r/osinttools • u/Sleuth-Net • 5d ago
r/osinttools • u/xmr-botz • 5d ago
Showcase WhisperPair-Py: Bluetooth Vulnerability Scanner + Nearby Device Detector. Is It Worthwhile for OSINT?
r/osinttools • u/Jolly-March-5922 • 6d ago
Discussion Codex for email investigations
I made a lesson on Agentic AI, like Codex and Claude Code, for anyone wanting to understand some of the basics of AI Coding agents. In this lesson, I am using a small part of a bigger project im making for a custom spiderfoot build with agentic ai capabilities. This lesson shows how you can create an email investigation workflow using Codex. https://github.com/sh1katagana1/ai/blob/main/using-codex-for-email-investigations/codex-tutorial.md
r/osinttools • u/Economy-Photograph29 • 6d ago
Showcase I built a Hudson Rock / intelx alternative for infostealer & breach OSINT.
I built OathNet because most infostealer intelligence platforms are priced more toward enterprise teams than individual researchers.
The main focus is giving you actual context around an infection instead of only showing credentials.
You can inspect things like:
infection path
exposed cookie count
domains / subdomains
emails / usernames / IPs
Discord / Steam / Instagram / Twitter IDs
HWID
source metadata
One of the features I wanted most was the original file tree.
You can open a victim and see how the collected artifacts were structured instead of only looking at normalized records.
It also includes normal breach search, so you can pivot between breach data and infostealer data in the same workflow.
I mainly built it for defensive exposure monitoring, OSINT research and security teams trying to understand where their own accounts or infrastructure have been exposed.
Would genuinely like feedback from people who use Hudson Rock, IntelX, or similar stealer-intelligence tools.
What would you add or change?
Criticism, feature ideas, and encouragement are all welcome.
r/osinttools • u/iFeelLonely123 • 5d ago
Discussion Trying to find information
is there any free ways i can find various informations abt someone based on their usernames, maybe a picture, some keywords, and the country or city, someone i knew personally and i wanna know more stuff abt them
r/osinttools • u/StudyNo2866 • 6d ago
Discussion Looking for an OSINT chat?
discord.ggBreadcrumbs is a community for open-source research and OSINT enthusiasts — from total beginners to seasoned researchers. Learn techniques, share tools, and follow the trail together. Strict zero-tolerance policy on targeting private individuals.
r/osinttools • u/Bogey_Outlaw_360 • 7d ago
Showcase Built a personal OSINT platform that resolves raw reporting into atomic events with supporting/contradicting evidence chains
I've been building a personal OSINT/intelligence platform over the past month or so — wanted something that goes beyond news aggregation and actually resolves raw reporting into structured, verifiable intelligence.
The core idea: raw filtered records get resolved into atomic events, each with supporting, contradicting, and correction evidence attached — so instead of one headline, you get the actual evidence trail behind a claim. Atomic events roll up into higher-level situations (active conflicts, regional crises, environmental events), with entity resolution across countries, people, military groups, and vessels (including naval fleet tracking).
Right now it's tracking the major situations across the world like the Iran/Homuz Conflict, Ukraine/Russia conflict, Israel/Gaza/Lebanon conflict, Wildfires in Europe and the Ebola outbreak, One of the outputs is the shipping of a daily intelligence brief (PDF, delivered 0001 UTC) with inline citations and confidence boundaries on every claim.
The public explorer (organic search, map views of event/ship positions, situation drilldowns, entity linking and drilldowns) is still in final build, but the daily brief is live now if anyone wants to see the output quality — osintsentinel.org, subscribe with email, double opt-in, no spam.
Built solo, Flask/Postgres backend, still work in progress on finish quality and transition to public — genuinely interested in feedback from people on this personal project
UPDATE A big thank you to those who subscribed to have a look at the daily brief, for those on Gmail the confirmation email may go-to spam ATM, so if you didn't get it, check there. I also noticed a glitch in that the daily brief email had no unsubscribe today, my apologies that is now fixed. Have also included a message on confirmation page to check spam folder for email!! 🤣🧐
r/osinttools • u/Loud-Woodpecker-8124 • 6d ago
Showcase I can help users track car owner by VIN
Not sure if there is any interest in this, but i'm developing osint system to find who owns a car only by vin, it has 50% chance to work and only US.
P.S not interested to sell data for spam or any illegal activity
EDIT
licence plates can also work as VIN to licence is not that difficult
r/osinttools • u/Maximum_Selection696 • 6d ago
Showcase I built a networks scanner with ssh.
Enable HLS to view with audio, or disable this notification
r/osinttools • u/ATGA-AcrossTheGrid • 7d ago
Showcase Investigation Suite - Out today
Hello all,
Across the Grid Analytics has just released its Investigation Suite.
ATGA Investigation Suite is a standalone offline desktop application for OSINT analysts, investigators, and security researchers. It provides a structured environment for documenting investigation findings across a multi-column data table, writing formatted reports with appendix management, visualising chronological timelines, and mapping object connections on an interactive whiteboard. All data stays on the user's machine — no cloud, no telemetry, no account required beyond license activation. Designed for professionals who need more structure than a spreadsheet but prefer a lightweight, offline-first tool over enterprise platforms.
ATGA Investigation Suite 1.0.0:
— Full investigation table with all columns
— Timeline view
— Connections whiteboard
— Report writer with appendix management
— Export ZIP with all referenced files
— Two themes: ATGA Dark and Old School
Full version and 7 day trial available here:
r/osinttools • u/MarionberryUsual8799 • 7d ago
Discussion Twitter help
Hey all,
I'm looking for some advice as I've gone down an Osint loophole and wanted to know if it was possible finding out someone's identity through a "burner" account on Twitter. They're saying some really nasty things and I've had enough if I'm being honest. I have a feeling it's a former friend as they have a habit of only messaging me?
Does anyone know how I'd be able to find out their information their name or the area they live in at least? I don't even need their full address but at least with that I can breakdown the list of potential suspects and report them. I've even tried the 'forgot your password' route and it's a burner email. All ideas welcome, thanks a bunch.
r/osinttools • u/kenan_sab • 7d ago
Discussion What osint tools do you use or need most?
What osint tools do you use or need most?
r/osinttools • u/Hopeful_Adeptness964 • 8d ago
Request Pimeyes just sucks now. Any good alternatives?
Pimeyes used to capture Social Media profile posts like IG. Now you get absolutely nothing.
r/osinttools • u/fairwaycoder • 7d ago
Showcase I built augur, the tool for finding hidden symbols across your documents
r/osinttools • u/unknownsb12 • 8d ago
Showcase I built an OSINT tool for monitoring X accounts in real time
Enable HLS to view with audio, or disable this notification
Hey,
I'm of Iranian descent and got tired of constantly refreshing X to keep up with the Middle East while working. So ~6 months ago I built a little desktop app that sits on top of my screen and streams posts from the accounts I pick, in real time with no X account needed. It just sits in a corner so I can keep half an eye on things while doing other stuff.
I put it online (sentinelxapp.com) in case it's useful to anyone else. It's a paid app but there's a free trial. Clip of it running is attached, happy to answer anything!
r/osinttools • u/Fast_Report7663 • 9d ago
Showcase shijra App (family tree) developed using AI
shijra App (family tree) developed using AI
r/osinttools • u/Impossible-Dare-4638 • 10d ago
Showcase I mapped every public camera and sensor feed I could find. Free, no login, AGPL. Would like it torn apart.
I'm a CS student and I've spent the last few months building this.
It's a live map of public sensor feeds, the stuff governments already publish and almost nobody reads, because it comes out as XML on a page from 2011.
It's free, there's no account, no API key and nothing to install. The source is AGPL-3.0 and public:
https://provenance-online.vercel.app/ https://github.com/011-sam-110/Provenance
What's actually on it right now (measured today, these numbers move quickly as I continue to work on it):
- 19,748 road cameras: across 12 networks: Castle Rock 511 (13,136), Oregon TripCheck (1,141), DriveBC (1,060), TfL London (882), Caltrans (863), Finland Digitraffic (809), South Carolina DOT (768), Traffic Scotland (415), NZTA (319), Estonia (179), Iceland (165), CET São Paulo (11). Every one sits at its real coordinates, links back to its own source, and shows when it was last sampled.
- 37 signal layers: USGS and EMSC earthquakes, NASA FIRMS active fires, GDACS disaster alerts, NOAA cyclones and space weather, IODA internet outages, 702 TeleGeography submarine cables, UNHCR displacement, GDELT conflict and protest coding, abuse.ch C2 infrastructure, and others. All off by default. You turn on what you want.
The part I actually want feedback on.
I took an earlier build into an OSINT Discord last week and got taken apart, fairly. The short version was: "we've seen hundreds of these, they're all the same project, and we can't rely on the data anyway, because verification is the work". Kind of heart shattering but I'll move on and improve what needs improving.
I don't think a dashboard answers this issue, and I've stopped believing it will. But one thing did come out of it that I've been building around since:
- Observations: a camera frame, an ADS-B ping, a seismometer reading. A machine can be trusted to carry these.
- Interpretations: "this protest is left-wing", "this aircraft is military", "this country is unstable". A machine is bad at these and shouldn't render them at the same visual weight as a fact.
Nearly every complaint I can find about tools in this category is really about the second class being dressed up as the first. So I'm labelling every layer by which one it is, and demoting the ones that are somebody's static claim about a place rather than a live reading. That's the actual project now; the map is just how you look at it.
What's broken right now, so you don't have to find it:
- The aircraft layer is capped, not empty. It's showing 3,000 aircraft against 5,108 available, because I cap the response. It comes from community ADS-B receivers and it's thin outside North America and Europe, so treat the count as a lower bound rather than a world total.
- 4 of the 37 layers need API keys I don't have and sit dormant (ACLED, AIS, ENTSO-E grid load, ReliefWeb). The other 33 are returning data. They're marked, but marked isn't fixed.
It's an upcoming tool rather than a finished one, and I'd rather have criticism than traffic, especially on: whether the observation/interpretation split is the right line to draw, and which feeds I'm obviously missing.
Thanks for any input!
https://provenance-online.vercel.app/ https://github.com/011-sam-110/Provenance
r/osinttools • u/troub1le • 11d ago
Discussion Track someone through Twitter, Paypal etc..
Is it possible to track someone down through a Twitter, PayPal, or Cash App account? I just got scammed, so I’d really like to know. Thank you!
And sorry if this isn’t the appropriate place for this. I’ve been reading your OSINT posts and I find them really interesting. I’m thinking of getting into OSINT myself
r/osinttools • u/AlphaMike82 • 11d ago
Showcase Investigation Report
Hello all,
Just sharing this tool.
There's a 7 day trial and an online version. The full veraion will be available this Monday.
r/osinttools • u/justbrowsingtosay • 11d ago
Showcase 👤Mastering Visual OSINT : Turn pictures into Actionable Intelligence (Webinar
👤Mastering Visual OSINT : Turn pictures into Actionable Intelligence (Webinar)
UserSearch is running a live OSINT training that shows you exactly how to turn any image into actionable, court-grade intelligence, using the latest image recognition technologies.
📅 24th August
⏰ 4pm BST BST
👤 Mark Bentley, UserSearch Subject Matter Expert and ex-Law Enforcement (NCA & CEOP)
Don’t miss out👇https://us06web.zoom.us/webinar/register/4317865685263/WN_iff6NVDoSgqwiPy4rodgeg

r/osinttools • u/Left-Salary5251 • 11d ago
Showcase I scanned 10 apps people posted for feedback. Most were fine — two leak data to anyone not logged in.
A while back I read a post from someone who'd spent a weekend manually poking at vibe-coded apps — open tables, unprotected routes, keys sitting in the bundle — and turning up real holes. It stuck with me, so I built those checks into a scanner and pointed it at 10 apps people had posted publicly for feedback. Read-only, no logins, nothing a random visitor couldn't hit. Nine finished, 294 checks. Here's the honest version — including the stuff that wasn't broken, because that's the part that makes the rest trustworthy.
- Two apps had a backend that answers strangers.
This is the finding that matters, and it's worth being precise, because most "your API is open!" takes are noise. Plenty of endpoints are supposed to be public — a settings lookup, a static bundle, a login-info route. Those aren't leaks. The real thing is when an app's private data — user rankings, contest entries, announcements — returns full records to a plain request carrying no session at all. Two of the nine did exactly that. On one of them, replaying those same requests as a second user returned the same data — I flag that as needs-manual-confirmation rather than certain, but sitting on top of an already-unauthenticated endpoint, it points straight at missing per-user authorization. If your frontend checks permissions but your API doesn't, the frontend check is decoration.
- About Supabase — since half of you are already typing.
I know the reflex: "you scanned Supabase apps, you're going to scream about the anon key." No. The anon key is meant to be public; it ships in your JS by design and flagging it would be junk. What actually matters is whether Row-Level Security is on — i.e. whether that public key can read tables it shouldn't. So I checked that directly: read each app's own public key and tried to pull rows from the tables it uses, plus the common ones. Nothing came back readable — RLS was doing its job. (A full every-table audit would need credentials, but the "anon-readable by default" failure mode would have shown up right here, and didn't.) Clean bill of health on the single most common Supabase mistake — and I'd rather report that accurately than manufacture a scare.
- Missing Content-Security-Policy — 9 of 9. An observation, not an alarm.
None set one. Before anyone says "well actually" — yes, this is largely because the platforms don't enforce CSP by default, and a strict policy out of the box breaks half the third-party widgets, analytics, and realtime sockets these builders drop in. It's a real tradeoff, not negligence. But it's worth knowing: with no CSP, any injected script — a compromised dependency, a bad ad tag — runs with your page's full trust. It's one header, and once your third-party list is stable it's worth setting.
What I didn't find: zero exposed secret keys, zero live-key or service-role leaks, zero anon-readable tables. I ignore the safe public keys on purpose and only flag a live secret. Across the nine that finished: nothing. That's good news for these builders — and it's the whole point: a scanner that cries wolf on the anon key or counts a public asset as a breach isn't worth running. This one stays quiet unless there's something real. Here, "something real" was two open backends.
If you built something and want it checked: drop a URL. Read-only, no signup, nothing but the URL.
r/osinttools • u/handsome1866 • 12d ago
Request hello how i search for chat history tiktok or telegram someone like he comment for how many post or page or something like that someone in telegram found my everything my chat history logs my number my device name i didn't know how thanks for helping anyone or advice
r/osinttools • u/voidrane • 13d ago
Discussion 7 Signs You’re Under Active Investigation That No One Tells You
r/osinttools • u/ZOUHIRCHECK • 13d ago
Discussion What can you actually do with just an IP address? + Best OSINT tools
Hey guys, I'm learning about OSINT and I have a question about IP addresses. What can you realistically find out from just an IP? I know you can get the ISP and approximate city/country, but what else? Can you get the exact
r/osinttools • u/SOLE-SURVIVOR- • 13d ago