Skip to content
Osintpro

OSINT Tools List, Organized by the Question You Are Answering

Most OSINT tool lists are alphabetical directories of several hundred links, which is the least useful possible ordering. You do not have a category. You have a question.

This list is grouped by the question, kept short on purpose, and each entry says what the tool is actually for. Last reviewed 4 September 2026.

See pricing
  • Passive collection only.
  • Public sources.
  • Findings carry their record.
  • Domains only, never a person.

Who runs this domain, and what does it expose?

Osintpro domain footprint

Use it when
You need the answer in a form somebody else will review.
Note
DNS, registration, certificate authorization and hosting in one scoped pass, every finding sourced and timestamped.

dig / DNS-over-HTTPS resolvers

Use it when
You want one record, exactly, right now.
Note
Nothing is faster or more precise. You are the evidence chain.

RDAP (rdap.org)

Use it when
You need registration data in structured form.
Note
The standardized replacement for port-43 WHOIS. JSON, per-registry, and it tells you which server answered.

crt.sh

Use it when
You need hostnames that DNS enumeration missed.
Note
Certificate transparency logs surface names that were issued for and then forgotten. Often the best single source for a forgotten estate.

OWASP Amass

Use it when
You need depth and you have time.
Note
The most thorough open-source mapping there is. Long runs, real output.

Shodan / Censys

Use it when
You need to know what is listening.
Note
Active scanning at their end. Excellent on your own estate; think about authorization before pointing it elsewhere.

Is this company what it says it is?

Companies House (UK)

Use it when
The counterparty is UK registered.
Note
Free, structured, and includes filing history, officers and charges. One of the best public registries anywhere.

SEC EDGAR (US)

Use it when
The counterparty is a US public filer.
Note
Full text search across filings. Slow to learn, extremely rich once you can read a 10-K.

OpenCorporates

Use it when
You do not know the jurisdiction yet.
Note
Aggregates many registries. Coverage and freshness vary by jurisdiction, so treat it as a pointer to the primary source rather than the source.

National sanctions and PEP lists

Use it when
You have a compliance obligation.
Note
Use the official publisher, not a mirror. The date of the list matters as much as the hit.

Domain registration age

Use it when
The company is new to you.
Note
Cheapest fraud check available. See the WHOIS lookup tool.

Can this domain be abused against us?

SPF, DKIM and DMARC posture

Use it when
Anyone can send mail claiming to be you.
Note
The single highest-value ten-minute check on any estate. Run it with the DNS lookup tool.

CAA records

Use it when
You want to close the certificate issuance surface.
Note
Without CAA any publicly trusted authority may issue for your name.

Lookalike domain registration

Use it when
Your brand is being imitated.
Note
New registrations resembling your name, with the registration evidence attached, are the start of most phishing infrastructure.

Certificate transparency monitoring

Use it when
You want to know when someone issues for a name near yours.
Note
CT logs are public and near real time.

What is deliberately not on this list.

No people-search, username-lookup or reverse-email tools appear here, and that is not an oversight.

Those tools exist, they get enormous search volume, and building a page around them would be the easiest traffic on this site to win. They also point at exactly the use we refuse to serve, and a list that quietly includes them while the rest of the site promises authorized use only would be dishonest.

Where a lawful basis genuinely exists, for example consent-backed corporate screening, that work belongs inside a scoped case with the basis recorded, not inside a lookup box. Our position is set out in full on social media OSINT and in the FAQ.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.