Free OSINT Tools That Are Genuinely Good, and Where They Stop
We sell a paid OSINT platform, so read this with that in mind. It is still true: free tooling is excellent at collection, most analysts should learn it first, and for a large share of work it is all you need.
What it does not give you is a scope record, a provable retrieval time, a chain from a claim back to its record, or a report. That is the line, and it only matters once a finding has consequences.
- Passive collection only.
- Public sources.
- Findings carry their record.
- Domains only, never a person.
The free tools worth knowing, described fairly.
theHarvester
- What it is genuinely good at
- Fast enumeration of subdomains, hosts and email patterns across many public sources at once. Still the quickest way to get an initial surface for a domain.
- Where it stops
- Output is a terminal dump. No case, no timestamping of individual results, no severity, no report.
OWASP Amass
- What it is genuinely good at
- Deep, thorough subdomain and network mapping with a real graph model underneath. On coverage it is very hard to beat.
- Where it stops
- Steep to run well, long run times, and the output is a dataset that still needs interpreting and writing up.
Shodan (free tier)
- What it is genuinely good at
- Finding exposed services and devices on infrastructure you own. Unmatched for the "what of ours is listening on the internet" question.
- Where it stops
- The free tier is rate limited and shallow, and results carry a scan timestamp rather than a case-level evidence chain.
OSINT Framework
- What it is genuinely good at
- A large, well-known directory of sources organized by discipline. A good map of the territory.
- Where it stops
- It is a directory, not a tool. Nothing is collected, correlated, dated or reported.
crt.sh and certificate transparency
- What it is genuinely good at
- Historical certificate issuance for a domain, which frequently reveals hostnames DNS enumeration misses entirely.
- Where it stops
- Raw log records. Interpreting them, dating them into a case and explaining them to a non-technical reader is all manual.
dig, whois, host
- What it is genuinely good at
- Precise, scriptable, always available, and they are what the paid tools are running underneath.
- Where it stops
- You are the evidence chain. Whatever you do not paste and date, does not exist later.
These are all worth learning, and an analyst who cannot use them will not get more out of a paid platform. Nothing on this list is a bad tool.
The four things free tooling does not do, in order of how much they hurt.
There is no record of authorized scope
Free tools do not ask why you are running them, so nothing in your output shows what you were permitted to look at. When a legal or HR reviewer asks that question later, and they do, the honest answer is that it was never written down. This is the one that stops OSINT tooling in procurement.
Retrieval time is not attached to the finding
A file timestamp is not a retrieval timestamp. DNS answers, registrant data and certificates all change, so a claim about a record without the moment it was read is an assertion. You know it was true. You cannot show it.
The chain from claim to record is manual
You wrote "the vendor has no DMARC enforcement" and somewhere there is a terminal buffer that supports it. Reconnecting those two things three weeks later, for a reviewer, is work that nobody costed.
There is no report and no retention control
The write-up is the expensive part, and free tooling leaves all of it with you. There is also nothing governing how long the collected material sits on your laptop, which is its own problem once personal data is anywhere in it.
A straight answer on when free is enough.
If nothing happens as a result of the finding, use free tools.
Curiosity, learning, a quick sanity check before a meeting, an internal look at your own estate that nobody will audit: free tooling is the right choice and paying for a platform would be waste.
The moment a finding causes something to happen, the calculation changes. A vendor is rejected. An employee is confronted. A deal price moves. A claim goes to counsel or to an insurer. At that point the first question is where this came from and when, and the second is what you were authorized to look at. Free tooling answers neither, and reconstructing the answers after the fact is both expensive and unconvincing.
That is the whole pitch, and it is narrower than most vendors in this category would tell you. If you are not in that second situation, keep your money. If you are, see what the plans include or read the comparison of the main platforms.
And here is free tooling next to the paid platforms.
Same table we show everywhere else on the site, with free tooling on it as a real row rather than a straw man.
Osintpro
Case-first
- You end up holding
- A sourced, timestamped report
- Authorized scope
- Declared before collection, stamped on the report
- Evidence chain
- Raw record, source endpoint and UTC time on every finding
- Price anchor
- $149 to $1,190 a month
Maltego
Graph-first
- You end up holding
- A link chart you write up by hand
- Authorized scope
- Not recorded
- Evidence chain
- Entity provenance, no retrieval timestamp on the finding
- Price anchor
- Free tier, then EUR 3,000 or EUR 7,500 a year plus credits
SpiderFoot HX
Collection-first
- You end up holding
- A large raw result set
- Authorized scope
- Not recorded
- Evidence chain
- Module output, packaging is yours
- Price anchor
- Open source free. HX sold by Intel 471, price not published
Recorded Future, Intel 471
Feed-first
- You end up holding
- Global threat intelligence, not an entity dossier
- Authorized scope
- Not applicable to the model
- Evidence chain
- Analyst-written intelligence reporting
- Price anchor
- Commonly $50k or more a year, annual contract
Free tooling
Toolbox
- You end up holding
- Terminal output and screenshots
- Authorized scope
- Not recorded
- Evidence chain
- Whatever you save by hand
- Price anchor
- Free
Prices are the public list anchors these vendors publish or that buyers commonly report, not quotes. Every one of these tools is good at the job it was built for. The column that matters here is the authorized-scope column, because that is the one no other row fills in.
More OSINT tools and lookups
New to the category? Start with open source intelligence, then see how a scoped case runs or read the analyst notes on the blog.
Run one scoped sweep and see what a sourced finding looks like.
The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.
- Passive collection only, from public sources.
- A domain, never a person. There is no input for one.
- Your case data stays yours. No card required.