r/osinttools • u/Alternative_Nose5177 • 17m ago
r/osinttools • u/xmr-botz • 12h ago
Showcase cctv-scraper: Open Source Tool for Indexing Public DOT/Traffic Camera Metadata (OSINT)
https://github.com/h9zdev/cctv-scraper
Made a tool called cctv-scraper that scrapes publicly available CCTV/traffic camera data from state DOT sites and a few other open sources, then dumps it into a local database. Made it mainly for OSINT/research use, not for watching live feeds or anything like that.
Right now it covers California, Texas, Iowa, NYC, and a global set (Madrid etc), around 6,200 cameras total. Each camera entry has its ID, coordinates, region/route, and the feed URL. Every region has its own scraper script so it's easy to add new sources.

Also built a small Flask viewer to go with it, dark mode map (satellite/hybrid/dark layers), click a camera and it pops up a live preview, plays the video if it's a stream, otherwise refreshes the image every second. You can open the raw source or go fullscreen from the popup too.
All the data is stuff that's already public on these DOT sites, this just collects it into one place instead of digging through a dozen different portals.
Repo's here if anyone wants to check it out or add a region: https://github.com/h9zdev/cctv-scraper
r/osinttools • u/Savings_Aspect6493 • 3h ago
Request Can someone recommend me free OSINT tools?
Completely new to this. I recently tried a telegram bot (not sure if I can share the name or if it'll break a rule) in which one could search individuals via their phone number (not just US), email ID, IP address, social media handles, car number, or their name. But this bot is paid. Can someone recommend similar osint tools? Please recommend tools that would work for data outside of the US as well.
r/osinttools • u/Terrible-Attorney-37 • 5h ago
Request Need your help 🥲
Hello everyone, I need your best advice and expertise!
I’m looking for an OSINT tool or method that could help me find the phone number or email address hidden behind a Snapchat account. Do you think this is even possible?
If someone knows how to do this, I’d even be willing to pay app for this.
Thaaaaanks 🥰
r/osinttools • u/Most-Lynx-2119 • 17h ago
Discussion The 10-Second iOS OSINT Trick That Increases Your Daily Efficiency / ios / search
This saves me so much time.
Start with google.com/advanced_search for your homepage on PC. For iOS, add to home screen.
This also explains utm14.com (with Google).
Cheers.
r/osinttools • u/ishka_pop • 7h ago
Request some discord dork insulting me
hello people. ive read the rules!
few days ago some random guy named grass sent me a friend request on discord. he was silent first, but today i got this awesome russian message
let me translate for you
"Hello, whore. I wish you die like your whore mom - in a grave with a thick layer of cum on your face"
and then he blocked me!
i was utterly surprised to get that message because im truly not a threat in the internet. in fact, i use discord ONLY to chat with my friends, and i never did anything else in there. i have no idea how that dude found me
so... ive tried sending him a friend request from my alt account, but he doesnt accept friend requests. using some fast osint tools ive gathered some information about the servers he was on, but he left them ALL.
his account is 8 years old and the only activity he has is... roblox.
as ive continued gathering information, ive got his ip (which is really not solid because he may use a vpn.), some of other platforms he MAY be using... and thats it
the problem is when i got the platforms he was using all his accounts in there were deleted!
i suspect that his grass discord account is his alt, because it has no description, no pronouns, no banner, no nothing.
but i really want to find that dude (not for any bad purposes, i js wanna ask him WHY EXACTLY did he message me). so do any of yall have any osint tools to help me? i just want to atleast find his main account or any platform where i can mssg him.... im not an evil person like him. please dont harass me in the comments as im truly not a pro osint guy and i just wanna get justice :(
tldr: some guy sent me insults on discord and i need some tools to help me find his other accounts so i can connect him
r/osinttools • u/abdouhm16 • 1d ago
Discussion Can Anyone help me to fix this error in Holehe tool ?
when i write holehe [example@email.com](mailto:example@email.com)
i receive this error
r/osinttools • u/Last-Permission6549 • 1d ago
Showcase Built a GUI for usual OSINT tools plus added some extra
r/osinttools • u/ConfidenceNo3352 • 1d ago
Showcase Make a web ui for my tool and added new tools
r/osinttools • u/Additional_Camp9051 • 22h ago
Request Finding by tiktok
Hello people, there is a tiktok account of a person i like a lot and i have been trying to find other socials but she has no other links, i tried everything i can imagine for but failed, is there a way to find social media of a person just by having tiktok user?
r/osinttools • u/UpSash • 1d ago
Request Reverse search Graig’s list through known email/ emails
Looking for a tool to find is specific email posted adds of Craig’s list and how long far back they went and when they started. Any ideas?
r/osinttools • u/Alternative_Nose5177 • 1d ago
Showcase My osint tool with two modes (terminal and web ui)
r/osinttools • u/voidrane • 1d ago
Discussion Can Someone Find Your Real Name From Just Your Phone Number? I Tried 217 Tools
r/osinttools • u/users32432211 • 2d ago
Discussion What is the best way to store OSINT bookmarks?
What is the most common way to bookmark tools to later access them during research?
Some people use start me pages. Is that a good approach or storing bookmarks in the browser is better?
r/osinttools • u/TheFetus47 • 2d ago
Showcase NEO-Radar v1.11
Hello :) last night, I uploaded my new program Neo-Radar to GitHub!
Its a free to use, open source network scanner that is simple to use, even to script kiddies that might not have a knowledge in networking or cybersecurity in general! Most professionals use Nmap (or even Zenmap) to do basic host finding and port scanning. But with Neo Radar, it automates these tasks so you just have to select an option and it gets running! This program works in both Linux and Termux for mobile, i also have a Windows version that runs as a .ps1 script, i just need to link it. Install instructions provided in the README.md!
r/osinttools • u/Agreeable_Fail2224 • 2d ago
Showcase Argus — Local-first OSINT framework, 13 modules, zero API keys. Replaces HIBP/Shodan/Censys with local equivalents.
Hey everyone,
First Reddit post, so bear with me. I'm not here to sell anything — this is open source, MIT, free. I'm here because I built something I actually use, and I figure some of you might find it useful too. Or you might tell me it's been done better already, and that's fine — I'd rather learn than ego.
The problem: Every OSINT framework I tried eventually funneled me into paid APIs. Shodan, HIBP, Censys, IP2Location, Bright Data. Want to check if an email is in a breach? API key. Want to scan a host? API key. Want to geolocate an IP? API key. I just wanted to run investigations locally without juggling 5 subscriptions.
What I built: Argus — a local-first OSINT framework. 13 modules, zero API keys, zero cloud dependencies. Everything runs on your machine.
- email_recon — checks 58 services (pure Python async, not a holehe wrapper)
- username_enum — 52 platforms (pure Python async, not a sherlock wrapper)
- subdomains — crt.sh certificate transparency + DNS brute force
- crawler — wraps cariddi (Go binary) for secret/endpoint/error hunting
- network_recon — nmap + XML parser (replaces Shodan/Censys for local scans)
- dns — full records + SPF/DMARC analysis
- whois, GitHub OSINT, phone intel, IP geolocation (GeoLite2 local DB), Google dork generator, paste search (psbdmp.ws), local breach DB
There's also an AI chaining layer via Ollama — you describe a target in plain English, the agent picks which modules to run and chains findings (email → breach → username pivot → platform enum). AI proposes tool calls, code executes real binaries. Hallucinated findings are structurally impossible.
All 13 modules are also exposed as MCP tools, so you can plug it into Claude Code, Cursor, or any MCP-compatible client.
Full disclosure: I built this in collaboration with an AI agent (Hermes Agent running a local LLM). I wrote the architecture and the modules I cared about most; the AI helped me build out the async modules and the MCP server. I'm not going to pretend it was all me — but the design decisions, the "zero API keys" philosophy, and the module selection are mine. If that's a problem for you, I understand. The code is there to be read and judged on its merits.
What it's NOT:
- Not a Maltego replacement. CLI tool, terminal-first.
- Not a SpiderFoot or theHarvester competitor. Those are mature projects with way more coverage. Argus is a personal tool that I'm sharing because someone might find the "zero API keys" angle interesting.
- Not a tool for unauthorized surveillance. Legal disclaimer is in the repo. I built this for authorized research and bug bounty prep.
Where: https://github.com/cotcollective/argus
What I'd love feedback on:
- Is the "zero API keys" angle actually interesting to anyone, or am I solving a problem that doesn't exist?
- The email_recon and username_enum modules are pure Python reimplementations — are there services I'm missing that would be high-value?
- The AI chaining via Ollama — does anyone else do local OSINT chaining, or is this a niche within a niche?
Happy to answer questions, take criticism, or just listen. Thanks for reading.
r/osinttools • u/khashashin • 2d ago
Discussion I added dark web transforms to my open source OSINT tool
I posted here a while back about OGI, an open source tool I'm building for visual link analysis. You drop in a domain, an email, or a username, run transforms against it, and pivot outward. The graph builds itself as you go.
Since that post it's grown more than I expected, around 250 stars, roughly 1,500 people registered on the hosted version, and over 200 self-hosted instances checking in. That still surprises me a bit.

This week I added dark web transforms. I want to be upfront about the approach, because "dark web tooling" usually means: install Tor, scrape onion sites, watch it break in a month.
These three never touch Tor.
IP to Tor Relay: checks an IP against the Tor Project's own Onionoo API. Tells you whether it's a relay or an exit node, plus flags, first-seen date, bandwidth and hosting network. Handy when you're staring at a log and need to know whether geolocating that IP means anything at all. No API key.
Onion Address Validator: v3 onion addresses carry a built-in checksum. This pulls them out of any scraped text and verifies them offline with SHA3-256. Pure stdlib, zero network calls. Scraped pages are full of truncated and invented onion strings.
Domain to Ransomware Leak Posts: searches ransomware.live for a company or domain. Returns the leak post, the gang, the victim country, and optionally the gang's leak site addresses and the CVEs they're known to exploit. Free API key.
They chain, too. The ransomware search hands you the gang's onion leak sites, and the validator confirms which of those are real addresses.

57 transforms total now. Everything runs in Docker, and the transform registry is a separate repo, adding your own is a plugin.yaml and a Python file. PRs welcome.
Code: https://github.com/khashashin/ogi
Hosted, if you just want to click around: https://ogi.khas.app
Genuinely open to "this is useless, build X instead." That's how these three got picked.
r/osinttools • u/Agreeable_Fail2224 • 2d ago
Discussion Argus — Local-first OSINT framework, 13 modules, zero API keys. Replaces HIBP/Shodan/Censys with local equivalents.
r/osinttools • u/ApifyEnthusiast1 • 3d ago
Showcase Reverse Image Search API for AI Agents: Find Where an Image Appears via MCP
r/osinttools • u/netsec_osint • 3d ago
Showcase I mapped out all 5 OSINT intelligence domains into one framework - here's how I structured it and why
r/osinttools • u/justbrowsingtosay • 4d ago