Open source intelligence tools: 10 OSINT tools ranked for 2026

· Prefer this source on Google

Quick comparison of the best OSINT tools

The table orders all ten open source intelligence tools by final position. Reach figures are each vendor's own headline number, read in September 2026, and they count different units, so read them within a row. Entry price is the cheapest plan one analyst can buy for twelve months.

#ProviderPublished reachEntry priceBest fit
1Maltego100+ data connectors, 200+ social platforms€3,000/yr (Entry); free Basic, 200 credits/moLink analysis across people, companies and infrastructure
2Intelligence X200 billion+ records, 12 selector types€2,500/yr (Researcher); free, 50 searches/dayLeak, paste and darknet search
3Censys3 billion+ services, all 65,535 ports$100 credit pack; free, 100 credits/moInternet-facing asset discovery
4Have I Been Pwned17.8 billion addresses, 1,038 breaches$52.68/yr (Core 1)Breach exposure checks on your own domains
5theHarvester50+ passive sources$0, open sourceCommand-line recon on one domain
6ShodanFull internet crawl at least weekly$49 one-time (Membership)Open ports and exposed devices
7OSINT Industries1,500+ sources claimed£19/mo (Basic), 30 creditsEmail, phone and username lookups
8SpiderFoot200+ modules$0, open sourceSelf-hosted automated scans
9Recorded Future1.2 million sources$70,375/yr median*Enterprise threat intelligence programs
10Social Links500+ sources, 1,700 methodsQuote onlySocial media and messenger investigations

The median marked * is an anonymised buyer-reported contract value published by Vendr. Everything else is the price the vendor publishes itself, read in September 2026.

Where these figures come from

Reach and price figures come from each vendor's own product, pricing or documentation page, linked inside each entry: maltego.com/pricing, intelx.io/product, docs.censys.com, haveibeenpwned.com/Subscription, account.shodan.io/billing and osint.industries/pricing. theHarvester and SpiderFoot figures come from their GitHub repositories.

The Recorded Future median is the header stat on Vendr's Recorded Future page, from 47 purchases. Social Links publishes no price and Vendr carries no figure for it, and none of the ten publishes a data-accuracy rate, so no row claims one. User quotes in the entries come from G2, Hacker News and LinkedIn, and G2's own moderation figures are in the Is G2 legit report.

Back to top ↑
Worth checking

None of these ten vendors appears in another ranking on this site. The nearest neighbours rank adjacent jobs: the technographic data providers ranking covers what a company runs as seen from outside, the data enrichment tools ranking covers email and phone lookups for sales teams, and the alternative data providers ranking covers commercially available data sold to investors.

Open source intelligence (OSINT) is intelligence built from publicly available information. US law defines it as intelligence "collected, exploited, and disseminated in a timely manner to an appropriate audience for the purpose of addressing a specific intelligence requirement," in Section 931 of the 2006 defense authorization act.

OSINT tools automate that data collection. They collect data from search engines, breach dumps, certificate logs, social media platforms and dark web forums, then hand an analyst the results in a graph, a table or an API response.

This page ranks ten open source intelligence tools against five criteria a buyer can test. Security teams, investigative journalists, fraud analysts, academic research groups and corporate due-diligence staff are the audience, and all of them use OSINT techniques for intelligence gathering on people, companies and infrastructure. Prices and limits come straight from the horse's mouth, each vendor's own pages, checked in September 2026.

Three of the ten changed hands or restructured pricing inside the last 24 months: Mastercard closed its $2.65 billion purchase of Recorded Future in December 2024, Have I Been Pwned replaced every API plan in March 2026, and Censys retires its Legacy Search API this month. A first paid year for one analyst now runs from $0 to a $70,375 median.

Price ladder of the first paid year for one analyst across ten OSINT tools, from free open-source software and Shodan's $49 membership to Intelligence X at €2,500, Maltego at €3,000 and a $70,375 Vendr median for Recorded Future
Six of the ten can be bought or run for under 300 a year in the vendor's currency; Recorded Future's Vendr median is $70,375 and Social Links quotes every deal.

Evaluation criteria for open source intelligence tools

Five criteria decide the shortlist, and the ranking below applies them in this order. Each one is worth 0 to 2 points, for a maximum of 10. Ties break on criterion four, then criterion one. The list covers popular OSINT tools that a single analyst can buy or install, so government-only platforms sit outside it.

Source breadth across five families

Count how many of five source families the vendor's own pages say the tool searches: people and social accounts, companies and public records, internet infrastructure, breach and leak data, and the dark web. Four or five families earn 2 points. Two or three earn 1, and a single family earns 0.

First paid year for one analyst

Take the cheapest plan one person can buy for a year. A published list price under 1,000 in the vendor's currency earns 2 points. A higher list price, or a Vendr median where no list exists, earns 1. A quote-only price earns 0.

By the numbers
2 of 10

Tools on this list that sell only through a demo: Recorded Future and Social Links. The other eight let a buyer start on a free tier or open-source code.

Free allowance for a pilot

A buyer should be able to test 20 known targets before paying. A free tier with at least 100 queries or credits a month, or free open-source software, earns 2 points. A free tier with a smaller, unstated or eligibility-gated cap earns 1. Demo-only access earns 0.

Documented API limit

OSINT collection at volume runs through an API, so the limit has to be written down. A published rate or quota in numbers earns 2 points, an API without a published number earns 1, and no hosted API earns 0. The market intelligence API ranking applies the same test to commercial data feeds.

Dated release in the last 12 months

Sources change their formats every quarter, and a tool nobody patches stops returning results. A dated release or product changelog entry within 3 months of 24 September 2026 earns 2 points. One from 3 to 12 months earns 1, and anything older earns 0.

Bar chart of total scores out of 10 for ten OSINT tools, from Maltego at 9, Intelligence X and Censys at 8 and Have I Been Pwned at 7 down to Recorded Future at 4 and Social Links at 2
Maltego drops one point, on price. Recorded Future and Social Links lose most of theirs on price, free access and published API limits.
ToolBreadthPriceFree allowanceAPI limitReleaseTotal
Maltego2 (5 families)1222 (17 Sep 2026)9
Intelligence X1 (3)1222 (11 Sep 2026)8
Censys0 (1)2222 (15 Jul 2026)8
Have I Been Pwned0 (1)2221 (31 Mar 2026)7
theHarvester1 (2)2201 (3 Jun 2026)6
Shodan0 (1)2120 (7 Aug 2024)5
OSINT Industries0 (1)2111 (2 Feb 2026)5
SpiderFoot1 (2)2200 (7 Apr 2022)5
Recorded Future1 (3)1011 (11 Jun 2026)4
Social Links1 (2)0010 (13 Jun 2025)2

Breadth shows points, then the number of source families in brackets. Release shows points, then the date of the most recent dated release or product change.

The 10 best OSINT tools, ranked

Ranked on source breadth, first-year price, free allowance, documented API limits and release activity, in that order, with ties broken on API limits and then breadth.

01

Maltego

Back to top ↑

Best fit

An investigator who pivots from a person to their companies, domains and leaked credentials inside one graph.

Maltego Technologies has built link-analysis software in Munich since 2008 and says its tools have supported over one million investigations. The desktop Graph client ships built-in data transformations, called transforms, which run live queries against a data source and draw every result as an entity you can pivot from.

Its Graph product page lists over 1 billion online identities, 200+ social media platforms, 200 million company records and over 1 TB of breached data. Deep and dark web investigations and domain and infrastructure investigation sit on the same page, which makes Maltego the only tool here covering all five source families.

Key features

  • 100+ ready-made Connectors to outside data sources, keyed with your own API keys.
  • Transform partners including Team Cymru, SOCRadar, Epieos and Criminal IP on the Transform Hub.
  • Hunchly web-capture tool, bundled from the Entry plan up after the May 2025 acquisition, so one licence kills two birds with one stone for capture & analysis.
  • Maltego One, launched 27 October 2025, with browser-based link analysis and an AI Assistant.
  • Graph Desktop 4.13.0, released 17 September 2026, which saves graphs as MTGJ files.

Pricing

The pricing page lists Basic at €0 with 200 credits a month, Entry Standard at €3,000 a year with 10,000 credits, and Professional at €7,500 a year for up to 5 users. Entry is sold only to users who pass vetting, and teams that outgrow 200 free credits have to bite the bullet on €3,000. Enterprise is quoted.

Pros

  • Covers people, companies, infrastructure, breach data and the dark web from one client.
  • Free Basic plan with 200 credits a month for a pilot.
  • Six desktop releases between December 2025 and September 2026.

Cons

Running short of credits is par for the course on the lower plans. A small-business reviewer on G2 in August 2023 wrote: "Access to number of transform runs, they can run out quickly."

Why it’s ranked #1. Maltego scores 9 of 10 and beats Intelligence X on criterion one, searching five source families to IntelX's three. It loses a point only on price, where €3,000 sits above the €1,000 line.

02

Intelligence X

Back to top ↑

Best fit

A researcher who needs to check if an email, domain, IP or wallet appears in leaks, pastes or darknet archives.

Peter Kleissner founded Intelligence X in Prague in 2018, and the search engine went live on 10 October 2018. The product page says it searches more than 200 billion records and keeps historical copies of websites & documents, much like the Wayback Machine.

Twelve selector types are searchable, from email address and IPv6 CIDR range to Bitcoin address and IBAN. Results come from eight categories: paste sites, Tor and I2P darknet, Wikileaks & Cryptome, North Korean and Russian government sites, data leaks, whois data, the public web and a catch-all category it calls Dumpster.

Key features

  • Phonebook lookups that expand a partial selector into every matching email, domain or URL.
  • Identity Portal with line-by-line results and CSV export of leaked accounts.
  • Stealer-log export, added in February 2026.
  • Inline preview of archived PDFs, Word files and darknet pages.
  • Search API on every paid tier, with product-integration rights from the €7,000 API license.

Pricing

Researcher costs €2,500 a year for 200 selector searches a day, API €7,000, Identity Portal €10,000 and Enterprise €20,000. Free accounts get 50 searches a day. The API license rose to €7,000 in June 2025, for the first time since 2022.

Pros

  • The largest published record count on this list.
  • 50 free searches a day, enough for a real pilot.
  • Daily search quotas published per tier, from 200 to 5,000+.

Cons

  • Leak export and reverse lookup start at the €10,000 Identity Portal tier.
  • The terms promise 95% monthly availability and support replies within 7 days.
  • All fees are non-refundable.

One Hacker News user, writing in February 2022, described what a leak index is for in practice: "This site and a few other OSINT tools was how I discovered who 'sold out' my CV to some of the questionable 'recruiting agencies'."

Why it’s ranked #2. Intelligence X ties Censys at 8 points and wins the tie on breadth, three source families to one. It trails Maltego by a point because it covers three families to Maltego's five.

03

Censys

Back to top ↑

Best fit

A security team mapping every internet-facing host, certificate and service it owns, including the ones that stayed under the radar of the asset inventory.

Censys grew out of ZMap, which Zakir Durumeric built at the University of Michigan in 2013, and became a company in 2017. Its scanning documentation says it scans the whole public IPv4 space on all 65,535 ports, tracks over 3 billion services and detects over 200 Layer 7 protocols.

Freshness is the number that separates it from Shodan. Censys puts the average age of high-value service data at about 16 hours, and predictive scanning finds over 40% of the services it records. For security professionals, a 16-hour-old view of exposed hosts gives situational awareness recent enough to act on before threat actors do, the same argument the real-time market intelligence guide makes for commercial data.

Key features

  • Certificates dataset of over 15 billion records.
  • 30+ integrations, including Splunk, Google SecOps, ServiceNow, Maltego and Wiz.
  • Unlimited Enrichment, a credit-free lookup API launched 15 July 2026.
  • DNS intelligence in the Internet Map, added 8 July 2026.

Pricing

The Free tier gives 100 credits a month that expire monthly, and a standard query costs 5 credits. Starter credit packs begin at $100 and last 12 months. Core, Adversary Investigation and Security Operations plans are quoted, with the Enrichment API at 20,000 calls a day on Core.

Pros

  • Every port scanned, with a published 16-hour data age.
  • API quotas written into the pricing page.
  • Raised $70 million in March 2026, led by Morgan Stanley Expansion Capital.

Cons

  • 100 free credits cover about 20 standard queries a month.
  • Free search returns one page of 100 results with no history.
  • Legacy Search and its API retire in September 2026, so saved queries need rewriting.

"The API also works great, is very well documented, and is adaptable to our use cases, like generating alerts on specific types of exposures, generating alerts on vulnerable software, statistical analysis, etc."

Miguel F., enterprise reviewer, G2, December 2023

A financial-services reviewer on the same page flagged the maintenance cost: "It seems to not be able to tell when seed a data is no longer valid after some time and the user needs to perform manual clean up."

Why it’s ranked #3. Censys scores 8 and loses the tie with Intelligence X on breadth, one source family to three. It beats Have I Been Pwned on maintenance, with a July 2026 release against HIBP's March 2026 plan change.

04

Have I Been Pwned

Back to top ↑

Best fit

An IT or security lead who wants to know which company addresses turned up in data breaches.

Troy Hunt has run Have I Been Pwned since 2013. The homepage counts 1,038 pwned websites and 17,837,211,580 pwned addresses, and the service checks if an email account has been compromised in any of them.

Organizations use it to locate data leaks and track data breaches on their own domains. The pricing page says over 400,000 domains are monitored by more than 200,000 organisations.

Key features

  • Domain search across every breached address on a verified domain.
  • Pwned Passwords, a k-anonymity API serving 18 billion+ requests a month with no key.
  • Stealer-log data on Pro plans.
  • Email notifications when a monitored address appears in a new breach.

Pricing

Core 1 costs $52.68 a year for 10 requests a minute and one domain of up to 25 breached addresses. Pro 1 costs $4,548 a year for 1,000 RPM and 50 domains. High RPM plans reach 24,000 requests a minute for $69,996 a year. These tiers replaced the old Pwned 1 to 5 plans in March 2026.

Pros

  • The cheapest paid API on this list at $4.39 a month.
  • Rate limits published for every tier, from 10 to 24,000 RPM.
  • Pwned Passwords stays free with no rate limit.

Cons

  • Free domain search stops at 10 breached addresses.
  • Stealer logs and k-anonymity email search start at $4,548 a year.
  • Username and phone search left the website in May 2025.

"I just added my domain to the site again and I see "2,243 Total Breached Addresses", and "18 Addresses excluding Spam Lists", but I have no idea what they are. Attempting to click the links shows me I need to "upgrade" to see them"

stevekemp, Hacker News, May 2025

Another user in that thread paid once and left: "I ended up signing up for a subscription, checked my domains, and then cancelled the subscription."

Why it’s ranked #4. HIBP scores 7, one point behind Censys, whose July 2026 release beats HIBP's March 2026 update. It beats theHarvester on criterion four with RPM limits published from 10 to 24,000, where theHarvester runs only as local software.

05

theHarvester

Back to top ↑

Best fit

A penetration tester gathering information on one target domain, its emails, subdomains and hostnames, before an engagement.

Christian Martorella wrote theHarvester, and it now has 17.3k GitHub stars. The README says it gathers open source intelligence about a domain from search engines, certificate transparency logs, DNS datasets, code repositories and threat intelligence platforms, and lists more than 50 passive sources.

Key features

  • Passive modules for crt.sh, Censys, Shodan, VirusTotal, Hunter, IntelX, urlscan and the Wayback archive.
  • Optional active steps, DNS brute force and screenshots, run only when selected.
  • Local harvestview web app and API on 127.0.0.1:5000.
  • Version 4.11.0 on 23 May 2026 added Mojeek and Shodan InternetDB sources.

Pricing

Free and open source. The cost sits in the sources, since Censys, Hunter, IntelX, Shodan and others need their own API keys stored in api-keys.yaml.

Pros

  • $0 to install and run, with no vetting step.
  • Four releases between January and June 2026.
  • Runs from one command against one domain.

Cons

  • Requires Python 3.14.
  • Modules without API keys run without warning and return nothing.
  • No hosted API, so scheduling and scale are your job.

The silent-failure problem came up in a June 2021 Hacker News thread: "some of the sources require you to provide API credentials, but run without warning (and without results) if you don't." Another user in the thread had "used TH on many engagements as a starting point for osint."

Why it’s ranked #5. theHarvester scores 6, a point behind HIBP's documented 10 to 24,000 RPM API. It beats Shodan on maintenance, with release 4.11.1 on 3 June 2026 against Shodan's last dated product post on 7 August 2024.

06

Shodan

Back to top ↑

Best fit

An analyst who needs open ports, banners and exposed devices for a list of IP addresses, cheaply.

Shodan is a search engine for internet-connected devices, collecting data since 2009. It crawls the entire internet at least once a week, and main search covers the past 30 days, with Trends data back to 2017.

Security teams use it to identify vulnerabilities before threat actors do, and to spot security threats on hosts nobody patched. The vuln filter lists hosts running unpatched software by CVE, but only from the Small Business plan up.

Key features

  • Shodan Monitor alerts to email, Slack, Microsoft Teams, Discord, Telegram, PagerDuty and webhooks.
  • Free InternetDB API returning open ports for any IP.
  • On-demand scans at 1 scan credit per IP.
  • Free CVEDB API and browser plugins for Chrome and Firefox.

Pricing

The billing page lists Membership at $49 one-time with 100 query credits a month, Freelancer at $69 a month, Small Business at $359 and Corporate at $1,099. Every API plan runs at 1 request per second.

Pros

  • $49 buys a lifetime account upgrade.
  • API plans priced by usage, with one key shareable across a whole organization.
  • Rate limit and credits published per plan.

Cons

  • The vuln and tag filters need $359 and $1,099 a month.
  • 1 request per second applies even on Corporate.
  • No product post on the Shodan blog since 7 August 2024.

A CTO reviewing it on G2 in April 2026 summed up the entry plans in one line: "limited results with my subscription, search engine tags were difficult to use."

"We specifically use Shodan to track and find network-related information, basically the open ports data related to our client-related assets. Thus ensuring a better security strategy."

Hemanth K., cyber security analyst, enterprise, G2, January 2025

Why it’s ranked #6. Shodan scores 5 and trails theHarvester by one point on maintenance. It wins the three-way tie at 5 on criterion four, publishing a 1-request-per-second limit where OSINT Industries publishes only a 25 to 80 second timeout.

07

OSINT Industries

Back to top ↑

Best fit

A fraud or trust-and-safety analyst who starts from an email address, phone number or username.

OSINT Industries Ltd is a London company, incorporated on 3 July 2023. One search takes an email, phone number, username, name or crypto wallet and runs it across every source module at once.

Read between the lines of its source count, because the number depends on the page. The homepage claims 1,500+ sources worldwide, while the getting-started docs say over 300.

Key features

  • Five selector types, including ETH, BTC and TRC wallets.
  • Premium modules such as Snapchat and TikTok at 3 extra credits.
  • Palette add-ons for Pipl and other data at 3 credits each.
  • Exports to PDF, DOC, Excel and JSON.

Pricing

Basic costs £19 a month for 30 credits, Intermediate £49 for 100 credits with API access, and Advanced £99 for 300. One search costs one credit. Law enforcement, government, journalists and non-profits can apply for free access.

Pros

  • Monthly billing from £19, with extra credits sold up to 30,000.
  • API access from the £49 plan.
  • Premium API modules added on 2 February 2026.

Cons

  • Source counts of 1,500+ and 300 on two of its own pages.
  • The pricing FAQ says credits don't expire monthly, while terms section 9.4 says unused credits don't roll over.
  • Username searches moved from free beta to paid credits in February 2025.

Feedback on the vendor's January 2025 LinkedIn post split two ways. Danny De Hek wrote, "Absolutely love the software guys it's helping me do a lot of investigations thank you." William J. Jones reported that "the button to sign in once you've been granted early access, is not working."

Why it’s ranked #7. OSINT Industries ties Shodan and SpiderFoot at 5 and loses to Shodan's published 1-per-second API limit. It beats SpiderFoot on the same criterion, selling API access from £49 a month where open-source SpiderFoot runs only as local software.

08

SpiderFoot

Back to top ↑

Best fit

A technical user who wants a free, self-hosted scanner and can maintain Python code.

Steve Micallef released SpiderFoot as open source under the MIT license, and the repository carries 22.4k stars. It integrates data from over 200 modules and runs a correlation engine with 37 predefined rules across the results.

Intel 471 acquired SpiderFoot on 2 November 2022 to fold it into its TITAN platform. The last release, v4.0, shipped on 7 April 2022, and spiderfoot.net now redirects to intel471.com.

Key features

  • Web UI and command line, with CSV, JSON and GEXF exports.
  • Tor integration for dark web searches.
  • Calls Nmap, DNSTwist and WhatWeb as external tools.
  • YAML-configurable correlation rules, on any operating system with Python 3.7 or later.

Pricing

The open-source edition is free. The hosted SpiderFoot HX tiers, once €19 to €599 a month, now return a 404 page.

Pros

  • $0 and self-hosted, so target data stays on your own machine.
  • 200+ modules in one scan.
  • Covers infrastructure & the dark web.

Cons

  • No release in 53 months and no commit since November 2023.
  • Many modules need paid API keys from other vendors.
  • No hosted API since the HX product page went dark.

"Looking at the repo and some of the open issues, there have been little development activity over the last year and SpiderFoot is currently not in working condition."

redoubt, Hacker News, July 2024

A reply disagreed: "I use it frequently and it just works."

Why it’s ranked #8. SpiderFoot scores 5 and loses the tie to OSINT Industries, scoring 0 on the API criterion to its 1. It beats Recorded Future by one point on cost, $0 against a $70,375 Vendr median with no free tier.

09

Recorded Future

Back to top ↑

Best fit

A security operations team with a six-figure budget that wants threat intelligence scored and pushed into its SIEM.

Christopher Ahlberg & Staffan Truvé founded Recorded Future in Boston in 2009. Mastercard completed the $2.65 billion acquisition on 20 December 2024.

Its Intelligence Graph indexes data from over a million sources, including the open web, dark web, technical feeds and customer telemetry. The April 2026 packages post puts the figure at 1.2 million sources and 26 billion entities.

Key features

  • Four solutions: Cyber Operations, Digital Risk Protection, Third-Party Risk and Payment Fraud.
  • Recorded Future AI, launched April 2023.
  • Autonomous Threat Operations, generally available by March 2026.
  • Impact and Metrics Dashboard for every customer from 11 June 2026.

Pricing

The vendor doesn't publish prices and sells Core, Professional and Elite packages sized by workforce credentials. Vendr's anonymised buyer data shows a $70,375 median a year across 47 purchases, ranging from $27,000 to $216,385.

Pros

  • The largest source index on this list, at 1.2 million sources.
  • Risk scores based on current threat activity, built with machine learning over the Intelligence Graph.
  • Unlimited users and integrations in every package.

Cons

  • No free tier and no public price.
  • API capacity comes as defined usage per package, with no published number.
  • G2's review summary counts 18 mentions of a learning curve & 21 of expense.

"The first thing is the price. It's an elite tool and it shows on the bill; for the average user, it's unthinkable and for companies, it's a heavy investment that you have to justify very well."

Daniel A., infrastructure and systems support engineer, enterprise, G2, May 2026

"Unlike the industry standard CVSS, which tends to mark everything as critical, Recorded Future provides me with a score based on what is happening in real time, which is invaluable for deciding what to patch first in Fujitsu's infrastructure."

The same reviewer, same review

Why it’s ranked #9. Recorded Future scores 4, one point behind SpiderFoot, losing on price and free access. It beats Social Links by two points because Vendr publishes a $70,375 median from 47 purchases, while Social Links quotes every deal privately.

What open source intelligence (OSINT) tools do across the intelligence cycle

The US intelligence community describes six stages: planning, collection, processing, analysis, dissemination and evaluation. OSINT tools mostly automate the second and third, so analysts spend their hours on analysis. Before these tools, gathering information from each source by hand took days of intelligence gathering. Tools that collect data automatically return the same results as a queue to review.

  • Planning: define intelligence requirements, the questions the collection has to answer.
  • Collection: gather intelligence from search engines, records and feeds, the OSINT collection stage.
  • Processing: clean, normalize and deduplicate raw data.
  • Analysis: link entities, analyze data, draw conclusions and rate confidence, the step the market intelligence analysis guide breaks down for commercial research.
  • Dissemination: hand actionable intelligence and actionable insights to whoever makes informed decisions.

Free tools cut corners at the processing stage. theHarvester and SpiderFoot return every hit from every module, and deduplicating a long subdomain list by hand turns into a wild goose chase that Maltego handles by merging duplicate entities in the graph. Teams that need to analyze data at volume after collection pair OSINT tools with data mining tools.

Collection itself comes in two forms. SANS instructor Ritu Gill defines passive collection as not engaging with a target, while active collection means "engaging with a target in some fashion," such as adding a profile as a friend. Scraping public web pages and reading Shodan's existing crawl are passive. theHarvester's DNS brute force and Shodan's on-demand scans send traffic to the target.

Where OSINT data comes from

OSINT data is scattered across sources that share no format, and gathering information from all of them by hand is slow. A single investigation into one company can touch public records, court documents, business filings, news articles, social media accounts, certificate logs and breach dumps. The market intelligence data guide sorts the commercial equivalents by type.

  • Search engines: Google, Bing and Mojeek, queried with advanced search operators.
  • Public records: court documents, business filings and property registries.
  • News & media: news articles and broadcast transcripts, tracked with media monitoring tools.
  • Social media platforms: profiles, posts and connections, the field social listening tools cover for brands.
  • Internet infrastructure: IP addresses, domains, certificates and open ports.
  • Breach & leak data: credential dumps, stealer logs and paste sites.
  • Deep web and dark web: deep web databases search engines don't index, plus Tor and I2P sites and dark web forums.
Quick tip

Google dorking means stacking advanced search operators such as site: and filetype: to find exposed data a normal query buries. Google documents the operators in its Search Central guide, and they turn a needle in a haystack, one misconfigured spreadsheet among millions of results, into a single query.

Web scraping and social media analytics fill the rest, since scraping data from social media channels and public web pages is how most automated tools extract data at scale. For bulk extraction from sites without an API, the web scraping tools ranking covers the collection layer. Company data such as funding rounds and business filings sits in databases like Crunchbase, and a site's technology stack shows up in BuiltWith lookups.

Reusing data somebody else already published is secondary research, and the secondary market intelligence guide covers how to source and cite it. The Internet Archive's Wayback Machine passed 1 trillion preserved web pages on 22 October 2025, and it's the first stop when a target deletes a page.

The OSINT Framework and other free directories

The OSINT Framework is a clickable tree of free OSINT resources, built by Justin Nordine from an information security point of view. Its GitHub repository has 12.1k stars. Each link carries a code: T for a local install, D for a Google dork, R for requires registration and M for a manual URL edit.

The OSINT Framework is a directory, with its tools grouped by the selector you start from. Bellingcat's Online Investigation Toolkit takes the same directory approach across 12 categories, from maps and satellites to transport and archiving. Both are good maps for OSINT research and both are directories of untested links, so the ranking above scores ten of those tools on price and limits.

Free OSINT tools and what they can't do

Eight of the ten tools offer something free, and the free versions share three limits: capped results, short or missing history, and API keys for someone else's data. Recorded Future & Social Links sell through demos only.

  • Maltego Basic: 200 credits a month, 24 results per transform.
  • Censys Free: 100 credits a month, one page of 100 results, no history.
  • Intelligence X Free: 50 searches a day, 2 when logged out.
  • Have I Been Pwned: free email search and Pwned Passwords, domains capped at 10 breached addresses.
  • Shodan: a free account with a free API plan.
  • theHarvester and SpiderFoot: free software, paid source keys.
Dot plot of the most recent dated release for each OSINT tool, from SpiderFoot's v4.0 in April 2022 and Shodan's last blog post in August 2024 to Intelligence X and Maltego in September 2026
Seven of the ten shipped a dated release or product change in the 12 months to 24 September 2026. SpiderFoot's last release is from April 2022.
Important

Free tools also age. SpiderFoot's last release is 53 months old, and a scanner calling dead endpoints returns empty results that look like a clean target. That's a red flag worth checking before trusting any open-source tool, since an OSINT finding is only as good as the module that produced it.

OSINT tool pricing, from $0 to $70,375

The scenario for comparison is one analyst's first paid year. Under it, prices run from $0 for theHarvester to a $70,375 Vendr median for Recorded Future, and the published tiers cluster in three bands.

  • Under $300: Shodan $49 once, HIBP $52.68, Censys $100 in credits, OSINT Industries £228.
  • €2,500 to €3,000: Intelligence X Researcher and Maltego Entry.
  • Five figures and up: Recorded Future, and Social Links on quote.

The devil's in the details of what each unit buys. A Shodan query credit downloads 100 results, a Censys standard query costs 5 credits, an OSINT Industries search costs 1 credit plus 3 for premium modules, and Maltego counts transform runs. Budgeting across tools means converting all of them to lookups per month. Buying Recorded Future for one analyst's lookups would cost an arm and a leg next to a $49 Shodan membership.

Three costs sit outside the list price. Source API keys for theHarvester and SpiderFoot are paid separately. Maltego's Entry plan requires vetting. Social Links' Maltego package needs a Maltego license on top, so a buyer pays twice to run one workflow.

How security teams use OSINT

Security teams and security professionals run OSINT against their own organization first, because threat actors run it too. Cybercriminals use the same public data to craft targeted phishing and attack campaigns: employee names from LinkedIn, email formats from theHarvester, and reused passwords from breach dumps.

  • Map the external attack surface and identify vulnerabilities in exposed hosts with Censys or Shodan, the public data threat actors scan first.
  • Find unpatched software by CVE with Shodan's vuln filter.
  • Locate data leaks and breached staff credentials with HIBP domain search.
  • Check what sensitive information employees publish on social media.
  • Monitor dark web forums and the deep web for company names and executive mentions.

Analyst coverage limits dark web monitoring, since each OSINT finding still needs a person to read it. A human can read only so many Tor forums, which is why Recorded Future and Intelligence X index them at scale and sell search over the archive. Security teams can score the resulting security risks & their owners in a risk assessment matrix.

OSINT also has business uses outside security. Market research, competitive intelligence and monitoring public opinion all draw on the same public sources, which the four types of market intelligence split by question, and the competitive intelligence tools ranking covers software built for that job.

How to run an OSINT tool trial

Quick tip

A trial on 20 known targets beats a demo for judging OSINT tools. Pick targets where you already know the answer, run them through the free tier, and count what comes back.

  1. Define the intelligence requirements: the three to five questions the tool must answer.
  2. Pick 20 targets with known answers, such as your own domains and staff emails.
  3. Run each target through the free allowance and log hits, misses and false positives.
  4. Cross-verify every hit against a second independent source.
  5. Price the volume you'll need per month in the vendor's own unit.

Raw OSINT data is unverified. Bitsight's framework guide lists misattributed IP addresses, false positives and outdated records as causes of wrong conclusions, and names information overload as the first challenge. Step four exists for that reason, and OSINT findings that fail it stay out of the report. The data source attribution guide covers how to record where each finding came from.

Limit data collection to relevant information the requirements need. Collecting everything on a person because the tool allows it creates a storage and privacy liability outside the requirements. The guide to gathering market intelligence applies the same requirements-first method to commercial research.

Is OSINT legal? Privacy and ethical considerations

OSINT starts from publicly accessible information anyone can reach, and the legal duties attach to what you do with personal data afterward.

Important

Under GDPR Article 14, a controller that collects personal data from publicly accessible sources must tell the person where the data came from, within one month at the latest, unless notice would involve disproportionate effort.

Ethical considerations run past the statute, and every stored profile is a compliance risk. Respecting privacy means minimising what you store, securing it, and deleting it when the case closes. Tools with stealer-log data, credit card and Social Security number selectors, like Intelligence X, hold sensitive data that most corporate use cases can skip.

A short history of open source intelligence

Open source intelligence predates the Cold War, and the intelligence community ran it long before the term OSINT existed. The CIA dates the Foreign Broadcast Monitoring Service to February 1941, created to monitor foreign print and radio, and it became the Foreign Broadcast Information Service inside the new CIA by 1946.

The Director of National Intelligence set up the Open Source Center in 2005 as FBIS's successor. On 8 March 2024, ODNI and the CIA released the IC OSINT Strategy for 2024-2026, which defines OSINT as intelligence derived exclusively from publicly or commercially available information. OSINT sits beside human intelligence and signals intelligence as one collection discipline.

National security agencies now buy the same commercial data the private sector does, and the public sector market intelligence guide covers how government buyers source it.

By the numbers
$2.65B

Mastercard's price for Recorded Future, closed 20 December 2024. Intel 471 bought SpiderFoot in 2022, and Maltego raised over $100 million in April 2023 before buying Hunchly in May 2025.

Open source intelligence tools FAQ

Is OSINT just googling?

Google is one OSINT tool, and dorking search engines with advanced search operators is a real technique. OSINT tools add sources Google doesn't index, such as certificate logs, breach dumps and Tor sites, and keep the results linked for analysis.

Is there a free OSINT tool?

theHarvester and SpiderFoot are free open-source software, and Maltego, Censys, Intelligence X, Shodan and HIBP all have free tiers. theHarvester is the best free pick on this list because its last release came in June 2026.

Which AI is best for OSINT?

Artificial intelligence features now ship inside open source intelligence tools. Maltego One added an AI Assistant in October 2025, and Recorded Future AI has run since April 2023. Machine learning and artificial intelligence help rank results for intelligence gathering at volume, and a human still verifies each finding before its actionable insights go into a report.

Does the CIA use OSINT?

Yes, open source intelligence (OSINT) is a formal CIA discipline. The CIA's Directorate of Digital Innovation traces its open-source mission to the 1941 monitoring service, and the CIA co-released the 2024-2026 IC OSINT Strategy with ODNI.

Are OSINT skills worth learning?

OSINT skills transfer across security, journalism, fraud and academic research, because analyzing publicly available data follows the same method in each. Free tiers from Maltego, Censys and Intelligence X let a beginner practise on real data at $0.

What are the main OSINT techniques?

The common OSINT techniques are search-engine dorking, breach lookups, certificate and DNS enumeration, social media account discovery and archive searches. Passive collection reads what's already published, and active collection touches the target.

What is the OSINT Framework?

The OSINT Framework is a free directory of OSINT resources grouped by what you're searching for, such as usernames, email addresses or domain names. It links out to each tool, and the search runs on that tool's own site.

Bottom line

Maltego is the best open source intelligence (OSINT) tool for most investigators in 2026. It covers all five source families, publishes its prices and shipped a release on 17 September 2026. Budget €3,000 for Entry once the 200 free credits run out.

Pick Intelligence X for leaks and darknet archives, Censys for internet-facing assets, and Have I Been Pwned for breach exposure on your own domains at $52.68 a year. theHarvester is the free starting point for domain recon.

Recorded Future fits security leaders whose operations team can justify a $70,375 median contract. Most teams shouldn't put all their eggs in one basket or leave the security risks of a single source unchecked, and Maltego Entry plus a $100 Censys credit pack adds 16-hour infrastructure data to the graph for one analyst.