Skip to content
Osintpro

Free OSINT Tools That Are Genuinely Good, and Where They Stop

We sell a paid OSINT platform, so read this with that in mind. It is still true: free tooling is excellent at collection, most analysts should learn it first, and for a large share of work it is all you need.

What it does not give you is a scope record, a provable retrieval time, a chain from a claim back to its record, or a report. That is the line, and it only matters once a finding has consequences.

See pricing
  • Passive collection only.
  • Public sources.
  • Findings carry their record.
  • Domains only, never a person.

The free tools worth knowing, described fairly.

theHarvester

What it is genuinely good at
Fast enumeration of subdomains, hosts and email patterns across many public sources at once. Still the quickest way to get an initial surface for a domain.
Where it stops
Output is a terminal dump. No case, no timestamping of individual results, no severity, no report.

OWASP Amass

What it is genuinely good at
Deep, thorough subdomain and network mapping with a real graph model underneath. On coverage it is very hard to beat.
Where it stops
Steep to run well, long run times, and the output is a dataset that still needs interpreting and writing up.

Shodan (free tier)

What it is genuinely good at
Finding exposed services and devices on infrastructure you own. Unmatched for the "what of ours is listening on the internet" question.
Where it stops
The free tier is rate limited and shallow, and results carry a scan timestamp rather than a case-level evidence chain.

OSINT Framework

What it is genuinely good at
A large, well-known directory of sources organized by discipline. A good map of the territory.
Where it stops
It is a directory, not a tool. Nothing is collected, correlated, dated or reported.

crt.sh and certificate transparency

What it is genuinely good at
Historical certificate issuance for a domain, which frequently reveals hostnames DNS enumeration misses entirely.
Where it stops
Raw log records. Interpreting them, dating them into a case and explaining them to a non-technical reader is all manual.

dig, whois, host

What it is genuinely good at
Precise, scriptable, always available, and they are what the paid tools are running underneath.
Where it stops
You are the evidence chain. Whatever you do not paste and date, does not exist later.

These are all worth learning, and an analyst who cannot use them will not get more out of a paid platform. Nothing on this list is a bad tool.

The four things free tooling does not do, in order of how much they hurt.

There is no record of authorized scope

Free tools do not ask why you are running them, so nothing in your output shows what you were permitted to look at. When a legal or HR reviewer asks that question later, and they do, the honest answer is that it was never written down. This is the one that stops OSINT tooling in procurement.

Retrieval time is not attached to the finding

A file timestamp is not a retrieval timestamp. DNS answers, registrant data and certificates all change, so a claim about a record without the moment it was read is an assertion. You know it was true. You cannot show it.

The chain from claim to record is manual

You wrote "the vendor has no DMARC enforcement" and somewhere there is a terminal buffer that supports it. Reconnecting those two things three weeks later, for a reviewer, is work that nobody costed.

There is no report and no retention control

The write-up is the expensive part, and free tooling leaves all of it with you. There is also nothing governing how long the collected material sits on your laptop, which is its own problem once personal data is anywhere in it.

A straight answer on when free is enough.

If nothing happens as a result of the finding, use free tools.

Curiosity, learning, a quick sanity check before a meeting, an internal look at your own estate that nobody will audit: free tooling is the right choice and paying for a platform would be waste.

The moment a finding causes something to happen, the calculation changes. A vendor is rejected. An employee is confronted. A deal price moves. A claim goes to counsel or to an insurer. At that point the first question is where this came from and when, and the second is what you were authorized to look at. Free tooling answers neither, and reconstructing the answers after the fact is both expensive and unconvincing.

That is the whole pitch, and it is narrower than most vendors in this category would tell you. If you are not in that second situation, keep your money. If you are, see what the plans include or read the comparison of the main platforms.

And here is free tooling next to the paid platforms.

Same table we show everywhere else on the site, with free tooling on it as a real row rather than a straw man.

Osintpro

Case-first

You end up holding
A sourced, timestamped report
Authorized scope
Declared before collection, stamped on the report
Evidence chain
Raw record, source endpoint and UTC time on every finding
Price anchor
$149 to $1,190 a month

Maltego

Graph-first

You end up holding
A link chart you write up by hand
Authorized scope
Not recorded
Evidence chain
Entity provenance, no retrieval timestamp on the finding
Price anchor
Free tier, then EUR 3,000 or EUR 7,500 a year plus credits

SpiderFoot HX

Collection-first

You end up holding
A large raw result set
Authorized scope
Not recorded
Evidence chain
Module output, packaging is yours
Price anchor
Open source free. HX sold by Intel 471, price not published

Recorded Future, Intel 471

Feed-first

You end up holding
Global threat intelligence, not an entity dossier
Authorized scope
Not applicable to the model
Evidence chain
Analyst-written intelligence reporting
Price anchor
Commonly $50k or more a year, annual contract

Free tooling

Toolbox

You end up holding
Terminal output and screenshots
Authorized scope
Not recorded
Evidence chain
Whatever you save by hand
Price anchor
Free

Prices are the public list anchors these vendors publish or that buyers commonly report, not quotes. Every one of these tools is good at the job it was built for. The column that matters here is the authorized-scope column, because that is the one no other row fills in.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.