Skip to content
Osintpro

OSINT Search Engine: Searching Records, Not Web Pages

People searching for an OSINT search engine usually want one of two different things: a way to query infrastructure record systems directly, or a single box that searches across many public sources at once. They have very different answers.

This page explains what is actually searchable, what is not, and why the format of the answer matters more than the size of the index.

See pricing
  • Passive collection only.
  • Public sources.
  • Findings carry their record.
  • Domains only, never a person.

Two different things go by the same name.

Record search engines

Shodan, Censys and similar systems index the internet itself rather than the web on top of it. They scan address space, record what services answer, and let you query the result. That is genuinely a search engine, and it is the closest thing the field has to one. It is also active collection at the scanning end, which is why the question of who is authorized to look matters even when the index is public.

Aggregators over public sources

The other meaning is a single interface that queries many public record systems and returns a combined answer for one entity. This is what most people mean when they type the phrase, and it is what Osintpro does for a domain: DNS, registration, certificate authorization and hosting, in one pass, from a single subject.

The distinction matters because they fail differently. A record search engine gives you an enormous, undated index and leaves the correlation to you. An aggregator gives you a correlated answer about one entity and leaves the coverage question open. Osintpro is the second kind and says so, including which modules ran on each report.

What is genuinely searchable from public records.

The DNS namespace

Not searchable in bulk, but fully queryable per name. You cannot ask for every subdomain of a zone, which is why hostname discovery works by inference from certificate logs and by probing known label patterns.

Registration data

RDAP answers per domain, not per registrant, since redaction removed the reverse lookup for most names. Age, registrar, status and delegation are all reliably available.

Certificate transparency

Genuinely searchable and genuinely bulk. Every publicly trusted certificate is logged, which makes CT the single richest public source for hostnames an organization forgot it had.

Corporate registries

Searchable per jurisdiction, with wildly varying quality. Companies House in the UK and the SEC in the US are excellent. Many others are neither structured nor free.

Announced network space

BGP and RIR data are public and structured, and they tell you which address blocks an organization announces. Useful for scoping an attack surface review honestly.

People

Deliberately not part of this platform. Searching for a person is where OSINT tooling turns into surveillance, and our acceptable use boundary covers why we refuse it.

One subject in, a correlated answer out.

This is the aggregator pattern working on a real domain, against live public endpoints, in your browser. Declare the scope, pick your modules, and read the findings with their sources attached.

  • It runs in your browser. Queries go to public DNS and RDAP endpoints, not through us.

  • Nothing reaches the subject. The domain you enter is never contacted, probed or scanned.

  • A domain, never a person. There is no input on this panel that accepts an individual.

  • Findings carry their evidence. Raw record, source endpoint and the UTC moment of retrieval.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

The format of the answer beats the size of the index.

A bigger index does not make a finding defensible. Attaching the record does.

It is easy to compete on coverage claims and impossible to verify them. What a reviewer can verify is whether a specific claim in your report came with the record behind it, the endpoint it came from and the moment it was read. That is checkable in seconds and it is the property we optimize for.

If you want breadth of raw collection, the free tools listed on free OSINT tools will get you a long way, and so will a Shodan or Censys subscription. If you want the answer in a form that survives someone disagreeing with it, that is a different design goal.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.