OSINT tools for reconnaissance

Every external penetration test, red team and phishing simulation starts with reconnaissance: finding out what an attacker could learn about the target without touching it. That means the staff behind the email addresses, the accounts they reuse across sites, the domains and infrastructure in the company's name, and what has already leaked.

OSINT tools do that collection. Some check a username or email address against hundreds of sites, some search breach data and darknet sources, and some pull many sources into one graph. Testers use them to scope social engineering, to find exposed credentials and forgotten assets, and to show a client what its public footprint gives away.

8 tools

Maigret

Open source
Maigret (open source) · MIT

Open-source tool that builds a profile from a username across thousands of sites, with HTML and PDF reports.

Does: Username search, Recursive search, Profile data extraction, HTML and PDF reports
Reads: Usernames

Sherlock

Open source
Sherlock Project (open source) · MIT

Open-source command-line tool that checks a username across 400+ social networks.

Does: Username search, Batch username checks, CSV and XLSX export
Reads: Usernames

SpiderFoot

Open source
SpiderFoot (open source) · MIT

Open-source OSINT automation with 200+ modules for threat intelligence and attack surface mapping.

Does: Automated OSINT collection, Attack surface mapping, Correlation rules, Tor search
Reads: Domains, IP addresses, Email addresses, Names

WhatsMyName

Open source
WhatsMyName (community project) · CC-BY-SA-4.0

Community-maintained list of 700+ sites for username checks, with a free browser tool.

Does: Username search, Open dataset
Reads: Usernames

Intelligence X

Commercial
Intelligence X · Commercial

Search engine for leaks, pastes, stealer logs, darknet and WHOIS data, queried by email, domain, IP and other selectors.

Does: Leak search, Stealer-log search, Darknet search, WHOIS search, API
Reads: Email addresses, Domains, IP addresses, CIDR ranges

Maltego

Commercial
Maltego Technologies · Commercial

OSINT and link analysis platform that maps people, organisations and infrastructure on an investigation graph.

Does: Link analysis, Entity graphing, Third-party data integrations, Evidence capture
Reads: People, Organisations, Email addresses, Domains, IP addresses
OSINT Industries · Commercial

Real-time lookups by email, phone number, username, name or crypto wallet, compiled into a profile of linked accounts.

Does: Email lookup, Phone lookup, Username search, Crypto wallet search, API
Reads: Email addresses, Phone numbers, Usernames, Names, Crypto wallets

Missing one? Suggest a tool

Questions

Is OSINT part of a penetration test?

Often. External tests, red teams and phishing simulations usually include a reconnaissance phase that maps the target's staff, accounts, domains and exposed data before any active testing. Whether it is in scope, and how far it goes into individual employees, should be agreed in the rules of engagement.

Does a username match prove an account belongs to the target?

No. The same username on two sites does not prove it is the same person. Treat matches as leads and confirm them with names, photos and links before they go in a report.

Which OSINT tools are free?

Sherlock, Maigret and SpiderFoot are open source under the MIT licence. The WhatsMyName dataset is free under CC BY-SA 4.0, with a free web tool on top. Maltego has a free Basic plan and Intelligence X a free tier. Opsis and OSINT Industries are paid services.