of you, not a raw score.

  • 2

    The raw record. Exactly as the source returned it, unedited.

  • 3

    The source endpoint. Where it came from, so a reviewer can re-run it.

  • 4

    The UTC retrieval time. Records change. Without this, a finding is an assertion.

One finding, taken apart

github.com, mail posture module

Medium

DMARC policy is p=quarantine

Failing mail is delivered to spam rather than rejected. Partial enforcement.

v=DMARC1; p=quarantine; sp=reject; pct=100; rua=mailto:dmarc@github.com
source: GET dns.google/resolve?name=_dmarc.github.com&type=TXT retrieved: 2026-09-04T18:41:07Z

Left of the title: the severity, set by what the record says and nothing else.

In the bracket: the record itself. Not a paraphrase of it.

Below it: the exact request that produced the record.

Beside that: the UTC instant, because this answer will change.

That finding is real. Run the DNS lookup tool against the same domain and you will get the same record with a fresh timestamp.

How a case runs

Four steps, and the scope comes first on purpose.

  1. Step 1

    Declare the scope

    Pick the purpose and confirm your authorization. It is stamped on the case header before a single lookup runs, so the record of why exists before the record of what.

  2. Step 2

    Select the modules

    DNS and mail posture, registration, certificate and hostname surface, hosting fingerprint. Turn off what is out of scope and the case says so.

  3. Step 3

    Collect passively

    Osintpro reads public records. It does not scan, probe, authenticate or send a packet the target would log as an attack.

  4. Step 4

    Export the report

    PDF or DOCX, findings ordered by severity, every one carrying its record, its endpoint and its UTC retrieval time.

A real case, start to finish

One domain in. One dossier out.

This is the vendor due-diligence case a risk manager runs before signature, reproduced exactly as the tool produces it. The records below were retrieved on 4 September 2026 and you can re-run every one of them yourself.

Input

scope: vendor due diligence

subject: github.com

modules: 4 of 4

Output

11 findings, 3 needing attention, every one sourced and timestamped.

Time from scope declaration to exportable report: under a minute.

[github.com]

Scope: Vendor due diligence

retrieved 2026-09-04T18:41:07Z

Medium

DMARC policy is p=quarantine

Failing mail is delivered to spam rather than rejected. Partial enforcement.

v=DMARC1; p=quarantine; sp=reject; pct=100; rua=mailto:dmarc@github.com

source: GET dns.google/resolve?name=_dmarc.github.com&type=TXT

Medium

SPF ends in a soft fail

Receivers are told to accept unauthorised mail and mark it, which weakens the control.

v=spf1 ip4:192.30.252.0/22 include:spf.protection.outlook.com ... ~all

source: GET dns.google/resolve?name=github.com&type=TXT

Info

Mail handled by Microsoft 365

1 mail exchanger published. The mail provider is the phishing surface an attacker will imitate.

0 github-com.mail.protection.outlook.com.

source: GET dns.google/resolve?name=github.com&type=MX

Pass

Domain registered 18.9 years ago

Registration age is consistent with an established operation.

registration 2007-10-09T18:20:50Z | expiration 2026-10-09T18:20:50Z

source: GET rdap.org/domain/github.com

Pass

Transfer lock is set on the domain

The name cannot be transferred away without the lock being lifted first.

client delete prohibited, client transfer prohibited, client update prohibited

source: GET rdap.org/domain/github.com

Pass

Certificate issuance restricted to 4 authority set

A CAA record tells every public CA who may issue for this name.

0 issue "digicert.com" | 0 issue "letsencrypt.org" | 0 issue "sectigo.com"

source: GET dns.google/resolve?name=github.com&type=CAA

Info

DNS served by Amazon Route 53 + NS1 (IBM)

Two independent DNS providers are delegated. A deliberate resilience choice.

dns1.p08.nsone.net | ns-520.awsdns-01.net | ns-1283.awsdns-32.org

source: GET dns.google/resolve?name=github.com&type=NS

Four more findings in the full dossier. on any domain you are authorized to assess.

For whoever signs the invoice

The write-up is the line item nobody put on the budget.

A risk team screening 120 vendors a year, at 3.5 hours of write-up per vendor, at an $85 loaded hourly cost, spends 420 hours and roughly $35,700 a year turning findings into documents. Team is $4,488 a year. The arithmetic is shown so you can argue with it, and the inputs are assumptions rather than measurements from customers we do not have.

The second number is harder to put on a spreadsheet and it is the one a general counsel cares about. An undocumented investigation is a liability. A scoped, timestamped one is a defense. Read how that plays out in third party risk management software.

Your numbers

hours a year on write-up

at your loaded cost

working days, at 7.5 hours a day

hours per analyst a year, across

Arithmetic: These are your assumptions, not a measurement we took.

Named, and described fairly

Everyone else optimizes collection. We optimize what survives review.

Osintpro

Case-first

You end up holding
A sourced, timestamped report
Authorized scope
Declared before collection, stamped on the report
Evidence chain
Raw record, source endpoint and UTC time on every finding
Price anchor
$149 to $1,190 a month

Maltego

Graph-first

You end up holding
A link chart you write up by hand
Authorized scope
Not recorded
Evidence chain
Entity provenance, no retrieval timestamp on the finding
Price anchor
Free tier, then EUR 3,000 or EUR 7,500 a year plus credits

SpiderFoot HX

Collection-first

You end up holding
A large raw result set
Authorized scope
Not recorded
Evidence chain
Module output, packaging is yours
Price anchor
Open source free. HX sold by Intel 471, price not published

Recorded Future, Intel 471

Feed-first

You end up holding
Global threat intelligence, not an entity dossier
Authorized scope
Not applicable to the model
Evidence chain
Analyst-written intelligence reporting
Price anchor
Commonly $50k or more a year, annual contract

Free tooling

Toolbox

You end up holding
Terminal output and screenshots
Authorized scope
Not recorded
Evidence chain
Whatever you save by hand
Price anchor
Free

Prices are the public list anchors these vendors publish or that buyers commonly report, not quotes. Every one of these tools is good at the job it was built for. The column that matters here is the authorized-scope column, because that is the one no other row fills in.

"We already have Maltego."

Then you already have the graph. The question is who writes the report from it, how long that takes, and whether the finished document says where each entity came from and when. Osintpro sits after collection, not instead of it. See the Maltego alternative page.

"Our analysts can do this with free tools."

They can, and they should know how. Free tooling collects well. What it does not produce is a scope record, a retrieval timestamp you can prove, or a report. We say so plainly on free OSINT tools.

"Legal will never approve an OSINT tool."

Legal blocks tools that cannot show what the analyst was authorized to look at. That is the exact gap this product was built around, and it is why the scope declaration comes before collection rather than after it.

What procurement asks for

The checklist that decides whether a tool gets in the door.

SSO and SAML

Okta, Entra ID or any SAML 2.0 provider

SCIM provisioning

Joiners and leavers handled by your directory

Roles and permissions

Who may open a case, who may sign one off

Audit log

Every case, every export, every scope declaration

Data residency

Choose where case data is stored

SLA

Written availability and support commitments

DPA

Signed data processing agreement

Invoicing and PO

Annual invoice, purchase order, net terms

Priced against what it replaces

Four plans. No free tier, because the demo is the free tier.

Analyst

Solo analyst, investigator or consultant

$149/mo

$124/mo billed yearly ($1,488/yr)

1 seat 25 cases a month
  • All collection modules
  • Every finding sourced and timestamped
  • Scope record on every case
  • PDF and DOCX report export
  • 12-month case retention
Get started

Team

A security or third-party risk team

$449/mo

$374/mo billed yearly ($4,488/yr)

5 seats 150 cases a month
  • Everything in Analyst
  • Shared case library
  • Saved investigation templates
  • Reviewer sign-off on a report
  • Team roles
  • 24-month retention

Practice

An investigations unit, agency or MSSP

$1,190/mo

$990/mo billed yearly ($11,880/yr)

15 seats 600 cases a month
  • Everything in Team
  • Client and matter separation
  • White-labeled reports
  • Bulk vendor screening
  • API access
  • Custom retention

Enterprise

A regulated enterprise with a procurement process

Custom

Annual agreement, invoiced

Unlimited seats Unlimited cases
  • Everything in Practice
  • SSO / SAML and SCIM provisioning
  • Granular roles and permissions
  • Full audit log export
  • Configurable data residency
  • SLA, DPA and security review support
  • Invoicing and PO terms, named CSM

No free plan. The domain footprint demo is the free taste, and it stays free. Prices in USD, excluding local tax.

The questions that decide it

Answered plainly, including the ones with a no.

More on is OSINT legal and where our acceptable use boundary sits on social media OSINT.

The three answers people look for first

  • We never touch the target. Collection is passive, from public records only.
  • You cannot look up a person. The demo takes a domain and has no input for a person.
  • It is not a background check. Not for FCRA-regulated consumer decisions, ever.

Open source intelligence is the collection and analysis of information that is already publicly available, and collecting public information is lawful in most jurisdictions. Legality turns on four things: the source, the purpose, the jurisdiction and your lawful basis. Reading a public DNS record, a company registry filing or a certificate transparency log is not the same act as accessing a system without authorization, scraping in breach of a contract you accepted, or processing personal data with no lawful basis under GDPR or a similar regime. Osintpro is built around that distinction: collection is passive and from public records only, and every case carries a written scope declaration so the purpose is on the record before the work starts. This is general information about how the category works and it is not legal advice. Take your own advice for your jurisdiction and your matter.

No. Collection is passive. Osintpro reads public records: DNS answers from public resolvers, RDAP and WHOIS registration data, certificate transparency logs, corporate registry filings and other public sources. It does not port scan, does not probe applications, does not attempt authentication, does not send traffic that a target would see as an attack, and does not need credentials. That boundary is what makes the tool usable on a vendor or an acquisition target you have no authorization to test. It is stated in full on the Security page.

No, and the demo has no input that would let you. The Domain Footprint demo accepts a domain and nothing else, which is a structural limit rather than a promise. Our acceptable use policy prohibits monitoring, profiling or locating an individual without a lawful basis, and prohibits harassment, stalking and any use intended to intimidate. Named refusals published in public are part of what makes this tool buyable inside a regulated organization.

Not for decisions regulated under the US Fair Credit Reporting Act, and not as a consumer background check of any kind. Osintpro is not a consumer reporting agency and its output is not a consumer report. Pre-engagement screening on this platform means authorized, consent-backed corporate screening of a business counterparty, with the basis recorded in the case scope. If you are making an employment, credit, insurance or tenancy decision about a consumer, use an FCRA-compliant provider instead.

Maltego is graph-first: it is very good at showing you how entities connect, and you still write the report by hand afterwards. SpiderFoot is collection-first: it will return hundreds of raw results, and the signal-to-noise work is yours. Both optimize collection. Osintpro optimizes what happens after collection. The unit of work is a scoped case rather than a query, every finding carries its raw record, its source endpoint and its UTC retrieval time, and the report is the native output rather than something you assemble at the end of the day.

Free tooling is genuinely good. theHarvester, Amass, the OSINT Framework directory and Shodan's free tier will collect a great deal, and every analyst should know them. The line where they stop is not collection, it is defensibility: no record of what you were authorized to look at, no retrieval timestamps you can prove, no chain from a claim back to the record it came from, no retention control and no report. As long as a finding has no consequences, free tooling is enough. The moment a vendor gets rejected or a claim goes to counsel, it is not.

All ten questions

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.