Skip to content
Osintpro

OSINT Analysis Tools, Module by Module

Four passive collection modules, a derivation layer that turns records into graded findings, and a report that is the native output rather than something you assemble afterwards.

  • Four collection modules.
  • All of them on every plan.
  • Every finding sourced and timestamped.
  • PDF and DOCX export.

What the collection actually does

Four modules, and what each one is looking for.

Module 1

DNS and mail posture

A, AAAA, MX, NS, TXT and CAA, plus the DMARC policy record. The value is not the dump, it is the derivation: SPF qualifier read against DMARC enforcement to decide whether the domain can actually be spoofed, mail provider attributed from the MX set, vendor verification strings surfaced from TXT, and certificate issuance control read from CAA.

Findings it emits

  • SPF present, soft-fail, hard-fail or missing
  • DMARC policy none, quarantine or reject
  • Mail provider attribution
  • CAA issuer restriction present or absent
  • Vendor verification strings in TXT

DNS lookup tool

Module 2

Registration through RDAP

RDAP is the structured, HTTPS, JSON successor to port-43 WHOIS, served by the authoritative registry or registrar. It carries explicit event records for registration, expiry and last change, plus the registry status codes that describe which locks are set and by whom. Raw JSON is retained as the evidence and the answering endpoint is recorded.

Findings it emits

  • Registration age against claimed history
  • Registrar of record
  • Status codes with their plain meaning
  • Expiry window and lapse risk
  • Delegated nameservers

WHOIS lookup tool

Module 3

Certificate and hostname surface

Certificate transparency logs are an append-only public record of every publicly trusted certificate issued, and subject alternative names make them a reliable hostname inventory. Combined with resolution of common administrative labels, this is where an estate discovers the staging host nobody remembered.

Findings it emits

  • Hostnames from transparency logs
  • Which of those still resolve
  • Administrative and pre-production labels answering publicly
  • Issuance history with dates

Attack surface management

Module 4

Hosting and infrastructure fingerprint

Nameserver delegation names the vendor that can change every record on the domain, including where mail goes, which makes it the highest-leverage account in an estate. Apex addressing, IPv6 posture and reverse records attribute the hosting network and expose concentration risk.

Findings it emits

  • DNS vendor attribution and redundancy
  • Apex addressing and IPv6 posture
  • Reverse record attribution
  • Concentration and single-vendor risk

The discipline map

Around the collection

The case features that make the output defensible.

Scope record on every case

Subject, purpose, basis and exclusions, written before collection and stamped on the report header. Chronology is what makes it a decision rather than a justification.

Source endpoint on every finding

Specific enough for a reviewer to re-run. Not a tool name, an endpoint.

UTC retrieval timestamp

ISO 8601 with the Z suffix, on every finding including the negative ones. Records change, so an undated claim cannot be verified later.

Raw record retained as returned

Quoted, not paraphrased and not screenshotted. The evidence is the record, not a picture of it.

Severity grading

A small, defined set: high, medium, informational, pass. Defined once so the words mean the same thing in every case your team writes.

Negative findings kept

What was looked for and not found, dated the same way. This is what bounds the work and stops silence being read as coverage.

Report export in PDF and DOCX

Scope header, findings, negative findings, method appendix. The native output, not an afterthought.

Re-run for a diff

Same scope, same modules, new timestamps. What changed between two dated collections is the finding leadership actually wants.

Case library and templates

Shared cases, saved investigation templates and reviewer sign-off on Team and above. See the plan ladder.

Modules one, two and four, live

Switch a module off and watch the report change.

Open the collection modules, turn one off, and run it. The report states what was not collected rather than leaving a reader to assume coverage. That is a small thing that matters enormously when somebody reviews the file six months later.

Honest boundary: this demo runs the DNS, registration and infrastructure derivations live against public endpoints from your browser. It does not perform the registry or breach-exposure collection the platform describes.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

On Enterprise

Controls a regulated organization needs.

SSO and SAML

Okta, Entra ID or any SAML 2.0 provider

SCIM provisioning

Joiners and leavers handled by your directory

Roles and permissions

Who may open a case, who may sign one off

Audit log

Every case, every export, every scope declaration

Data residency

Choose where case data is stored

SLA

Written availability and support commitments

DPA

Signed data processing agreement

Invoicing and PO

Annual invoice, purchase order, net terms

Data handling, retention and the passive-collection guarantee are set out on the security page. Plan boundaries are on pricing.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.