mirror of
https://github.com/lockfale/OSINT-Framework.git
synced 2026-08-17 19:35:41 +02:00
Merges two related top-level categories into a unified "Security Intelligence" category with 9 clear subcategories: Advisories, Attack Surface / Security Testing, Default Passwords, Exploits, IOC Tools, Phishing, Terrorism & Extremism, Threat Feeds & Platforms, and TTPs. All 62 URL entries preserved. No tools added or removed. Co-Authored-By: Paperclip <noreply@paperclip.ing>
21183 lines
959 KiB
JSON
21183 lines
959 KiB
JSON
{
|
|
"name": "OSINT Framework",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Username",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Username Search Engines",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "WhatsMyName Web",
|
|
"type": "url",
|
|
"url": "https://whatsmyname.app/",
|
|
"description": "Free web-based OSINT username enumeration tool that searches for a specified username across 1500+ websites and platforms simultaneously, returning direct links to matching profiles.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick web-based username enumeration across social media, forums, gaming platforms, and professional networks",
|
|
"input": "Username",
|
|
"output": "List of sites where the username exists with direct profile links",
|
|
"opsec": "active",
|
|
"opsecNote": "Makes HTTP requests to each target site to check for username existence, however it does it from WhatsMyName infrastructure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "WhatsMyName (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/WebBreacher/WhatsMyName",
|
|
"description": "OSINT project maintaining a curated JSON database of website detection patterns for username enumeration. Web interface available at whatsmyname.app.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Username enumeration using community-maintained site detection data",
|
|
"input": "Username",
|
|
"output": "List of sites where the username exists, based on HTTP response pattern matching",
|
|
"opsec": "active",
|
|
"opsecNote": "Makes HTTP requests to each target site to check for username existence.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Sylva Identity Discovery (T)",
|
|
"type": "url",
|
|
"url": "https://sylva.pfeister.dev/",
|
|
"description": "Open-source CLI tool for username and identity discovery with branch discovery to expand searches as additional linked identities are uncovered.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Username enumeration with identity branching",
|
|
"input": "Username",
|
|
"output": "Linked accounts and identities across platforms",
|
|
"opsec": "active",
|
|
"opsecNote": "Makes requests to target platforms to check username existence; external API keys may be used.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Sherlock (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/sherlock-project/sherlock",
|
|
"description": "Python CLI tool that hunts down social media accounts by username across 400+ social networks. Supports Tor routing, proxy configuration, and CSV/XLSX export.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Mass username enumeration across 400+ sites",
|
|
"input": "Username(s)",
|
|
"output": "List of discovered profile URLs across social networks",
|
|
"opsec": "active",
|
|
"opsecNote": "Directly queries each target site to check username existence; supports Tor/proxy for anonymity.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Namechk",
|
|
"type": "url",
|
|
"url": "https://namechk.com/",
|
|
"description": "Web-based username and domain availability checker that searches 100+ social media platforms and 36 domain extensions simultaneously.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick username availability check across social media and domains",
|
|
"input": "Username or domain name",
|
|
"output": "Availability status across 100+ platforms and domain extensions",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are routed through Namechk's servers; target accounts are not directly contacted by the user.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Thats Them",
|
|
"type": "url",
|
|
"url": "https://thatsthem.com/",
|
|
"description": "Free people search engine aggregating data from 50+ sources. Supports lookups by name, address, phone number, or email.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "People search by name, email, phone, or address",
|
|
"input": "Name, email address, phone number, or physical address",
|
|
"output": "Contact info, residential details, demographics, and financial estimates",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are routed through ThatsThem's servers; the target is not alerted.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "NameCheckup",
|
|
"type": "url",
|
|
"url": "https://namecheckup.com/",
|
|
"description": "Free web-based username and domain availability checker that searches across 20+ social media platforms and 40+ domain extensions with WHOIS lookup support.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Username and domain availability checking with WHOIS info",
|
|
"input": "Username or domain name",
|
|
"output": "Availability status across social platforms and domain extensions, with WHOIS data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are proxied through NameCheckup's servers; no direct contact with target platforms by the user.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "GitFive (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/mxrch/GitFive",
|
|
"description": "OSINT CLI tool for investigating GitHub profiles. Tracks username/name history, maps emails to accounts, extracts SSH public keys, and exports findings as JSON.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Deep investigation of GitHub user profiles and email-to-account mapping",
|
|
"input": "GitHub username or email address",
|
|
"output": "Profile history, linked emails, SSH keys, repository analysis, JSON export",
|
|
"opsec": "active",
|
|
"opsecNote": "Queries GitHub API directly; developer recommends using a secondary GitHub account.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Sherlock",
|
|
"type": "url",
|
|
"url": "https://github.com/sherlock-project/sherlock",
|
|
"description": "Python CLI tool that hunts down social media accounts by username across 400+ social networks. Supports Tor routing, proxy configuration, and CSV/XLSX export.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Mass username enumeration across 400+ sites",
|
|
"input": "Username(s)",
|
|
"output": "List of discovered profile URLs across social networks",
|
|
"opsec": "active",
|
|
"opsecNote": "Directly queries each target site to check username existence; supports Tor/proxy for anonymity.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Names Directory",
|
|
"type": "url",
|
|
"url": "https://namesdir.com/",
|
|
"description": "Searchable database of 1B+ name combinations collected from public sources. Allows bidirectional lookup to find first names by surname or surnames by first name.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding name combinations and frequency data for a given first or last name",
|
|
"input": "First name or surname",
|
|
"output": "Associated name combinations with frequency counts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries a static public database; no contact with any target individual.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Lullar",
|
|
"type": "url",
|
|
"url": "https://com.lullar.com",
|
|
"description": "Free people search and username lookup tool that searches across 148+ social media platforms including Instagram, TikTok, Facebook, and LinkedIn.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Social media profile discovery by username, email, or name",
|
|
"input": "Email address, full name, or username",
|
|
"output": "Social media profiles found across 148+ platforms",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are routed through Lullar's servers; no direct queries from the user to target platforms.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Specific Sites",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Amazon Usernames (M)",
|
|
"type": "url",
|
|
"url": "https://www.google.com/search?q=site:amazon.com+%3Cusername%3E",
|
|
"description": "Google dork that searches Amazon.com for pages associated with a specific username, surfacing public profiles, wishlists, and reviews.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding Amazon public profiles, wishlists, and review activity by username",
|
|
"input": "Username (inserted into Google search query)",
|
|
"output": "Google search results linking to Amazon pages mentioning the username",
|
|
"opsec": "passive",
|
|
"opsecNote": "Query goes to Google, not Amazon directly. Google may log the search but the target is not alerted.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Github User (M)",
|
|
"type": "url",
|
|
"url": "https://api.github.com/users/%3Cusername%3E/events/public",
|
|
"description": "Queries the GitHub public Events API to retrieve a user's recent public activity, including pushes, pull requests, issues, and other repository events.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Enumerating a GitHub user's recent public activity and repository interactions",
|
|
"input": "GitHub username (inserted into URL path)",
|
|
"output": "JSON array of public events (pushes, PRs, issues, comments) with timestamps and repo details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Unauthenticated API call; GitHub rate-limits by IP (60 req/hr) but does not notify the target user.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Tinder Usernames (M)",
|
|
"type": "url",
|
|
"url": "https://www.gotinder.com/@%3Cusername%3E",
|
|
"description": "Accesses a Tinder user's public web profile via their username. The gotinder.com domain redirects to tinder.com.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Confirming existence of a Tinder profile and viewing public profile details",
|
|
"input": "Tinder username (appended to URL after @)",
|
|
"output": "Public profile page with name, photo, and basic info if the user has web sharing enabled",
|
|
"opsec": "passive",
|
|
"opsecNote": "Simple HTTP GET to a public page; target is not notified of profile views via the web URL.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Keybase",
|
|
"type": "url",
|
|
"url": "https://keybase.io/",
|
|
"description": "Platform for cryptographic identity verification, linking social media accounts, PGP keys, and cryptocurrency addresses to a single profile. Acquired by Zoom in 2020 but still operational.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Looking up verified social accounts, PGP keys, and crypto wallets tied to a username",
|
|
"input": "Username",
|
|
"output": "User profile showing verified identities across platforms, PGP keys, cryptocurrency addresses, and devices",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public profile lookups are passive web requests. No login required to view profiles.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MIT PGP Key Server",
|
|
"type": "url",
|
|
"url": "https://pgp.mit.edu/",
|
|
"description": "MIT PGP Public Key Server for searching, submitting, and removing PGP public keys. Look up keys by name, email, or key ID to find associated cryptographic identities.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Looking up PGP public keys associated with a username or email address",
|
|
"input": "Name, email address, or key ID",
|
|
"output": "PGP public key data, key fingerprints, associated UIDs/email addresses, and key metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public key server query; no authentication required and target is not notified of lookups.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ProtonMail users (M)",
|
|
"type": "url",
|
|
"url": "https://api.protonmail.ch/pks/lookup?op=index&search=<username>@protonmail.com",
|
|
"description": "Queries ProtonMail's HKP-compatible PGP key server to look up the public key for a ProtonMail username. A successful response confirms the account exists.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Confirming whether a ProtonMail username exists and retrieving its PGP public key",
|
|
"input": "ProtonMail username (appended with @protonmail.com)",
|
|
"output": "PGP key index with public key fingerprint, algorithm, creation timestamp, and email UID",
|
|
"opsec": "passive",
|
|
"opsecNote": "Unauthenticated API query to ProtonMail's public key server. Target user is not notified. Enables user enumeration.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ProtonMail Domains (M)",
|
|
"type": "url",
|
|
"url": "https://api.protonmail.ch/pks/lookup?op=index&search=<email_address>",
|
|
"description": "Queries ProtonMail's HKP key server with a full email address to check for a PGP public key. Useful for identifying ProtonMail users on custom domains.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Checking if an email address on a custom domain is hosted on ProtonMail",
|
|
"input": "Full email address (any domain that may be hosted on ProtonMail)",
|
|
"output": "PGP key index with public key fingerprint, algorithm, creation timestamp, and email UID",
|
|
"opsec": "passive",
|
|
"opsecNote": "Unauthenticated public HKP endpoint. Target is not notified. Can reveal whether a custom domain uses ProtonMail.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Email Address",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Email Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Sylva Identity Discovery (T)",
|
|
"type": "url",
|
|
"url": "https://sylva.pfeister.dev/",
|
|
"description": "Identity discovery utility that searches GitHub and PGP key servers to link identities across platforms using email addresses, usernames, or PGP keys.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Identity correlation via GitHub and PGP",
|
|
"input": "Email, username, or PGP fingerprint",
|
|
"output": "Linked identities, GitHub profiles, PGP keys",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public GitHub and PGP servers without direct target contact.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ThatsThem",
|
|
"type": "url",
|
|
"url": "https://thatsthem.com/reverse-email-lookup",
|
|
"description": "Reverse email lookup tool that searches a database of hundreds of millions of emails to reveal name, address, phone number, and public records associated with an email address.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Reverse email lookup, person identification",
|
|
"input": "Email address",
|
|
"output": "Name, address, phone number, education",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries ThatsThem's public database without alerting the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Hunter",
|
|
"type": "url",
|
|
"url": "https://hunter.io/",
|
|
"description": "Email finder and verifier that discovers business email addresses from company domains, names, and social profiles with up to 98% accuracy rate.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Business email discovery, email verification",
|
|
"input": "Domain name, person name, or company info",
|
|
"output": "Verified business email addresses",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries Hunter's database of public emails; does not contact targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Email to Address (R)",
|
|
"type": "url",
|
|
"url": "https://www.melissa.com/",
|
|
"description": "Melissa.com's data quality and verification service that validates and enriches email addresses with supplementary contact information.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Email validation, address enrichment",
|
|
"input": "Email addresses, contact data",
|
|
"output": "Validated email, postal address, phone",
|
|
"opsec": "passive",
|
|
"opsecNote": "Data verification service; does not perform reconnaissance.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "VoilaNorbert",
|
|
"type": "url",
|
|
"url": "https://www.voilanorbert.com/",
|
|
"description": "Email finder and verifier with 98% success rate that discovers business emails by company/domain, person name, or LinkedIn profile with bulk upload capability.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Business email discovery, bulk email finding",
|
|
"input": "Domain, name, or LinkedIn URL",
|
|
"output": "Business email addresses, verification status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches public email database; does not contact targets directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "GHunt (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/mxrch/GHunt",
|
|
"description": "Offensive Google framework that investigates Google accounts using email addresses to uncover YouTube channels, Google Photos, Maps reviews, and associated artifacts.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Google account investigation, YouTube/Google Photos OSINT",
|
|
"input": "Gmail address or GAIA ID",
|
|
"output": "YouTube channels, Google Photos, Maps reviews, device info",
|
|
"opsec": "active",
|
|
"opsecNote": "Requires Google login via browser extension; may be detected by Google.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OSINT Industries",
|
|
"type": "url",
|
|
"url": "https://www.osint.industries/",
|
|
"description": "Account linking service that extracts all registered accounts tied to an email or phone across 500+ platforms including social media, messaging apps, and lifestyle services.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Account enumeration, breach detection, digital footprint mapping",
|
|
"input": "Email address, phone number, username, or crypto wallet",
|
|
"output": "Linked accounts, breach information, geospatial data, timeline",
|
|
"opsec": "passive",
|
|
"opsecNote": "Scours public websites and databases without contacting the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "theHarvester (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/laramies/theHarvester",
|
|
"description": "Command-line tool for gathering emails, subdomains, IPs, and URLs from public sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Email harvesting, subdomain enumeration, passive recon",
|
|
"input": "Domain name",
|
|
"output": "Email addresses, subdomains, IPs, URLs",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries third-party search engines and APIs. Does not contact the target directly.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Infoga (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/m4ll0k/infoga",
|
|
"description": "Python-based email OSINT tool that gathers email account information (IP, hostname, country) from search engines, PGP servers, and Shodan, with breach checking via haveibeenpwned.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Early-stage email reconnaissance, information gathering",
|
|
"input": "Email address",
|
|
"output": "IP addresses, hostnames, country, breach status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries search engines and public APIs without direct target contact.",
|
|
"localInstall": true,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Skymem",
|
|
"type": "url",
|
|
"url": "https://www.skymem.info/",
|
|
"description": "Email finder that discovers company and personal email addresses by domain or name, with bulk search, email list creation, and advanced filtering capabilities.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Email discovery by domain, bulk email list creation",
|
|
"input": "Domain name or person name + domain",
|
|
"output": "Email addresses, bulk email lists",
|
|
"opsec": "passive",
|
|
"opsecNote": "Scrapes and aggregates public email data from websites and profiles.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Epieos Email Tool",
|
|
"type": "url",
|
|
"url": "https://tools.epieos.com/email.php",
|
|
"description": "Freemium OSINT tool performing email reverse lookups to uncover associated social media profiles across 120+ websites and services with breach detection.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Email reverse lookup, social media profile discovery",
|
|
"input": "Email address or phone number",
|
|
"output": "Associated social media profiles, forum posts, breach info",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive reconnaissance across 120+ websites; does not alert the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "breach.vip",
|
|
"type": "url",
|
|
"url": "https://breach.vip/",
|
|
"description": "Free database search engine providing access to 1000+ breach databases for research, email searching, and analysis of compromised credentials.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Breach database search, credential lookup",
|
|
"input": "Email, domain, Discord ID, or phone number",
|
|
"output": "Breach records, leaked credentials",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries aggregated public breach databases.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Holehe (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/megadose/holehe",
|
|
"description": "Python-based email enumeration tool that checks if an email is registered across 120+ websites and services using password-reset mechanisms.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Email account enumeration, service detection",
|
|
"input": "Email address",
|
|
"output": "List of websites where email is registered",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses password-reset functionality without sending emails or alerting targets.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Common Email Formats",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Email Format",
|
|
"type": "url",
|
|
"url": "https://www.email-format.com/",
|
|
"description": "Tool for analyzing and discovering corporate email address patterns and formats to predict valid employee email addresses within an organization.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Corporate email pattern analysis, email format discovery",
|
|
"input": "Sample email addresses or company info",
|
|
"output": "Predicted email format patterns",
|
|
"opsec": "passive",
|
|
"opsecNote": "Statistical analysis of publicly known email patterns.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Email Permutator",
|
|
"type": "url",
|
|
"url": "https://metricsparrow.com/toolkit/email-permutator/",
|
|
"description": "OSINT tool that generates all possible email address combinations from a person's name and domain(s) for reconnaissance and email guessing.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Email pattern generation, targeted email guessing",
|
|
"input": "Person name, nickname, domain(s)",
|
|
"output": "List of possible email address variations",
|
|
"opsec": "passive",
|
|
"opsecNote": "Generates permutations without any network contact.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Email Verification",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Reacher Github (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/reacherhq/check-if-email-exists",
|
|
"description": "Open-source Rust-based email verification API that checks email deliverability without sending messages, detecting catch-all and disposable addresses.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Email verification, bounce detection, list cleaning",
|
|
"input": "Email address",
|
|
"output": "Deliverability status, MX records, bounce type",
|
|
"opsec": "passive",
|
|
"opsecNote": "Verifies email existence through MTA queries without sending mail.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Reacher Demo",
|
|
"type": "url",
|
|
"url": "https://reacher.email",
|
|
"description": "Hosted demo of the Reacher email verification API allowing free testing of email validation and deliverability checks online.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Email verification testing, demonstration",
|
|
"input": "Email address",
|
|
"output": "Deliverability status, bounce information",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive MTA-based verification without sending emails.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MailScrap",
|
|
"type": "url",
|
|
"url": "https://mailscrap.com/",
|
|
"description": "Email verification tool that connects to mail servers to verify mailbox existence and removes disposable email addresses from lists.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Email validation, list cleaning, disposable email detection",
|
|
"input": "Email addresses or email lists",
|
|
"output": "Validation status, mailbox existence",
|
|
"opsec": "passive",
|
|
"opsecNote": "Connects to mail servers for verification without sending messages.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Read Notify",
|
|
"type": "url",
|
|
"url": "https://www.readnotify.com/",
|
|
"description": "Email tracking and read receipt service that monitors email opens and engagement, useful for confirming email validity through delivery.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Email delivery confirmation, read receipt tracking",
|
|
"input": "Email address",
|
|
"output": "Delivery and read status",
|
|
"opsec": "active",
|
|
"opsecNote": "Sends tracking pixels; may alert targets to monitoring.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Email Reputation",
|
|
"type": "url",
|
|
"url": "https://emailrep.io/",
|
|
"description": "Tool that checks email reputation, risk scoring, and breach history to identify phishing emails, compromised accounts, and risky addresses.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Email reputation checking, risk assessment",
|
|
"input": "Email address",
|
|
"output": "Reputation score, risk level, breach history",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive database lookup without target contact.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MailboxValidator",
|
|
"type": "url",
|
|
"url": "https://www.mailboxvalidator.com/demo",
|
|
"description": "Email verification API that validates email deliverability, detects catch-all addresses, and provides risk scoring for bulk email list cleaning.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Email validation, list cleaning, bounce prevention",
|
|
"input": "Email addresses or bulk lists",
|
|
"output": "Validation status, risk score, catch-all detection",
|
|
"opsec": "passive",
|
|
"opsecNote": "Server-based verification without sending emails.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "VerifyEmail (R$)",
|
|
"type": "url",
|
|
"url": "https://emailable.com/"
|
|
},
|
|
{
|
|
"name": "Disposable Email Domains (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/disposable-email-domains/disposable-email-domains",
|
|
"description": "Community-maintained blocklist of 5,000+ disposable email domains with allowlist support and multi-language implementation examples. Used by PyPI and other projects.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Detecting disposable and temporary email addresses during verification",
|
|
"input": "Domain name to check against the blocklist",
|
|
"output": "Match result against the disposable email domain blocklist",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local list comparison; no external requests made during lookup.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Disposable Emails Registry",
|
|
"type": "url",
|
|
"url": "https://disposable-emails.github.io/",
|
|
"description": "Searchable registry of disposable email domains with bulk download support for threat intelligence integration.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Bulk blocking and threat intelligence integration for disposable email detection",
|
|
"input": "Domain name or bulk list download",
|
|
"output": "Match result or full disposable domain list (/list.txt)",
|
|
"opsec": "passive",
|
|
"opsecNote": "Static list download; community-sourced submissions, no external lookups required.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Burner Email Providers (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/wesbos/burner-email-providers",
|
|
"description": "Curated list of temporary email service domains with API references and detection library implementations across multiple languages.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Identifying burner email providers for integration into custom investigation tools",
|
|
"input": "Email domain",
|
|
"output": "Match result against known burner/temporary email providers",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local list comparison; MIT licensed for integration use.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Breach Data",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Have I been pwned?",
|
|
"type": "url",
|
|
"url": "https://haveibeenpwned.com/",
|
|
"description": "Database of breached credentials and email addresses from known data breaches.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Breach detection, credential exposure checks",
|
|
"input": "Email address, phone number, password hash",
|
|
"output": "Breach names, breach dates, exposed data types",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries breach database via API. Target is not notified of lookups.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Hudson Rock",
|
|
"type": "url",
|
|
"url": "https://www.hudsonrock.com/threat-intelligence-cybercrime-tools",
|
|
"description": "Infostealer threat intelligence platform that searches a database of compromised devices and stolen credentials to identify if emails have been exposed via malware infections.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Infostealer detection, breach assessment, device compromise verification",
|
|
"input": "Email address, domain, username, or IP",
|
|
"output": "Infostealer hits, compromised account data, breach details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public infostealer database compiled from malware captures.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DeHashed (R)",
|
|
"type": "url",
|
|
"url": "https://dehashed.com/",
|
|
"description": "Modern breach search engine indexing historical breach data over a decade old, enabling searches by email, username, password, domain, phone, and IP address.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Breach searching, credential lookup, historical breach analysis",
|
|
"input": "Email, username, password, domain, phone, or IP",
|
|
"output": "Breach records, exposed credentials, breach dates",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches aggregated public breach databases.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Vigilante.pw",
|
|
"type": "url",
|
|
"url": "https://www.vigilante.pw/",
|
|
"description": "Breach database directory and search platform raising awareness of data breaches by aggregating publicly leaked database information and breach details.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Breach research, public breach database navigation",
|
|
"input": "Email, username, domain",
|
|
"output": "Breach records, exposed data information",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregates and indexes publicly disclosed breach data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Mail Blacklists",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "MxToolbox",
|
|
"type": "url",
|
|
"url": "https://mxtoolbox.com/",
|
|
"description": "Email deliverability diagnostics tool that checks MX records, SPF, DKIM, DMARC configuration, and server health to prevent email delivery issues.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Email server diagnostics, deliverability testing, DNS validation",
|
|
"input": "Domain name or email address",
|
|
"output": "MX records, SPF/DKIM/DMARC status, blacklist info",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public DNS lookups and SMTP diagnostics without target alerting.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Domain Name",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Whois Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Domain Dossier",
|
|
"type": "url",
|
|
"url": "https://centralops.net/co/DomainDossier.aspx",
|
|
"description": "Free web-based tool that aggregates WHOIS, DNS, and network information for domains and IP addresses into a single consolidated report.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick domain and IP reconnaissance with DNS and WHOIS data",
|
|
"input": "Domain name or IP address",
|
|
"output": "WHOIS records, DNS records, IP information, registration details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public WHOIS and DNS records; does not contact the target domain directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "domainIQ",
|
|
"type": "url",
|
|
"url": "https://www.domainiq.com/",
|
|
"description": "Comprehensive domain intelligence platform offering reverse lookups, ownership history, and related domain discovery. Trusted by government agencies, domain investors, and legal firms.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Domain ownership history, reverse analytics lookup, competitor domain research",
|
|
"input": "Domain name",
|
|
"output": "Domain owner information, historical ownership, similar domains, analytics data, reverse MX/IP/DNS lookups",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries aggregated domain data; does not probe the target directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DomainTools Whois",
|
|
"type": "url",
|
|
"url": "https://whois.domaintools.com/",
|
|
"description": "Enterprise-grade WHOIS API with decades of historical domain data and rapid query response. The industry leader for threat intelligence and domain tracking.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Historical WHOIS research, threat actor tracking, enterprise domain intelligence",
|
|
"input": "Domain name or IP address",
|
|
"output": "Current and historical WHOIS records, registrant details, hosting history",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries cached WHOIS data; no direct contact with target infrastructure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "SWITCH Internet Domains Whois (.ch)",
|
|
"type": "url",
|
|
"url": "https://www.nic.ch/whois/",
|
|
"description": "Official Swiss domain registry WHOIS lookup service operated by SWITCH for .ch and .li country-code domains. Public registry with all owner contact details visible.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": ".ch and .li domain ownership research, Swiss Internet infrastructure lookup",
|
|
"input": ".ch or .li domain name",
|
|
"output": "Registrant contact details, creation/expiry dates, nameservers, registration status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries the official SWITCH registry database; does not probe the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Whoisology",
|
|
"type": "url",
|
|
"url": "https://whoisology.com/#advanced",
|
|
"description": "Searchable archive of billions of current and historical domain WHOIS records with cross-referencing capabilities. Designed for InfoSec, legal, and research professionals.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Historical domain ownership, reverse WHOIS lookups, domain connection tracking",
|
|
"input": "Domain name, email, registrant name",
|
|
"output": "Historical WHOIS records, ownership changes, registrant information across domains",
|
|
"opsec": "passive",
|
|
"opsecNote": "Accesses archived WHOIS data; no direct probing of target domains.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Whois ARIN",
|
|
"type": "url",
|
|
"url": "https://whois.arin.net/ui/advanced.jsp",
|
|
"description": "Official American Registry for Internet Numbers WHOIS and RDAP lookup service for IPv4, IPv6, ASNs, and organizations in the North American region.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IP address and ASN registration data, North American internet resource tracking",
|
|
"input": "IP address, ASN, organization name, contact information",
|
|
"output": "IP ownership, organization details, Points of Contact (POCs), ASN information",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries official ARIN database; does not contact targets or perform active scanning.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DNSstuff",
|
|
"type": "url",
|
|
"url": "https://www.dnsstuff.com/freetools",
|
|
"description": "Suite of free DNS and network tools providing lookups, DNS checks, and WHOIS information for domain reconnaissance.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick DNS and WHOIS lookups, network diagnostics",
|
|
"input": "Domain name, IP address",
|
|
"output": "DNS records, WHOIS data, DNS propagation checks, nameserver information",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public DNS and WHOIS servers; does not probe target infrastructure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Robtex (R)",
|
|
"type": "url",
|
|
"url": "https://robtex.com/",
|
|
"description": "Comprehensive free DNS lookup and network intelligence tool with decade-spanning database containing billions of documents of internet data. Useful for forensics and threat actor tracking.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "DNS reconnaissance, IP and domain relationship mapping, historical internet data lookup",
|
|
"input": "Domain name, IP address, hostname, autonomous system",
|
|
"output": "DNS records, IP information, SEO data, reputation scores, historical relationships",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches historical and cached DNS data; does not perform active probing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Domaincrawler.com",
|
|
"type": "url",
|
|
"url": "https://domaincrawler.com/",
|
|
"description": "Enterprise-grade domain database covering 1.4+ billion registered and unregistered domains with 80+ billion historical records since 2008. Used by brand protection and OSINT professionals.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Large-scale domain research, brand protection monitoring, zone file analysis, market intelligence",
|
|
"input": "Domain name, DNS data, technology stack filters",
|
|
"output": "Domain metadata, DNS configuration, SSL certificates, technology stack, ownership connections, historical data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries aggregated domain database updated every 7 days; no active scanning of targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MarkMonitor Whois Search",
|
|
"type": "url",
|
|
"url": "https://domains.markmonitor.com/whois/",
|
|
"description": "ICANN-accredited registrar and brand protection company offering WHOIS lookup and domain management services. Exclusively serves corporate clients including major global brands.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Corporate domain portfolio management, brand protection, trademark monitoring",
|
|
"input": "Domain name",
|
|
"output": "WHOIS records, registration data, brand portfolio information",
|
|
"opsec": "passive",
|
|
"opsecNote": "Accesses standard WHOIS records through registered domain lookups; no direct target probing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "easyWhois",
|
|
"type": "url",
|
|
"url": "https://www.easywhois.com/",
|
|
"description": "Free domain WHOIS lookup and DNS tools service. Now operated under the DomainHelp platform, providing domain registration information and DNS lookups.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick domain WHOIS lookups and DNS checks",
|
|
"input": "Domain name",
|
|
"output": "WHOIS records, DNS information, registrant details, nameservers",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public WHOIS and DNS data; does not contact the target domain.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Website Informer",
|
|
"type": "url",
|
|
"url": "https://website.informer.com/",
|
|
"description": "Free domain and website information aggregator providing visitor statistics, safety status, Alexa rankings, ownership data, and technical details about websites.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Website profiling, ownership verification, traffic estimation, technical stack discovery",
|
|
"input": "Domain name or URL",
|
|
"output": "Visitor statistics, safety ratings, domain owner information, technology stack, Alexa rank, historical snapshots",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregates public website data and statistics; does not contact the target infrastructure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Who.is",
|
|
"type": "url",
|
|
"url": "https://who.is/",
|
|
"description": "Comprehensive WHOIS and RDAP lookup service with large database of domain registration, DNS records, and IP information. Provides both current and historical data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Domain registration research, WHOIS lookups, RDAP queries, IP tracking",
|
|
"input": "Domain name or IP address",
|
|
"output": "WHOIS records, RDAP data, DNS records, nameservers, registrant information",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public WHOIS and RDAP databases; does not perform active scanning.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Whois AMPed",
|
|
"type": "url",
|
|
"url": "https://whoisamped.com/",
|
|
"description": "Mobile-optimized WHOIS lookup service accessible via web interface for domain registration information and WHOIS queries.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Mobile-friendly WHOIS lookups, quick domain information retrieval",
|
|
"input": "Domain name",
|
|
"output": "WHOIS records, domain registration information, registrant details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Accesses public WHOIS data; no target probing or direct contact.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ViewDNS.info",
|
|
"type": "url",
|
|
"url": "https://viewdns.info/",
|
|
"description": "Comprehensive DNS lookup and WHOIS service providing detailed DNS records, reverse IP lookups, reverse WHOIS searches, and API access for automated queries.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "DNS reconnaissance, reverse IP and reverse WHOIS lookups, historical DNS tracking",
|
|
"input": "Domain name, IP address, registrant name/email, nameserver",
|
|
"output": "DNS records, WHOIS information, reverse lookups, IP hosting, historical DNS changes",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public DNS and WHOIS data; does not perform active probing of targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Daily DNS Changes",
|
|
"type": "url",
|
|
"url": "https://dailychanges.domaintools.com/",
|
|
"description": "DomainTools service monitoring DNS record changes across domains, detecting newly registered subdomains and tracking DNS infrastructure modifications.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "DNS change detection, subdomain discovery, infrastructure monitoring",
|
|
"input": "Domain name",
|
|
"output": "New DNS records, nameserver changes, subdomain discoveries, historical DNS changes",
|
|
"opsec": "passive",
|
|
"opsecNote": "Monitors public DNS records for changes; no active scanning or direct contact.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "IP2WHOIS",
|
|
"type": "url",
|
|
"url": "https://www.ip2whois.com",
|
|
"description": "Free WHOIS lookup service for domain names and IP addresses, providing registration details, registrant information, location data, and API access.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Domain and IP WHOIS lookups, registrant research",
|
|
"input": "Domain name or IP address",
|
|
"output": "WHOIS records, registrant details, location information, registration dates",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public WHOIS databases; does not contact the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Netlas.io",
|
|
"type": "url",
|
|
"url": "https://app.netlas.io/whois_domains/",
|
|
"description": "Comprehensive internet-wide scanning and OSINT platform providing DNS, WHOIS, SSL, and network reconnaissance with attack surface discovery capabilities.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Internet reconnaissance, DNS and WHOIS lookups, attack surface discovery, vulnerability research",
|
|
"input": "Domain name, IP address, ASN, DNS records",
|
|
"output": "DNS records, WHOIS data, open ports, SSL certificates, service information, historical data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries cached internet scanning data; free tier available with 50 daily requests.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Subdomains",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "SynapsInt",
|
|
"type": "url",
|
|
"url": "https://synapsint.com",
|
|
"description": "Unified web-based OSINT research platform supporting domain, IP, SSL, analytics, email, phone, and social media lookups with subdomain enumeration.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Unified OSINT research, subdomain discovery, multi-vector intelligence gathering",
|
|
"input": "Domain, IP, email, phone, username, CVE ID",
|
|
"output": "Subdomains, DNS records, WHOIS data, open ports, vulnerabilities, social media accounts, historical data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregates publicly available information from multiple sources; no direct target contact.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Aquatone (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/michenriksen/aquatone",
|
|
"description": "Go-based tool for domain reconnaissance that automates subdomain discovery, HTTP service scanning, screenshot capture, and visual HTML report generation for attack surface analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Visual subdomain reconnaissance, HTTP service discovery, attack surface mapping",
|
|
"input": "Domain name",
|
|
"output": "Discovered subdomains, open ports, HTTP screenshots, consolidated reconnaissance report",
|
|
"opsec": "active",
|
|
"opsecNote": "Makes HTTP requests to discovered hosts to capture screenshots and fingerprint services; supports integration with passive enumeration tools.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FindSubDomains",
|
|
"type": "url",
|
|
"url": "https://findsubdomains.com/",
|
|
"description": "Free web-based automated subdomain discovery tool with filtering and analysis capabilities, showing organization names, relationships, and top subdomain statistics.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Automated subdomain enumeration, organization name filtering, subdomain statistics",
|
|
"input": "Domain name or keyword",
|
|
"output": "Discovered subdomains, organization associations, popularity metrics, filtering options",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses passive DNS and search-based methods for subdomain discovery; no active probing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Subdomains (D)",
|
|
"type": "url",
|
|
"url": "https://www.google.com/?gws_rd=ssl#q=site:%3Cdomain.com%3E",
|
|
"description": "Google Dork technique using the 'site:' operator to enumerate subdomains of a target domain via Google's search index.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Indexed subdomain discovery, publicly visible subdomain enumeration",
|
|
"input": "Domain name (as Google Dork syntax: site:domain.com)",
|
|
"output": "Indexed subdomains and pages from Google search results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses Google's search index; no direct contact with the target domain.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Recon-ng (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/lanmaster53/recon-ng",
|
|
"description": "Full-featured web reconnaissance framework with independent modules for data gathering.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Modular web recon, API-driven data collection",
|
|
"input": "Domain, company name, email, IP",
|
|
"output": "Contacts, hosts, credentials, ports via module-specific results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries third-party APIs and data sources. Does not probe the target unless specific modules are configured to do so.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "XRay",
|
|
"type": "url",
|
|
"url": "https://github.com/evilsocket/xray",
|
|
"description": "Go-based network reconnaissance tool that automates subdomain enumeration via DNS brute force, integrates Shodan for port discovery, and gathers banner information with web UI visualization.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Automated subdomain discovery with banner grabbing, open port enumeration, Shodan integration",
|
|
"input": "Domain name, subdomain wordlist, Shodan API key (optional), ViewDNS API key (optional)",
|
|
"output": "Enumerated subdomains, open ports, banner information, historical data, web-based results UI",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs DNS brute force for subdomain enumeration and makes banner grabbing connections to discovered services.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DNS Recon (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/darkoperator/dnsrecon",
|
|
"description": "Python-based DNS enumeration script supporting zone transfers, standard record enumeration, TLD expansion, DNS brute force, and PTR lookups.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "DNS enumeration, zone transfer testing, subdomain brute forcing, DNS security assessment",
|
|
"input": "Domain name, IP range/CIDR, subdomain wordlist, DNS server address",
|
|
"output": "NS/SOA/MX/A records, discovered subdomains, zone transfer results, PTR records, wildcard resolution status",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs active DNS queries and brute force attempts; does not probe target services directly but makes repeated DNS requests.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Gobuster (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/OJ/gobuster",
|
|
"description": "Multi-mode brute-force tool for DNS subdomain, virtual host, and directory discovery.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Fast DNS and vhost brute-force enumeration",
|
|
"input": "Domain, wordlist, and optional resolver/thread settings",
|
|
"output": "Discovered subdomains, vhosts, or directories with response details",
|
|
"opsec": "active",
|
|
"opsecNote": "Sends direct DNS/HTTP probes and can generate noisy traffic patterns.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Fierce Domain Scanner (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/davidpepper/fierce-domain-scanner",
|
|
"description": "DNS reconnaissance tool focused on subdomain discovery and non-contiguous IP space mapping.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "DNS recon and subdomain-to-IP mapping",
|
|
"input": "Domain, DNS server options, and optional wordlist/range parameters",
|
|
"output": "Subdomains, resolved IPs, and DNS reconnaissance findings",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs direct DNS lookups and optional scans that can be logged by infrastructure.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Bluto (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/darryllane/Bluto",
|
|
"description": "Recon utility for domain intelligence including DNS records, email patterns, and infrastructure clues.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Initial domain footprinting and asset discovery",
|
|
"input": "Target domain and optional scan switches",
|
|
"output": "Aggregated recon output including DNS and related domain artifacts",
|
|
"opsec": "active",
|
|
"opsecNote": "Runs active lookups against target-related infrastructure and third-party services.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OWASP Maryam (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/saeeddhqan/Maryam",
|
|
"description": "Modular OWASP OSINT framework with footprinting and search modules for multi-source reconnaissance.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Scriptable multi-module OSINT reconnaissance workflows",
|
|
"input": "Domain, IP, email, username, or module-specific query terms",
|
|
"output": "Module-based findings such as subdomains, metadata, and related intelligence",
|
|
"opsec": "active",
|
|
"opsecNote": "Can issue direct queries and module-driven probes depending on selected workflow.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "theHarvester (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/laramies/theHarvester",
|
|
"description": "Command-line tool for harvesting emails, subdomains, hosts, and URLs from public data sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Passive email and subdomain collection from indexed sources",
|
|
"input": "Domain and selected data source(s)",
|
|
"output": "Email addresses, subdomains, hostnames, IPs, and related metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries third-party sources instead of directly interacting with the target host.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Pentest-tools.com Subdomains",
|
|
"type": "url",
|
|
"url": "https://pentest-tools.com/information-gathering/find-subdomains-of-domain",
|
|
"description": "Web-based subdomain finder that enumerates subdomains for a given domain through hosted scanning.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Quick browser-based subdomain discovery without local setup",
|
|
"input": "Domain name",
|
|
"output": "List of discovered subdomains and related DNS intelligence",
|
|
"opsec": "passive",
|
|
"opsecNote": "Scanning is performed by Pentest-Tools infrastructure, not directly from your host.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "SecLists DNS Subdomains (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/danielmiessler/SecLists/tree/master/Discovery/DNS",
|
|
"description": "Community-maintained DNS wordlist collection used to power subdomain brute-force workflows.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Supplying high-quality DNS wordlists for enumeration tools",
|
|
"input": "Domain and chosen wordlist file used in external tooling",
|
|
"output": "Wordlist candidates for subdomain brute-force and permutation attacks",
|
|
"opsec": "passive",
|
|
"opsecNote": "Repository itself is passive; OPSEC impact depends on how the lists are used.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "dnspop (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/bitquark/dnspop",
|
|
"description": "DNS reconnaissance utility for enumerating records and identifying domain-related infrastructure.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Command-line DNS recon and record analysis",
|
|
"input": "Domain and optional scan parameters",
|
|
"output": "DNS records, discovered hosts, and recon findings",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs direct DNS queries against resolvers and target-associated records.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "gdns (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/hrbrmstr/gdns",
|
|
"description": "Google DNS-focused command-line tool for DNS lookup and domain record exploration.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick DNS enumeration via Google DNS services",
|
|
"input": "Domain and query options",
|
|
"output": "Resolved DNS records and related lookup results",
|
|
"opsec": "active",
|
|
"opsecNote": "Issues active DNS lookup requests that may be observable at resolver level.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Sublist3r",
|
|
"type": "url",
|
|
"url": "https://github.com/aboul3la/Sublist3r",
|
|
"description": "Python tool for subdomain enumeration using search engines, passive sources, and optional brute-force.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Combining passive and active subdomain discovery in one tool",
|
|
"input": "Domain and optional brute-force/thread settings",
|
|
"output": "Consolidated list of discovered subdomains",
|
|
"opsec": "active",
|
|
"opsecNote": "Uses multiple external sources and optional brute-force that can generate detectable traffic.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "AltDNS (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/infosec-au/altdns",
|
|
"description": "Permutation-based DNS tool that generates and resolves alternative subdomains from known names.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Discovering likely subdomain variants through permutations",
|
|
"input": "Known subdomains, wordlist, and target domain",
|
|
"output": "Resolved alternative subdomains and permutation results",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs direct DNS resolution on generated permutations, creating active query footprints.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Netlas.io",
|
|
"type": "url",
|
|
"url": "https://app.netlas.io/domains/",
|
|
"description": "Comprehensive internet-wide scanning and OSINT platform providing DNS, WHOIS, SSL, and network reconnaissance with attack surface discovery capabilities.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Internet reconnaissance, DNS and WHOIS lookups, attack surface discovery, vulnerability research",
|
|
"input": "Domain name, IP address, ASN, DNS records",
|
|
"output": "DNS records, WHOIS data, open ports, SSL certificates, service information, historical data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries cached internet scanning data; free tier available with 50 daily requests.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Discovery",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Shodan",
|
|
"type": "url",
|
|
"url": "https://www.shodan.io/",
|
|
"description": "Search engine for internet-exposed devices, services, and security-relevant banners.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Finding exposed services and infrastructure risk indicators",
|
|
"input": "IP, domain, ASN, organization, or filter-based search query",
|
|
"output": "Service banners, open ports, geolocation, vulnerabilities, and host metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses Shodan indexed scan data; target systems are not probed from your local host.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Netlas.io",
|
|
"type": "url",
|
|
"url": "https://app.netlas.io/",
|
|
"description": "Comprehensive internet-wide scanning and OSINT platform providing DNS, WHOIS, SSL, and network reconnaissance with attack surface discovery capabilities.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Internet reconnaissance, DNS and WHOIS lookups, attack surface discovery, vulnerability research",
|
|
"input": "Domain name, IP address, ASN, DNS records",
|
|
"output": "DNS records, WHOIS data, open ports, SSL certificates, service information, historical data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries cached internet scanning data; free tier available with 50 daily requests.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Kraken (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/Sw4mpf0x/Kraken",
|
|
"description": "Open-source reconnaissance utility for domain and network intelligence gathering workflows.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "CLI-driven reconnaissance against domain and host assets",
|
|
"input": "Domain, host, or target parameters supported by selected module",
|
|
"output": "Recon findings across DNS, host intelligence, and related artifacts",
|
|
"opsec": "active",
|
|
"opsecNote": "Runs active collection modules that can generate requests visible to target infrastructure.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Online Nikto scanner",
|
|
"type": "url",
|
|
"url": "https://nikto.online/",
|
|
"description": "Hosted version of the Nikto web server scanner for identifying vulnerabilities, misconfigurations, and exposed files.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Web server vulnerability scanning",
|
|
"input": "URLs",
|
|
"output": "Vulnerability and misconfiguration reports",
|
|
"opsec": "active",
|
|
"opsecNote": "Generates noisy scan traffic visible in target server logs; likely to trigger WAF/IDS alerts",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "urlscan.io",
|
|
"type": "url",
|
|
"url": "https://urlscan.io/search/#*",
|
|
"description": "URL and domain analysis service that captures page loads, requests, and security-relevant artifacts.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Investigating suspicious URLs with scan snapshots and indicators",
|
|
"input": "URL or domain",
|
|
"output": "Scan reports including redirects, requests, domains, IPs, and screenshots",
|
|
"opsec": "passive",
|
|
"opsecNote": "Analysis runs on urlscan infrastructure; target contact is performed from their scanners.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Daily DNS Changes",
|
|
"type": "url",
|
|
"url": "https://dailychanges.domaintools.com/",
|
|
"description": "DomainTools service monitoring DNS record changes across domains, detecting newly registered subdomains and tracking DNS infrastructure modifications.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "DNS change detection, subdomain discovery, infrastructure monitoring",
|
|
"input": "Domain name",
|
|
"output": "New DNS records, nameserver changes, subdomain discoveries, historical DNS changes",
|
|
"opsec": "passive",
|
|
"opsecNote": "Monitors public DNS records for changes; no active scanning or direct contact.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Redirect Detective",
|
|
"type": "url",
|
|
"url": "https://redirectdetective.com/",
|
|
"description": "Web tool that traces URL redirect chains and final destinations across multi-hop redirects.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Understanding redirect paths and affiliate or cloaking behavior",
|
|
"input": "URL",
|
|
"output": "Redirect chain, intermediate hops, and final destination URL",
|
|
"opsec": "passive",
|
|
"opsecNote": "Redirect checks are initiated through the service, limiting direct local target interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Sitediff (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/digininja/sitediff",
|
|
"description": "Command-line utility for comparing website versions to detect content and structural changes.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Tracking site changes between snapshots for monitoring and QA",
|
|
"input": "Two URLs or snapshots to compare",
|
|
"output": "Diff output highlighting content and structural deltas",
|
|
"opsec": "passive",
|
|
"opsecNote": "Primarily compares fetched content; does not perform intrusive probing by design.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "BuiltWith",
|
|
"type": "url",
|
|
"url": "https://builtwith.com/",
|
|
"description": "Technology profiling platform that identifies web stacks, frameworks, analytics, and hosting signals.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Website technology stack fingerprinting and ecosystem mapping",
|
|
"input": "Domain or URL",
|
|
"output": "Detected technologies, hosting/CDN indicators, and related site intelligence",
|
|
"opsec": "passive",
|
|
"opsecNote": "Returns platform-collected intelligence and does not require direct target probing by the user.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Wappalyzer",
|
|
"type": "url",
|
|
"url": "https://www.wappalyzer.com/",
|
|
"description": "Technology detection platform and browser tooling for identifying frameworks, CMS, and SaaS usage.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Detecting web technologies and software dependencies at scale",
|
|
"input": "Domain, URL, or browsed webpage",
|
|
"output": "Detected technologies by category with confidence indicators",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses extension/service analysis of page resources; minimal direct probing behavior.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "AnalyzeID",
|
|
"type": "url",
|
|
"url": "https://analyzeid.com/",
|
|
"description": "Reverse lookup service for tracking IDs such as Google Analytics, AdSense, and affiliate identifiers.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Pivoting from shared tracking IDs to related domains",
|
|
"input": "Tracking ID (analytics, ads, affiliate, or publisher ID)",
|
|
"output": "Associated domains and identifier reuse relationships",
|
|
"opsec": "passive",
|
|
"opsecNote": "Operates on indexed identifier-to-domain mappings without active target interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Criminal IP Search",
|
|
"type": "url",
|
|
"url": "https://www.criminalip.io/",
|
|
"description": "Cyber threat intelligence search engine for exposed assets, domains, vulnerabilities, and risk indicators.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Threat-focused lookup of internet-facing assets and exposures",
|
|
"input": "IP, domain, ASN, CVE, or filter-based threat query",
|
|
"output": "Asset details, risk scores, service fingerprints, and vulnerability context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches provider datasets rather than scanning targets directly from analyst infrastructure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "urlDNA",
|
|
"type": "url",
|
|
"url": "https://urldna.io",
|
|
"description": "URL intelligence service for investigating domains, redirects, and related reputation indicators.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Quick URL/domain triage and intelligence pivoting",
|
|
"input": "URL or domain",
|
|
"output": "URL analysis details, related domains, and risk-relevant metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses service-side analysis and historical datasets instead of direct local probing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ZoomEye.ai",
|
|
"type": "url",
|
|
"url": "https://www.zoomeye.org/",
|
|
"description": "Cyberspace search engine indexing internet-connected devices, services, and vulnerabilities globally. Provides AI-powered search via ZoomEyeGPT with support for ZoomEye dorks for targeted reconnaissance.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Internet device discovery, service enumeration, vulnerability mapping, attack surface assessment",
|
|
"input": "Domain, IP, port, service, or natural language query",
|
|
"output": "Device list, port data, banner info, vulnerability details, geographic distribution",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries ZoomEye's pre-scanned internet data; does not probe targets during search.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Certificate Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Shodan",
|
|
"type": "url",
|
|
"url": "https://www.shodan.io/"
|
|
},
|
|
{
|
|
"name": "Google's Certificate Transparency",
|
|
"type": "url",
|
|
"url": "https://www.certificate-transparency.org/known-logs",
|
|
"description": "Directory of all known Certificate Transparency logs monitored by Chrome and other browsers. Browse CT log records to discover issued certificates, identify unauthorized domain certificates, and monitor for certificate misuse.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Certificate discovery, unauthorized cert detection, domain monitoring",
|
|
"input": "Domain name or certificate fingerprint",
|
|
"output": "List of CT logs and certificates issued for the specified domain",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public certificate logs without contacting the target domain.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Spyse",
|
|
"type": "url",
|
|
"url": "https://spyse.com/search/certificate",
|
|
"description": "Internet assets registry providing certificate search, domain intelligence, and vulnerability discovery. Scans domains, subdomains, certificates, emails, and open ports across the global internet.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Domain intelligence, certificate discovery, subdomain enumeration, vulnerability identification",
|
|
"input": "Domain, IP, certificate, email, or organization name",
|
|
"output": "Domain details, subdomains, certificates, WHOIS info, CVEs, open ports, scraped emails",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries Spyse's pre-scanned database; does not contact the target directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Censys",
|
|
"type": "url",
|
|
"url": "https://censys.io/",
|
|
"description": "Internet-wide scanner and search engine for hosts, certificates, and services.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Certificate discovery, host enumeration, exposure monitoring",
|
|
"input": "Domain, IP, certificate fingerprint, search query",
|
|
"output": "Host details, open ports, TLS certificates, service banners",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries pre-scanned data. Does not probe the target directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "crt.sh - Certificate Search",
|
|
"type": "url",
|
|
"url": "https://crt.sh/?",
|
|
"description": "CT log viewer aggregating certificate data from multiple Certificate Transparency logs. Search for all certificates ever issued to a domain to discover subdomains and detect certificate misuse.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Certificate search, subdomain discovery via CT logs, detecting unauthorized certificates",
|
|
"input": "Domain name (with or without wildcard)",
|
|
"output": "List of certificates issued to the domain with Subject Alternative Names and issue/expiry dates",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public Certificate Transparency logs; does not contact the target domain.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "CertKit - Certificate Transparency Log Search",
|
|
"type": "url",
|
|
"url": "https://www.certkit.io/tools/ct-logs/",
|
|
"description": "Fast Certificate Transparency log search tool using Clickhouse for sub-second queries. Discover all certificates issued to a domain, including Subject Alternative Names, to reveal hidden infrastructure.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "CT certificate search, subdomain enumeration, certificate misuse detection",
|
|
"input": "Domain name",
|
|
"output": "List of certificates with issuance dates, expiry dates, and Subject Alternative Names",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public Certificate Transparency logs; does not contact the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "certgraph (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/lanrat/certgraph",
|
|
"description": "CLI tool that crawls SSL certificates via Certificate Transparency logs to create a directed graph of domain relationships. Supports multiple drivers including crt.sh, Censys, HTTPS, and SMTP.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Certificate mapping, domain relationship discovery, hostname enumeration via SSL certificates",
|
|
"input": "Hostname or domain name",
|
|
"output": "Directed graph showing domain nodes and certificate alternative name connections between domains",
|
|
"opsec": "passive",
|
|
"opsecNote": "Default HTTPS driver can make connections to hosts; alternative drivers query CT logs passively. Use CT drivers for stealth.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Netlas.io",
|
|
"type": "url",
|
|
"url": "https://app.netlas.io/certs/",
|
|
"description": "Comprehensive internet-wide scanning and OSINT platform providing DNS, WHOIS, SSL, and network reconnaissance with attack surface discovery capabilities.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Internet reconnaissance, DNS and WHOIS lookups, attack surface discovery, vulnerability research",
|
|
"input": "Domain name, IP address, ASN, DNS records",
|
|
"output": "DNS records, WHOIS data, open ports, SSL certificates, service information, historical data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries cached internet scanning data; free tier available with 50 daily requests.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "PassiveDNS",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Mnemonic",
|
|
"type": "url",
|
|
"url": "https://passivedns.mnemonic.no/",
|
|
"description": "Mnemonic's public PassiveDNS service providing historical and current DNS records collected from global sensor networks. Unauthenticated queries available with rate limiting.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Passive DNS lookups, historical domain resolutions, DNS reconnaissance",
|
|
"input": "Domain or IP address",
|
|
"output": "DNS query history with timestamps, associated IPs, and historical resolutions",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries a passive database of DNS records; does not contact the target domain.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DNS Dumpster",
|
|
"type": "url",
|
|
"url": "https://dnsdumpster.com/",
|
|
"description": "Free domain research tool that discovers hosts and subdomains related to a domain. Provides DNS record enumeration (MX, TXT, Host) with a visual map of discovered infrastructure.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Subdomain enumeration, DNS reconnaissance, infrastructure mapping",
|
|
"input": "Domain name",
|
|
"output": "MX records, TXT records, Host records, subdomains, infrastructure map",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive DNS research without sending direct DNS requests or probing the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Deteque (R)",
|
|
"type": "url",
|
|
"url": "https://www.deteque.com/",
|
|
"description": "Real-time IP, domain, and threat intelligence from Spamhaus and abuse.ch alliance. Provides comprehensive malware, botnet, and abuse data with diverse IOC coverage (IPs, domains, URLs, files, cryptos).",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Domain/IP threat intelligence, malware tracking, botnet detection, abuse data",
|
|
"input": "Domain, IP, URL, file hash, or AS number",
|
|
"output": "Threat classification, malware associations, botnet data, historical records (up to 12 months)",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries threat intelligence database; does not contact or probe the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Reputation",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "UrlQuery.net",
|
|
"type": "url",
|
|
"url": "https://urlquery.net/",
|
|
"description": "Free online URL scanner that analyzes webpages for malware, suspicious elements, and phishing threats. Provides comprehensive threat detection reports with threat briefs on emerging campaigns.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "URL reputation scanning, malware detection, phishing detection, threat analysis",
|
|
"input": "URL or webpage",
|
|
"output": "Threat report, detected threats, malicious behavior, anomalies, security assessment",
|
|
"opsec": "active",
|
|
"opsecNote": "Visits and analyzes the submitted URL; the target server may detect the scan.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "URL Void",
|
|
"type": "url",
|
|
"url": "https://www.urlvoid.com/",
|
|
"description": "Free website reputation checker that scans URLs against 30+ blocklist engines and reputation services. Detects fraudulent and malicious websites with browser extension available.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Website reputation checking, malware/phishing detection, threat analysis",
|
|
"input": "Website URL",
|
|
"output": "Safety report from 30+ blocklists, IP details, domain age, server location, threat indicators",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries blocklist and reputation services; does not directly visit or probe the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FortiGuard Reputation Service",
|
|
"type": "url",
|
|
"url": "https://fortiguard.com/iprep",
|
|
"description": "Fortinet's IP reputation service aggregating malicious source IP data from global threat sensors and collaborators. Blocks botnets, DDoS sources, and IPs associated with phishing, scanning, and malware.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IP reputation lookup, botnet/malware source identification, threat intelligence",
|
|
"input": "IP address or IP range",
|
|
"output": "IP reputation score, threat categories, malware associations, botnet status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries Fortinet's IP reputation database without contacting the target IP.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Trend Micro Site Safety Center",
|
|
"type": "url",
|
|
"url": "https://global.sitesafety.trendmicro.com/",
|
|
"description": "Free service that checks website safety ratings from Trend Micro's research and reputation sources. Identifies websites with malware, phishing activity, or suspicious behavior.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Website safety verification, malware/phishing detection, threat assessment",
|
|
"input": "Website URL",
|
|
"output": "Safety rating, category classification, threat indicators, historical data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries Trend Micro's pre-scanned website reputation database without contacting the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "WatchGuard ReputationAuthority",
|
|
"type": "url",
|
|
"url": "https://www.reputationauthority.org/",
|
|
"description": "In-the-cloud reputation monitoring service analyzing URL and IP threat risk. Assigns reputation scores between 1-100 using data from global sources and deployed systems.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "URL/IP reputation scoring, threat risk assessment, malicious source identification",
|
|
"input": "URL or IP address",
|
|
"output": "Reputation score (1-100), threat risk level, URL category, blocking recommendations",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries WatchGuard's reputation servers without contacting the target directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Sucuri SiteCheck",
|
|
"type": "url",
|
|
"url": "https://sitecheck.sucuri.net/",
|
|
"description": "Free remote website scanner that checks for malware, security threats, blacklisting, and vulnerabilities. Detects outdated CMS versions, insecure configurations, and security anomalies.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Website malware scanning, vulnerability detection, security assessment",
|
|
"input": "Website URL",
|
|
"output": "Security scan report, malware detection, blacklist status, vulnerable plugin/CMS details",
|
|
"opsec": "active",
|
|
"opsecNote": "Remotely visits the website to check source code and security; may be detectable by WAF/IDS.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ThreatMiner.org",
|
|
"type": "url",
|
|
"url": "https://www.threatminer.org/",
|
|
"description": "Non-profit threat intelligence portal providing IOC research including domains, IPs, malware samples, SSL certificates, WHOIS data, and malicious URLs under Creative Commons license.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Threat intelligence research, IOC investigation, malware/phishing link analysis",
|
|
"input": "Domain, IP, file hash (MD5/SHA1/SHA256), SSL certificate, or URL",
|
|
"output": "Threat reports, IOC data, WHOIS info, malware associations, related indicators",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries aggregated threat intelligence data from multiple sources; does not probe targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "BlueCoat WebPulse",
|
|
"type": "url",
|
|
"url": "https://sitereview.bluecoat.com/sitereview.jsp",
|
|
"description": "Web reputation filtering service rating URLs with 50+ language support. Processes 180+ million rating requests daily with Dynamic Link Analysis for attack injection detection.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "URL categorization, website reputation filtering, malicious link detection",
|
|
"input": "Website URL",
|
|
"output": "URL category, reputation rating, threat indicators, web content classification",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries Blue Coat's cloud-based URL reputation database without directly probing targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Zscaler Zulu URL Risk Analyzer",
|
|
"type": "url",
|
|
"url": "https://zulu.zscaler.com/",
|
|
"description": "Free dynamic risk scoring engine for web content analysis. Assesses URLs from multiple perspectives: content analysis, URL patterns, and host reputation using machine learning.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "URL risk scoring, web threat detection, malicious content analysis",
|
|
"input": "Website URL",
|
|
"output": "Risk score, threat assessment at content/URL/host levels, malicious behavior detection",
|
|
"opsec": "active",
|
|
"opsecNote": "Uses sandboxing to execute URLs in an isolated environment; may detect analysis activity.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Joe Sandbox Url Analyzer",
|
|
"type": "url",
|
|
"url": "https://www.url-analyzer.net/",
|
|
"description": "Deep URL and document analysis using real browser execution in isolated environments. Detects malware, phishing, and suspicious behavior with detailed system/network monitoring.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Malware/phishing analysis, URL behavior detection, deep web threat investigation",
|
|
"input": "URL or document file",
|
|
"output": "Detailed behavior analysis, DOM tree, browser data, network capture, threat assessment",
|
|
"opsec": "active",
|
|
"opsecNote": "Executes URLs in real browsers; detectable by advanced anti-analysis techniques.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Deepviz Domain Search",
|
|
"type": "url",
|
|
"url": "https://search.deepviz.com/",
|
|
"description": "Threat intelligence platform providing domain, IP, and malware sample search with daily threat feeds. Includes similar sample finding, malware family clustering, and API/Splunk integration.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Domain/IP threat intelligence, malware analysis, threat feed subscription",
|
|
"input": "Domain, IP, file hash (MD5), or malware sample",
|
|
"output": "Threat intelligence data, malware associations, related IOCs, daily threat feeds",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries threat intelligence databases without contacting the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "AVG Threat Labs",
|
|
"type": "url",
|
|
"url": "https://www.avg.com/en/signal/website-safety",
|
|
"description": "Website security analysis tool providing instant safety assessment of sites. Merges quantitative threat detection from 100M AVG users with LinkScanner technology in graphical reports.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Website safety assessment, threat detection reports, website popularity tracking",
|
|
"input": "Website URL",
|
|
"output": "Safety analysis, threat report, popularity status, server location, detection timeline",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries AVG's threat detection database; does not contact the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Webroot BrightCloud URL/IP Lookup",
|
|
"type": "url",
|
|
"url": "https://www.brightcloud.com/tools/url-ip-lookup.php",
|
|
"description": "Web classification and reputation tool providing URL/IP threat and content analysis. Uses machine learning reputation scoring across 82 content categories with IP risk tiering.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "URL/IP reputation lookup, web classification, threat intelligence, web categorization",
|
|
"input": "URL or IP address",
|
|
"output": "Threat assessment, content category, reputation score, WHOIS data, risk level",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries BrightCloud's reputation database without directly contacting the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "vURL Online",
|
|
"type": "url",
|
|
"url": "https://vurldissect.co.uk/",
|
|
"description": "URL and domain dissection tool providing detailed reputation analysis and security assessment.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "URL/domain dissection and reputation",
|
|
"input": "URL or domain",
|
|
"output": "Detailed dissection report",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive analysis of URL components and reputation data",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "AlienVault Open Threat Exchange",
|
|
"type": "url",
|
|
"url": "https://otx.alienvault.com/browse/pulses/",
|
|
"description": "Community-driven threat intelligence platform enabling collaborative defense with 180K+ participants sharing 19M+ threats daily.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Community threat intelligence sharing",
|
|
"input": "Domain, IP, URL, file hash",
|
|
"output": "Threat pulses, reputation data, indicators",
|
|
"opsec": "passive",
|
|
"opsecNote": "Community-sourced intelligence; free API access with registration",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Malware Domain List",
|
|
"type": "url",
|
|
"url": "https://www.malwaredomainlist.com/mdl.php",
|
|
"description": "Interactive malware domain reputation lookup providing verified malicious domain intelligence.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Malware domain reputation queries",
|
|
"input": "Domain name",
|
|
"output": "Domain reputation report",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries curated malware domain database; passive lookup only",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Web Inspector Online Scan",
|
|
"type": "url",
|
|
"url": "https://www.webinspector.com/website-malware-scanner/",
|
|
"description": "Free cloud-based website malware scanner with daily automated scanning and blacklist checking capabilities.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Website malware scanning",
|
|
"input": "Website URL",
|
|
"output": "Malware scan report, vulnerability assessment",
|
|
"opsec": "active",
|
|
"opsecNote": "Active scanning required; connects to target website to analyze content",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Safe Browsing API",
|
|
"type": "url",
|
|
"url": "https://developers.google.com/safe-browsing/?csw=1",
|
|
"description": "Google's free API detecting malicious URLs and phishing sites with protection across billions of devices.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Malware and phishing URL detection",
|
|
"input": "URL or domain",
|
|
"output": "Safe/unsafe classification, threat type",
|
|
"opsec": "passive",
|
|
"opsecNote": "Free for non-commercial use; commercial use requires Web Risk API (paid)",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Cisco Talos",
|
|
"type": "url",
|
|
"url": "https://talosintelligence.com/",
|
|
"description": "Cisco's comprehensive IP and domain reputation intelligence system with real-time threat detection spanning millions of sensors.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IP/domain reputation intelligence",
|
|
"input": "IP address or domain",
|
|
"output": "Reputation score, threat indicators, intelligence reports",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive intelligence from Cisco's extensive network of sensors and endpoints",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Domain Blacklists",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Threatexpert.com Malicious URLs",
|
|
"type": "url",
|
|
"url": "https://www.networksec.org/grabbho/block.txt",
|
|
"description": "Malicious URL blacklist feed from abuse.ch's URL repository tracking malware distribution vectors.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Malware URL intelligence",
|
|
"input": "Domain or URL",
|
|
"output": "Blocklist/Feed format",
|
|
"opsec": "passive",
|
|
"opsecNote": "Retrieves historical blocklist data from abuse.ch infrastructure",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Zeus C2 Tracker",
|
|
"type": "url",
|
|
"url": "https://zeustracker.abuse.ch/blocklist.php?download=domainblocklist",
|
|
"description": "abuse.ch project tracking Zeus command and control servers with domain and IP blocklists.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Zeus botnet C2 blocking",
|
|
"input": "None (blocklist provider)",
|
|
"output": "Domain/IP blocklist, Snort rules, Squid format",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public Zeus tracker database; no active scanning",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Malware Domains Blacklist",
|
|
"type": "url",
|
|
"url": "https://mirror1.malwaredomains.com/files/domains.txt",
|
|
"description": "Historical malware domains blocklist providing hosts file format malicious domain list.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Malware domain blocking (legacy)",
|
|
"input": "None (blocklist provider)",
|
|
"output": "Hosts file format",
|
|
"opsec": "passive",
|
|
"opsecNote": "Legacy service; no longer maintained",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Blackweb",
|
|
"type": "url",
|
|
"url": "https://github.com/maravento/blackweb",
|
|
"description": "Open-source project consolidating public malware domain blacklists optimized for Squid-Cache compatibility.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Squid proxy malware filtering",
|
|
"input": "None (aggregated blocklist)",
|
|
"output": "Squid-compatible blocklist format",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregates existing public blacklist sources; requires DNS verification",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Critical Stack Intel (R)",
|
|
"type": "url",
|
|
"url": "https://intel.criticalstack.com/",
|
|
"description": "Free threat intelligence feeds integrated with Bro/Zeek network security monitoring systems.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Network IDS threat intelligence",
|
|
"input": "Bro/Zeek intel format",
|
|
"output": "Intel.log entries, network alerts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Requires registration; polled hourly from curated threat intelligence feeds",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DNS Sinkhole",
|
|
"type": "url",
|
|
"url": "https://malc0de.com/bl/",
|
|
"description": "Malware domain sinkhole from malc0de.com providing DNS-based threat blocking zones.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "DNS-based malware blocking",
|
|
"input": "DNS zone file",
|
|
"output": "Malware domain sinkhole list",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public malware database; Cloudflare CAPTCHA protection added",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DNS-BH Malware Domain Blocklist",
|
|
"type": "url",
|
|
"url": "https://www.malwaredomains.com/wordpress/?page_id=66",
|
|
"description": "Legacy malware domain blocklist from RiskAnalytics using Black Hole DNS sinkhole technology.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Malware domain blocking (legacy)",
|
|
"input": "None (blocklist provider)",
|
|
"output": "Multiple formats (BIND, BOOT, ISA, MaraDNS)",
|
|
"opsec": "passive",
|
|
"opsecNote": "Service sunset; merged into ShadowNet",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Malware Domain List",
|
|
"type": "url",
|
|
"url": "https://www.malwaredomainlist.com/hostslist/hosts.txt",
|
|
"description": "Interactive malware domain reputation lookup providing verified malicious domain intelligence.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Malware domain reputation queries",
|
|
"input": "Domain name",
|
|
"output": "Domain reputation report",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries curated malware domain database; passive lookup only",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MalwareURL (R)",
|
|
"type": "url",
|
|
"url": "https://www.malwareurl.com/index.php",
|
|
"description": "Commercial malware URL reputation checker and blocklist service protecting networks from known malicious websites.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Malware URL reputation checking",
|
|
"input": "URL",
|
|
"output": "Reputation report, blocklist data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Free lookup service available; commercial network integration available",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "scumware.org",
|
|
"type": "url",
|
|
"url": "https://www.scumware.org/",
|
|
"description": "Free malware and spyware tracking domain blacklist maintained by security community for 18+ years.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Malware and spyware domain research",
|
|
"input": "Domain or URL",
|
|
"output": "Domain reputation/blocklist data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Community-maintained research database; passive lookup only",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ZeuS Tracker",
|
|
"type": "url",
|
|
"url": "https://zeustracker.abuse.ch/blocklist.php",
|
|
"description": "abuse.ch project providing comprehensive tracking of Zeus botnet C2 infrastructure with domain and IP blocklists.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Zeus botnet tracking and blocking",
|
|
"input": "None (blocklist provider)",
|
|
"output": "Domain blocklist, IP blocklist, Snort rules, Squid format",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public tracker; passive monitoring of Zeus C2 activity",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Shadowserver Foundation",
|
|
"type": "url",
|
|
"url": "https://www.shadowserver.org/",
|
|
"description": "Nonprofit providing comprehensive IP reputation intelligence and automated abuse reporting through daily network scanning.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IP/domain reputation and abuse intelligence",
|
|
"input": "IP address or domain",
|
|
"output": "Reputation reports, blocklists, abuse intelligence",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive intelligence from honeypots and network sensors; no active scanning",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Email Domain Validation",
|
|
"type": "url",
|
|
"url": "https://www.mailboxvalidator.com/domain",
|
|
"description": "Free email domain validation tool checking DNS records, MX records, and mail server connectivity.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Email domain and mailbox verification",
|
|
"input": "Email domain or address",
|
|
"output": "Domain validation report, MX records",
|
|
"opsec": "active",
|
|
"opsecNote": "Active mail server connectivity checks required for validation",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Typosquatting",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "DNS Twist (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/elceef/dnstwist",
|
|
"description": "Domain name permutation engine for detecting homograph phishing attacks and typosquatting with fuzzy hashing.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Typosquatting and phishing domain detection",
|
|
"input": "Domain name",
|
|
"output": "Domain permutation list, DNS records, HTTP similarity",
|
|
"opsec": "active",
|
|
"opsecNote": "Active DNS queries required; queries can be resource-intensive (300K+ queries for google.com)",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "URLCrazy (T)",
|
|
"type": "url",
|
|
"url": "https://www.morningstarsecurity.com/research/urlcrazy",
|
|
"description": "Ruby-based typosquatting domain generator supporting 15 variation types and 8000+ common misspellings.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Typosquatting domain discovery",
|
|
"input": "Domain name",
|
|
"output": "Domain variant list, registration status",
|
|
"opsec": "active",
|
|
"opsecNote": "Generates 2000+ variants requiring DNS queries for availability checking",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "dnstwister",
|
|
"type": "url",
|
|
"url": "https://dnstwister.report/",
|
|
"description": "Web-based domain permutation tool with free lookup and paid monitoring plans for typosquatting detection.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Typosquatting monitoring",
|
|
"input": "Domain name",
|
|
"output": "Domain variants, registration status, DNS records",
|
|
"opsec": "active",
|
|
"opsecNote": "Active DNS queries required for variant checking; paid plans enable continuous monitoring",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Catphish (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/ring0lab/catphish",
|
|
"description": "Red team tool for generating phishing domains using homoglyphs, punycode, and domain manipulation techniques.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Red team phishing domain generation",
|
|
"input": "Target domain",
|
|
"output": "Phishing domain variants, categorization status",
|
|
"opsec": "active",
|
|
"opsecNote": "Generates domains for red team operations; checks domain categorization to evade proxies",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Analytics",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "BuiltWith",
|
|
"type": "url",
|
|
"url": "https://builtwith.com/",
|
|
"description": "Web technology profiler identifying CMS platforms, frameworks, analytics, and 2500+ technologies used by websites.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Web technology intelligence and competitive analysis",
|
|
"input": "Website URL or domain",
|
|
"output": "Technology stack report, lead generation data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public website analysis; passive technical reconnaissance",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "SiteSleuth",
|
|
"type": "url",
|
|
"url": "https://www.sitesleuth.io/",
|
|
"description": "OSINT domain analytics tool tracking Google Analytics, AdSense, and Stripe keys across 32+ million websites.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Tracking code intelligence and related domain discovery",
|
|
"input": "Domain, Google Analytics ID, AdSense ID, or Stripe key",
|
|
"output": "List of associated domains and tracking codes",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive intelligence from indexed tracking identifiers; no direct queries to targets",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Wappalyzer (T)",
|
|
"type": "url",
|
|
"url": "https://www.wappalyzer.com/",
|
|
"description": "Technology stack profiler that identifies CMS, frameworks, analytics, and infrastructure used by a website.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Technology stack fingerprinting and recon",
|
|
"input": "Domain or URL",
|
|
"output": "Detected technologies, categories, versions, and metadata",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs direct analysis of target pages when scanning live URLs.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "SEMrush",
|
|
"type": "url",
|
|
"url": "https://www.semrush.com/",
|
|
"description": "SEO intelligence platform for domain analytics, keyword intelligence, backlinks, and competitor profiling.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Traffic and backlink competitive analysis",
|
|
"input": "Domain",
|
|
"output": "Keywords, backlinks, ranking trends, and traffic estimates",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses provider-side indexed datasets and does not require direct probing by the user.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Moonsearch",
|
|
"type": "url",
|
|
"url": "https://moonsearch.com/",
|
|
"description": "Legacy reverse-WHOIS style domain correlation service with unclear current availability.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Historical domain ownership correlation",
|
|
"input": "Domain or registrant details",
|
|
"output": "Potentially related domains and ownership links",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Service availability is inconsistent; treat results as unverified and re-check before use.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Ewhois",
|
|
"type": "url",
|
|
"url": "https://www.ewhois.com/",
|
|
"description": "Web WHOIS lookup utility for registration, registrar, and nameserver details.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick WHOIS lookups",
|
|
"input": "Domain",
|
|
"output": "Registrant, registrar, dates, and nameserver records",
|
|
"opsec": "passive",
|
|
"opsecNote": "Performs standard registration lookups with low operational risk.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "StatsCrop",
|
|
"type": "url",
|
|
"url": "https://www.statscrop.com/",
|
|
"description": "Website statistics portal with traffic rank snapshots and related metadata.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick website popularity snapshots",
|
|
"input": "Domain",
|
|
"output": "Traffic rank estimates and summary site stats",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reads provider-side metrics without direct target interaction by the user.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Open Site Explorer",
|
|
"type": "url",
|
|
"url": "https://moz.com/link-explorer",
|
|
"description": "Legacy Moz Open Site Explorer entry now represented by Moz Link Explorer for backlink analysis.",
|
|
"status": "degraded",
|
|
"pricing": "freemium",
|
|
"bestFor": "Backlink and linking-domain analysis",
|
|
"input": "Domain or URL",
|
|
"output": "Backlinks, authority-style metrics, and linking domains",
|
|
"opsec": "passive",
|
|
"opsecNote": "Modern functionality persists under Moz Link Explorer; legacy naming retained for framework continuity.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "SpyOnWeb",
|
|
"type": "url",
|
|
"url": "https://www.spyonweb.com/",
|
|
"description": "Correlation tool that links domains by shared tracking and advertising identifiers.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Finding related infrastructure via shared IDs",
|
|
"input": "Domain or analytics/ad IDs",
|
|
"output": "Related domains and shared identifier pivots",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses indexed identifier data and does not require active probing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Keyword Density",
|
|
"type": "url",
|
|
"url": "https://tools.seobook.com/general/keyword-density/",
|
|
"description": "Text and page analyzer that measures keyword frequency and relative density.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "On-page keyword frequency analysis",
|
|
"input": "URL or text",
|
|
"output": "Keyword counts and density metrics",
|
|
"opsec": "active",
|
|
"opsecNote": "May fetch target content directly for analysis when URL input is used.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Alexa Site Statistics",
|
|
"type": "url",
|
|
"url": "https://alexa.amazon.com/about",
|
|
"description": "Historical Alexa Internet traffic-statistics entry; service was discontinued in 2022.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference only",
|
|
"input": "Domain",
|
|
"output": "Legacy traffic ranking context (archival)",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Alexa Internet shut down on May 1, 2022; keep as deprecated reference only.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Cisco Umbrella Popularity List",
|
|
"type": "url",
|
|
"url": "https://s3-us-west-1.amazonaws.com/umbrella-static/index.html",
|
|
"description": "Domain popularity ranking based on Cisco Umbrella DNS telemetry.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Top-domain popularity and DNS trend context",
|
|
"input": "Domain or list lookup",
|
|
"output": "Popularity ranking and related DNS-derived context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Consumes published ranking data with low direct exposure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Alexa Top 500 Global Sites",
|
|
"type": "url",
|
|
"url": "https://alexa.amazon.com/about",
|
|
"description": "Historical Alexa Top Sites list reference; no longer maintained after Alexa shutdown.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Historical popularity-list reference",
|
|
"input": "N/A",
|
|
"output": "Legacy ranking context only",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Alexa Internet ended on May 1, 2022; this entry is retained only as deprecated legacy context.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Sitedossier",
|
|
"type": "url",
|
|
"url": "https://www.sitedossier.com/",
|
|
"description": "Domain dossier aggregator with WHOIS, DNS, and linked infrastructure context.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick domain intelligence aggregation",
|
|
"input": "Domain or IP",
|
|
"output": "WHOIS, DNS, and related-site context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregates public records and indexed data with limited operator exposure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Visual Site Mapper",
|
|
"type": "url",
|
|
"url": "https://github.com/alentum/sitemapper-nodejs",
|
|
"description": "Site-crawling mapper used to visualize website structure and page relationships.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Generating website structure maps",
|
|
"input": "Domain or URL seed",
|
|
"output": "Crawl graph and site map structure",
|
|
"opsec": "active",
|
|
"opsecNote": "Actively crawls target pages and generates repeated requests.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ClearWebStats.com",
|
|
"type": "url",
|
|
"url": "https://www.clearwebstats.com/",
|
|
"description": "Public site-statistics index showing traffic and rank snapshots for domains.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Lightweight web popularity lookups",
|
|
"input": "Domain",
|
|
"output": "Estimated rank and summary traffic metrics",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses provider-collected analytics rather than direct target scanning.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "PubDB",
|
|
"type": "url",
|
|
"url": "https://pub-db.com/",
|
|
"description": "Legacy public-database lookup entry with expired or unavailable service state.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference only",
|
|
"input": "Query terms",
|
|
"output": "Unavailable/legacy output",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Service appears expired or defunct; verify alternatives before operational use.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "SimilarWeb",
|
|
"type": "url",
|
|
"url": "https://www.similarweb.com/",
|
|
"description": "Digital intelligence platform for traffic estimates, referrals, and audience insights.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Competitor traffic and referral analysis",
|
|
"input": "Domain",
|
|
"output": "Traffic channels, engagement, and competitor benchmarking",
|
|
"opsec": "passive",
|
|
"opsecNote": "Relies on provider-side datasets and panels; no active probing required by user.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Siteliner",
|
|
"type": "url",
|
|
"url": "https://www.siteliner.com/",
|
|
"description": "Website crawler that highlights duplicate content, broken links, and SEO quality issues.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Duplicate-content and link-health audits",
|
|
"input": "Domain",
|
|
"output": "Duplicate-content metrics, broken links, and crawl summaries",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs active crawl requests against the target site.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "WhatWeb",
|
|
"type": "url",
|
|
"url": "https://github.com/urbanadventurer/WhatWeb",
|
|
"description": "Open-source fingerprinting scanner for identifying technologies, frameworks, and server-side indicators.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "CLI-based web technology fingerprinting",
|
|
"input": "Domain or URL",
|
|
"output": "Detected technologies, headers, and fingerprint matches",
|
|
"opsec": "active",
|
|
"opsecNote": "Directly scans target endpoints and can be noisy depending on scan options.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "URL Expanders",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Link Expander",
|
|
"type": "url",
|
|
"url": "https://www.linkexpander.com/",
|
|
"description": "Short-link expansion tool that resolves redirects to destination URLs.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Expanding shortened links safely",
|
|
"input": "Shortened URL",
|
|
"output": "Resolved destination URL and redirect behavior",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses preview/expansion workflows and avoids direct navigation in the browser.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "CheckShortURL",
|
|
"type": "url",
|
|
"url": "https://checkshorturl.com/",
|
|
"description": "Preview service for shortened URLs with destination and threat-check context.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Safe short-link destination checks",
|
|
"input": "Shortened URL",
|
|
"output": "Expanded destination and warning context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passively expands links before user navigation.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "URL Expander",
|
|
"type": "url",
|
|
"url": "https://urlex.org/",
|
|
"description": "Link resolver for unshortening and inspecting redirect destination chains.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Resolving opaque short links",
|
|
"input": "Shortened URL",
|
|
"output": "Expanded URL and redirect details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Primarily destination resolution with low direct operational exposure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Where Does This Link Go?",
|
|
"type": "url",
|
|
"url": "https://wheregoes.com/",
|
|
"description": "Redirect-chain inspector that traces and visualizes final destination paths.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Tracing redirect chains for suspicious links",
|
|
"input": "URL",
|
|
"output": "Redirect hops, response codes, and final destination",
|
|
"opsec": "passive",
|
|
"opsecNote": "Provides passive redirect tracing before manual browser interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "KnowURL",
|
|
"type": "url",
|
|
"url": "https://www.knowurl.com/",
|
|
"description": "Legacy URL intelligence entry with uncertain availability and reliability.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference only",
|
|
"input": "URL",
|
|
"output": "Unreliable or unavailable metadata",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Current service status is unclear; verify manually before relying on output.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Change Detection",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "VisualPing",
|
|
"type": "url",
|
|
"url": "https://visualping.io/",
|
|
"description": "Website monitoring platform that alerts on page content or visual changes.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Automated webpage change monitoring",
|
|
"input": "URL and watch settings",
|
|
"output": "Change alerts with visual or text diffs",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs recurring fetches of target pages based on monitoring cadence.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Change Detection",
|
|
"type": "url",
|
|
"url": "https://changedetection.io/",
|
|
"description": "Open-source change-monitoring system for tracking updates on websites over time.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Self-hosted page change monitoring",
|
|
"input": "URL and monitoring rules",
|
|
"output": "Diffs and notifications when monitored content changes",
|
|
"opsec": "active",
|
|
"opsecNote": "Generates recurring requests to monitored targets; tune intervals for OPSEC.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "UPcheck",
|
|
"type": "url",
|
|
"url": "https://upcheck.online/",
|
|
"description": "Website uptime checker that tests if a site is currently accessible.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Quick site availability checks",
|
|
"input": "URL/domain",
|
|
"output": "Up/down status",
|
|
"opsec": "passive",
|
|
"opsecNote": "No identification risk; passive status check only",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Follow That Page",
|
|
"type": "url",
|
|
"url": "https://www.followthatpage.com/",
|
|
"description": "Website monitoring service that checks pages for changes and sends alerts when tracked content updates. Supports keyword-based notifications for focused monitoring.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Tracking updates on specific web pages by keyword",
|
|
"input": "Target page URL and optional keyword filters",
|
|
"output": "Email alerts showing detected page changes",
|
|
"opsec": "passive",
|
|
"opsecNote": "Monitoring requests are performed by Follow That Page infrastructure rather than directly from the investigator's workstation.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Urlwatch",
|
|
"type": "url",
|
|
"url": "https://github.com/thp/urlwatch",
|
|
"description": "Open-source Python CLI tool for monitoring webpages and feeds for changes. Supports multiple filters, reporters, and scheduled checks via local automation.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Self-hosted web page change monitoring automation",
|
|
"input": "URLs, feeds, and local watch configuration",
|
|
"output": "Diffs and alerts through email, console, or integrations",
|
|
"opsec": "passive",
|
|
"opsecNote": "Can run locally or on controlled infrastructure, allowing investigators to manage request origin and monitoring cadence.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "WatchThatPage",
|
|
"type": "url",
|
|
"url": "https://watchthatpage.com/",
|
|
"description": "Web-based page monitoring platform that detects content changes and notifies users by email. Useful for tracking updates on websites without RSS feeds.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Monitoring static web pages for updates over time",
|
|
"input": "Web page URL and watch configuration",
|
|
"output": "Email notifications and change history snapshots",
|
|
"opsec": "passive",
|
|
"opsecNote": "Page checks originate from WatchThatPage systems instead of directly from the investigator.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ChangeDetect",
|
|
"type": "url",
|
|
"url": "https://changedetection.io/",
|
|
"description": "Open-source website change detection platform with both self-hosted and hosted options. Supports visual diffs, notifications, and automation workflows.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Flexible page change monitoring with self-hosted control",
|
|
"input": "Target URL and optional monitoring rules/selectors",
|
|
"output": "Change alerts, snapshots, and webhook/integration notifications",
|
|
"opsec": "passive",
|
|
"opsecNote": "When self-hosted, investigators control infrastructure and request origin; hosted mode proxies checks through provider systems.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Social Analysis",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Google Trends",
|
|
"type": "url",
|
|
"url": "https://trends.google.com/trends/",
|
|
"description": "Google's search trend analysis tool for tracking keyword popularity and comparing search interest over time.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Search trend analysis and keyword research",
|
|
"input": "Keywords or domains",
|
|
"output": "Trend data and comparative interest graphs",
|
|
"opsec": "passive",
|
|
"opsecNote": "Google-tracked; your queries may be associated with your account or IP",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "DNSSEC",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "DNSSEC Analyzer",
|
|
"type": "url",
|
|
"url": "https://dnssec-analyzer.verisignlabs.com/",
|
|
"description": "Verisign's DNSSEC validation tool that checks the DNSSEC chain of trust for a domain.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "DNSSEC chain-of-trust validation",
|
|
"input": "Domain names",
|
|
"output": "DNSSEC validation status and chain details",
|
|
"opsec": "passive",
|
|
"opsecNote": "No identification risk; passive DNS lookup",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DNSViz",
|
|
"type": "url",
|
|
"url": "https://dnsviz.net/",
|
|
"description": "DNS and DNSSEC analysis platform that visualizes delegation chains and cryptographic validation paths. Helps diagnose trust and signing issues in domain configurations.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Visual DNSSEC validation and DNS misconfiguration analysis",
|
|
"input": "Domain name",
|
|
"output": "DNS resolution graphs, DNSSEC status, and validation diagnostics",
|
|
"opsec": "passive",
|
|
"opsecNote": "Analysis runs against public DNS infrastructure without direct interaction with domain owners.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Vulnerabilities",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Scanners",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Sn1per (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/1N3/Sn1per",
|
|
"description": "Automated reconnaissance and penetration testing framework combining multiple scanning tools for full-scope target enumeration.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Full-scope pentest automation and recon",
|
|
"input": "Target domains or IPs",
|
|
"output": "Recon data, open ports, vulnerabilities, and footprinting results",
|
|
"opsec": "active",
|
|
"opsecNote": "Generates significant network traffic and alerts; high IDS/WAF detection risk",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Online Nikto scanner",
|
|
"type": "url",
|
|
"url": "https://nikto.online/",
|
|
"description": "Hosted version of the Nikto web server scanner for identifying vulnerabilities, misconfigurations, and exposed files.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Web server vulnerability scanning",
|
|
"input": "URLs",
|
|
"output": "Vulnerability and misconfiguration reports",
|
|
"opsec": "active",
|
|
"opsecNote": "Generates noisy scan traffic visible in target server logs; likely to trigger WAF/IDS alerts",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Web Data Exposure Scanner (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/eduardoit/web-data-exposure-scanner",
|
|
"description": "Open-source scanner for detecting exposed web application data and sensitive file disclosures on web servers.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Detecting exposed sensitive data on web servers",
|
|
"input": "URLs/domains",
|
|
"output": "Exposed data findings",
|
|
"opsec": "active",
|
|
"opsecNote": "Active scanning may generate server logs and trigger alerts",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Disclosure Sites",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Zone-H.org",
|
|
"type": "url",
|
|
"url": "https://zone-h.org/archive",
|
|
"description": "Archive of reported website defacements and related incident metadata maintained by the Zone-H community.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Historical tracking of website defacement incidents",
|
|
"input": "Search terms, domains, or browsing archive filters",
|
|
"output": "Defacement records with timestamps and mirrored evidence",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses a third-party archive and does not require direct interaction with target infrastructure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "RobotsDisallowed",
|
|
"type": "url",
|
|
"url": "https://github.com/danielmiessler/RobotsDisallowed",
|
|
"description": "Curated wordlist of top disallowed paths harvested from robots.txt files across high-traffic websites.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "robots.txt enumeration and directory discovery",
|
|
"input": "Used as wordlist input for directory brute-forcing",
|
|
"output": "Directory path wordlist",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive wordlist only; no requests made to target during list use",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Tools",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Belati (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/aancw/Belati",
|
|
"description": "Open-source OSINT data collection and automation framework for gathering information from multiple sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Multi-source OSINT collection automation",
|
|
"input": "Domains and targets",
|
|
"output": "Aggregated OSINT data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Primarily passive; behavior depends on configured modules",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Burp Suite (T)",
|
|
"type": "url",
|
|
"url": "https://portswigger.net/burp",
|
|
"description": "Industry-standard web application security testing platform for manual and automated vulnerability assessment.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Web application penetration testing",
|
|
"input": "Web applications and URLs",
|
|
"output": "Security findings, intercepted traffic, and vulnerability reports",
|
|
"opsec": "active",
|
|
"opsecNote": "Full active scanning; generates extensive server logs and may trigger WAF/IDS alerts",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "EyeWitness (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/ChrisTruncer/EyeWitness",
|
|
"description": "Open-source tool for automated website screenshotting, service header collection, and default credential identification.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Visual site enumeration and credential identification",
|
|
"input": "URL lists",
|
|
"output": "Screenshots, headers, and default credential matches",
|
|
"opsec": "passive",
|
|
"opsecNote": "HTTP requests visible in target server logs; screenshots leave network footprint",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Hunting-New-Registered-Domains (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/gfek/Hunting-New-Registered-Domains",
|
|
"description": "Open-source tool for identifying newly registered domains matching patterns, useful for phishing and brand threat detection.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Phishing domain detection and brand threat monitoring",
|
|
"input": "Domain patterns or keywords",
|
|
"output": "List of newly registered matching domains",
|
|
"opsec": "passive",
|
|
"opsecNote": "WHOIS queries may create observable patterns; otherwise passive",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "International Domain Name Conversion Tool",
|
|
"type": "url",
|
|
"url": "https://mct.verisign-grs.com/",
|
|
"description": "Verisign's IDN/Punycode bidirectional converter for translating international domain names to and from ASCII-compatible encoding.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IDN and Punycode domain analysis",
|
|
"input": "International or Punycode domain names",
|
|
"output": "Converted domain equivalents",
|
|
"opsec": "passive",
|
|
"opsecNote": "No identification risk; local conversion tool",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Online Nikto scanner",
|
|
"type": "url",
|
|
"url": "https://nikto.online/",
|
|
"description": "Hosted version of the Nikto web server scanner for identifying vulnerabilities, misconfigurations, and exposed files.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Web server vulnerability scanning",
|
|
"input": "URLs",
|
|
"output": "Vulnerability and misconfiguration reports",
|
|
"opsec": "active",
|
|
"opsecNote": "Generates noisy scan traffic visible in target server logs; likely to trigger WAF/IDS alerts",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Report Malicious Sites",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Windows Defender Security Intelligence (WDSI)",
|
|
"type": "url",
|
|
"url": "https://www.microsoft.com/en-us/wdsi",
|
|
"description": "Microsoft's security intelligence portal for reporting malicious URLs and checking Windows Defender threat assessments.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Reporting malicious sites to Microsoft and checking URL threat status",
|
|
"input": "URLs",
|
|
"output": "Threat status and submission confirmation",
|
|
"opsec": "passive",
|
|
"opsecNote": "Microsoft-tracked; submissions aggregated for threat intelligence",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Safe Browsing",
|
|
"type": "url",
|
|
"url": "https://safebrowsing.google.com/",
|
|
"description": "Google's phishing and malware reporting portal for submitting suspicious URLs for review.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Reporting malicious sites to Google and checking URL safety status",
|
|
"input": "URLs",
|
|
"output": "Safety status and submission confirmation",
|
|
"opsec": "passive",
|
|
"opsecNote": "Google-tracked; searches and submissions aggregated at scale",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Cloud Infrastructure",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "AWS Enumeration",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "AWSBucketDump (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/jordanpotti/AWSBucketDump",
|
|
"description": "Python tool that enumerates AWS S3 buckets and optionally downloads accessible objects using keyword and pattern-based discovery.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Targeted S3 bucket discovery and object collection",
|
|
"input": "AWS account naming patterns, keywords, and optional wordlists",
|
|
"output": "Discovered bucket names and downloadable object listings/files",
|
|
"opsec": "active",
|
|
"opsecNote": "Actively sends requests to S3 endpoints and can download objects.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "cloud_enum (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/initstring/cloud_enum",
|
|
"description": "Multi-cloud enumeration tool that looks for exposed AWS, Azure, and GCP storage assets from target naming patterns.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Rapid discovery of cloud storage exposure across major providers",
|
|
"input": "Company names, domains, and custom keywords/wordlists",
|
|
"output": "Potentially exposed cloud storage resources by provider",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs direct enumeration requests against cloud provider endpoints.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Subfinder (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/projectdiscovery/subfinder",
|
|
"description": "Fast passive subdomain discovery utility that aggregates results from many curated OSINT and API-backed sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Passive subdomain enumeration for cloud asset inventorying",
|
|
"input": "Domain name and optional API credentials for data sources",
|
|
"output": "Resolved and unresolved subdomain candidates",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses third-party data sources by default and avoids active probing unless paired with other tools.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Azure/GCP Discovery",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "AADInternals (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/Gerenios/AADInternals",
|
|
"description": "PowerShell toolkit for Azure AD and Entra ID assessment, including tenant reconnaissance and hybrid identity attack-path analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Deep Azure AD reconnaissance and security assessment",
|
|
"input": "Tenant identifiers, domain names, and account context",
|
|
"output": "Tenant/user intelligence, configuration findings, and attack-path indicators",
|
|
"opsec": "active",
|
|
"opsecNote": "Queries Microsoft identity services directly and may generate tenant-visible activity.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "GCPBucketBrute (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/RhinoSecurityLabs/GCPBucketBrute",
|
|
"description": "Google Cloud Storage bucket enumeration utility for identifying publicly accessible or weakly protected buckets.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Enumerating likely GCS bucket names at scale",
|
|
"input": "Target company names, domains, and custom wordlists",
|
|
"output": "Valid bucket names with access status and findings",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs direct requests against GCS endpoints and can be detected in provider logs.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MicroBurst (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/NetSPI/MicroBurst",
|
|
"description": "PowerShell collection focused on Azure security assessment, including subscription discovery and cloud service misconfiguration checks.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Azure subscription and service-level exposure testing",
|
|
"input": "Azure tenant/subscription context and optional credentials",
|
|
"output": "Recon data and security findings for Azure resources",
|
|
"opsec": "active",
|
|
"opsecNote": "Runs active checks against Azure control/data plane endpoints.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ROADtools (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/dirkjanm/roadtools",
|
|
"description": "Azure AD exploration framework for dumping tenant objects, principals, and permissions to support attack-path and privilege analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Enumerating Azure AD objects and privilege relationships",
|
|
"input": "Azure AD tenant context and authentication tokens/credentials",
|
|
"output": "Users, groups, applications, roles, and privilege mappings",
|
|
"opsec": "active",
|
|
"opsecNote": "Interacts directly with Microsoft Graph and Azure AD endpoints.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Stormspotter (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/Azure/Stormspotter",
|
|
"description": "Graph-based Azure reconnaissance platform that maps cloud attack paths and trust relationships using Neo4j-backed visualization.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Visual analysis of Azure attack paths and privilege chains",
|
|
"input": "Azure subscription/tenant metadata collected by collectors",
|
|
"output": "Interactive graph of Azure identities, resources, and attack edges",
|
|
"opsec": "active",
|
|
"opsecNote": "Collection phase performs authenticated queries against Azure APIs.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "S3/Blob Storage",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "BucketLoot (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/redhuntlabs/BucketLoot",
|
|
"description": "Open-source cloud bucket discovery utility with limited current documentation and unclear maintenance signals.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Supplemental bucket discovery when validating legacy workflows",
|
|
"input": "Bucket name patterns and target-related keywords",
|
|
"output": "Candidate bucket names and accessible resource indications",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "Insufficient current documentation to classify behavior confidently.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "goblob (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/Macmod/goblob",
|
|
"description": "Go-based Azure blob storage enumeration utility designed for fast discovery of publicly exposed containers and blobs.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Enumerating Azure blob container exposure quickly",
|
|
"input": "Target naming patterns and optional custom wordlists",
|
|
"output": "Discovered blob storage endpoints and access results",
|
|
"opsec": "active",
|
|
"opsecNote": "Sends direct requests to Azure storage endpoints during enumeration.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "lazys3 (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/nahamsec/lazys3",
|
|
"description": "S3 bucket brute-forcing utility that generates candidate names from permutations and checks bucket accessibility.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick permutation-based S3 bucket name discovery",
|
|
"input": "Base target keywords and optional custom wordlists",
|
|
"output": "Potential S3 buckets with accessible bucket responses",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs direct requests against AWS S3 bucket endpoints.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Public Buckets",
|
|
"type": "url",
|
|
"url": "https://buckets.grayhatwarfare.com/",
|
|
"description": "Search interface for publicly indexed cloud object storage buckets and files across multiple providers.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Investigating exposed bucket contents without running local scanners",
|
|
"input": "Keywords, domains, filenames, and object metadata filters",
|
|
"output": "Indexed public bucket/object matches with downloadable links",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries an existing index rather than probing target infrastructure directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "S3Scanner (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/sa7mon/s3scanner",
|
|
"description": "Command-line scanner for enumerating and checking S3 bucket misconfigurations across AWS and compatible object storage services.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Validating bucket exposure and permissions across S3-compatible targets",
|
|
"input": "Bucket names, generated candidates, or wordlist-driven targets",
|
|
"output": "Bucket existence and permission states (list/read/write/public indicators)",
|
|
"opsec": "active",
|
|
"opsecNote": "Actively queries cloud storage endpoints and leaves provider-side request logs.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Cloud Configuration Analysis",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Checkov (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/bridgecrewio/checkov",
|
|
"description": "Infrastructure-as-code security scanner that checks Terraform, CloudFormation, Kubernetes, and other cloud configs against policy rules.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Shift-left cloud misconfiguration detection in IaC repositories",
|
|
"input": "IaC source files, templates, and configuration manifests",
|
|
"output": "Policy violations with severity and remediation context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Analyzes local code/config files without probing target cloud environments directly.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Cloud Custodian (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/cloud-custodian/cloud-custodian",
|
|
"description": "Policy-as-code engine for cloud governance and security that can detect and remediate risky cloud configurations.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Automated cloud governance and continuous configuration enforcement",
|
|
"input": "Cloud account credentials and YAML policy definitions",
|
|
"output": "Matched resources, policy findings, and optional remediation actions",
|
|
"opsec": "active",
|
|
"opsecNote": "Uses cloud APIs directly and can trigger enforcement actions when configured.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Prowler (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/prowler-cloud/prowler",
|
|
"description": "Cloud security posture and compliance assessment framework covering AWS, Azure, GCP, Kubernetes, and SaaS surfaces.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Broad cloud security and compliance baseline assessments",
|
|
"input": "Cloud account credentials, profiles, and optional compliance benchmarks",
|
|
"output": "Findings by control/check with compliance mapping and export options",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs authenticated API checks against cloud environments and logs activity.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ScoutSuite (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/nccgroup/ScoutSuite",
|
|
"description": "Multi-cloud auditing tool that inventories cloud resources and highlights security risks in an interactive HTML report.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Snapshot-style multi-cloud security posture reviews",
|
|
"input": "Cloud account credentials and provider-specific profile configuration",
|
|
"output": "Interactive audit report with categorized misconfiguration findings",
|
|
"opsec": "active",
|
|
"opsecNote": "Collects cloud metadata directly from provider APIs using granted credentials.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Steampipe (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/turbot/steampipe",
|
|
"description": "SQL interface over cloud APIs and services, enabling ad hoc querying of AWS, Azure, GCP, and many other data sources.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "SQL-driven cloud inventory and security query workflows",
|
|
"input": "SQL queries and plugin connections to cloud/provider APIs",
|
|
"output": "Tabular query results from live cloud metadata",
|
|
"opsec": "active",
|
|
"opsecNote": "Executes API-backed queries against connected cloud accounts.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "SaaS Footprinting",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Amass (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/owasp-amass/amass",
|
|
"description": "Advanced attack surface mapping framework for DNS and subdomain enumeration with graph correlation and extensive data-source support.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Comprehensive external attack-surface and subdomain mapping",
|
|
"input": "Domain names, ASN data, CIDRs, and optional API credentials",
|
|
"output": "Correlated graph of domains, subdomains, infrastructure, and relationships",
|
|
"opsec": "active",
|
|
"opsecNote": "Supports both passive and active techniques, including DNS probing and brute-force modes.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "dnsrecon (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/darkoperator/dnsrecon",
|
|
"description": "DNS enumeration script for recon workflows, supporting record discovery, zone transfer checks, brute-force, and reverse lookups.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Detailed DNS reconnaissance and validation",
|
|
"input": "Domain names, name servers, and optional DNS wordlists",
|
|
"output": "DNS records, discovered hosts, and transfer/bruteforce findings",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs direct DNS queries and active enumeration techniques against target infrastructure.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "SpiderFoot (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/smicallef/spiderfoot",
|
|
"description": "Automated OSINT collection tool with 200+ modules for reconnaissance and threat intelligence.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Automated recon, attack surface mapping, threat intelligence",
|
|
"input": "Domain, IP, email, name, phone, subnet",
|
|
"output": "Correlated intelligence graph, structured findings across modules",
|
|
"opsec": "active",
|
|
"opsecNote": "Some modules actively probe targets. Review module settings before running.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Sublist3r (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/aboul3la/Sublist3r",
|
|
"description": "Passive subdomain enumeration tool that aggregates subdomains from public search engines and certificate-related sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick passive subdomain discovery for reconnaissance",
|
|
"input": "Domain name",
|
|
"output": "Discovered subdomain list and optional live-host checks",
|
|
"opsec": "passive",
|
|
"opsecNote": "Primarily uses third-party data sources and search interfaces for discovery.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "theHarvester (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/laramies/theHarvester",
|
|
"description": "Reconnaissance tool for gathering emails, domains, hosts, and employee-related intelligence from public search and data sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Email and host discovery tied to a target organization",
|
|
"input": "Domain names, company names, and selected data-source modules",
|
|
"output": "Emails, hosts, domains, IPs, and related reconnaissance artifacts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries third-party search engines and APIs. Does not contact the target directly.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "IP & MAC Address",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Geolocation",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "MaxMind Demo",
|
|
"type": "url",
|
|
"url": "https://www.maxmind.com/en/home",
|
|
"description": "Web-based IP geolocation demo with location, ASN, and network data from MaxMind's GeoIP database.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick IP geolocation",
|
|
"input": "IP address",
|
|
"output": "Country, region, city, coordinates, ASN",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries MaxMind; submissions logged.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "IPv4/IPv6 lists by country code",
|
|
"type": "url",
|
|
"url": "https://github.com/ipverse/",
|
|
"description": "Database of IPv4 and IPv6 address ranges organized by country for geographic IP filtering.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Country-level IP enumeration",
|
|
"input": "Country code",
|
|
"output": "IP ranges in CIDR notation",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of public IP allocations.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "IP2Location.com",
|
|
"type": "url",
|
|
"url": "https://www.ip2location.com/demo",
|
|
"description": "Commercial IP geolocation service with free demo and database. Provides location, proxy detection, and network data.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Accurate geolocation with proxy detection",
|
|
"input": "IP address",
|
|
"output": "Location, ASN, proxy type, VPN status, timezone",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive database lookup; free tier limited.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "IP Fingerprints",
|
|
"type": "url",
|
|
"url": "https://ipfingerprints.com/",
|
|
"description": "Reverse IP lookup service identifying all domains hosted on a given IP address.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Find domains on shared hosting",
|
|
"input": "IP address",
|
|
"output": "List of domains on IP",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses public DNS reverse lookup data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DB-IP",
|
|
"type": "url",
|
|
"url": "https://db-ip.com/",
|
|
"description": "Lightweight IP geolocation API covering 46M+ IPv4/IPv6 blocks with city-level accuracy.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Accurate IP geolocation with developer API",
|
|
"input": "IP address",
|
|
"output": "Location, timezone, ISP, coordinates",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive database lookup; free API rate limited.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "IP Location Finder",
|
|
"type": "url",
|
|
"url": "https://www.iplocation.net/",
|
|
"description": "Web-based tool for IP geolocation with maps and detailed location information.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick IP location with maps",
|
|
"input": "IP address",
|
|
"output": "City, coordinates, ISP, hostname",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup; no notification to target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Info Sniper",
|
|
"type": "url",
|
|
"url": "https://www.infosniper.net/",
|
|
"description": "Multi-field reverse OSINT tool for IP, email, phone lookups with social media enumeration.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Multi-field reverse lookup (IP/email/phone)",
|
|
"input": "IP, email, or phone",
|
|
"output": "Associated accounts and social profiles",
|
|
"opsec": "passive",
|
|
"opsecNote": "Correlates public data; paid features available.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "utrace",
|
|
"type": "url",
|
|
"url": "https://en.utrace.de/",
|
|
"description": "IP geolocation and reverse DNS lookup tool with network traceroute visualization.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IP location and traceroute",
|
|
"input": "IP or hostname",
|
|
"output": "Location, ASN, reverse DNS, route path",
|
|
"opsec": "active",
|
|
"opsecNote": "Traceroute is active; geolocation is passive.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Host / Port Discovery",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "urlscan.io",
|
|
"type": "url",
|
|
"url": "https://urlscan.io/search/#*",
|
|
"description": "Website scanner analyzing URLs and domains for malicious content with infrastructure intelligence.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "URL/domain scanning for malware and phishing",
|
|
"input": "URL or domain",
|
|
"output": "Screenshot, DNS, IP, certificates, cookies",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive scanning; no direct contact with target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Spyse",
|
|
"type": "url",
|
|
"url": "https://spyse.com/search/ip",
|
|
"description": "Internet assets search engine collecting and analyzing public data for attack surface management.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Internet asset discovery and reconnaissance",
|
|
"input": "IP, domain, email, organization",
|
|
"output": "Subdomains, services, vulnerabilities, data breaches",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive data collection; requires account for full access.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Shodan",
|
|
"type": "url",
|
|
"url": "https://www.shodan.io/",
|
|
"description": "Search engine for internet-connected devices, providing visibility into exposed services and vulnerabilities.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Find exposed IoT and network services",
|
|
"input": "IP, port, service type",
|
|
"output": "Service banners, open ports, vulnerabilities, location",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive data collection; InternetDB API free for non-commercial use.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Netlas.io",
|
|
"type": "url",
|
|
"url": "https://netlas.io/",
|
|
"description": "Comprehensive internet scanning platform with OSINT, DNS, and WHOIS data. Free tier: 50 requests/day.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Internet asset reconnaissance with web, DNS, WHOIS",
|
|
"input": "IP, domain, ASN",
|
|
"output": "Open ports, services, certificates, DNS records, WHOIS",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive scanning with account-based rate limits.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Portmap",
|
|
"type": "url",
|
|
"url": "https://portmap.com/",
|
|
"description": "Port mapping tool that scans for open ports and services on target IP addresses.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Port scanning and service discovery",
|
|
"input": "IP address or hostname",
|
|
"output": "Open ports, service types, versions",
|
|
"opsec": "active",
|
|
"opsecNote": "Active port scanning probes target network.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Scans.io",
|
|
"type": "url",
|
|
"url": "https://scans.io/",
|
|
"description": "Archive of internet-wide scan data including censys scans and other reconnaissance data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Historical internet scan data access",
|
|
"input": "IP or domain",
|
|
"output": "Historical scan results, service history",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive access to historical scanning archives.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Nmap (T)",
|
|
"type": "url",
|
|
"url": "https://nmap.org/download.html",
|
|
"description": "Open-source network mapping and port scanning tool with OS detection and service version identification.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Network reconnaissance and port scanning",
|
|
"input": "IP range or hostname",
|
|
"output": "Open ports, OS type, service versions, MAC addresses",
|
|
"opsec": "active",
|
|
"opsecNote": "Active scanning tool; generates network traffic.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Online Port scanner",
|
|
"type": "url",
|
|
"url": "https://portscanner.online/",
|
|
"description": "Web-based port scanner checking open ports on target IP addresses without installation.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick port scanning without tools",
|
|
"input": "IP address and port range",
|
|
"output": "Open ports, response times",
|
|
"opsec": "active",
|
|
"opsecNote": "Active port scanning; limited to common ports on free tier.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Internet Census Search",
|
|
"type": "url",
|
|
"url": "https://www.exfiltrated.com/querystart.php",
|
|
"description": "Search interface for the Shodan-like internet census data and open services.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Search open services and devices",
|
|
"input": "Service type, IP range, port",
|
|
"output": "List of exposed services and IPs",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive data search of known internet census.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Criminal IP Search",
|
|
"type": "url",
|
|
"url": "https://www.criminalip.io/",
|
|
"description": "IP reputation and threat intelligence platform analyzing malicious IP addresses and attacks.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "IP reputation and malicious activity analysis",
|
|
"input": "IP address",
|
|
"output": "Threat reports, activity logs, attack types",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive threat intelligence lookup.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Scanless (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/vesche/scanless",
|
|
"description": "Command-line tool for port scanning without leaving traces on target using third-party services.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Stealthy port scanning via proxies",
|
|
"input": "IP and port",
|
|
"output": "Open port results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Routes scans through third-party services for stealth.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "BinaryEdge (R)",
|
|
"type": "url",
|
|
"url": "https://www.binaryedge.io/",
|
|
"description": "Commercial security research platform with internet-wide scanning and module-based detection.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Commercial internet threat intelligence",
|
|
"input": "IP, domain, query",
|
|
"output": "Services, vulnerabilities, threat modules",
|
|
"opsec": "passive",
|
|
"opsecNote": "Commercial threat intelligence requiring subscription.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Masscan (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/robertdavidgraham/masscan",
|
|
"description": "Ultra-fast TCP port scanner designed for scanning large IP ranges and entire networks.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Large-scale network port scanning",
|
|
"input": "IP range",
|
|
"output": "Open ports, response times",
|
|
"opsec": "active",
|
|
"opsecNote": "Active scanner; generates significant network traffic.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "IPv4",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "ASlookup.com",
|
|
"type": "url",
|
|
"url": "https://aslookup.com/",
|
|
"description": "BGP and autonomous system lookup tool for finding IP ranges and ownership information.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "BGP and ASN lookup",
|
|
"input": "ASN or IP address",
|
|
"output": "IP ranges, organization, peering info",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of public BGP data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Port scanner Online",
|
|
"type": "url",
|
|
"url": "https://portscanner.online/",
|
|
"description": "Simple web-based port scanner for checking common ports on target IPs.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick port availability checks",
|
|
"input": "IP and port",
|
|
"output": "Port status (open/closed)",
|
|
"opsec": "active",
|
|
"opsecNote": "Active probing; may be logged by firewalls.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Onyphe",
|
|
"type": "url",
|
|
"url": "https://www.onyphe.io/",
|
|
"description": "Cyber defense search engine with internet scanning, threat intelligence, and attack surface management.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Internet asset discovery and threat intel",
|
|
"input": "IP, domain, CVE",
|
|
"output": "Services, vulnerabilities, certificates, datasources",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive intelligence from public sources.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "IPv4 CIDR Report",
|
|
"type": "url",
|
|
"url": "https://www.cidr-report.org/as2.0/",
|
|
"description": "Tool for analyzing IPv4 CIDR blocks and finding contained IP addresses and subnets.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "CIDR block analysis and subnet enumeration",
|
|
"input": "CIDR block",
|
|
"output": "IP ranges, subnet breakdown",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive analysis of IP allocation data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Reverse.report",
|
|
"type": "url",
|
|
"url": "https://reverse.report/",
|
|
"description": "Comprehensive reverse lookup tool for IP to domain, email, and phone number associations.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Reverse IP and domain lookups",
|
|
"input": "IP address or domain",
|
|
"output": "Associated domains, subdomains, history",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of DNS and WHOIS data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Team Cymru IP to ASN",
|
|
"type": "url",
|
|
"url": "https://asn.cymru.com/",
|
|
"description": "IP to ASN mapping tool providing autonomous system ownership and prefix information.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IP to ASN mapping",
|
|
"input": "IP address",
|
|
"output": "ASN, organization, prefix",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of BGP and WHOIS data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "IP to ASN DB",
|
|
"type": "url",
|
|
"url": "https://iptoasn.com/",
|
|
"description": "Database and API service for looking up which ASN owns a given IP address.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IP to ASN lookup with historical data",
|
|
"input": "IP address",
|
|
"output": "ASN, organization, prefix, company info",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive database lookup.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Hacker Target - Reverse DNS",
|
|
"type": "url",
|
|
"url": "https://hackertarget.com/reverse-dns-lookup/",
|
|
"description": "Reverse DNS lookup tool and API finding domain names associated with IP addresses.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Reverse DNS lookup of IP addresses",
|
|
"input": "IP address or range",
|
|
"output": "Associated domains and PTR records",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive DNS lookup; includes free API tier.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "IPv6",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "IPv6 CIDR Report",
|
|
"type": "url",
|
|
"url": "https://www.cidr-report.org/v6/as2.0/",
|
|
"description": "CIDR block analysis tool for IPv6 address ranges and subnet enumeration.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IPv6 CIDR block analysis",
|
|
"input": "IPv6 CIDR block",
|
|
"output": "IPv6 ranges, subnet breakdown",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive analysis of IPv6 allocation data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "BGP",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Hurricane Electric BGP Toolkit",
|
|
"type": "url",
|
|
"url": "https://bgp.he.net/",
|
|
"description": "BGP and network routing analysis tools including AS to prefix lookup and BGP prefix information.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "BGP analysis and routing intelligence",
|
|
"input": "ASN, IP range, or prefix",
|
|
"output": "BGP routes, peering, organization info",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of public BGP data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "BGP Malicious Content Ranking",
|
|
"type": "url",
|
|
"url": "https://bgpranking.circl.lu/",
|
|
"description": "Platform ranking ASNs and BGP prefixes by malicious content and security threats.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Identify malicious ASNs and networks",
|
|
"input": "ASN or prefix",
|
|
"output": "Threat ranking, malicious activity metrics",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive threat intelligence from public sources.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "PeeringDB",
|
|
"type": "url",
|
|
"url": "https://www.peeringdb.com/advanced_search",
|
|
"description": "Database of internet exchange points, member networks, and AS relationships for network mapping.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Internet peering and AS relationship mapping",
|
|
"input": "ASN, organization, or IX",
|
|
"output": "Peering relationships, exchange points, contacts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of public peering data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "BGP Tools",
|
|
"type": "url",
|
|
"url": "https://www.bgp4.as/tools",
|
|
"description": "Collection of BGP analysis and AS number lookup tools for network intelligence.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "BGP routing and AS analysis",
|
|
"input": "ASN, IP, or prefix",
|
|
"output": "Routes, prefixes, organizations",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive analysis of public BGP data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Reputation",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "IP Void",
|
|
"type": "url",
|
|
"url": "https://www.ipvoid.com/",
|
|
"description": "IP reputation and threat intelligence service analyzing blacklist status and security risks.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Check IP reputation and blacklist status",
|
|
"input": "IP address",
|
|
"output": "Threat score, blacklist status, reports",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive reputation lookup; account needed for full data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ExoneraTor",
|
|
"type": "url",
|
|
"url": "https://exonerator.torproject.org/",
|
|
"description": "Tool for checking if an IP address belonged to Tor at a specific date.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Verify Tor relay membership by date",
|
|
"input": "IP address and date",
|
|
"output": "Tor exit/entry node status confirmation",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive historical Tor relay lookup from public archives.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Grey Noise",
|
|
"type": "url",
|
|
"url": "https://viz.greynoise.io/",
|
|
"description": "Platform for analyzing internet background noise and identifying benign scanning activity.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Distinguish malicious from benign internet activity",
|
|
"input": "IP address",
|
|
"output": "Classification, scanner type, threat assessment",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive threat intelligence; free tier available.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Blacklists",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Blocklist.de",
|
|
"type": "url",
|
|
"url": "https://www.blocklist.de/en/index.html",
|
|
"description": "Community-contributed blocklist of IP addresses involved in attacks and malicious activity.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Check IP blacklist status",
|
|
"input": "IP address",
|
|
"output": "Blacklist status, attack types logged",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of community blocklist.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DShield API",
|
|
"type": "url",
|
|
"url": "https://isc.sans.edu/api/",
|
|
"description": "API and database of security events and IPs involved in attacks monitored by SANS.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Query IPs involved in attacks",
|
|
"input": "IP address",
|
|
"output": "Attack reports, threat activity",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive threat intelligence from SANS monitored networks.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FireHOL IP Lists ",
|
|
"type": "url",
|
|
"url": "https://iplists.firehol.org/",
|
|
"description": "Collection of firewall-friendly IP lists for blocking malicious and spam sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Block malicious/spam IP sources",
|
|
"input": "IP address or list download",
|
|
"output": "Blacklist membership status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of public IP reputation lists.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Project Honey Pot",
|
|
"type": "url",
|
|
"url": "https://www.projecthoneypot.org/list_of_ips.php",
|
|
"description": "Global honeypot network collecting spam and attack data with IP reputation service.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Check IP for spam and attack history",
|
|
"input": "IP address",
|
|
"output": "Threat score, spam reports, attack activity",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of honeypot-collected threat data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Neighbor Domains",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "IP Fingerprints - Reverse IP Lookup",
|
|
"type": "url",
|
|
"url": "https://ipfingerprints.com/reverseip.php",
|
|
"description": "Find all domains hosted on a shared IP address through reverse IP lookup.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Find domains on shared hosting",
|
|
"input": "IP address",
|
|
"output": "List of domains on IP",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive DNS reverse lookup.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Bing IP Search (D)",
|
|
"type": "url",
|
|
"url": "https://www.bing.com/search?q=ip%3A8.8.8.8",
|
|
"description": "Bing search operator for finding domains and subdomains hosted on a specific IP address.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Find domains on IP using Bing index",
|
|
"input": "IP address",
|
|
"output": "Domains indexed by Bing on that IP",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive search using Bing's public index.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "TCP/IP Utils - Domain Neighbors",
|
|
"type": "url",
|
|
"url": "https://dnslytics.com/",
|
|
"description": "Find all domains on the same IP and subdomain information via reverse IP lookups.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Identify related domains on same IP",
|
|
"input": "Domain or IP",
|
|
"output": "Neighbor domains, IP info",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive DNS and IP lookup data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MyIPNeighbors",
|
|
"type": "url",
|
|
"url": "https://www.my-ip-neighbors.com/",
|
|
"description": "Reverse IP lookup tool for discovering all domains and subdomains on an IP address.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Find all domains on same shared IP",
|
|
"input": "IP address",
|
|
"output": "List of domains on IP, subdomains",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive DNS reverse lookup.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Protected by Cloud Services",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "CloudFlare Watch",
|
|
"type": "url",
|
|
"url": "https://www.crimeflare.com/",
|
|
"description": "Tool for identifying and analyzing websites protected by Cloudflare's CDN and security services.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Identify Cloudflare-protected sites",
|
|
"input": "Domain or IP",
|
|
"output": "Cloudflare status, origin IP (if discoverable)",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of Cloudflare configurations.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "CloudFail (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/m0rtem/CloudFail",
|
|
"description": "Tool for finding origin IPs of Cloudflare-protected websites through enumeration techniques.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Bypass Cloudflare to find origin IP",
|
|
"input": "Domain protected by Cloudflare",
|
|
"output": "Origin IP address (if discoverable)",
|
|
"opsec": "active",
|
|
"opsecNote": "Uses active enumeration and DNS history techniques.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Wireless Network Info",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "WiGLE: Wireless Network Mapping",
|
|
"type": "url",
|
|
"url": "https://wigle.net/",
|
|
"description": "Global database of wireless networks (WiFi, Bluetooth, cellular) with mapping and signal strength data.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Map wireless networks and find signal coverage",
|
|
"input": "Location, SSID, or BSSID",
|
|
"output": "Network locations, signal maps, network details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Crowdsourced wireless network data; passive lookup.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OpenCellid: Database of Cell Towers",
|
|
"type": "url",
|
|
"url": "https://opencellid.org/",
|
|
"description": "Open database of cellular tower locations and coverage for mobile network geolocation.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Find cellular tower locations and coverage",
|
|
"input": "Cell tower ID or location",
|
|
"output": "Tower coordinates, operator, coverage area",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of public cellular network data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Network Analysis Tools",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Wireshark",
|
|
"type": "url",
|
|
"url": "https://www.wireshark.org/download.html",
|
|
"description": "Open-source network packet analyzer for deep packet inspection and network troubleshooting.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Network packet analysis and protocol debugging",
|
|
"input": "Network traffic capture file",
|
|
"output": "Detailed packet analysis, protocol breakdown",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "Tool-dependent; passive capture or active sniffing possible.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "NetworkMiner",
|
|
"type": "url",
|
|
"url": "https://www.netresec.com/?page=Networkminer",
|
|
"description": "Passive network forensics tool for extracting files and data from network traffic captures.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Network forensics and file extraction from traffic",
|
|
"input": "PCAP network traffic files",
|
|
"output": "Extracted files, metadata, network sessions",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive analysis of already-captured traffic.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Packet Total",
|
|
"type": "url",
|
|
"url": "https://www.packettotal.com/",
|
|
"description": "Online platform for uploading and analyzing network packet captures (PCAP files).",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Cloud-based network forensics analysis",
|
|
"input": "PCAP files",
|
|
"output": "Traffic analysis, threat indicators, IoCs",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "Passive analysis of PCAP; consider privacy of uploaded data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "checkip (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/jreisinger/checkip",
|
|
"description": "Command-line utility for checking local machine IP address and network connectivity.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Display local IP and network info",
|
|
"input": "Local system (no input needed)",
|
|
"output": "Local IP, gateway, DNS servers",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive system utility; local only.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "IP Loggers",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Ki.tc",
|
|
"type": "url",
|
|
"url": "https://ki.tc",
|
|
"description": "IP logging service that generates trackable links for IP/browser info collection.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Generate trackable links to log visitor IPs",
|
|
"input": "Target URL or destination",
|
|
"output": "Tracker link, IP logs, browser info",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "Creates tracking mechanism; detection depends on how link is used.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Grabify",
|
|
"type": "url",
|
|
"url": "https://grabify.link",
|
|
"description": "URL shortener service that logs IP addresses and device information of link clickers.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Shorten URLs and log visitor IPs",
|
|
"input": "URL to shorten",
|
|
"output": "Short URL with IP logging",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "Creates tracking link; malicious uses common.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "IP Logger",
|
|
"type": "url",
|
|
"url": "https://iplogger.com/",
|
|
"description": "IP logging and URL shortening service tracking visitor IP, location, and browser data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Track visitor IPs through shortened links",
|
|
"input": "URL to wrap",
|
|
"output": "Logging URL, visitor IP/location data",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "Tracking service; ethical and legal concerns apply.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Images / Videos / Docs",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Images",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Google Images",
|
|
"type": "url",
|
|
"url": "https://images.google.com/",
|
|
"description": "Google's reverse image and visual search via Lens for finding matches, source pages, and related images across the web.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Broad reverse image search and source discovery",
|
|
"input": "Image upload or image URL",
|
|
"output": "Visually similar images, matching pages, and indexed source sites",
|
|
"opsec": "passive",
|
|
"opsecNote": "Standard search query against Google; no direct interaction with target accounts.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Bing Images",
|
|
"type": "url",
|
|
"url": "https://www.bing.com/images",
|
|
"description": "Microsoft visual search engine with reverse image lookup and crop-based matching for partial-object analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Cropped reverse-image matching and visual component analysis",
|
|
"input": "Image upload, image URL, or cropped image region",
|
|
"output": "Matching images, related pages, and object-level visual matches",
|
|
"opsec": "passive",
|
|
"opsecNote": "Performs web search queries without direct interaction with target identities.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FaceCheck Facial Recognition Search",
|
|
"type": "url",
|
|
"url": "https://facecheck.id/",
|
|
"description": "Facial recognition search engine that finds publicly indexed face matches across web and social sources.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Finding public social profiles by face image",
|
|
"input": "Face photo upload",
|
|
"output": "Potential face matches with source links and similarity scoring",
|
|
"opsec": "active",
|
|
"opsecNote": "Uploads target imagery to a third-party face-search service; treat as active collection.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Surfface Face & People Search Engine",
|
|
"type": "url",
|
|
"url": "https://surfface.com/",
|
|
"description": "AI-based face and people search platform focused on open-source identity discovery and correlation.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Identity correlation from face imagery",
|
|
"input": "Face photo and optional identifying context",
|
|
"output": "Candidate profile matches from publicly available web sources",
|
|
"opsec": "active",
|
|
"opsecNote": "Submits facial data to vendor infrastructure for matching against indexed sources.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "PimEyes Face Search Engine",
|
|
"type": "url",
|
|
"url": "https://pimeyes.com/en",
|
|
"description": "Commercial reverse face search engine for locating appearances of a face on publicly indexed websites.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "High-coverage reverse face search investigations",
|
|
"input": "Face photo upload",
|
|
"output": "Matched face thumbnails and source-page links",
|
|
"opsec": "active",
|
|
"opsecNote": "Face image is uploaded and processed by a third-party biometric search provider.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Yandex Images",
|
|
"type": "url",
|
|
"url": "https://yandex.com/images/",
|
|
"description": "Reverse image search engine with strong matching for Eastern European and Asian web sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding non-Western image sources and modified variants",
|
|
"input": "Image upload or image URL",
|
|
"output": "Similar images, likely originals, and source webpages",
|
|
"opsec": "passive",
|
|
"opsecNote": "Standard search requests to Yandex index; no direct account interaction required.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Baidu Images",
|
|
"type": "url",
|
|
"url": "https://image.baidu.com/",
|
|
"description": "Chinese reverse image search platform useful for discovering image reuse on China-centric websites.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "China-specific image source discovery",
|
|
"input": "Image upload or image URL",
|
|
"output": "Visually similar images from Chinese websites and platforms",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries Baidu index only; no direct contact with target entities.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Twitter Image Search (M)",
|
|
"type": "url",
|
|
"url": "https://twitter.com/search?q=%3Csearchterm%3E&src=typd&vertical=default&f=images",
|
|
"description": "Manual X/Twitter query template for finding tweets containing images for a target keyword or account.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding image-containing tweets by keyword or operator",
|
|
"input": "Edited URL query (keyword, account, and search operators)",
|
|
"output": "Tweets and accounts with matching image/media posts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches public timeline content; no direct engagement with targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Imgur Search",
|
|
"type": "url",
|
|
"url": "https://imgur.com/search",
|
|
"description": "Search interface for Imgur-hosted public images, albums, and community media posts.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Locating reposted images and public gallery content on Imgur",
|
|
"input": "Keyword, tag, or user/gallery query",
|
|
"output": "Public image posts, albums, and account-linked media results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses public site search and does not directly contact targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Photobucket",
|
|
"type": "url",
|
|
"url": "https://photobucket.com/",
|
|
"description": "Long-running image hosting platform with public galleries and legacy web-hosted photo content.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Finding legacy hosted images and user gallery artifacts",
|
|
"input": "Keyword, user, or gallery search",
|
|
"output": "Public image galleries and hosted photo assets",
|
|
"opsec": "passive",
|
|
"opsecNote": "Investigations remain on public gallery pages and search views.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "7Photos.net",
|
|
"type": "url",
|
|
"url": "https://7photos.net/",
|
|
"description": "Unclear image-related web service with an active domain but limited publicly verifiable functionality.",
|
|
"status": "degraded",
|
|
"pricing": "unknown",
|
|
"bestFor": "Unknown; requires additional validation before operational use",
|
|
"input": "Presumed image upload",
|
|
"output": "Unclear due to gated/redirected workflow",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Observed authentication-style redirect behavior; service behavior is not fully observable.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Current Location",
|
|
"type": "url",
|
|
"url": "https://current-location.com/",
|
|
"description": "Location-based photo discovery tool that aggregates geotagged images from public platforms on an interactive map.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Discovering geotagged photos near a location of interest",
|
|
"input": "Map location, coordinates, or browser geolocation",
|
|
"output": "Geotagged image results with source context from supported platforms",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries publicly indexed geotagged photos; no direct interaction with uploaders.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Lenso.ai",
|
|
"type": "url",
|
|
"url": "https://lenso.ai/",
|
|
"description": "AI reverse image and face matching platform designed to find similar or edited visual content.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Matching altered or low-quality images and face lookups",
|
|
"input": "Image or face photo upload",
|
|
"output": "Visual matches, related occurrences, and similarity-ranked results",
|
|
"opsec": "active",
|
|
"opsecNote": "Uploads target imagery to external AI service for analysis and indexing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "CC Search",
|
|
"type": "url",
|
|
"url": "https://search.creativecommons.org/",
|
|
"description": "Creative Commons search portal for discovering openly licensed and public-domain images.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding license-safe imagery and attribution-ready sources",
|
|
"input": "Keyword search with license/source filters",
|
|
"output": "CC/public-domain image results across partner collections",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregated search over open repositories with no target interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "CamFind App",
|
|
"type": "url",
|
|
"url": "https://camfindapp.com/",
|
|
"description": "Mobile visual search app that identifies objects, landmarks, and products from photos.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "On-device object identification and quick visual lookups",
|
|
"input": "Mobile camera image",
|
|
"output": "Object labels, related images, and linked web results",
|
|
"opsec": "active",
|
|
"opsecNote": "Uploads captured images to remote processing service for recognition.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "RevEye Reverse Image Search (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/steven2358/reveye",
|
|
"description": "Open-source browser extension that launches reverse image searches across multiple engines from one menu.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Multi-engine reverse image pivoting from a single browser action",
|
|
"input": "Right-click target image in browser",
|
|
"output": "Parallel reverse-search results in configured engines",
|
|
"opsec": "passive",
|
|
"opsecNote": "Client-side extension submits search queries to selected engines only.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "SmugMug Search",
|
|
"type": "url",
|
|
"url": "https://www.smugmug.com/",
|
|
"description": "Photo hosting and portfolio platform with searchable public galleries and photographer profiles.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Finding public photographer portfolios and gallery artifacts",
|
|
"input": "Keyword, gallery, or photographer search",
|
|
"output": "Public albums, image sets, and profile-linked photo collections",
|
|
"opsec": "passive",
|
|
"opsecNote": "Research is limited to publicly exposed gallery content.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ImageNet",
|
|
"type": "url",
|
|
"url": "https://image-net.org/",
|
|
"description": "Large-scale labeled image dataset used for computer vision and image classification research.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Reference classification sets and ML-oriented visual taxonomy work",
|
|
"input": "Category/synset browsing and dataset queries",
|
|
"output": "Labeled image classes, metadata, and downloadable dataset resources",
|
|
"opsec": "passive",
|
|
"opsecNote": "Academic dataset access with no direct subject engagement.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Places2",
|
|
"type": "url",
|
|
"url": "http://places2.csail.mit.edu/",
|
|
"description": "MIT CSAIL scene-recognition dataset containing millions of place-labeled images for visual analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Scene classification reference and location-context model training",
|
|
"input": "Scene categories and dataset download requests",
|
|
"output": "Scene-labeled image datasets and related research resources",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public academic dataset access; no direct target interaction.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Image Identification Project",
|
|
"type": "url",
|
|
"url": "https://www.imageidentify.com/",
|
|
"description": "Online image recognition service that labels uploaded images with machine-generated tags and confidence scores.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Quick machine-labeling of unknown image content",
|
|
"input": "Image upload",
|
|
"output": "Predicted tags, object labels, and confidence values",
|
|
"opsec": "active",
|
|
"opsecNote": "Uploaded images are processed on third-party infrastructure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "SauceNAO",
|
|
"type": "url",
|
|
"url": "https://saucenao.com/",
|
|
"description": "Reverse image source finder widely used to trace artwork, anime frames, and reposted media to origin sites.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Tracing image origins and duplicate postings",
|
|
"input": "Image upload or image URL",
|
|
"output": "Likely source links, matching images, and similarity metrics",
|
|
"opsec": "passive",
|
|
"opsecNote": "Search workflow only; does not interact with target accounts directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Picarta",
|
|
"type": "url",
|
|
"url": "https://picarta.ai/",
|
|
"description": "AI geolocation tool that estimates likely photo capture locations from visual scene analysis.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Estimating geographic origin of photos without metadata",
|
|
"input": "Image upload",
|
|
"output": "Predicted coordinates and location confidence cues",
|
|
"opsec": "active",
|
|
"opsecNote": "Image content is uploaded to a third-party AI geolocation service.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FaceSeek Face Search Engine",
|
|
"type": "url",
|
|
"url": "https://www.faceseek.online/",
|
|
"description": "Face-matching web tool for locating visually similar faces across indexed online content.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Supplemental reverse face lookup and comparison",
|
|
"input": "Face photo upload",
|
|
"output": "Potential facial matches with source references",
|
|
"opsec": "active",
|
|
"opsecNote": "Uploads biometric imagery to a hosted face-search platform.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Instagram",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Webstigram",
|
|
"type": "url",
|
|
"url": "https://websta.me/search-engine-optimization/",
|
|
"description": "Legacy Webstagram endpoint historically used for Instagram search workflows; currently not verifiable as a standalone active OSINT tool.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference while migrating to active Instagram tooling",
|
|
"input": "Instagram usernames or tags (legacy workflow)",
|
|
"output": "Unreliable/limited Instagram lookup results",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Tool status is unclear and behavior is inconsistent; validate with alternative tools before operational use.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Instagram",
|
|
"type": "url",
|
|
"url": "https://www.instagram.com/",
|
|
"description": "Main Instagram platform used for public profile, hashtag, and location OSINT collection.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Social profiling and image discovery",
|
|
"input": "Usernames, hashtags, locations",
|
|
"output": "Profiles, posts, location signals, and network context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Viewing public content is low-friction, but platform telemetry and account controls still apply.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Mini Instagram",
|
|
"type": "url",
|
|
"url": "https://mini-for-instagram.en.softonic.com/",
|
|
"description": "Lightweight Instagram client utility used to simplify media viewing and downloading workflows.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Preserving Instagram media for offline review",
|
|
"input": "Instagram profile or post URLs",
|
|
"output": "Downloaded Instagram images and videos",
|
|
"opsec": "passive",
|
|
"opsecNote": "Client-side utility; still follow account and platform ToS constraints.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Imgrab",
|
|
"type": "url",
|
|
"url": "https://www.imgrab.com/",
|
|
"description": "Image download utility family used for saving individual or batch media from web pages.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Batch image capture and archive building",
|
|
"input": "Web pages or direct image URLs",
|
|
"output": "Downloaded image files",
|
|
"opsec": "passive",
|
|
"opsecNote": "Primarily local processing; risk profile depends on source websites being queried.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Tofo.me",
|
|
"type": "url",
|
|
"url": "https://tofo.me/",
|
|
"description": "Legacy Instagram-related endpoint with unclear current functionality and limited verifiable OSINT value.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference only",
|
|
"input": "Unknown",
|
|
"output": "Unclear or inconsistent output",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Service behavior is not reliably documented; prefer validated alternatives.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Flickr",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Flickr",
|
|
"type": "url",
|
|
"url": "https://www.flickr.com/",
|
|
"description": "Photo hosting platform that often preserves useful image metadata and geotags for OSINT workflows.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Image metadata and geolocation investigation",
|
|
"input": "Usernames, tags, photo links, map regions",
|
|
"output": "Public photos with metadata and account context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public browsing is generally low-risk; API and account use may be logged.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Flickr Map",
|
|
"type": "url",
|
|
"url": "https://www.flickr.com/map/",
|
|
"description": "Flickr map interface for browsing geotagged photos by area and time.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Map-based discovery of geotagged Flickr images",
|
|
"input": "Geographic area and map navigation",
|
|
"output": "Geotagged photos plotted on interactive map tiles",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses public Flickr geotag data; activity remains normal web browsing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "My Pics Map",
|
|
"type": "url",
|
|
"url": "https://www.mypicsmap.com/",
|
|
"description": "Photo mapping utility reference with unclear present-day availability as a distinct OSINT tool.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference for photo geotag visualization",
|
|
"input": "Photo collections with location data",
|
|
"output": "Mapped photo points (when service is operational)",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Current reliability is uncertain; validate output against active mapping alternatives.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "idGettr",
|
|
"type": "url",
|
|
"url": "https://www.webfx.com/tools/idgettr/",
|
|
"description": "Web utility for resolving Instagram usernames to numeric account IDs.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Converting Instagram handles into numeric IDs for follow-on tooling",
|
|
"input": "Instagram username",
|
|
"output": "Numeric Instagram user ID",
|
|
"opsec": "passive",
|
|
"opsecNote": "Lookup is performed through the service; avoid using sensitive operational accounts.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Flickr Hive Mind",
|
|
"type": "url",
|
|
"url": "https://flickrhivemind.net/",
|
|
"description": "Advanced Flickr search and data-mining interface for tags, users, text, and date filters.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Targeted Flickr dataset discovery and batch result review",
|
|
"input": "Tags, usernames, free text, date constraints",
|
|
"output": "Filtered photo result sets and source links",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public Flickr data through a third-party interface.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Metadata",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "ExifEditor",
|
|
"type": "url",
|
|
"url": "https://exifeditor.io",
|
|
"description": "Browser-based EXIF metadata viewer and editor for quick image metadata inspection or sanitization.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Fast EXIF inspection and metadata cleanup in-browser",
|
|
"input": "Image files (JPEG/PNG)",
|
|
"output": "Displayed EXIF fields and optionally edited image file",
|
|
"opsec": "passive",
|
|
"opsecNote": "Primarily local browser processing; metadata edits are active data changes.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ExifTool (T)",
|
|
"type": "url",
|
|
"url": "https://exiftool.org/",
|
|
"description": "Widely used command-line toolkit for reading and writing EXIF, IPTC, XMP, and other metadata formats.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Comprehensive multi-format metadata extraction",
|
|
"input": "Image, video, audio, and document files",
|
|
"output": "Structured metadata fields and optional file metadata updates",
|
|
"opsec": "passive",
|
|
"opsecNote": "Read operations are passive; write mode modifies source metadata.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ExifViewer",
|
|
"type": "url",
|
|
"url": "https://www.exifviewer.org/",
|
|
"description": "Online EXIF inspection utility for camera, location, and embedded image metadata fields.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick EXIF inspection without local CLI tools",
|
|
"input": "Image file uploads or image URLs",
|
|
"output": "Human-readable EXIF and geolocation data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uploads may route through third-party infrastructure depending on deployment.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FOCA (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/ElevenPaths/FOCA",
|
|
"description": "Desktop reconnaissance tool that gathers public documents from target domains and extracts embedded metadata.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Corporate document metadata reconnaissance",
|
|
"input": "Target domains and document repositories",
|
|
"output": "Extracted usernames, paths, software fingerprints, and document metadata",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs active collection and download actions that may be logged by target infrastructure.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "GeoSetter",
|
|
"type": "url",
|
|
"url": "https://geosetter.de/en/main-en/",
|
|
"description": "Windows desktop utility for viewing and editing photo geotags and EXIF/XMP metadata fields in bulk.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Bulk geolocation metadata review and correction",
|
|
"input": "Image files with embedded or missing location metadata",
|
|
"output": "Updated geotags and metadata-enhanced image sets",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local tool; editing metadata is an active modification step.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Jeffrey's Exif Viewer",
|
|
"type": "url",
|
|
"url": "https://regex.info/blog/",
|
|
"description": "Formerly popular EXIF web viewer that is now discontinued and kept as historical reference.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference only",
|
|
"input": "Image files (service discontinued)",
|
|
"output": "No active EXIF processing available",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Service is discontinued; use active alternatives for operational work.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "JPEGsnoop (T)",
|
|
"type": "url",
|
|
"url": "https://www.impulseadventure.com/photo/jpeg-snoop.html",
|
|
"description": "Windows forensic utility for deep JPEG structure analysis, recompression detection, and authenticity clues.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "JPEG forensic analysis and tamper signal detection",
|
|
"input": "JPEG and supported media/document files",
|
|
"output": "Compression signatures, structure details, and edit indicators",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local forensic analysis with no inherent outbound activity.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Metapicz",
|
|
"type": "url",
|
|
"url": "https://metapicz.com/#landing",
|
|
"description": "Online EXIF parser historically used for quick camera and location metadata reads, now showing signs of limited maintenance.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Legacy metadata checks when primary tools are unavailable",
|
|
"input": "Image files",
|
|
"output": "Formatted EXIF metadata when service is functioning",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reliability appears inconsistent; verify findings with maintained alternatives.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Search by Exif",
|
|
"type": "url",
|
|
"url": "https://exif.osint-tool.com",
|
|
"description": "Web EXIF inspection tool focused on extracting metadata and GPS clues from supplied images.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Rapid EXIF and geolocation extraction",
|
|
"input": "Image files",
|
|
"output": "EXIF metadata with location-relevant fields",
|
|
"opsec": "passive",
|
|
"opsecNote": "Web-hosted processing can expose uploads to third-party infrastructure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "xeuledoc - Fetch metadata about any public Google document",
|
|
"type": "url",
|
|
"url": "https://github.com/Malfrats/xeuledoc",
|
|
"description": "Python tool that extracts metadata from public Google Docs, Sheets, and Slides links.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Google document attribution and metadata extraction",
|
|
"input": "Public Google document URLs",
|
|
"output": "Owner identifiers, account metadata, and document context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reads only public docs without authentication bypass, but still queries Google infrastructure.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Exiv2 (T)",
|
|
"type": "url",
|
|
"url": "https://exiv2.org/",
|
|
"description": "Cross-platform library and CLI for reading and modifying EXIF, IPTC, XMP, and ICC metadata.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Programmatic metadata parsing and editing pipelines",
|
|
"input": "Image files with embedded metadata",
|
|
"output": "Metadata dumps and optional metadata writes",
|
|
"opsec": "passive",
|
|
"opsecNote": "Read operations are passive; write actions alter evidence files.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MediaInfo (T)",
|
|
"type": "url",
|
|
"url": "https://mediaarea.net/en/MediaInfo",
|
|
"description": "Cross-platform utility for extracting technical metadata from video and audio media files.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Media codec and container metadata profiling",
|
|
"input": "Video and audio files",
|
|
"output": "Codec, bitrate, duration, stream, and tag metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local analysis utility with no required outbound collection.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Apache Tika (T)",
|
|
"type": "url",
|
|
"url": "https://tika.apache.org/",
|
|
"description": "Apache content analysis framework for extracting metadata and text across a very broad set of file formats.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Scalable metadata extraction across heterogeneous document sets",
|
|
"input": "Documents, archives, media, and structured file types",
|
|
"output": "Normalized metadata fields and extracted text content",
|
|
"opsec": "passive",
|
|
"opsecNote": "Operational exposure depends on deployment mode (local vs server-based processing).",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "oletools (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/decalage2/oletools",
|
|
"description": "Python toolkit for analyzing OLE and Office documents, including macro extraction and suspicious object detection.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Office document security triage and embedded code inspection",
|
|
"input": "OLE/OOXML/RTF Office documents",
|
|
"output": "Macro code, suspicious indicators, embedded object details, and metadata",
|
|
"opsec": "active",
|
|
"opsecNote": "Malicious samples can trigger security tooling; run analysis in isolated environments.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Hachoir (T)",
|
|
"type": "url",
|
|
"url": "https://hachoir.readthedocs.io/"
|
|
},
|
|
{
|
|
"name": "C2PA Verify",
|
|
"type": "url",
|
|
"url": "https://c2paviewer.com/"
|
|
},
|
|
{
|
|
"name": "Metadata2Go",
|
|
"type": "url",
|
|
"url": "https://www.metadata2go.com/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Forensics",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Ghiro (T)",
|
|
"type": "url",
|
|
"url": "https://getghiro.org/"
|
|
},
|
|
{
|
|
"name": "Forensically",
|
|
"type": "url",
|
|
"url": "https://29a.ch/photo-forensics/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "OCR",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "i2OCR",
|
|
"type": "url",
|
|
"url": "https://www.i2ocr.com/"
|
|
},
|
|
{
|
|
"name": "New OCR",
|
|
"type": "url",
|
|
"url": "https://www.newocr.com/"
|
|
},
|
|
{
|
|
"name": "Online OCR",
|
|
"type": "url",
|
|
"url": "https://www.onlineocr.net/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Tools",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Creepy (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/ilektrojohn/creepy"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Videos",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Google Videos",
|
|
"type": "url",
|
|
"url": "https://www.google.com/videohp"
|
|
},
|
|
{
|
|
"name": "Bing Videos",
|
|
"type": "url",
|
|
"url": "https://www.bing.com/videos"
|
|
},
|
|
{
|
|
"name": "Internet Archive Videos",
|
|
"type": "url",
|
|
"url": "https://archive.org/details/movies"
|
|
},
|
|
{
|
|
"name": "Vines (D)",
|
|
"type": "url",
|
|
"url": "https://www.google.com/search?q=site:vine.co+%3Csearchterm%3E"
|
|
},
|
|
{
|
|
"name": "Dogpile",
|
|
"type": "url",
|
|
"url": "https://www.dogpile.com/"
|
|
},
|
|
{
|
|
"name": "Geo Search Tool",
|
|
"type": "url",
|
|
"url": "https://youtube.github.io/geo-search-tool/"
|
|
},
|
|
{
|
|
"name": "blinkx Video Search",
|
|
"type": "url",
|
|
"url": "https://blinkx.com/"
|
|
},
|
|
{
|
|
"name": "Facebook Live Map",
|
|
"type": "url",
|
|
"url": "https://facebook.com/live"
|
|
},
|
|
{
|
|
"name": "LiveLeak (D)",
|
|
"type": "url",
|
|
"url": "https://www.liveleak.com/"
|
|
},
|
|
{
|
|
"name": "Metatube",
|
|
"type": "url",
|
|
"url": "https://github.com/JVT038/MetaTube"
|
|
},
|
|
{
|
|
"name": "Yahoo Video Search",
|
|
"type": "url",
|
|
"url": "https://video.search.yahoo.com/"
|
|
},
|
|
{
|
|
"name": "Search YouTube by Location",
|
|
"type": "url",
|
|
"url": "https://mattw.io/youtube-geofind/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Analyze / Record",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Print YouTube StoryBoard Instructions",
|
|
"type": "url",
|
|
"url": "https://www.labnol.org/internet/print-youtube-video/28217"
|
|
},
|
|
{
|
|
"name": "Print Storyboard from Youtube",
|
|
"type": "url",
|
|
"url": "javascript:(function(){a=ytplayer.config.args.storyboard_spec;if(!a){alert(\"Sorry we cannot process this YouTube video. Could you please try another one\");exit();}b=a.split(\"|\");base=b[0].split(\"$\")[0]+\"2/M\";c=b[3].split(\"%23\");sigh=c[c.length-1];var imgs=\"\";t=ytplayer.config.args.length_seconds;n=Math.ceil(c[2]/(c[3]*c[4]));for(i=0;i<n;i++){imgs+=\"<PICTURE='\"+base+i+\".jpg%3Fsigh=\"+sigh+\"'><br/>\";}var title=ytplayer.config.args.title;msg=\"<body style='background-color:#444;color:#eee;margin:20px%20auto;width:90%;text-align:center'%3E%3Ch2%3ETITLE%3C/h2%3E%3Cdiv%3EIMAGES%3C/div%3E%3Cbr/%3E%3Cem%3E%3Ca%20href='http://labnol.org/?p=28217'%20style='text-decoration:none;color:#fff;font-style:bold'%3EPrinted%20using%20the%20YouTube%20bookmarklet.%3C/a%3E%3C/em%3E%3C/body%3E%22;msg=msg.replace(%22TITLE%22,title).replace(%22IMAGES%22,imgs).replace(/PICTURE/g,%22img%20src%22);var%20labnol=window.open();labnol.document.open();labnol.document.write(msg);labnol.document.close();})();"
|
|
},
|
|
{
|
|
"name": "Frame by Frame for YouTube (T)",
|
|
"type": "url",
|
|
"url": "https://chrome.google.com/webstore/detail/frame-by-frame-for-youtub/elkadbdicdciddfkdpmaolomehalghio?hl=en-GB"
|
|
},
|
|
{
|
|
"name": "TubeChop",
|
|
"type": "url",
|
|
"url": "https://tubechop.com/"
|
|
},
|
|
{
|
|
"name": "YouTube Data Tools",
|
|
"type": "url",
|
|
"url": "https://tools.digitalmethods.net/netvizz/youtube/"
|
|
},
|
|
{
|
|
"name": "Hooktube",
|
|
"type": "url",
|
|
"url": "https://hooktube.com/"
|
|
},
|
|
{
|
|
"name": "yasiv-youtube",
|
|
"type": "url",
|
|
"url": "https://yasiv.com/youtube/"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Webcams",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "SeeAllTheThings",
|
|
"type": "url",
|
|
"url": "https://github.com/baywolf88/seeallthethings"
|
|
},
|
|
{
|
|
"name": "Insecam",
|
|
"type": "url",
|
|
"url": "https://insecam.org/"
|
|
},
|
|
{
|
|
"name": "EarthCam",
|
|
"type": "url",
|
|
"url": "https://www.earthcam.com/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Documents",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Common GoogleDorks",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "GoogleDocs (D)",
|
|
"type": "url",
|
|
"url": "https://www.google.com/?q=site:docs.google.com+%3Csearchterm%3E"
|
|
},
|
|
{
|
|
"name": "GoogleDrive (D)",
|
|
"type": "url",
|
|
"url": "https://www.google.com/?q=site:drive.google.com+%3Csearchterm%3E"
|
|
},
|
|
{
|
|
"name": "Dropbox (D)",
|
|
"type": "url",
|
|
"url": "https://www.google.com/?q=site:dl.dropbox.com+%3Csearchterm%3E"
|
|
},
|
|
{
|
|
"name": "Amazon AWS (D)",
|
|
"type": "url",
|
|
"url": "https://www.google.com/search?q=site:s3.amazonaws.com+%3Csearchterm%3E"
|
|
},
|
|
{
|
|
"name": "OneDrive (D)",
|
|
"type": "url",
|
|
"url": "https://www.google.com/search?safe=off&q=site:onedrive.live.com+%3Csearchterm%3E"
|
|
},
|
|
{
|
|
"name": "Cryptome (D)",
|
|
"type": "url",
|
|
"url": "https://www.google.com/search?q=site:cryptome.org+%3Csearchterm%3E"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Scribd",
|
|
"type": "url",
|
|
"url": "https://www.scribd.com/"
|
|
},
|
|
{
|
|
"name": "WikiLeaks Search",
|
|
"type": "url",
|
|
"url": "https://search.wikileaks.org/advanced"
|
|
},
|
|
{
|
|
"name": "RECAP Court Doc Repo",
|
|
"type": "url",
|
|
"url": "https://archive.recapthelaw.org/"
|
|
},
|
|
{
|
|
"name": "filessoo.com",
|
|
"type": "url",
|
|
"url": "https://filessoo.com/"
|
|
},
|
|
{
|
|
"name": "Leaked Cables",
|
|
"type": "url",
|
|
"url": "https://search.wikileaks.org/plusd/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Paste Sites",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Pastebin OSINT Harvester (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/needmorecowbell/sniff-paste"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Fonts",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "What The Font",
|
|
"type": "url",
|
|
"url": "https://www.myfonts.com/pages/whatthefont"
|
|
},
|
|
{
|
|
"name": "Font Squirrel",
|
|
"type": "url",
|
|
"url": "https://www.fontsquirrel.com/matcherator"
|
|
},
|
|
{
|
|
"name": "IdentiFont",
|
|
"type": "url",
|
|
"url": "https://www.identifont.com/index.html"
|
|
},
|
|
{
|
|
"name": "What Font Is",
|
|
"type": "url",
|
|
"url": "https://www.whatfontis.com/",
|
|
"description": "AI-powered font identification tool that analyzes images against a database of 1.2M+ typefaces to identify fonts.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Identifying fonts from screenshots and images",
|
|
"input": "Image files containing text (uploaded via drag-and-drop or file picker)",
|
|
"output": "Font matches with design details, download links, and up to 60+ similar alternatives",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uploads images to remote servers; consider OPSEC implications for sensitive screenshots or documents.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Social Networks",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Facebook",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "FB Email Search",
|
|
"type": "url",
|
|
"url": "https://www.facebook.com/public?query=email@gmail.com&nomc=0",
|
|
"description": "Facebook public search pattern used to test whether an email identifier resolves to matching profiles. Useful for quick account existence checks with manually edited query values.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick Facebook account existence checks from an email identifier",
|
|
"input": "Email address (replace the query value in the URL)",
|
|
"output": "Facebook public search results that may include matching profile records",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses Facebook web search endpoints without authentication, but query terms are visible in browser/network logs.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Recover FB Account",
|
|
"type": "url",
|
|
"url": "https://www.facebook.com/login/identify?ctx=recover",
|
|
"description": "Facebook account recovery endpoint that confirms whether an email or phone number is linked to an account and presents recovery options.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Validating whether a target email or phone is tied to a Facebook account",
|
|
"input": "Email address or phone number",
|
|
"output": "Account match confirmation and available recovery paths",
|
|
"opsec": "passive",
|
|
"opsecNote": "No login required, but submitted identifiers are sent directly to Facebook.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Facebook Photos by ID (M)",
|
|
"type": "url",
|
|
"url": "https://www.facebook.com/photo.php?fbid=PHOTO-ID-HERE",
|
|
"description": "Direct Facebook photo permalink format that retrieves a specific image when the photo ID is known.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Opening specific Facebook photos from known numeric IDs",
|
|
"input": "Photo ID value inserted into the URL",
|
|
"output": "Direct Facebook photo page for the supplied photo ID",
|
|
"opsec": "passive",
|
|
"opsecNote": "Accesses publicly available photo endpoints; visibility depends on the target photo privacy settings.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FB Lookup ID",
|
|
"type": "url",
|
|
"url": "https://lookup-id.com/",
|
|
"description": "Web utility that resolves Facebook profile, page, or group URLs into numeric Facebook IDs for downstream investigation tools.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Converting Facebook profile URLs into numeric IDs for pivoting",
|
|
"input": "Facebook profile/page/group URL",
|
|
"output": "Resolved numeric Facebook ID",
|
|
"opsec": "passive",
|
|
"opsecNote": "Processes public Facebook URLs through a third-party service.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FB Identify (Requires Logout)",
|
|
"type": "url",
|
|
"url": "https://www.facebook.com/login/identify",
|
|
"description": "Facebook identify endpoint used in recovery workflows to resolve account records from submitted identifiers; typically works best when not logged in.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Account discovery checks through Facebook identify flow",
|
|
"input": "Email address, phone number, or profile identifier",
|
|
"output": "Potential account matches and recovery prompts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Requires interacting with Facebook recovery interfaces and may produce different results when authenticated.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Fediverse/Mastodon",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Fedifinder",
|
|
"type": "url",
|
|
"url": "https://fedifinder.glitch.me/",
|
|
"description": "Web tool that scanned Twitter profiles to find Fediverse/Mastodon handles among your contacts and exported them as CSV. The hosted instance now returns HTTP 410 and is no longer functional due to Twitter API restrictions.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Finding Twitter contacts who moved to Mastodon/Fediverse",
|
|
"input": "Twitter/X account (via OAuth login)",
|
|
"output": "CSV list of discovered Fediverse handles from your Twitter contacts",
|
|
"opsec": "active",
|
|
"opsecNote": "Requires Twitter OAuth authentication; scans public bios and tweets of followed accounts.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Fediverse Observer",
|
|
"type": "url",
|
|
"url": "https://fediverse.observer/",
|
|
"description": "Real-time dashboard tracking Fediverse instances across Mastodon, Pleroma, Misskey, PeerTube, and other ActivityPub platforms with server statistics and geographic mapping.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Discovering and mapping Fediverse instances by software, country, or size",
|
|
"input": "Search filters (software type, country, language, instance name)",
|
|
"output": "Instance list with user counts, uptime, software version, registration status, and geographic location",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries the Fediverse Observer database, not individual instances; no contact with target servers.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Fediverse_OSINT (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/cyfinoid/fediverse_osint",
|
|
"description": "Python CLI tool for checking whether a domain belongs to the Fediverse and hunting usernames across discoverable Fediverse servers.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Cross-instance Fediverse user and content search",
|
|
"input": "Username or search terms",
|
|
"output": "User profiles and posts found across Fediverse instances",
|
|
"opsec": "active",
|
|
"opsecNote": "Queries multiple Fediverse instances directly; requests may be logged by instance administrators.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Masto (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/C3n7ral051nt4g3ncy/Masto",
|
|
"description": "Python-based Mastodon OSINT tool for investigating user accounts across instances. Retrieves profile details, toots, followers, and account metadata.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Mastodon user profile investigation and account analysis",
|
|
"input": "Mastodon username and instance (e.g., user@mastodon.social)",
|
|
"output": "Profile details, recent toots, follower/following lists, account creation date, and metadata",
|
|
"opsec": "active",
|
|
"opsecNote": "Makes API requests directly to the target Mastodon instance; instance admins can see request logs.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Instagram",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Inflact Instagram Viewer (Anonymous)",
|
|
"type": "url",
|
|
"url": "https://inflact.com/instagram-viewer/profile/",
|
|
"description": "Anonymous Instagram viewer for browsing public profiles, stories, and posts without authenticating to Instagram directly.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Anonymous reconnaissance of public Instagram profiles",
|
|
"input": "Instagram username or profile URL",
|
|
"output": "Profile details, posts, stories, and highlight content",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses a third-party proxy viewer; avoid entering sensitive target identifiers outside approved workflow.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Osintgram (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/Datalux/Osintgram",
|
|
"description": "Python-based Instagram OSINT toolkit for extracting data from public accounts, including posts, hashtags, and follower relationships.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Deep Instagram profile analysis from a local CLI workflow",
|
|
"input": "Instagram username and operator credentials for session access",
|
|
"output": "Posts, captions, hashtags, engagement metrics, and account metadata",
|
|
"opsec": "active",
|
|
"opsecNote": "Direct interaction with Instagram endpoints can trigger rate limits or account monitoring.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Twitter",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Twitter Advanced Search",
|
|
"type": "url",
|
|
"url": "https://twitter.com/search-advanced",
|
|
"description": "Built-in X/Twitter advanced search interface supporting operator-based filtering for users, terms, dates, and engagement constraints.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Targeted discovery of public tweets with complex filters",
|
|
"input": "Search operators and filter parameters (keywords, accounts, dates, media flags)",
|
|
"output": "Filtered tweet result set matching the applied criteria",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses native search features without direct interaction with target accounts.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Twitter Location Search",
|
|
"type": "url",
|
|
"url": "https://twitter.com/search?q=geocode%3A36.1143855%2C-115.1727518%2C1km&src=typd",
|
|
"description": "Operator-based X/Twitter search workflow for geotagged content using `geocode:` and location-focused query parameters.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding public tweets associated with specific coordinates and radius",
|
|
"input": "Latitude/longitude plus radius in search query",
|
|
"output": "Tweets matching the configured location filter",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches public indexed content; no outbound contact to targets beyond normal platform queries.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Twitter Date Search",
|
|
"type": "url",
|
|
"url": "https://twitter.com/search?q=SearchTerm%20since:2016-03-01%20until:2016-03-02",
|
|
"description": "Date-bounded X/Twitter search pattern using `since:` and `until:` operators to isolate tweets in a specific time window.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Timeline reconstruction and historical tweet collection",
|
|
"input": "Keywords plus `since:` and `until:` date operators",
|
|
"output": "Tweets posted within the requested date range",
|
|
"opsec": "passive",
|
|
"opsecNote": "Relies on platform search indexing and public content availability.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Followerwonk (R)",
|
|
"type": "url",
|
|
"url": "https://followerwonk.com/",
|
|
"description": "Follower analytics platform (now under Fedica) for examining X/Twitter audience demographics, account overlaps, and engagement trends.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Audience demographic analysis and account overlap discovery",
|
|
"input": "Twitter/X username or profile URL",
|
|
"output": "Follower demographics, activity analytics, and comparative account insights",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses platform-derived public profile and follower data via third-party analytics.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Twopcharts",
|
|
"type": "url",
|
|
"url": "https://twopcharts.com/",
|
|
"description": "Legacy Twitter statistics site for ranking active users by geography and language; coverage appears limited and stale.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Legacy exploratory checks of historical Twitter influence rankings",
|
|
"input": "City or language selection",
|
|
"output": "Ranked user lists and basic activity comparisons",
|
|
"opsec": "passive",
|
|
"opsecNote": "Data freshness is unclear; treat outputs as historical indicators rather than real-time intelligence.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "TweeterID",
|
|
"type": "url",
|
|
"url": "https://tweeterid.com/",
|
|
"description": "Bidirectional converter between X/Twitter usernames and numeric account IDs for correlation and API-ready pivots.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Converting Twitter handles to numeric IDs (and reverse)",
|
|
"input": "Twitter username or numeric Twitter ID",
|
|
"output": "Mapped username-ID pair for the submitted account",
|
|
"opsec": "passive",
|
|
"opsecNote": "Performs lookup against public account metadata through a third-party web interface.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Analytics",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Profile",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Tweepsect",
|
|
"type": "url",
|
|
"url": "https://tweepsect.com/",
|
|
"description": "Former Twitter overlap analysis tool for intersecting followers and following lists between accounts; no longer operational under current API limits.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference for follower overlap analysis workflows",
|
|
"input": "Twitter username(s)",
|
|
"output": "Follower/following intersection sets (historical behavior)",
|
|
"opsec": "passive",
|
|
"opsecNote": "Service endpoint is no longer functional; keep for historical context only.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Twitonomy",
|
|
"type": "url",
|
|
"url": "https://www.twitonomy.com/",
|
|
"description": "Twitter analytics platform for profile activity, hashtag usage, and follower/following behavior over time.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Profile-level Twitter analytics and behavior baselining",
|
|
"input": "Twitter/X username",
|
|
"output": "Activity timelines, hashtag/topic frequency, and account-level analytics",
|
|
"opsec": "passive",
|
|
"opsecNote": "Requires third-party platform access and may prompt X/Twitter sign-in for full features.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Foller.me Analytics",
|
|
"type": "url",
|
|
"url": "https://foller.me/",
|
|
"description": "Web analytics tool for summarizing public Twitter profile behavior, including hashtags, mentions, topics, and activity cadence.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick baseline profiling of a Twitter account",
|
|
"input": "Twitter/X username",
|
|
"output": "Follower counts, topic and hashtag summaries, posting-time patterns, and account metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries publicly visible profile data through a third-party interface.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "X0rz Tweets_analyzer (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/x0rz/tweets_analyzer",
|
|
"description": "Python CLI analyzer for profiling Twitter user behavior, including posting rhythm, language distribution, and source-client usage.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Behavioral profiling and temporal analysis of Twitter accounts",
|
|
"input": "Twitter username and API credentials",
|
|
"output": "Activity charts, language/source statistics, and account behavior indicators",
|
|
"opsec": "active",
|
|
"opsecNote": "Requires API-driven collection and can expose investigator infrastructure through API usage patterns.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Hashtag",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "RiteTag",
|
|
"type": "url",
|
|
"url": "https://ritetag.com/",
|
|
"description": "Hashtag intelligence platform that scores and recommends social tags based on trend velocity and engagement potential.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Hashtag trend analysis and campaign tag selection",
|
|
"input": "Keywords, draft text, or media captions",
|
|
"output": "Suggested hashtags with trend and visibility indicators",
|
|
"opsec": "passive",
|
|
"opsecNote": "Processes submitted content on third-party infrastructure for analytics.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "TAGSExplorer",
|
|
"type": "url",
|
|
"url": "https://tags.hawksey.info/tagsexplorer/",
|
|
"description": "Browser-based visualization layer for TAGS archives that maps mentions, replies, and retweet relationships from collected Twitter datasets.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Conversation network mapping from archived Twitter data",
|
|
"input": "Google Sheets data produced by TAGS collection workflows",
|
|
"output": "Interactive network graph and conversation summaries",
|
|
"opsec": "passive",
|
|
"opsecNote": "Works on previously collected datasets; no direct contact with target accounts during analysis.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Tweet Metadata",
|
|
"type": "url",
|
|
"url": "https://www.wsj.com/public/resources/documents/TweetMetadata.pdf",
|
|
"description": "Reference document and workflow aid for interpreting metadata fields embedded in tweet payloads and exports.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Understanding tweet metadata fields for forensic analysis",
|
|
"input": "Tweet JSON/export data and metadata field references",
|
|
"output": "Field-level interpretation guidance for tweet metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Documentation resource only; does not query live targets directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Birdwatcher (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/michenriksen/birdwatcher",
|
|
"description": "Open-source Twitter data harvesting and analysis framework for collecting tweets and producing offline analytical artifacts.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Local collection and analysis of Twitter datasets at scale",
|
|
"input": "Twitter account targets and API configuration",
|
|
"output": "Collected tweets, relationship data, and analysis-ready exports (including geospatial artifacts)",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs direct API/data collection activity from investigator infrastructure.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Tinfoleak Web",
|
|
"type": "url",
|
|
"url": "https://tinfoleak.com/",
|
|
"description": "Web-based platform for Twitter/X intelligence analysis, user profiling, and geolocation-oriented review of public activity.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Twitter profile and timeline intelligence",
|
|
"input": "Twitter/X username or profile URL",
|
|
"output": "Profile details, tweet history views, and account activity context",
|
|
"opsec": "active",
|
|
"opsecNote": "Queries are sent to third-party service infrastructure and may be logged.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Tinfoleak.py (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/vaguileradiaz/tinfoleak",
|
|
"description": "Python command-line tool for collecting Twitter/X account intelligence and metadata from target profiles.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "CLI-based Twitter metadata collection",
|
|
"input": "Twitter/X usernames or profile identifiers",
|
|
"output": "User profile metadata and related account intelligence artifacts",
|
|
"opsec": "active",
|
|
"opsecNote": "Direct requests to platform endpoints expose source IP and request patterns.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DMI-TCAT (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/digitalmethodsinitiative/dmi-tcat",
|
|
"description": "Twitter Capture and Analysis Toolset for collecting and analyzing Twitter datasets using self-hosted infrastructure.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Large-scale Twitter collection and analysis",
|
|
"input": "API credentials plus search terms, handles, or tracking filters",
|
|
"output": "Stored tweet datasets, exports, and analysis-ready records",
|
|
"opsec": "active",
|
|
"opsecNote": "Requires authenticated API collection and self-hosted data processing.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Twint (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/twintproject/twint",
|
|
"description": "Open-source Twitter scraping utility for collecting public tweet and user data without official API usage.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Historical Twitter scraping without API keys",
|
|
"input": "Handles, keywords, hashtags, and date filters",
|
|
"output": "Tweet collections, user metadata, and exportable structured results",
|
|
"opsec": "active",
|
|
"opsecNote": "Scraping activity can be detected and blocked by the target platform.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Location / Mapping",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "GeoSocial Footprint",
|
|
"type": "url",
|
|
"url": "https://geosocialfootprint.com/",
|
|
"description": "Geolocation-focused social media analysis service for mapping public location traces and movement patterns.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Location and movement pattern analysis",
|
|
"input": "Public social identifiers and geotagged content references",
|
|
"output": "Mapped points, movement timelines, and location summaries",
|
|
"opsec": "active",
|
|
"opsecNote": "Use may be logged by the provider and linked to investigator activity.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "One Million Tweet Map",
|
|
"type": "url",
|
|
"url": "https://onemilliontweetmap.com/",
|
|
"description": "Interactive map for viewing recent geolocated tweets and filtering by keyword and region.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Real-time geolocated tweet monitoring",
|
|
"input": "Keyword, map area, and time filters",
|
|
"output": "Mapped tweet locations with associated post content",
|
|
"opsec": "passive",
|
|
"opsecNote": "Read-only web usage with no direct target interaction required.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Creepy (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/ilektrojohn/creepy",
|
|
"description": "Desktop geolocation intelligence tool aggregating public geotagged data from supported social sources.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Cross-platform geolocation aggregation",
|
|
"input": "Usernames and supported social platform account identifiers",
|
|
"output": "Location points, maps, and metadata for linked accounts",
|
|
"opsec": "active",
|
|
"opsecNote": "Tool pulls remote platform data and can generate identifiable request traffic.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Fedica",
|
|
"type": "url",
|
|
"url": "https://fedica.com/",
|
|
"description": "Social analytics platform with audience and engagement insights across multiple social networks.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Cross-platform social analytics and tracking",
|
|
"input": "Connected social accounts or profile targets",
|
|
"output": "Engagement metrics, trend data, and audience analytics",
|
|
"opsec": "active",
|
|
"opsecNote": "Platform usage and connected account actions are visible to service provider logs.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Archive / Deleted Tweets",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "All My Tweets",
|
|
"type": "url",
|
|
"url": "https://www.allmytweets.net/",
|
|
"description": "Twitter/X account history viewer for reviewing public tweet timelines in a single interface.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick review of tweet history",
|
|
"input": "Twitter/X username",
|
|
"output": "Chronological list of public tweets and profile activity",
|
|
"opsec": "active",
|
|
"opsecNote": "Uses third-party web service access that can be logged by provider systems.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Spoonbill",
|
|
"type": "url",
|
|
"url": "https://spoonbill.io/",
|
|
"description": "Service that tracks Twitter/X profile changes such as bios, names, and avatars over time.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Monitoring profile change history",
|
|
"input": "Twitter/X usernames",
|
|
"output": "Historical profile snapshots and change alerts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Monitoring is indirect; investigator does not directly engage target accounts.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "TweetVacuum (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/UberKitten/TweetVacuum",
|
|
"description": "Tool for extracting larger Twitter/X timeline archives beyond default on-platform browsing constraints.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Expanded tweet history export",
|
|
"input": "Twitter/X account identifiers",
|
|
"output": "Archived tweet records in local export formats",
|
|
"opsec": "active",
|
|
"opsecNote": "Collection patterns may be visible through account- or IP-linked activity.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Reddit",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Reddit Metis",
|
|
"type": "url",
|
|
"url": "https://redditmetis.com/",
|
|
"description": "Reddit user analyzer summarizing posting behavior, language patterns, and subreddit activity.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Reddit user behavior profiling",
|
|
"input": "Reddit username",
|
|
"output": "Account statistics, subreddit distribution, and content summaries",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reads public Reddit data without direct interaction with target users.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Reddit Archive",
|
|
"type": "url",
|
|
"url": "https://www.redditarchive.com/",
|
|
"description": "Archive-oriented Reddit lookup resource for historical post and comment discovery workflows.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Historical Reddit content lookup",
|
|
"input": "Subreddit names, usernames, and keyword queries",
|
|
"output": "Archived post and comment references from historical datasets",
|
|
"opsec": "passive",
|
|
"opsecNote": "Read-only archive queries; availability may vary with backend data sources.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "subreddits",
|
|
"type": "url",
|
|
"url": "https://subreddits.org/",
|
|
"description": "Subreddit discovery index for identifying communities by topic and interest area.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Topic-based subreddit discovery",
|
|
"input": "Topic keywords or category browsing",
|
|
"output": "Lists of relevant subreddits and navigation paths",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public index browsing with no direct target engagement.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Reddit Comment History",
|
|
"type": "url",
|
|
"url": "https://roadtolarissa.com/javascript/reddit-comment-visualizer/",
|
|
"description": "Visualization utility for reviewing Reddit account comment history and timing patterns.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Comment activity timeline analysis",
|
|
"input": "Reddit username",
|
|
"output": "Comment history visualizations and posting cadence insights",
|
|
"opsec": "passive",
|
|
"opsecNote": "Analyzes publicly accessible Reddit comment data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "LinkedIn",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "LinkedInt - LinkedIn Recon Tool (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/vysecurity/LinkedInt",
|
|
"description": "LinkedIn reconnaissance script for enumerating employee profiles and organization-linked data points.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "LinkedIn employee enumeration",
|
|
"input": "Company names, LinkedIn URLs, and search targets",
|
|
"output": "Employee profile lists and organization intelligence leads",
|
|
"opsec": "active",
|
|
"opsecNote": "Automated LinkedIn collection can violate platform policy and trigger detection.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "ScrapedIn (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/dchrastil/ScrapedIn",
|
|
"description": "Open-source LinkedIn scraping utility for extracting profile and contact-style data from search results.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "LinkedIn profile data extraction",
|
|
"input": "LinkedIn search queries and profile targets",
|
|
"output": "Structured profile records and contact-oriented datasets",
|
|
"opsec": "active",
|
|
"opsecNote": "Scraping traffic and automated behavior are detectable by LinkedIn controls.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "InSpy (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/jobroche/InSpy",
|
|
"description": "LinkedIn-focused reconnaissance tool that combines profile discovery with email pattern generation.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Employee and email pattern discovery",
|
|
"input": "Company name and domain context",
|
|
"output": "Employee candidates with associated role and email pattern hints",
|
|
"opsec": "active",
|
|
"opsecNote": "Enumeration and enrichment workflows can expose investigator infrastructure.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "raven (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/0x09AL/raven",
|
|
"description": "LinkedIn information gathering utility for automated employee enumeration and role filtering.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Automated LinkedIn org mapping",
|
|
"input": "Company, role, and location filters",
|
|
"output": "Enumerated employee records and role-based lists",
|
|
"opsec": "active",
|
|
"opsecNote": "Automated platform queries can be rate-limited or flagged.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "TikTok",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "TikTok (M)",
|
|
"type": "url",
|
|
"url": "https://www.tiktok.com/@username",
|
|
"description": "Manual TikTok profile URL pattern for direct lookup of public account pages.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Fast manual TikTok profile checks",
|
|
"input": "TikTok username inserted into the URL",
|
|
"output": "Public profile page with videos, bio, and engagement counts",
|
|
"opsec": "active",
|
|
"opsecNote": "Direct visits are observable by platform infrastructure; use caution when logged in.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "TikTok-OSINT (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/Omicron166/TikTok-OSINT",
|
|
"description": "Python tool for extracting TikTok profile metadata and video-linked OSINT artifacts.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Automated TikTok metadata collection",
|
|
"input": "TikTok usernames or profile URLs",
|
|
"output": "Profile metadata, video details, and engagement-related fields",
|
|
"opsec": "active",
|
|
"opsecNote": "Automated requests can trigger anti-abuse controls and rate limits.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Unfurl",
|
|
"type": "url",
|
|
"url": "https://github.com/obsidianforensics/unfurl",
|
|
"description": "Forensic parser that extracts and visualizes metadata components embedded in URLs.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "URL parameter and metadata forensics",
|
|
"input": "URLs or encoded URL fragments",
|
|
"output": "Parsed components, decoded values, and relationship visualizations",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local analysis mode avoids contacting target platforms during parsing.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "yt-dlp (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/yt-dlp/yt-dlp",
|
|
"description": "Actively maintained command-line downloader for collecting video content and metadata from many platforms.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Video evidence preservation and metadata export",
|
|
"input": "Video, playlist, or channel URLs",
|
|
"output": "Media files, JSON metadata, thumbnails, subtitles, and related artifacts",
|
|
"opsec": "active",
|
|
"opsecNote": "Direct content fetch requests expose investigator network identifiers.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Bluesky",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Treeverse (T)",
|
|
"type": "url",
|
|
"url": "https://treeverse.app/",
|
|
"description": "Thread visualization tool for exploring conversation trees on supported social platforms.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Conversation structure mapping",
|
|
"input": "Post or thread URLs",
|
|
"output": "Hierarchical thread trees with participant and reply context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public-content visualization without direct target interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Threads",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Bellingcat Meta Content Library",
|
|
"type": "url",
|
|
"url": "https://bellingcat.gitbook.io/toolkit/more/all-tools/meta-content-library",
|
|
"description": "Guide to Meta Content Library access for researching public Facebook, Instagram, and Threads content.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Meta platform archive research for eligible organizations",
|
|
"input": "Approved research queries and archive search filters",
|
|
"output": "Searchable public-content archive results and metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Archive-centric workflow with eligibility gate; no direct account engagement.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": true,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Threads Dashboard",
|
|
"type": "url",
|
|
"url": "https://www.threadsdashboard.com/",
|
|
"description": "Analytics and insights platform for Threads accounts using the official API. Tracks audience demographics, engagement metrics, and historical posting data.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Threads account analytics and engagement investigation",
|
|
"input": "Threads username or account URL",
|
|
"output": "Audience demographics, engagement rates, posting frequency, optimal posting times, and historical data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Retrieves data via Meta's official Threads API; no direct contact with the target account.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Threads-Scraper (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/Zeeshanahmad4/Threads-Scraper",
|
|
"description": "Python browser automation tool that scrapes public Threads posts and profiles without authentication, outputting structured data in JSON, CSV, or XML. Last updated July 2023.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Bulk extraction of Threads posts for offline analysis",
|
|
"input": "Threads profile URL or post URL",
|
|
"output": "Extracted posts in JSON, CSV, or XML format with metadata",
|
|
"opsec": "active",
|
|
"opsecNote": "Scrapes Threads directly; depends on site structure and may trigger rate limiting.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ThreadsRecon (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/offseq/threadsrecon",
|
|
"description": "Python OSINT tool for Threads profile analysis including sentiment analysis, network visualization, and automated PDF reporting.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Threads profile investigation with sentiment and network analysis",
|
|
"input": "Threads username",
|
|
"output": "Profile analysis, sentiment scores, network graphs, and PDF investigation reports",
|
|
"opsec": "active",
|
|
"opsecNote": "Makes direct requests to Threads to collect profile and post data for analysis.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Steam, Discord & Gaming Networks",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "SteamOSINT (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/Frontline-Femmes/Steam-OSINT"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Other Social Networks",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Ask FM",
|
|
"type": "url",
|
|
"url": "https://ask.fm/%3Cusername%3E"
|
|
},
|
|
{
|
|
"name": "Myspace",
|
|
"type": "url",
|
|
"url": "https://myspace.com/"
|
|
},
|
|
{
|
|
"name": "Tumblr",
|
|
"type": "url",
|
|
"url": "https://www.tumblr.com/tagged/search"
|
|
},
|
|
{
|
|
"name": "TheHoodUp (NSFW)",
|
|
"type": "url",
|
|
"url": "https://thehoodup.com/board/"
|
|
},
|
|
{
|
|
"name": "Share Secret Feedback (M)",
|
|
"type": "url",
|
|
"url": "https://secreto.site/en/%3Cuser_id%3E"
|
|
},
|
|
{
|
|
"name": "BlackPlanet.com - Member Find",
|
|
"type": "url",
|
|
"url": "https://www.blackplanet.com/user_search/index.html"
|
|
},
|
|
{
|
|
"name": "MiGente (Latino)",
|
|
"type": "url",
|
|
"url": "https://migente.com/wp-login.php?redirect_to=https%3A%2F%2Fmigente.com%2Fuser_search%2Findex.html&bp-auth=1&action=bpnoaccess"
|
|
},
|
|
{
|
|
"name": "Asian Avenue",
|
|
"type": "url",
|
|
"url": "https://blackplanet.com/"
|
|
},
|
|
{
|
|
"name": "Orkut (Brazil)",
|
|
"type": "url",
|
|
"url": "https://orkut.google.com/"
|
|
},
|
|
{
|
|
"name": "Odnoklassniki",
|
|
"type": "url",
|
|
"url": "https://ok.ru/"
|
|
},
|
|
{
|
|
"name": "VK",
|
|
"type": "url",
|
|
"url": "https://vk.com/"
|
|
},
|
|
{
|
|
"name": "Delicious",
|
|
"type": "url",
|
|
"url": "https://del.icio.us/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Social Searcher",
|
|
"type": "url",
|
|
"url": "https://www.social-searcher.com/"
|
|
},
|
|
{
|
|
"name": "Google Social Search",
|
|
"type": "url",
|
|
"url": "https://www.social-searcher.com/google-social-search/"
|
|
},
|
|
{
|
|
"name": "Talkwalker Social Media Search (R)",
|
|
"type": "url",
|
|
"url": "https://www.talkwalker.com/social-media-analytics-search"
|
|
},
|
|
{
|
|
"name": "PinGroupie",
|
|
"type": "url",
|
|
"url": "https://pingroupie.com/"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Instant Messaging",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Chat Archive Analysis",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Comms Analyzer Toolbox (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/bitsofinfo/comms-analyzer-toolbox",
|
|
"description": "Open-source toolkit for forensic analysis of communication archives with Elasticsearch/Kibana dashboards for message timelines and pattern analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Email/SMS chat archive forensics and timeline analysis",
|
|
"input": "Communication exports and structured message datasets",
|
|
"output": "Searchable communication records, timelines, and analytics dashboards",
|
|
"opsec": "passive",
|
|
"opsecNote": "Performs local analysis on collected datasets and does not contact targets by default.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Discord",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Disboard",
|
|
"type": "url",
|
|
"url": "https://disboard.org/",
|
|
"description": "Public Discord server discovery platform used to find communities by topic, language, and popularity.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Discovering public Discord communities and server metadata",
|
|
"input": "Keyword, category, or tag searches",
|
|
"output": "Indexed public Discord server listings with invite links and tags",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are performed against Disboard listings; browsing does not interact with target users directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DiscordOSINT (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/husseinmuhaisen/DiscordOSINT",
|
|
"description": "GitHub repository of Discord investigation techniques, queries, and tooling references for OSINT workflows.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Learning Discord investigation methods and toolchains",
|
|
"input": "Manual review of documentation and linked resources",
|
|
"output": "Investigation guidance, resource links, and workflow references",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reference material only; OPSEC depends on which downstream tools are executed.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Resources",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Awesome OSINT",
|
|
"type": "url",
|
|
"url": "https://github.com/jivoi/awesome-osint",
|
|
"description": "Large curated OSINT resource list covering investigation tools, techniques, and training references.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Broad OSINT tool discovery and methodology reference",
|
|
"input": "Manual browsing by topic",
|
|
"output": "Categorized links to OSINT tools and learning resources",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reference index only; OPSEC depends on the external resources selected.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Signal / Phone Lookup",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "OSINT Industries",
|
|
"type": "url",
|
|
"url": "https://www.osint.industries/",
|
|
"description": "Commercial OSINT investigation platform focused on account attribution and cross-platform identity correlation.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Enterprise-grade identity enrichment and account correlation",
|
|
"input": "Email addresses, usernames, phone numbers, and account identifiers",
|
|
"output": "Correlated identity intelligence and linked platform account results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Lookups run through the provider platform; no direct contact with targets is required for standard queries.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Slack",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "SlackPirate (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/emtunc/SlackPirate",
|
|
"description": "Security testing tool for Slack workspaces that enumerates channels and extracts accessible messages/files from authenticated sessions.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Slack workspace enumeration and sensitive data exposure assessment",
|
|
"input": "Authenticated Slack session/token and workspace target",
|
|
"output": "Channel/user inventory and extracted accessible Slack content",
|
|
"opsec": "active",
|
|
"opsecNote": "Interacts directly with Slack workspace APIs and can leave observable request activity.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "slack-intelbot (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/pun1sh3r/slack-intelbot",
|
|
"description": "Slack bot that enriches indicators such as domains, IPs, and hashes by querying external threat intelligence services.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "In-channel IOC enrichment for threat intelligence triage",
|
|
"input": "Indicators posted in Slack and configured API credentials",
|
|
"output": "Automated enrichment responses with indicator context and reputation data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries third-party intelligence APIs; no direct interaction with investigation targets by default.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "slack-web-scraper (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/iulspop/slack-web-scraper",
|
|
"description": "Automation script for collecting Slack channel history and metadata from accessible workspaces.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Archiving Slack channel content for offline analysis",
|
|
"input": "Slack-authenticated browser/session context",
|
|
"output": "Scraped channel messages and related metadata exports",
|
|
"opsec": "active",
|
|
"opsecNote": "Direct scraping activity against Slack endpoints may be logged and rate-limited.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Telegram",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Google CSE for Telegram links",
|
|
"type": "url",
|
|
"url": "https://cse.google.com/cse?cx=006368593537057042503:efxu7xprihg",
|
|
"description": "Preconfigured Google Custom Search Engine focused on public Telegram links and channel discovery.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding public Telegram channels and groups by keyword",
|
|
"input": "Keyword search terms",
|
|
"output": "Google CSE results linking to public Telegram resources",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries are sent to Google CSE rather than directly to Telegram services.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Telegago (T)",
|
|
"type": "url",
|
|
"url": "https://tools.osintnewsletter.com/osint-tools/telegago-telegram",
|
|
"description": "Telegram-focused search interface built on Google CSE to discover public channels, groups, and related pages.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Keyword discovery across publicly indexed Telegram content",
|
|
"input": "Keyword search terms",
|
|
"output": "Search results pointing to public Telegram channels and posts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses indexed search results and does not require direct interaction with target accounts.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Telegram-OSINT (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/The-Osint-Toolbox/Telegram-OSINT",
|
|
"description": "Curated Telegram OSINT repository linking tools, techniques, and investigative references.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Sourcing Telegram-specific tooling and investigative playbooks",
|
|
"input": "Manual review of listed tools and references",
|
|
"output": "Collection of Telegram OSINT resources and workflows",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reference repository only; OPSEC depends on the selected downstream tools.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "TGStat",
|
|
"type": "url",
|
|
"url": "https://tgstat.com/",
|
|
"description": "Telegram analytics platform indexing public channels and chats with growth, engagement, and content metrics.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Telegram channel trend analysis and engagement benchmarking",
|
|
"input": "Channel names, keywords, and Telegram entity identifiers",
|
|
"output": "Audience metrics, posting statistics, and channel ranking insights",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reads TGStat indexed analytics data; no direct contact with targets for normal lookups.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Tosint (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/drego85/tosint",
|
|
"description": "Telegram OSINT script for profiling bots, extracting public metadata, and correlating related infrastructure clues.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Telegram bot reconnaissance and metadata extraction",
|
|
"input": "Telegram bot usernames, links, or identifiers",
|
|
"output": "Extracted bot metadata, discovery artifacts, and investigation leads",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs direct queries to Telegram services for target resolution and metadata retrieval.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "WeChat / LINE",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Sogou WeChat Search",
|
|
"type": "url",
|
|
"url": "https://weixin.sogou.com/",
|
|
"description": "Chinese search portal indexing publicly accessible WeChat articles and official account content.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Discovering public WeChat posts and organization presence",
|
|
"input": "Chinese keywords, account names, or article titles",
|
|
"output": "Indexed WeChat article pages and related account search results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries Sogou index results and does not require direct access to target accounts.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "WechatSogou (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/Chowency/WechatSogou",
|
|
"description": "Python package for automating Sogou WeChat searches and parsing returned article/account results.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Automating batch WeChat article and account discovery",
|
|
"input": "Search keywords and query parameters",
|
|
"output": "Parsed WeChat article and account metadata from Sogou results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Automates queries to Sogou search endpoints; no direct messaging-platform interaction with target users.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "wechat-dump (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/ppwwyyxx/wechat-dump",
|
|
"description": "Tool for exporting WeChat chat data from rooted Android devices for forensic examination and recovery.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Authorized mobile WeChat chat history extraction and preservation",
|
|
"input": "Rooted Android device data and WeChat app storage",
|
|
"output": "Extracted local WeChat message databases and media artifacts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Operates on local device data and does not require contacting external targets.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "wechat-text-backup (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/zhaofeng-shu33/wechat-text-backup",
|
|
"description": "WeChat database decryption and backup utility for exporting local message history into readable text formats.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Decrypting and backing up local WeChat message archives",
|
|
"input": "Local WeChat database files and decryption context",
|
|
"output": "Decrypted, readable WeChat chat history exports",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs direct decryption and extraction actions against local account data stores.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "linelog2py (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/jyu0414/linelog2py",
|
|
"description": "Python parser for processing exported LINE chat logs into structured records for analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Converting LINE chat exports for downstream analysis workflows",
|
|
"input": "Exported LINE chat history files",
|
|
"output": "Structured parsed LINE messages and conversation artifacts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Processes local chat export files without contacting target services.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "line-message-analyzer (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/chonyy/line-message-analyzer",
|
|
"description": "Local analysis utility for LINE chat exports that computes message statistics and conversational activity patterns.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "LINE conversation frequency and behavior analysis",
|
|
"input": "LINE exported chat history files",
|
|
"output": "Message analytics, usage trends, and conversation summaries",
|
|
"opsec": "passive",
|
|
"opsecNote": "Runs locally on exported chat data and does not directly query target accounts.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "WhatsApp",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Email2WhatsApp (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/dsonbaker/email2whatsapp",
|
|
"description": "OSINT utility for correlating email addresses to potential WhatsApp identifiers and account traces.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Email-to-WhatsApp account correlation during profiling",
|
|
"input": "Email address targets",
|
|
"output": "Potential linked WhatsApp account indicators and correlation results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Primarily performs correlation lookups without messaging target accounts directly.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "WhatsApp-OSINT (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/kinghacker0/WhatsApp-OSINT",
|
|
"description": "WhatsApp reconnaissance toolchain using API-backed lookups for account and device-related intelligence collection.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Rapid WhatsApp account reconnaissance and metadata checks",
|
|
"input": "Phone numbers or WhatsApp account identifiers",
|
|
"output": "Enriched account metadata and reconnaissance results",
|
|
"opsec": "active",
|
|
"opsecNote": "Direct API-driven lookups against messaging infrastructure may be logged by providers.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "People Search Engines",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "General People Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "InfoFlow Public People Search In Chilean",
|
|
"type": "url",
|
|
"url": "https://infoflow.cloud/",
|
|
"description": "Chilean public records lookup service for vehicle registrations, personal ID numbers (RUN), company information, and reverse name-to-RUN lookups via web portal, WhatsApp, or Telegram.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Chilean public records and identity verification",
|
|
"input": "Name, RUN (Chilean ID number), or vehicle plate",
|
|
"output": "Personal identification data, vehicle registration, company records",
|
|
"opsec": "active",
|
|
"opsecNote": "Requires registration with Chilean RUT; queries may be logged.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ThatsThem",
|
|
"type": "url",
|
|
"url": "https://thatsthem.com/name-address-search",
|
|
"description": "Free people search engine with 2.2 billion indexed names. Provides reverse phone, email, address, and IP lookups alongside standard name searches.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Quick free people lookups by name, address, phone, email, or IP",
|
|
"input": "Name, address, phone number, email, or IP address",
|
|
"output": "Contact details, associated addresses, phone numbers, email addresses",
|
|
"opsec": "passive",
|
|
"opsecNote": "Free tier has daily lookup limits; no account required for basic searches.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Melissa Data - People Finder (R)",
|
|
"type": "url",
|
|
"url": "https://www.melissa.com/",
|
|
"description": "Enterprise data quality and identity verification platform offering people search, address verification, phone append, and email verification across global datasets.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Enterprise-grade identity verification and data enrichment",
|
|
"input": "Name, address, phone, or email",
|
|
"output": "Verified contact data, address standardization, identity confirmation",
|
|
"opsec": "active",
|
|
"opsecNote": "Enterprise service; queries logged and usage tracked under account.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "PeekYou",
|
|
"type": "url",
|
|
"url": "https://www.peekyou.com/",
|
|
"description": "Free people search engine indexing over 300 million profiles. Aggregates social media accounts, public records, and web presence into unified profiles.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding social media profiles and web presence by name",
|
|
"input": "Name and optional location, or username",
|
|
"output": "Aggregated social media profiles, contact information, web presence",
|
|
"opsec": "passive",
|
|
"opsecNote": "No registration required; all searches use public data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Webmii",
|
|
"type": "url",
|
|
"url": "https://webmii.com/",
|
|
"description": "Free people search engine that calculates a web visibility score based on online presence across social networks, news, and web pages.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Assessing online visibility and web footprint",
|
|
"input": "First and last name",
|
|
"output": "Web visibility score, social profiles, images, videos, news mentions",
|
|
"opsec": "passive",
|
|
"opsecNote": "No registration required; searches public web data only.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Snitch.name",
|
|
"type": "url",
|
|
"url": "https://snitch.name/",
|
|
"description": "People profile search engine checking approximately 40 social networks including Facebook, Twitter, LinkedIn, Xing, and government databases.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Cross-platform social media profile discovery",
|
|
"input": "First and last name",
|
|
"output": "Social media profiles across ~40 platforms",
|
|
"opsec": "passive",
|
|
"opsecNote": "SSL certificate expired; browsers will show security warnings.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Lullar",
|
|
"type": "url",
|
|
"url": "https://com.lullar.com/",
|
|
"description": "Free people search tool that checks 148+ social media platforms for matching profiles by email or username. No sign-up or payment required.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Username and email-based social media profile enumeration",
|
|
"input": "Email address or username",
|
|
"output": "Matching profiles across 148+ social media platforms",
|
|
"opsec": "passive",
|
|
"opsecNote": "No registration required; searches public profiles only.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Yasni",
|
|
"type": "url",
|
|
"url": "https://www.yasni.com/",
|
|
"description": "Free people search engine allowing searches by name, location, profession, company, or skills. Also offers professional Expose profile pages.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Name-based people search with professional context",
|
|
"input": "Name, location, profession, company, or skills",
|
|
"output": "Aggregated web presence, professional profiles, contact information",
|
|
"opsec": "passive",
|
|
"opsecNote": "No registration for searches; account needed for profile creation features.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "findmypast.com",
|
|
"type": "url",
|
|
"url": "https://www.findmypast.com/discover",
|
|
"description": "UK-focused genealogy and historical records platform with billions of records covering census, birth, marriage, death, military, and immigration documents.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "UK and Irish genealogy and historical records research",
|
|
"input": "Name, date of birth, location, or family details",
|
|
"output": "Historical records, census data, BMD certificates, military records",
|
|
"opsec": "active",
|
|
"opsecNote": "Subscription required for full record access; free trial available.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "IDCrawl",
|
|
"type": "url",
|
|
"url": "https://www.idcrawl.com/",
|
|
"description": "Free people search aggregator that finds social media profiles, photos, and public records across major platforms including Instagram, Facebook, and LinkedIn.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Aggregated people search across social media and public records",
|
|
"input": "Name, username, phone, or email",
|
|
"output": "Social media profiles, photos, public records, contact information",
|
|
"opsec": "passive",
|
|
"opsecNote": "Cloudflare-protected; no registration required.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FamilySearch.org",
|
|
"type": "url",
|
|
"url": "https://familysearch.org/search/",
|
|
"description": "Free genealogy platform operated by The Church of Jesus Christ of Latter-day Saints with billions of historical records, family trees, and digitized documents worldwide.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Free genealogy research and historical record access",
|
|
"input": "Name, date, place, or family relationships",
|
|
"output": "Historical records, family trees, digitized documents, cemetery records",
|
|
"opsec": "passive",
|
|
"opsecNote": "Basic search is free without login; account needed for Family Tree features.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Ancestry.com",
|
|
"type": "url",
|
|
"url": "https://www.ancestry.com/search/",
|
|
"description": "World's largest genealogy platform with over 40 billion historical records including census, immigration, military, and vital records across 80+ countries.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Comprehensive genealogy and family history research",
|
|
"input": "Name, date of birth, location, or family details",
|
|
"output": "Historical records, DNA matches, family trees, immigration records",
|
|
"opsec": "active",
|
|
"opsecNote": "Free basic search; subscription required for full record access and DNA features.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "AnyWho",
|
|
"type": "url",
|
|
"url": "https://www.anywho.com/whitepages",
|
|
"description": "Free white pages directory providing people search by name, reverse phone lookup, and address lookup for US-based contacts.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "US white pages people and phone lookups",
|
|
"input": "Name, phone number, or address",
|
|
"output": "Contact details, address, phone numbers, associated people",
|
|
"opsec": "passive",
|
|
"opsecNote": "Free service; may have bot protection on automated access.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Addresses.com",
|
|
"type": "url",
|
|
"url": "https://www.addresses.com/",
|
|
"description": "Free people search engine for name, phone, and address lookups. Basic results are free; detailed reports redirect to Intelius (paid).",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Quick US people and address lookups",
|
|
"input": "Name, phone number, or address",
|
|
"output": "Name, age, partial phone numbers, associated addresses",
|
|
"opsec": "passive",
|
|
"opsecNote": "Free basic searches; detailed reports require Intelius subscription.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FaceCheckID",
|
|
"type": "url",
|
|
"url": "https://facecheck.id/",
|
|
"description": "Reverse image face search engine that matches uploaded photos against social media, news, and mugshot databases to identify individuals.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Reverse face image search and identity verification",
|
|
"input": "Uploaded face photograph",
|
|
"output": "Matching profiles, social media accounts, news articles, mugshots",
|
|
"opsec": "active",
|
|
"opsecNote": "Uploaded images are processed server-side; free tier has limited results, credits required for full access.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "usa-people-search.com",
|
|
"type": "url",
|
|
"url": "https://www.usa-people-search.com/",
|
|
"description": "US people search and background check service accessing public records.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "US background checks and people search via public records",
|
|
"input": "Name, address, or phone number",
|
|
"output": "Background reports, contact details, public records",
|
|
"opsec": "active",
|
|
"opsecNote": "Paid service; bot protection active.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Registries",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "The Knot",
|
|
"type": "url",
|
|
"url": "https://www.theknot.com/registry/couplesearch",
|
|
"description": "Wedding registry search allowing lookup of couples' wedding registries by name. Part of The Knot comprehensive wedding planning platform.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding wedding registries by couple name",
|
|
"input": "Couple first and last names",
|
|
"output": "Wedding registry links and gift lists",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public search; no registration required.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Registry Finder",
|
|
"type": "url",
|
|
"url": "https://registryfinder.com:443/",
|
|
"description": "Gift registry search aggregator searching across partner retailers including Amazon, Target, and Zola for wedding, baby, birthday, and other registries.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Cross-retailer gift registry search",
|
|
"input": "Registrant first and last name",
|
|
"output": "Registry links across multiple retailers",
|
|
"opsec": "passive",
|
|
"opsecNote": "No registration required; revenue from affiliate commissions.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "My Registry",
|
|
"type": "url",
|
|
"url": "https://www.myregistry.com/",
|
|
"description": "Universal gift registry platform allowing users to add gifts from any store worldwide into one shareable registry for weddings, babies, and other occasions.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Universal cross-store gift registry creation and search",
|
|
"input": "Registrant name",
|
|
"output": "Unified gift registry with items from multiple stores",
|
|
"opsec": "passive",
|
|
"opsecNote": "Free registry search; account needed to create registries.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Amazon Registry Search",
|
|
"type": "url",
|
|
"url": "https://www.amazon.com/registries",
|
|
"description": "Amazon gift registry search for wedding, baby, and other registries.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Finding Amazon gift registries by name",
|
|
"input": "Registrant name",
|
|
"output": "Amazon gift registry links and wish lists",
|
|
"opsec": "passive",
|
|
"opsecNote": "Amazon account may be required for full access.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "The Bump",
|
|
"type": "url",
|
|
"url": "https://registry.thebump.com/babyregistrysearch",
|
|
"description": "Baby registry finder from The Bump parenting platform. Search for baby registries by name to find gift lists.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding baby registries by parent name",
|
|
"input": "Parent first and last name",
|
|
"output": "Baby registry links and gift lists",
|
|
"opsec": "passive",
|
|
"opsecNote": "No registration required to search registries.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Dating",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "AYI.com",
|
|
"type": "url",
|
|
"url": "https://www.ayichat.com",
|
|
"description": "Online community for real-time meeting and chatting with singles across web and mobile platforms.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Real-time flirting and location-based casual dating",
|
|
"input": "Profile details and location",
|
|
"output": "User profiles, chat sessions, and location-based matches",
|
|
"opsec": "active",
|
|
"opsecNote": "Account activity and location sharing are logged by the platform.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Plenty Of Fish.com",
|
|
"type": "url",
|
|
"url": "https://www.pof.com/",
|
|
"description": "Freemium dating platform with large membership and profile-based discovery through filters and recommendations.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Casual dating and broad free profile discovery",
|
|
"input": "Profile details and search filters such as age and location",
|
|
"output": "Suggested profiles and messaging connections",
|
|
"opsec": "passive",
|
|
"opsecNote": "Most discovery is profile browsing; direct username search is limited.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "eHarmony",
|
|
"type": "url",
|
|
"url": "https://www.eharmony.com/",
|
|
"description": "Personality-based matchmaking platform focused on long-term relationships with curated compatibility-driven pairings.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Compatibility-matched dating for long-term relationships",
|
|
"input": "Account registration and personality questionnaire responses",
|
|
"output": "Curated compatibility matches and guided messaging options",
|
|
"opsec": "active",
|
|
"opsecNote": "Detailed personal and compatibility data are collected and used for matching.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Farmers Only",
|
|
"type": "url",
|
|
"url": "https://www.farmersonly.com/",
|
|
"description": "Niche dating service for rural communities including farmers and ranchers with lifestyle-focused matching.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Rural lifestyle dating and niche community matching",
|
|
"input": "Location and profile preferences",
|
|
"output": "Filtered profile matches and messaging opportunities",
|
|
"opsec": "passive",
|
|
"opsecNote": "Location and profile metadata are used for matching within a niche community.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Tinder (R)",
|
|
"type": "url",
|
|
"url": "https://tinder.com/",
|
|
"description": "Swipe-based dating platform emphasizing quick location-aware matching and in-app messaging.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "High-volume casual matching and rapid local discovery",
|
|
"input": "Profile details, preferences, and geolocation",
|
|
"output": "Swipe matches, profile suggestions, and messaging threads",
|
|
"opsec": "active",
|
|
"opsecNote": "Location and engagement behavior are continuously tracked for recommendations.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Bumble (R)",
|
|
"type": "url",
|
|
"url": "https://bumble.com/",
|
|
"description": "Swipe-based dating app with women-first messaging rules and location-based recommendations.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Women-initiated conversations and location-based dating",
|
|
"input": "Profile details, preferences, and geolocation",
|
|
"output": "Suggested matches and app-based messaging connections",
|
|
"opsec": "active",
|
|
"opsecNote": "Platform logs activity, messaging, and location-driven matching behavior.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Tantan (R)",
|
|
"type": "url",
|
|
"url": "https://int.tantanapp.com",
|
|
"description": "Swipe-based Asian-focused dating app with geolocation and algorithmic profile recommendations.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Asia-focused dating and geolocation-based matching",
|
|
"input": "Profile information and location",
|
|
"output": "Suggested matches, profile discovery, and messaging",
|
|
"opsec": "active",
|
|
"opsecNote": "Mobile-centric matching uses location and behavioral interaction data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "AdultFriendFinder",
|
|
"type": "url",
|
|
"url": "https://www.adultfriendfinder.com",
|
|
"description": "Adult-oriented social and dating platform with searchable profiles and preference-driven discovery.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Adult dating, explicit preference filtering, and username-based discovery",
|
|
"input": "Profile details, interests, and search terms",
|
|
"output": "Browsable profiles, messages, and preference-matched results",
|
|
"opsec": "active",
|
|
"opsecNote": "Search and interaction activity can expose sensitive preference and account data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "BeautifulPeople.com",
|
|
"type": "url",
|
|
"url": "https://www.beautifulpeople.com/en-US",
|
|
"description": "Dating community with verification-oriented onboarding and profile access tied to membership standards.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Identity-verified social discovery and premium dating communities",
|
|
"input": "Registration details and profile photos",
|
|
"output": "Verified profile access, match suggestions, and messaging",
|
|
"opsec": "active",
|
|
"opsecNote": "Identity-linked profile verification and social activity are stored by the platform.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Badoo",
|
|
"type": "url",
|
|
"url": "https://badoo.com",
|
|
"description": "Global social dating platform with swipe-based matching, nearby discovery, and in-app messaging.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Global-scale casual dating and people-nearby discovery",
|
|
"input": "Profile details, distance, age range, and preferences",
|
|
"output": "Suggested profiles, swipe matches, and direct messages",
|
|
"opsec": "active",
|
|
"opsecNote": "Location, profile interactions, and behavioral signals are collected for matching.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Spark.com",
|
|
"type": "url",
|
|
"url": "https://spark.com",
|
|
"description": "Long-running relationship-focused dating service with profile filtering and compatibility-oriented matching tools.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Relationship-seeking users and compatibility-based matching",
|
|
"input": "Profile details, preferences, and compatibility indicators",
|
|
"output": "Recommended profiles, search results, and messaging",
|
|
"opsec": "passive",
|
|
"opsecNote": "Profile and compatibility data are stored, with lower visibility than real-time swipe apps.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Meetup",
|
|
"type": "url",
|
|
"url": "https://www.meetup.com/",
|
|
"description": "Community event platform for discovering local groups and activities that can support social and relationship networking.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Interest-based in-person social discovery through events and groups",
|
|
"input": "Topics, location, and group preferences",
|
|
"output": "Group listings, event calendars, and participant profiles",
|
|
"opsec": "passive",
|
|
"opsecNote": "Event and group participation can reveal social interests and local activity patterns.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Hinge",
|
|
"type": "url",
|
|
"url": "https://hinge.co/en-gb",
|
|
"description": "Relationship-oriented dating app focused on prompt-driven profiles and conversation-first matching.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Intentional relationship-focused matching with richer profile context",
|
|
"input": "Profile prompts, preferences, and location",
|
|
"output": "Curated match recommendations and conversation-based interactions",
|
|
"opsec": "active",
|
|
"opsecNote": "User prompts, profile behavior, and matching interactions are logged by the platform.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Telephone Numbers",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Voicemail",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Slydial",
|
|
"type": "url",
|
|
"url": "https://www.slydial.com/",
|
|
"description": "Voicemail drop service that connects directly to a recipient voicemail box without ringing the handset.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Voicemail-based phone-number engagement checks",
|
|
"input": "Phone number (primarily US mobile numbers)",
|
|
"output": "Voicemail delivery result and call/session outcome",
|
|
"opsec": "active",
|
|
"opsecNote": "Initiates outbound telephony actions against the target number and can generate logs/alerts.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "International",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Numbering Plans",
|
|
"type": "url",
|
|
"url": "https://www.numberingplans.com/?page=analysis&sub=phonenr",
|
|
"description": "International numbering reference for E.164 plans, carrier codes, and dialing metadata.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Telephony standards and numbering-plan validation",
|
|
"input": "Country code, number range, or prefix",
|
|
"output": "Numbering-plan structure, carrier/routing metadata, and dialing references",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reference lookup against published numbering data; no interaction with the target number.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Numberway",
|
|
"type": "url",
|
|
"url": "https://www.numberway.com/",
|
|
"description": "Reverse phone lookup resource used to resolve ownership and location context from a phone number.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Reverse phone owner and location enrichment",
|
|
"input": "Phone number",
|
|
"output": "Potential owner identity, carrier, and geographic details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Query is brokered through third-party lookup infrastructure rather than direct target contact.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "WhoCalld",
|
|
"type": "url",
|
|
"url": "https://whocalld.com/",
|
|
"description": "Legacy reverse-caller-ID listing retained for historical continuity in this category.",
|
|
"status": "down",
|
|
"pricing": "freemium",
|
|
"bestFor": "Historical reference only (defunct per project guidance)",
|
|
"input": "Phone number",
|
|
"output": "Previously provided caller identity and spam context",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Marked defunct per CEO guidance; reliability and operational behavior are not trusted.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "CallerID Test",
|
|
"type": "url",
|
|
"url": "https://calleridtest.com/",
|
|
"description": "Caller ID and number-validation utility for checking formatting and telecom metadata responses.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Caller-ID behavior and number validity testing",
|
|
"input": "Phone number",
|
|
"output": "Validation status, format checks, and associated number metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Validation-style lookup with no direct contact to the target subscriber.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Twilio Lookup",
|
|
"type": "url",
|
|
"url": "https://www.twilio.com/lookup",
|
|
"description": "Twilio API endpoint for phone intelligence including line type, carrier, and validation data.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Programmatic carrier/type validation and fraud controls",
|
|
"input": "Phone number in E.164 format",
|
|
"output": "Carrier, line type, validity, and optional risk/intelligence attributes",
|
|
"opsec": "active",
|
|
"opsecNote": "API calls are authenticated and logged by the provider account and may be auditable.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Fone Finder",
|
|
"type": "url",
|
|
"url": "https://www.fonefinder.net/",
|
|
"description": "Legacy reverse phone lookup entry preserved for historical coverage in the framework.",
|
|
"status": "down",
|
|
"pricing": "freemium",
|
|
"bestFor": "Historical reference only (defunct per project guidance)",
|
|
"input": "Phone number",
|
|
"output": "Previously provided owner/location lookup details",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Marked defunct per CEO guidance; do not rely on this entry operationally.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "True Caller",
|
|
"type": "url",
|
|
"url": "https://www.truecaller.com/",
|
|
"description": "Caller identification platform and mobile app for reverse lookup and spam-call context.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Caller-ID enrichment and spam reputation checks",
|
|
"input": "Phone number",
|
|
"output": "Caller profile signals, spam labels, and identity hints",
|
|
"opsec": "passive",
|
|
"opsecNote": "Lookups are mediated by the platform; typical usage does not directly notify the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Reverse Genie",
|
|
"type": "url",
|
|
"url": "https://www.reversegenie.com/phone.php",
|
|
"description": "Reverse phone lookup service that returns publicly aggregated ownership and location hints.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick reverse-number triage from public-data aggregations",
|
|
"input": "Phone number",
|
|
"output": "Possible owner name, location, and related listing details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Search is executed through an aggregator site and is generally non-interactive for targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "SpyDialer",
|
|
"type": "url",
|
|
"url": "https://www.spydialer.com:443/default.aspx",
|
|
"description": "Reverse phone lookup platform with caller intelligence and voicemail-related lookup features.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Phone-number attribution and spam context pivoting",
|
|
"input": "Phone number",
|
|
"output": "Identity clues, carrier/location context, and related lookup data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Primary lookup behavior is database-driven, though some features may increase visibility.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Phone Validator",
|
|
"type": "url",
|
|
"url": "https://www.phonevalidator.com/index.aspx",
|
|
"description": "Number-validation utility focused on format, line-type, and carrier checks.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Phone format/type validation before deeper pivots",
|
|
"input": "Phone number",
|
|
"output": "Validity result, number type, and carrier/format metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Validation query against provider datasets with no direct target interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Phonerator",
|
|
"type": "url",
|
|
"url": "https://www.martinvigo.com/phonerator/",
|
|
"description": "Phone number generation and testing utility for telephony research workflows.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Generating test-number patterns for scripting and analysis",
|
|
"input": "Country/prefix pattern parameters",
|
|
"output": "Generated phone-number candidates and pattern outputs",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local generation/reference behavior; does not query target subscribers directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Mr. Number (M)",
|
|
"type": "url",
|
|
"url": "https://www.hiya.com/products/apps/hiya-spam-blocker",
|
|
"description": "Mr. Number functionality has been consolidated under Hiya; retained as a legacy reference entry.",
|
|
"status": "down",
|
|
"pricing": "paid",
|
|
"bestFor": "Historical mapping to Hiya for caller-ID workflows",
|
|
"input": "Phone number",
|
|
"output": "Previously returned spam and caller-ID context (now via Hiya platform)",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Standalone service is deprecated; use the Hiya entry for current functionality.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Next Caller (R)",
|
|
"type": "url",
|
|
"url": "https://nextcaller.com/",
|
|
"description": "Caller-identification and spam intelligence service for reverse lookup workflows.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Commercial caller-ID enrichment and number intelligence",
|
|
"input": "Phone number",
|
|
"output": "Caller identity indicators, spam reputation, and associated context",
|
|
"opsec": "active",
|
|
"opsecNote": "Account-based commercial lookups are provider-logged and attributable to operator credentials.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Data24-7 (R)",
|
|
"type": "url",
|
|
"url": "https://www.data24-7.com/signup.php",
|
|
"description": "Commercial data enrichment provider supporting phone-based identity and risk intelligence lookups.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Enterprise-scale person/contact enrichment from phone pivots",
|
|
"input": "Phone number (single or batch)",
|
|
"output": "Enriched identity, risk, and contact-profile datasets",
|
|
"opsec": "active",
|
|
"opsecNote": "B2B account activity is logged and tied to customer credentials and usage plans.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "HLR Lookup Portal (R)",
|
|
"type": "url",
|
|
"url": "https://www.hlr-lookups.com/en/start",
|
|
"description": "HLR lookup service for telecom reachability, network, and carrier status checks.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Mobile carrier/HLR validation and route intelligence",
|
|
"input": "Mobile number (E.164)",
|
|
"output": "HLR status, carrier/network identifiers, and routing metadata",
|
|
"opsec": "active",
|
|
"opsecNote": "Telecom lookup transactions are provider-recorded and typically require business credentials.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OpenCNAM API",
|
|
"type": "url",
|
|
"url": "https://api.opencnam.com/v2/phone/+19073372323",
|
|
"description": "CNAM lookup API for resolving caller-name metadata from North American numbers.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Programmatic caller-name enrichment in telecom workflows",
|
|
"input": "US/Canada phone number",
|
|
"output": "CNAM/caller-name string with associated lookup metadata",
|
|
"opsec": "active",
|
|
"opsecNote": "Authenticated API usage is logged and billable per account or subscription terms.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Numspy (T)",
|
|
"type": "python3 Module",
|
|
"url": "https://bhattsameer.github.io/numspy/",
|
|
"description": "OSINT-focused phone lookup utility with CLI-friendly workflows and metadata extraction features.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Technical lookup workflows and scripted number reconnaissance",
|
|
"input": "Phone number",
|
|
"output": "Carrier/region and related phone intelligence fields",
|
|
"opsec": "active",
|
|
"opsecNote": "Tool-driven queries can be attributable to operator infrastructure and API endpoints.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Numspy-Api",
|
|
"type": "url",
|
|
"url": "https://numspy.pythonanywhere.com/",
|
|
"description": "API wrapper for Numspy-style phone intelligence queries and automation use cases.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Programmatic phone-number verification and enrichment",
|
|
"input": "Phone number or batch input",
|
|
"output": "Structured verification and metadata response payloads",
|
|
"opsec": "active",
|
|
"opsecNote": "Remote API calls are logged by service operators and linked to originating access patterns.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Family Tree Now (M)",
|
|
"type": "url",
|
|
"url": "https://www.familytreenow.com/search/genealogy/results?phoneno=(555)555-5555",
|
|
"description": "People-search aggregator that can pivot from phone numbers to identity and relationship records.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Phone-to-person and household/relative pivoting",
|
|
"input": "Phone number",
|
|
"output": "Possible person records, addresses, and relationship links",
|
|
"opsec": "passive",
|
|
"opsecNote": "Search is platform-mediated and generally does not involve direct interaction with targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Whitepages Reverse Phone",
|
|
"type": "url",
|
|
"url": "https://www.whitepages.com/reverse-phone",
|
|
"description": "Reverse phone lookup product from Whitepages for US-focused identity and contact attribution.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "US reverse-phone attribution and address correlation",
|
|
"input": "Phone number (primarily US)",
|
|
"output": "Potential owner, location history, and related contact records",
|
|
"opsec": "passive",
|
|
"opsecNote": "Lookup occurs through a commercial data broker interface without direct target contact.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Hiya (R$)",
|
|
"type": "url",
|
|
"url": "https://www.hiya.com/",
|
|
"description": "Caller-ID and spam-protection platform with reverse lookup capabilities and mobile integrations.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Spam classification and caller-ID enrichment on mobile workflows",
|
|
"input": "Phone number",
|
|
"output": "Caller identity signals, spam ratings, and reputation context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Most checks are service-mediated; advanced features may still be account-tracked.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Public Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Property Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Melissa Data - Property Viewer (R)",
|
|
"type": "url",
|
|
"url": "https://melissa-data.com",
|
|
"description": "Commercial property lookup and real estate information provider with verified tax assessor data. Requires registration and payment for detailed property records.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Property ownership verification",
|
|
"input": "Address or property ID",
|
|
"output": "Property details, tax info, ownership history",
|
|
"opsec": "passive",
|
|
"opsecNote": "Commercial service; creates footprint",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Regrid (US Only)",
|
|
"type": "url",
|
|
"url": "https://regrid.com",
|
|
"description": "Interactive property mapping and parcel data tool covering most US counties. Provides parcel boundaries, assessment data, and ownership information.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Parcel mapping and property boundaries",
|
|
"input": "Address, parcel number, or map coordinates",
|
|
"output": "Parcel maps, ownership, assessment data",
|
|
"opsec": "passive",
|
|
"opsecNote": "US-only coverage; free tier limited",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Emporis",
|
|
"type": "url",
|
|
"url": "https://www.emporis.com/",
|
|
"description": "Buildings database and information portal. DEPRECATED - closed September 2022 by CoStar Group.",
|
|
"status": "down",
|
|
"pricing": "paid",
|
|
"bestFor": "N/A - Service shutdown",
|
|
"input": "N/A",
|
|
"output": "N/A",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "Service discontinued September 2022",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Neighbor Report",
|
|
"type": "url",
|
|
"url": "https://neighbor.report/",
|
|
"description": "Neighborhood and property statistics including crime data, schools, and community information. Aggregates public data into neighborhood profiles.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Neighborhood demographics and safety",
|
|
"input": "Address or zip code",
|
|
"output": "Crime stats, schools, community data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public aggregator, no footprint concerns",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Redfin",
|
|
"type": "url",
|
|
"url": "https://redfin.com",
|
|
"description": "Real estate marketplace with comprehensive property history, MLS data, and market analytics. Includes tax history and public records.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Property history and market data",
|
|
"input": "Address or property ID",
|
|
"output": "Sale history, price trends, tax info",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public real estate platform",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Court / Criminal Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Nationwide County Court Records",
|
|
"type": "url",
|
|
"url": "https://www.publicrecordcenter.com/onlinecourtrecords.htm",
|
|
"description": "Directory and aggregator linking to county court record systems across the United States. Provides navigation to local court databases.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Locating county court records",
|
|
"input": "County name and state",
|
|
"output": "Links to county court systems",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregator of public court links",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "World Legal Information Institute",
|
|
"type": "url",
|
|
"url": "https://worldlii.org",
|
|
"description": "International legal database aggregating laws, regulations, and court decisions from 140+ countries. Free access to legal documents.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "International legal research",
|
|
"input": "Jurisdiction, case name, statute",
|
|
"output": "Court decisions, laws, regulations",
|
|
"opsec": "passive",
|
|
"opsecNote": "Academic/government source",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Most Wanted Criminal Pages",
|
|
"type": "url",
|
|
"url": "https://www.fbi.gov/wanted/fugitives",
|
|
"description": "FBI's official wanted fugitives database featuring the Ten Most Wanted list and expanded fugitive database with photos and details.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Wanted fugitive identification",
|
|
"input": "Name, photo description",
|
|
"output": "Fugitive profiles, photos, rewards",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official FBI resource",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Black Book Online - Criminal Search",
|
|
"type": "url",
|
|
"url": "https://www.blackbookonline.info/",
|
|
"description": "Free public records search portal covering 37,000+ types of records including criminal records, court records, property records, and background checks.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Broad public records aggregation",
|
|
"input": "Name, location, record type",
|
|
"output": "Criminal records, property, court filings",
|
|
"opsec": "passive",
|
|
"opsecNote": "Not FCRA compliant; accuracy not guaranteed",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "CrimeReports.com",
|
|
"type": "url",
|
|
"url": "https://crimereports.com",
|
|
"description": "Real-time crime reporting map aggregating incident data from law enforcement agencies. Interactive map with searchable crime statistics.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Crime incident mapping",
|
|
"input": "Address or area",
|
|
"output": "Crime incidents, type, date, location",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public law enforcement data",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Familywatchdog - Sex Offender Search",
|
|
"type": "url",
|
|
"url": "https://www.familywatchdog.us/",
|
|
"description": "Free sex offender registry aggregator combining data from all US state registries. Interactive mapping of registered offenders.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Sex offender registry search",
|
|
"input": "Name or address",
|
|
"output": "Offender registry info, photo, location",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public registry aggregation",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "The Inmate Locator",
|
|
"type": "url",
|
|
"url": "https://www.bop.gov/inmateloc/",
|
|
"description": "Federal Bureau of Prisons official inmate search tool. Covers federal inmates incarcerated from 1982 to present with daily updates.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Federal inmate location",
|
|
"input": "Name or BOP register number",
|
|
"output": "Location, release date, facility",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official federal database",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "National Sex Offender Search",
|
|
"type": "url",
|
|
"url": "https://www.nsopw.gov/",
|
|
"description": "Official National Sex Offender Public Website aggregating state registry data. Comprehensive multi-state sex offender search tool.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "National sex offender search",
|
|
"input": "Name, address, jurisdiction",
|
|
"output": "Registry info, photo, address",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official government aggregator",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Mugshots.com",
|
|
"type": "url",
|
|
"url": "https://mugshots.com",
|
|
"description": "Searchable mugshot database aggregating arrest records and booking photos from law enforcement agencies nationwide.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Arrest record and mugshot lookup",
|
|
"input": "Name, location",
|
|
"output": "Mugshot, charges, arrest info",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public arrest booking data",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "judyrecords",
|
|
"type": "url",
|
|
"url": "https://www.judyrecords.com/",
|
|
"description": "Free nationwide court case search engine with 760M+ US court cases. Covers federal and state courts with 10x more cases than PACER.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Nationwide court case search",
|
|
"input": "Case name, parties, docket number",
|
|
"output": "Court documents, docket info, filings",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public domain court records",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Caselaw Access Project",
|
|
"type": "url",
|
|
"url": "https://case.law/",
|
|
"description": "Harvard-hosted comprehensive free legal database with 6M+ court opinions. Digitized legal decisions from centuries of US case law.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Historical legal opinion research",
|
|
"input": "Case name, court, year range",
|
|
"output": "Full text opinions, citations",
|
|
"opsec": "passive",
|
|
"opsecNote": "Academic/nonprofit source",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "CourtListener",
|
|
"type": "url",
|
|
"url": "https://courtlistener.com/",
|
|
"description": "Free legal research platform with millions of opinions, dockets, and RECAP data from US federal and appellate courts.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Federal court opinion and docket search",
|
|
"input": "Case name, docket number, judge",
|
|
"output": "Opinions, dockets, documents",
|
|
"opsec": "passive",
|
|
"opsecNote": "Nonprofit legal research platform",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Docket Alarm",
|
|
"type": "url",
|
|
"url": "https://docketalarm.com",
|
|
"description": "Federal and state litigation docket tracking and analysis. Free PACER alternative with real-time docket updates and case tracking.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Litigation docket tracking",
|
|
"input": "Case name or docket number",
|
|
"output": "Docket filings, case status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Incorporates free and paid PACER data",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Scholar Case Law",
|
|
"type": "url",
|
|
"url": "https://scholar.google.com/scholar_courts",
|
|
"description": "Google's free legal research tool indexing millions of court opinions from US federal and state courts.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick case law lookup",
|
|
"input": "Case name, citation, party",
|
|
"output": "Case opinions, related cases",
|
|
"opsec": "passive",
|
|
"opsecNote": "Google service - tracks searches",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "PACER",
|
|
"type": "url",
|
|
"url": "https://pacer.uscourts.gov/",
|
|
"description": "Public Access to Court Electronic Records. Official US federal court records system with fee-based access to documents.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Official federal court documents",
|
|
"input": "Case number, party name",
|
|
"output": "Court documents, dockets, filings",
|
|
"opsec": "passive",
|
|
"opsecNote": "$0.10/page cost; registration required",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Free Law RECAP Archive",
|
|
"type": "url",
|
|
"url": "https://www.courtlistener.com/recap/",
|
|
"description": "Free archive of PACER documents crowdsourced by Free Law Project. Contains millions of federal court documents without per-page fees.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Free federal court documents",
|
|
"input": "Docket number or case name",
|
|
"output": "Court documents, PACER filings",
|
|
"opsec": "passive",
|
|
"opsecNote": "Crowdsourced PACER data via CourtListener",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "UniCourt",
|
|
"type": "url",
|
|
"url": "https://unicourt.com/",
|
|
"description": "Free nationwide litigation database and docket analyzer. Aggregates state and federal court records with smart search and case tracking.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Multi-state litigation search",
|
|
"input": "Case name, parties, docket number",
|
|
"output": "Dockets, filings, case details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Free PACER alternative with additional data",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Federal Inmate Locator",
|
|
"type": "url",
|
|
"url": "https://www.bop.gov/inmateloc/",
|
|
"description": "Bureau of Prisons official inmate search tool covering federal inmates 1982-present. Daily database updates with release dates.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Federal inmate location and release dates",
|
|
"input": "Name or BOP register number",
|
|
"output": "Inmate location, facility, release date",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official federal database, daily updates",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Epstein Exposed",
|
|
"type": "url",
|
|
"url": "https://epsteinexposed.com/",
|
|
"description": "Comprehensive searchable database of Epstein case documents including court records, flight logs, emails, and financial records.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Epstein case document research",
|
|
"input": "Name, document type, keyword",
|
|
"output": "Court docs, emails, flight logs, connections",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public records aggregation; includes network analysis",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Government Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "NC Salary DB",
|
|
"type": "url",
|
|
"url": "https://www.ncosc.gov/public-information/state-employee-salary-database",
|
|
"description": "Official North Carolina state employee salary database. Published by Office of State Controller for transparency.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "NC public employee salary lookup",
|
|
"input": "Employee name, agency",
|
|
"output": "Salary, agency, position",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official state publication",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Gov Data Canada",
|
|
"type": "url",
|
|
"url": "https://open.canada.ca/data/en/dataset",
|
|
"description": "Government of Canada Open Data Portal. Federal open data including demographics, business info, and statistics.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Canadian federal public data",
|
|
"input": "Dataset name, keyword",
|
|
"output": "Open datasets, addresses, business data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official federal open data portal",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "CA Salary DB",
|
|
"type": "url",
|
|
"url": "https://transparentcalifornia.com/",
|
|
"description": "Comprehensive California government salary database covering state, local, schools, universities, and special districts.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "California public employee salary lookup",
|
|
"input": "Name, employer, position",
|
|
"output": "Salary, benefits, employer",
|
|
"opsec": "passive",
|
|
"opsecNote": "Transparency-focused public records",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Financial / Tax Resources",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "BIN Base",
|
|
"type": "url",
|
|
"url": "https://www.buybindatabase.binbase.com/",
|
|
"description": "Business Identification Number database for company registration lookups. Provides business registration and compliance information.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Business registration verification",
|
|
"input": "Company name or BIN",
|
|
"output": "Business registration, status, details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Commercial company database",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "VAT Research",
|
|
"type": "url",
|
|
"url": "https://www.belastingdienst.nl/",
|
|
"description": "Netherlands tax authorities (Belastingdienst) database. Allows VAT number verification through VIES system.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Dutch VAT number verification",
|
|
"input": "VAT number or company name",
|
|
"output": "VAT status, registration, business info",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official Dutch tax authority",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "NETR Online",
|
|
"type": "url",
|
|
"url": "https://publicrecords.netronline.com/",
|
|
"description": "Nationwide property records portal linking to county assessors and county recorders. Provides property tax, deed, and parcel data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "County property records aggregation",
|
|
"input": "Address, county name, owner name",
|
|
"output": "Property deeds, tax records, assessments",
|
|
"opsec": "passive",
|
|
"opsecNote": "Links to county systems; coverage varies",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Birth Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Sorted by Birth Date",
|
|
"type": "url",
|
|
"url": "https://www.bop.gov/inmateloc/",
|
|
"description": "Refers to inmate search filters available in state and federal inmate databases. Searchable by date of birth field.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Inmate lookup by birth date",
|
|
"input": "Date of birth, state/federal system",
|
|
"output": "Inmate records, location, release date",
|
|
"opsec": "passive",
|
|
"opsecNote": "Feature of various inmate databases",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Death Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Death Check",
|
|
"type": "url",
|
|
"url": "https://www.deathindexes.com/",
|
|
"description": "Directory of online death indexes, obituaries, and cemetery records. Aggregates links to state and national obituary databases.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Death record and obituary lookup",
|
|
"input": "Name, location, date range",
|
|
"output": "Obituaries, death certificates, dates",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregator of public death records",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Find A Grave",
|
|
"type": "url",
|
|
"url": "https://www.findagrave.com/",
|
|
"description": "Largest online cemetery database with 615M+ grave records from 250M+ graves in 500K+ cemeteries worldwide.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Cemetery and burial record search",
|
|
"input": "Name, cemetery, location",
|
|
"output": "Grave location, photos, dates",
|
|
"opsec": "passive",
|
|
"opsecNote": "User-contributed genealogical data",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "GraveInfo",
|
|
"type": "url",
|
|
"url": "https://billiongraves.com/",
|
|
"description": "Cemetery records database with GPS-marked grave locations and gravestone photos. Aggregates cemetery information with mobile crowdsourcing.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "GPS cemetery mapping",
|
|
"input": "Name, cemetery, location",
|
|
"output": "Grave location, coordinates, photos",
|
|
"opsec": "passive",
|
|
"opsecNote": "Crowdsourced cemetery photographs",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "US County Data",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "NACo County Explorer",
|
|
"type": "url",
|
|
"url": "https://explorer.naco.org/",
|
|
"description": "Interactive mapping tool with 1000+ demographic and economic indicators for all 3,069 US counties. National Association of Counties data portal.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "County-level demographic analysis",
|
|
"input": "County name, data indicator",
|
|
"output": "Demographics, economics, health, education",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public aggregated county data",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "US Voter Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Voter Registration Data",
|
|
"type": "url",
|
|
"url": "https://www.sos.secretary.state.gov/",
|
|
"description": "State-level voter registration databases. Varies significantly by state in coverage and access methods.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Voter registration verification",
|
|
"input": "Name, state, county",
|
|
"output": "Registration status, voting history",
|
|
"opsec": "passive",
|
|
"opsecNote": "State-specific access and restrictions vary",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Patent Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "US Patent Office Search",
|
|
"type": "url",
|
|
"url": "https://www.uspto.gov/patents/search",
|
|
"description": "Official US Patent and Trademark Office searchable patent database. Covers US patents and applications.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "US patent search",
|
|
"input": "Patent number, inventor name, keyword",
|
|
"output": "Patent documents, claims, assignee info",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official USPTO database",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Patent Search",
|
|
"type": "url",
|
|
"url": "https://patents.google.com/",
|
|
"description": "Google's searchable patent database covering US, EU, WIPO and other international patents. Full-text search with categorization.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "International patent research",
|
|
"input": "Patent number, inventor, keyword, CPC",
|
|
"output": "Patent docs, citations, families",
|
|
"opsec": "passive",
|
|
"opsecNote": "Google service tracks searches",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "US Political Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Political MoneyLine",
|
|
"type": "url",
|
|
"url": "https://www.opensecrets.org/",
|
|
"description": "Campaign finance and political money database aggregating federal election contributions and lobbying data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Campaign finance and lobbying tracking",
|
|
"input": "Candidate name, donor, committee",
|
|
"output": "Contributions, expenditures, disclosures",
|
|
"opsec": "passive",
|
|
"opsecNote": "OpenSecrets nonprofit database",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MelissaData - Campaign Contributions",
|
|
"type": "url",
|
|
"url": "https://melissa-data.com",
|
|
"description": "Commercial campaign contribution database with verified donor and contribution records. Requires subscription.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Verified campaign donation records",
|
|
"input": "Donor name, candidate, date range",
|
|
"output": "Contributions, amounts, recipients",
|
|
"opsec": "passive",
|
|
"opsecNote": "Commercial data service; subscription required",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Influence Explorer",
|
|
"type": "url",
|
|
"url": "https://influenceexplorer.com/",
|
|
"description": "Campaign finance, lobbying, and political data aggregator. Part of OpenSecrets ecosystem with federal and state data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Political influence and money tracking",
|
|
"input": "Name, organization, industry",
|
|
"output": "Political contributions, lobbying, connections",
|
|
"opsec": "passive",
|
|
"opsecNote": "OpenSecrets-affiliated nonprofit",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "US Federal Election Commission",
|
|
"type": "url",
|
|
"url": "https://fec.gov/data",
|
|
"description": "Official Federal Election Commission data portal. Searchable federal campaign finance disclosures and election data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Federal campaign finance records",
|
|
"input": "Candidate, committee, donor name",
|
|
"output": "Contributions, expenditures, disclosures",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official government source",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Every Politician",
|
|
"type": "url",
|
|
"url": "https://everypolitician.org/",
|
|
"description": "Open data project aggregating politician information globally. Structured data on politicians, positions, and affiliations.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Global politician data and positions",
|
|
"input": "Politician name, country, position",
|
|
"output": "Bio, positions, affiliations, contact",
|
|
"opsec": "passive",
|
|
"opsecNote": "Crowdsourced open government data",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Public Records?",
|
|
"type": "url",
|
|
"url": "https://www.brbpublications.com/",
|
|
"description": "Ambiguous entry - likely refers to BRB Publications' public records portal or aggregator. See BRB Public Records below for clarification.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Unclear - requires VP clarification",
|
|
"input": "Unknown",
|
|
"output": "Unknown",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "FLAG: Ambiguous tool name; VP guidance needed",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "The World Bank Open Data Catalog",
|
|
"type": "url",
|
|
"url": "https://datacatalog.worldbank.org/",
|
|
"description": "World Bank open development data portal with datasets on economics, demographics, and global development indicators.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Development data and statistics",
|
|
"input": "Country, indicator, dataset name",
|
|
"output": "Economic, social, health data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official World Bank datasets",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "BRB Public Records",
|
|
"type": "url",
|
|
"url": "https://www.brbpublications.com/",
|
|
"description": "BRB Publications portal linking to public records sources across US. Reference guide with 20K+ government agencies and vendors.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Public records source directory",
|
|
"input": "Record type, jurisdiction",
|
|
"output": "Agency links, access instructions",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregator of public access links",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "GOVDATA - Das Datenportal f\u00fcr Deutschland (German)",
|
|
"type": "url",
|
|
"url": "https://www.govdata.de/",
|
|
"description": "Official German government open data portal with 120K+ datasets. Centralized access to federal, state, and local administrative data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "German administrative data",
|
|
"input": "Dataset name, keyword, category",
|
|
"output": "Open datasets, metadata, downloads",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official German government portal",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Open-Data-Portal M\u00fcnchen (German)",
|
|
"type": "url",
|
|
"url": "https://opendata.muenchen.de/",
|
|
"description": "City of Munich open data portal with 331+ datasets. Provides administrative data from Munich government at city level.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Munich municipal administrative data",
|
|
"input": "Dataset name, category, keyword",
|
|
"output": "City datasets, statistics, services",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official Munich city data portal",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Searchable FCC ID Database",
|
|
"type": "url",
|
|
"url": "https://www.fcc.gov/oet/ea/fccid",
|
|
"description": "Official FCC database for electronic device certification. Searchable by FCC ID with product specs, manuals, and test reports.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Electronics device certification lookup",
|
|
"input": "FCC ID, device model, manufacturer",
|
|
"output": "Device specs, manuals, test reports, photos",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official FCC database",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Compliance & Risk Intelligence",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Sanctions Screening",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "OpenSanctions",
|
|
"type": "url",
|
|
"url": "https://www.opensanctions.org/",
|
|
"description": "Aggregated database of sanctioned entities, politically exposed persons, and persons of criminal interest from 329 global data sources.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Bulk sanctions and PEP screening across consolidated global watchlists",
|
|
"input": "Person or entity name",
|
|
"output": "Entity profiles with sanctions designations, PEP flags, and source metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookups against a public database; API usage requires an account and is logged.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OFAC Sanctions List Search",
|
|
"type": "url",
|
|
"url": "https://sanctionssearch.ofac.treas.gov/",
|
|
"description": "Official U.S. Treasury tool for searching OFAC Specially Designated Nationals and related sanctions lists with approximate string matching.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Checking individuals or entities against U.S. sanctions programs",
|
|
"input": "Name, address, entity type, ID number, or sanctions program",
|
|
"output": "Matched records with name, sanctions program, list designation, and confidence score",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public U.S. government search tool; queries are submitted to a federal server and may be logged.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "EU Sanctions Tool (D)",
|
|
"type": "url",
|
|
"url": "https://sanctions-tool.ec.europa.eu",
|
|
"description": "European Commission tool for searching EU restrictive measures and consolidated sanctions lists targeting persons, entities, and bodies.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Checking individuals or entities against EU sanctions regimes",
|
|
"input": "Person or entity name",
|
|
"output": "Matches against EU consolidated sanctions list with designation details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public EU government search tool; queries are submitted to an EU server and may be logged.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "dilisense",
|
|
"type": "url",
|
|
"url": "https://dilisense.com/en",
|
|
"description": "AML compliance platform that screens individuals and entities against sanctions, PEP, and watchlist data sources with fuzzy matching and confidence scoring.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Commercial AML/KYC sanctions screening and PEP checks",
|
|
"input": "Name, date of birth, citizenship, or other identifying information",
|
|
"output": "Match results with entity details, list sources, and confidence scores",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries sent to dilisense servers; registration required so searches are tied to an account.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "KYC / AML Tools",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "NameScan",
|
|
"type": "url",
|
|
"url": "https://namescan.io",
|
|
"description": "Compliance screening platform providing sanctions checks, PEP screenings, and adverse media searches against global government databases with a free tier.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Quick free sanctions and PEP screening with adverse media checks",
|
|
"input": "Individual or business name",
|
|
"output": "Screening reports with sanctions matches, PEP flags, and adverse media hits",
|
|
"opsec": "passive",
|
|
"opsecNote": "Free scans available without registration; full access requires account creation.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OpenScreening",
|
|
"type": "url",
|
|
"url": "https://resources.linkurious.com/openscreening",
|
|
"description": "Free graph-based PEP and sanctions screening tool by Linkurious that visualizes connections across persons of interest using OpenSanctions and ICIJ data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Visualizing connections between sanctioned entities, PEPs, and offshore structures",
|
|
"input": "Individual or organization name",
|
|
"output": "Interactive graph visualizations showing entity relationships and sanctions connections",
|
|
"opsec": "passive",
|
|
"opsecNote": "Web-based search against public datasets hosted by Linkurious; queries are sent to their servers.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Companies House (R)",
|
|
"type": "url",
|
|
"url": "https://find-and-update.company-information.service.gov.uk/",
|
|
"description": "Official UK government register for searching company information, officer appointments, and disqualified directors across all UK-registered companies.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Looking up UK company details, officers, and filing history",
|
|
"input": "Company name, company number, or officer name",
|
|
"output": "Company profiles, registered addresses, officer appointments, filing history, and document images",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public UK government service; searches are passive lookups against an open register.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Beneficial Ownership Lookup",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "OpenOwnership",
|
|
"type": "url",
|
|
"url": "https://www.openownership.org/en/",
|
|
"description": "Global hub for beneficial ownership transparency, providing data standards and a register linking corporate ownership data across jurisdictions.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Investigating beneficial ownership of corporate entities across jurisdictions",
|
|
"input": "Company name, jurisdiction, or person name",
|
|
"output": "Beneficial ownership chains, corporate structures, and linked entities across registers",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public web queries against open data; no notification to subjects.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ICIJ Offshore Leaks Database",
|
|
"type": "url",
|
|
"url": "https://offshoreleaks.icij.org/",
|
|
"description": "Searchable database of 800,000+ offshore entities from ICIJ investigations including Panama Papers, Paradise Papers, and Pandora Papers.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Tracing offshore company structures and hidden ownership from leaked documents",
|
|
"input": "Person name, company name, address, or jurisdiction",
|
|
"output": "Entity records, officer relationships, intermediary connections, and network graphs",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public database queries; no notification to subjects. Bulk data also available for download.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OCCRP Aleph (R)",
|
|
"type": "url",
|
|
"url": "https://aleph.occrp.org/",
|
|
"description": "Global archive of research material for investigative reporting, aggregating public records, court filings, company registries, and leaks from 200+ sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Cross-referencing persons and companies across public records, leaks, and investigative datasets",
|
|
"input": "Person name, company name, or document keywords",
|
|
"output": "Entity profiles, linked datasets, document matches, and relationship mappings",
|
|
"opsec": "passive",
|
|
"opsecNote": "Registration required for full access; queries are logged by OCCRP but subjects are not notified.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Public Records?",
|
|
"type": "url",
|
|
"url": "https://publicrecords.searchsystems.net/"
|
|
},
|
|
{
|
|
"name": "The World Bank Open Data Catalog",
|
|
"type": "url",
|
|
"url": "https://datacatalog.worldbank.org/"
|
|
},
|
|
{
|
|
"name": "BRB Public Records",
|
|
"type": "url",
|
|
"url": "https://www.brbpub.com/"
|
|
},
|
|
{
|
|
"name": "GOVDATA - Das Datenportal f\u00fcr Deutschland (German)",
|
|
"type": "url",
|
|
"url": "https://www.govdata.de/"
|
|
},
|
|
{
|
|
"name": "Open-Data-Portal M\u00fcnchen (German)",
|
|
"type": "url",
|
|
"url": "https://www.opengov-muenchen.de/"
|
|
},
|
|
{
|
|
"name": "Searchable FCC ID Database",
|
|
"type": "url",
|
|
"url": "https://fccid.io/"
|
|
},
|
|
{
|
|
"name": "Sanctions / PEP",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "PepChecker (R)",
|
|
"type": "url",
|
|
"url": "https://pepchecker.com",
|
|
"description": "PEP and sanctions screening tool offering checks against comprehensive PEP lists and global sanctions databases with a free tier of limited searches.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Screening individuals against PEP lists and international sanctions databases",
|
|
"input": "Person name",
|
|
"output": "PEP match results, sanctions list matches, risk indicators, and political exposure details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Web-based queries; registration required for workspace features. Subjects are not notified.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Ukraine PEP Register (D)",
|
|
"type": "url",
|
|
"url": "https://pep.org.ua/en/",
|
|
"description": "Formerly a database of Ukrainian politically exposed persons maintained by civil society. Now redirects to a static wartime advocacy page.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Previously used for checking Ukrainian politically exposed persons",
|
|
"input": "Person name (when operational)",
|
|
"output": "PEP profiles and political positions (when operational)",
|
|
"opsec": "passive",
|
|
"opsecNote": "Site is no longer functional; original database was a public web lookup.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "EveryPolitician",
|
|
"type": "url",
|
|
"url": "https://everypolitician.org/",
|
|
"description": "Global database of political office-holders now operated as part of the OpenSanctions project, providing structured data on politicians and public officials worldwide.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Looking up current and former political office-holders globally for PEP screening",
|
|
"input": "Person name, country, or political position",
|
|
"output": "Politician profiles, positions held, party affiliations, and jurisdictional data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public database queries against open data; no notification to subjects.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Business Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Annual Reports",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "AnnualReports.com",
|
|
"type": "url",
|
|
"url": "https://www.annualreports.com/",
|
|
"description": "Free directory of annual reports for thousands of public companies worldwide. Allows browsing and downloading official investor relations documents.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Locating and downloading public company annual reports",
|
|
"input": "Company name or ticker symbol",
|
|
"output": "Annual reports, sustainability reports, and proxy statements",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are routed through AnnualReports.com servers; no direct contact with target company.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Public Register Online",
|
|
"type": "url",
|
|
"url": "https://www.annualreportservice.com/",
|
|
"description": "Online directory for accessing annual reports and financial documents from companies that participate in the service.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Requesting hard copy or digital annual reports from participating companies",
|
|
"input": "Company name",
|
|
"output": "Annual report listings with request or download links",
|
|
"opsec": "passive",
|
|
"opsecNote": "Lookup requests go through the service's servers; no direct contact with target company.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Public Register's Annual Report Service",
|
|
"type": "url",
|
|
"url": "https://www.prars.com/search/alpha/A",
|
|
"description": "PRARS provides access to annual reports for thousands of publicly traded companies, organized alphabetically for browsing.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Browsing annual reports for US public companies alphabetically",
|
|
"input": "Company name (alphabetical browse)",
|
|
"output": "Annual reports and financial filings",
|
|
"opsec": "passive",
|
|
"opsecNote": "All requests pass through PRARS servers; no direct contact with target entity.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "International Registries",
|
|
"type": "url",
|
|
"url": "https://www.gov.uk/government/publications/overseas-registries/overseas-registries",
|
|
"description": "UK government page listing official overseas company registries for countries worldwide, linking to each nation's official registration authority.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding official company registry links for foreign jurisdictions",
|
|
"input": "Country name (browsed from list)",
|
|
"output": "Links to official company registration authorities by country",
|
|
"opsec": "passive",
|
|
"opsecNote": "Static reference page on gov.uk; no target interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "General Info & News",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Commercial Register - Worldwide",
|
|
"type": "url",
|
|
"url": "https://www.sg.ch/recht/handelsregister-notariate.html",
|
|
"description": "Canton of St. Gallen (Switzerland) official commercial register, providing a searchable database of businesses registered in the canton.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Searching Swiss corporate registry for businesses registered in St. Gallen",
|
|
"input": "Company name or registration number",
|
|
"output": "Business registration details, legal form, registered address",
|
|
"opsec": "passive",
|
|
"opsecNote": "Government registry query; no interaction with the target entity.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "SEC.gov - EDGAR",
|
|
"type": "url",
|
|
"url": "https://www.sec.gov/submit-filings",
|
|
"description": "The SEC's Electronic Data Gathering, Analysis, and Retrieval system provides free public access to corporate filings including 10-K, 10-Q, 8-K, and proxy statements.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Researching US public company financials, ownership, and regulatory filings",
|
|
"input": "Company name, ticker symbol, or CIK number",
|
|
"output": "SEC filings including annual reports, quarterly reports, insider transactions, and prospectuses",
|
|
"opsec": "passive",
|
|
"opsecNote": "Government public database; searches do not interact with the target company.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "International White Pages",
|
|
"type": "url",
|
|
"url": "https://www.wayp.com/",
|
|
"description": "WAYP.com is an international white pages and business directory aggregating contact listings from multiple countries.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "International business and personal contact lookups by country",
|
|
"input": "Name, business name, or phone number",
|
|
"output": "Contact listings including address and phone data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Lookup queries routed through WAYP servers; no direct contact with listed individuals.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "UK Companies",
|
|
"type": "url",
|
|
"url": "https://www.gov.uk/get-information-about-a-company",
|
|
"description": "Official UK government service providing free access to information about companies registered in England, Wales, Scotland, and Northern Ireland.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Looking up UK-registered company details, officers, and filing history",
|
|
"input": "Company name or registration number",
|
|
"output": "Registration details, officers, filing history, and charges",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official government service; queries do not interact with the target company.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Global EDGE Resource Directory",
|
|
"type": "url",
|
|
"url": "https://globaledge.msu.edu/global-resources",
|
|
"description": "MSU GlobalEdge curated directory of international business resources, organized by topic including trade, investment, finance, and country data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding international business intelligence resources and databases by topic",
|
|
"input": "Topic or resource category (browsed from directory)",
|
|
"output": "Curated links to international business data sources, reports, and tools",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reference directory; no interaction with targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Finance",
|
|
"type": "url",
|
|
"url": "https://www.google.com/finance/",
|
|
"description": "Google's financial data platform providing stock quotes, financial statements, news, and company overviews for publicly traded companies.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick financial overview, stock data, and news for public companies",
|
|
"input": "Company name or stock ticker",
|
|
"output": "Stock price, financial summaries, news, and related companies",
|
|
"opsec": "passive",
|
|
"opsecNote": "All queries routed through Google; no direct interaction with target company.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Company Profiles",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "OpenCorporates",
|
|
"type": "url",
|
|
"url": "https://opencorporates.com/",
|
|
"description": "The world's largest open database of companies, covering 200+ jurisdictions with over 200 million company records sourced directly from official registries.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Cross-jurisdictional company research and corporate network mapping",
|
|
"input": "Company name, registration number, or officer name",
|
|
"output": "Company registration details, officers, filings, and jurisdictional data",
|
|
"opsec": "passive",
|
|
"opsecNote": "All queries go through OpenCorporates servers; aggregates from public registries.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "AIHIT",
|
|
"type": "url",
|
|
"url": "https://www.aihitdata.com/",
|
|
"description": "B2B company intelligence platform providing data on millions of businesses including executives, contact information, and company profiles.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Company executive discovery and B2B contact data enrichment",
|
|
"input": "Company name or domain",
|
|
"output": "Company profile, executive contacts, industry classification, and revenue estimates",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries routed through AIHIT servers; aggregates from web sources.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Plonked",
|
|
"type": "url",
|
|
"url": "https://www.plonked.com/",
|
|
"description": "UK business directory service for locating companies and contact information.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "UK business lookup by name or location",
|
|
"input": "Business name or location",
|
|
"output": "Business contact details and address",
|
|
"opsec": "passive",
|
|
"opsecNote": "Directory service; no direct contact with listed businesses.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Buzzfile",
|
|
"type": "url",
|
|
"url": "https://www.buzzfile.com/Home/Basic",
|
|
"description": "US company database providing business profiles, SIC codes, employee counts, and contact information for millions of US businesses.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "US business lookup by name, location, or industry classification",
|
|
"input": "Company name, location, or SIC code",
|
|
"output": "Business profiles with contacts, employee count, and revenue estimates",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries processed through Buzzfile servers; aggregates from public records.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "LittleSis",
|
|
"type": "url",
|
|
"url": "https://littlesis.org/",
|
|
"description": "Free database mapping relationships between powerful people and organizations, tracking political donors, lobbyists, board members, and corporate networks.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Mapping power relationships between corporations, politicians, and elites",
|
|
"input": "Person name, organization, or entity",
|
|
"output": "Relationship graphs, board memberships, political donations, and affiliations",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries processed through LittleSis servers; data sourced from public records.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Rusprofile",
|
|
"type": "url",
|
|
"url": "https://www.rusprofile.ru/",
|
|
"description": "Russian company registry and business intelligence platform providing information on Russian legal entities from official government sources.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Researching Russian companies, directors, and legal entity registration",
|
|
"input": "Company name, INN (tax ID), or OGRN (registration number)",
|
|
"output": "Registration details, directors, financial data, and legal filings for Russian entities",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries routed through Rusprofile servers; aggregates from Russian government registries.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Companies House",
|
|
"type": "url",
|
|
"url": "https://beta.companieshouse.gov.uk/",
|
|
"description": "Official UK government company registry for England, Wales, Scotland, and Northern Ireland. Provides free access to company filings, officers, and registration details.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "UK company registration details, directors, and filed accounts",
|
|
"input": "Company name, registration number, or officer name",
|
|
"output": "Company profile, registered officers, filing history, and charges",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official government registry; queries do not interact with the target company.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Company Data Rex (EU)",
|
|
"type": "url",
|
|
"url": "https://www.cdrex.com/",
|
|
"description": "European company data aggregation platform providing business intelligence on EU-registered companies from multiple national registries.",
|
|
"status": "degraded",
|
|
"pricing": "freemium",
|
|
"bestFor": "Cross-border EU company research and registry data lookup",
|
|
"input": "Company name or registration number",
|
|
"output": "Company registration details, financial summaries, and officer information",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries processed through CDRex servers; aggregates from EU national registries.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Europages",
|
|
"type": "url",
|
|
"url": "https://www.europages.co.uk:443/",
|
|
"description": "European B2B marketplace and company directory covering 3+ million companies across 26 countries with product and service listings.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding European suppliers, manufacturers, and B2B companies by industry",
|
|
"input": "Company name, product, or industry sector",
|
|
"output": "Company listings with contact information, products, and certifications",
|
|
"opsec": "passive",
|
|
"opsecNote": "All queries routed through Europages servers; no direct contact with listed companies.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Owler (R)",
|
|
"type": "url",
|
|
"url": "https://www.owler.com/corp",
|
|
"description": "Competitive intelligence platform providing company profiles, revenue estimates, employee counts, news alerts, and competitor tracking. Requires registration for full access.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Competitive intelligence and company profile research",
|
|
"input": "Company name or domain",
|
|
"output": "Revenue estimates, employee count, funding history, competitors, and news",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries processed through Owler servers; aggregates from public and crowdsourced data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Vault",
|
|
"type": "url",
|
|
"url": "https://vault.com/",
|
|
"description": "Career research platform providing company profiles, employee reviews, salary data, and industry guides for job seekers and researchers.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Company culture research, salary benchmarking, and employee sentiment analysis",
|
|
"input": "Company name or industry",
|
|
"output": "Company profiles, employee reviews, rankings, and salary data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries processed through Vault servers; content sourced from employee submissions.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Companies In The UK",
|
|
"type": "url",
|
|
"url": "https://www.companiesintheuk.co.uk/",
|
|
"description": "UK company search engine aggregating information from Companies House, providing easy lookup of registered UK businesses.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick UK company lookup with simplified Companies House data",
|
|
"input": "Company name or registration number",
|
|
"output": "Company registration details, status, address, and SIC codes",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries processed through the service's servers using Companies House data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "UK Data",
|
|
"type": "url",
|
|
"url": "https://ukdata.com/",
|
|
"description": "UK company information and credit data service providing business intelligence on UK-registered companies.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "UK company credit checks and financial health assessment",
|
|
"input": "Company name or registration number",
|
|
"output": "Company credit scores, financial summaries, directors, and registration details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries processed through UK Data servers; aggregates from Companies House and financial sources.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Orbis Directory",
|
|
"type": "url",
|
|
"url": "https://orbisdirectory.bvdinfo.com/version-2016121/OrbisDirectory/Companies",
|
|
"description": "Bureau van Dijk's global company database covering 400+ million companies with standardized financial data, ownership structures, and M&A activity.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Deep financial analysis and global ownership structure research",
|
|
"input": "Company name, registration number, or BvD ID",
|
|
"output": "Standardized financials, ownership chains, subsidiaries, and M&A data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries processed through BvD servers; enterprise data product with institutional access.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Crunchbase",
|
|
"type": "url",
|
|
"url": "https://www.crunchbase.com/#/home/index",
|
|
"description": "Leading startup and investment intelligence platform tracking company funding rounds, acquisitions, investors, and executive profiles.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Startup funding research, investor mapping, and executive tracking",
|
|
"input": "Company name, person name, or investor name",
|
|
"output": "Funding history, investors, acquisitions, team profiles, and news",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries processed through Crunchbase servers; aggregates from public and submitted data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Employee Profiles & Resumes",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "RecruitEm",
|
|
"type": "url",
|
|
"url": "https://recruitin.net/",
|
|
"description": "Free X-Ray search tool for finding profiles on LinkedIn, GitHub, Twitter, and other platforms using Google's site: operator with customizable search parameters.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "X-Ray searching LinkedIn and other platforms for employee and candidate profiles",
|
|
"input": "Job title, skills, location, and target platform",
|
|
"output": "Google search query and direct results links for profile discovery",
|
|
"opsec": "passive",
|
|
"opsecNote": "Generates Google dork queries; actual searches routed through Google.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "LinkedIn",
|
|
"type": "url",
|
|
"url": "https://www.linkedin.com/",
|
|
"description": "World's largest professional network with 900+ million members. Provides company pages, employee listings, and professional history data.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Professional background research, employee enumeration, and corporate structure mapping",
|
|
"input": "Person name, company name, or job title",
|
|
"output": "Professional profiles, employment history, connections, company pages, and job listings",
|
|
"opsec": "active",
|
|
"opsecNote": "Profile views may be visible to the target; use private/restricted browsing mode to reduce visibility.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Jobster",
|
|
"type": "url",
|
|
"url": "https://jobster.com/",
|
|
"description": "Early job search and professional networking site that aggregated job listings and professional profiles.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Job listing and professional profile search (historical)",
|
|
"input": "Job title or person name",
|
|
"output": "Job listings and professional profiles",
|
|
"opsec": "passive",
|
|
"opsecNote": "Service is no longer operational.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "XING (R)",
|
|
"type": "url",
|
|
"url": "https://www.xing.com/",
|
|
"description": "European professional networking platform popular in German-speaking countries. Provides company profiles, employee listings, and career data. Requires registration to view profiles.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Professional background research for German and European contacts",
|
|
"input": "Person name or company name",
|
|
"output": "Professional profiles, employment history, company pages, and connections",
|
|
"opsec": "active",
|
|
"opsecNote": "Profile views may be visible to the target; use private browsing to reduce exposure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "CVGadget",
|
|
"type": "url",
|
|
"url": "https://cvgadget.com/",
|
|
"description": "CV and resume search tool using Google X-Ray techniques to find publicly posted resumes and CVs on the web.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Finding publicly posted resumes and CVs via Google X-Ray search",
|
|
"input": "Job title, skills, and location",
|
|
"output": "Google dork queries linking to publicly available CVs and resumes",
|
|
"opsec": "passive",
|
|
"opsecNote": "Generates Google dork queries; results routed through Google.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Additional Resources",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "RBA - Business Information Resources",
|
|
"type": "url",
|
|
"url": "https://www.rba.co.uk/sources/",
|
|
"description": "Curated directory maintained by Researching Business Activities, linking to free and paid business information sources organized by category.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding specialized business intelligence resources and databases by topic",
|
|
"input": "Topic or category (browsed from directory)",
|
|
"output": "Annotated links to business data sources, news aggregators, and research tools",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reference directory; no direct interaction with targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "VAT Number Validation",
|
|
"type": "url",
|
|
"url": "https://ec.europa.eu/taxation_customs/vies/?locale=en",
|
|
"description": "EU VIES (VAT Information Exchange System) allows validation of VAT numbers for businesses registered in EU member states.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Validating EU VAT registration numbers and identifying registered businesses",
|
|
"input": "EU VAT number (country code + number)",
|
|
"output": "VAT registration validity, company name, and registered address",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries processed through the EU VIES system; no direct interaction with the target company.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Transportation",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Vehicle Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "MyAccident - traffic accident map",
|
|
"type": "url",
|
|
"url": "https://myaccident.org/",
|
|
"description": "Free database of redacted US traffic accident reports with searchable crash records and location details.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "US accident history verification and claims investigations",
|
|
"input": "Accident location, address, or basic vehicle details",
|
|
"output": "Redacted accident reports, crash severity, and location data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Read-only public database access; no direct contact with investigation targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "NHTSA Vehicle API",
|
|
"type": "url",
|
|
"url": "https://vpic.nhtsa.dot.gov/api/",
|
|
"description": "Official US government VIN decoder API with vehicle specification and manufacturer data for model years 1981 onward.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "VIN decoding and US vehicle specification checks",
|
|
"input": "17-character VIN (full or partial with wildcards)",
|
|
"output": "Make, model, year, manufacturer, engine details, and related data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public government API endpoint with anonymous read access.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FindByPlate",
|
|
"type": "url",
|
|
"url": "https://findbyplate.com/",
|
|
"description": "US license plate lookup service for basic vehicle identification and ownership-related investigation leads.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "US license plate-based vehicle investigations",
|
|
"input": "US license plate number and state",
|
|
"output": "Vehicle make, model, year, and limited ownership hints",
|
|
"opsec": "passive",
|
|
"opsecNote": "Standard web lookup workflow without active interaction against the vehicle owner.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "carVertical VIN Decoder",
|
|
"type": "url",
|
|
"url": "https://www.carvertical.com/vin-decoder",
|
|
"description": "International VIN and registration decoder with vehicle history reporting across accident, theft, and ownership datasets.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Cross-border vehicle history and ownership verification",
|
|
"input": "VIN or vehicle registration number",
|
|
"output": "Vehicle specs, accident history, theft records, and ownership changes",
|
|
"opsec": "passive",
|
|
"opsecNote": "Web-based lookup with paid reporting layers; no direct target interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "autoDNA VIN Lookup",
|
|
"type": "url",
|
|
"url": "https://www.autodna.com/",
|
|
"description": "Vehicle history lookup platform with records from European and North American markets and paid report expansion.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "VIN-based damage, ownership, and service history checks",
|
|
"input": "17-character VIN",
|
|
"output": "Inspection, damage, repair, ownership, and mileage records",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup model; full intelligence requires paid report access.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "VinDecodr",
|
|
"type": "url",
|
|
"url": "https://vindecodr.com/",
|
|
"description": "Free VIN decoder for quick extraction of standard vehicle characteristics from 17-character VIN values.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Rapid vehicle specification lookup from VIN values",
|
|
"input": "17-character VIN",
|
|
"output": "Vehicle make, model, year, engine, and recall-related details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Simple public decoder workflow with no active probing against external systems.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "AutoRef (EU)",
|
|
"type": "url",
|
|
"url": "https://www.autoref.eu/en",
|
|
"description": "European VIN and plate intelligence service with free and paid tiers for technical vehicle profile data.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "EU vehicle specification lookup and plate-to-VIN workflows",
|
|
"input": "European VIN or license plate number",
|
|
"output": "Vehicle make, model, engine, registration, and technical profile data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive web queries with quota limits on the free tier.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Carnet.ai",
|
|
"type": "url",
|
|
"url": "https://carnet.ai/",
|
|
"description": "AI vehicle image recognition platform that identifies make/model/generation from submitted photos.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Vehicle identification from images in visual OSINT cases",
|
|
"input": "Vehicle image file or image URL",
|
|
"output": "Predicted make, model, generation year, and confidence score",
|
|
"opsec": "passive",
|
|
"opsecNote": "Image submission to hosted inference service without direct interaction with vehicle operators.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Finnik (NL)",
|
|
"type": "url",
|
|
"url": "https://finnik.nl/en",
|
|
"description": "Dutch license plate intelligence service using official RDW-linked records for vehicle profile and APK history.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Netherlands plate investigations and inspection history checks",
|
|
"input": "Dutch license plate number",
|
|
"output": "Vehicle specs, APK timeline, and related ownership/tax data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses public/government-linked datasets with user-initiated lookups.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Air Traffic Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Flightradar24.com",
|
|
"type": "url",
|
|
"url": "https://www.flightradar24.com/",
|
|
"description": "Global real-time flight tracking platform built on ADS-B and radar feeds with airport and route intelligence views.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Aircraft movement monitoring and flight status intelligence",
|
|
"input": "Flight number, aircraft registration, or airport code",
|
|
"output": "Real-time position, altitude, speed, routing, and departure/arrival status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive monitoring of broadcast and aggregated flight telemetry.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "World Aeronautical Database",
|
|
"type": "url",
|
|
"url": "https://worldaerodata.com/",
|
|
"description": "Reference database for airport, airline, and aircraft metadata to support aviation intelligence lookups.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Aviation reference checks for airports, airlines, and aircraft",
|
|
"input": "Airport code, airline, aircraft type, or route context",
|
|
"output": "Airport details, airline profiles, and aircraft-related reference data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public aviation reference retrieval with no target interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ADS-B Exchange",
|
|
"type": "url",
|
|
"url": "https://www.adsbexchange.com/",
|
|
"description": "Large community-driven unfiltered ADS-B flight tracking network with broad global aircraft coverage.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Unfiltered aircraft tracking and historical flight pattern analysis",
|
|
"input": "Aircraft identifier, registration, hex code, or location",
|
|
"output": "Live aircraft position, altitude, speed, and historical track data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Consumes broadcast telemetry from receiver networks without active interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ADS-B.NL",
|
|
"type": "url",
|
|
"url": "https://www.ads-b.nl/index.php?pageno=9999",
|
|
"description": "Netherlands-focused ADS-B tracking portal with emphasis on military and regional aviation movements.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "European and military aircraft movement monitoring",
|
|
"input": "Aircraft registration, military callsign, or track query",
|
|
"output": "Flight traces, movement history, and aircraft classification context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregates publicly broadcast ADS-B data in a read-only interface.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OpenAIP World Aeronautical Database",
|
|
"type": "url",
|
|
"url": "https://www.openaip.net/",
|
|
"description": "Open, community-maintained aeronautical dataset for airfields, airspace, navaids, and runway metadata.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Airspace and airfield intelligence with reusable open data",
|
|
"input": "Airfield name, coordinates, or airspace criteria",
|
|
"output": "Runway, frequency, elevation, navaid, and airspace structure data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Static open aviation data retrieval with no live target interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Marine Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Vessel Tracker",
|
|
"type": "url",
|
|
"url": "https://www.vesseltracker.com/",
|
|
"description": "Commercial maritime tracking platform combining AIS and satellite feeds for global vessel movement intelligence.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Maritime routing, vessel monitoring, and compliance investigations",
|
|
"input": "Vessel name, IMO, MMSI, or route context",
|
|
"output": "Live position, course, speed, destination, and vessel profile metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive consumption of maritime broadcasts and aggregation feeds.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Ship AIS",
|
|
"type": "url",
|
|
"url": "https://shipais.uk/",
|
|
"description": "UK-centered AIS ship tracker with live map views, movement details, and vessel identification data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "UK maritime activity monitoring and vessel identification",
|
|
"input": "Vessel name, MMSI, or local waterway context",
|
|
"output": "Current position, movement track, vessel details, and nearby traffic",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reads public AIS transmissions via community infrastructure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OpenSeaMap - The free nautical chart",
|
|
"type": "url",
|
|
"url": "https://www.openseamap.org",
|
|
"description": "Open nautical chart map built on collaborative maritime data for ports, aids to navigation, and coastal context.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Nautical geolocation and maritime infrastructure mapping",
|
|
"input": "Coordinates, port name, or map area",
|
|
"output": "Nautical chart overlays, navigational aids, port/marina, and depth context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Static map intelligence from crowd-sourced maritime geodata.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Vessel Finder",
|
|
"type": "url",
|
|
"url": "https://www.vesselfinder.com/",
|
|
"description": "Global AIS vessel tracking service for ship positions, voyage progress, and historical movement review.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Worldwide ship tracking and port-call timeline analysis",
|
|
"input": "Vessel name, IMO, MMSI, or geographic area",
|
|
"output": "Live vessel tracks, destination status, and historical route context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive maritime telemetry consumption through aggregated AIS feeds.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Global Fishing Watch",
|
|
"type": "url",
|
|
"url": "https://globalfishingwatch.org",
|
|
"description": "Nonprofit maritime transparency platform that maps global fishing activity from AIS/VMS-derived signals.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Illegal fishing detection and fisheries activity intelligence",
|
|
"input": "Vessel name/IMO, geography, and date range",
|
|
"output": "Fishing effort maps, vessel profiles, transshipment, and port visit patterns",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregated environmental and vessel tracking data with read-only access.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Railway Records",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Deutsche Bahn Open-Data-Portal (German)",
|
|
"type": "url",
|
|
"url": "https://data.deutschebahn.com/opendata",
|
|
"description": "German rail open-data portal for station, network, timetable, and real-time transportation datasets.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "German rail infrastructure and schedule intelligence",
|
|
"input": "Station ID, route query, or timetable parameters",
|
|
"output": "Station metadata, track/network data, timetables, and service status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Open government transport data consumption through public endpoints.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OpenRailwayMap",
|
|
"type": "url",
|
|
"url": "https://www.openrailwaymap.org/",
|
|
"description": "OpenStreetMap-based global railway map visualizing rail lines, infrastructure characteristics, and operations context.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Rail infrastructure mapping and line characteristic analysis",
|
|
"input": "Map coordinates, region, or railway line context",
|
|
"output": "Track layouts, rail types, electrification, speed classes, and map overlays",
|
|
"opsec": "passive",
|
|
"opsecNote": "Crowd-sourced mapping interface with passive read-only usage.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Satellite Tracking",
|
|
"type": "url",
|
|
"url": "https://www.n2yo.com/",
|
|
"description": "Satellite orbit tracking entry point for monitoring spacecraft position, trajectory, and pass predictions.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Space object and satellite movement monitoring",
|
|
"input": "Satellite name, NORAD ID, or orbital element query",
|
|
"output": "Orbital position, pass timing, altitude, and trajectory context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses public orbital datasets and tracking visualizations without active targeting.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Track-Trace",
|
|
"type": "url",
|
|
"url": "https://www.track-trace.com/",
|
|
"description": "Multi-carrier shipment tracking aggregator for parcel and freight status across global postal and logistics providers.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Package tracking and supply-chain movement checks",
|
|
"input": "Tracking number and optional carrier selection",
|
|
"output": "Shipment milestones, current location, route progress, and delivery status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reads carrier-provided tracking records via public lookup interfaces.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Geolocation Tools / Maps",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Geolocation Tools",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Astrometry",
|
|
"type": "url",
|
|
"url": "https://nova.astrometry.net/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Astrometry.net solves star-field images to estimate where and when a photo was taken.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Geolocating night sky photos by star patterns",
|
|
"input": "Astronomical image",
|
|
"output": "Solved coordinates, orientation, and object annotations"
|
|
},
|
|
{
|
|
"name": "SunCalc",
|
|
"type": "url",
|
|
"url": "https://suncalc.net/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Solar position calculator for estimating time and orientation from shadows in imagery.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Shadow-based time and location validation",
|
|
"input": "Date/time and coordinates",
|
|
"output": "Sun azimuth/elevation and daylight phase data"
|
|
},
|
|
{
|
|
"name": "SunCalc",
|
|
"type": "url",
|
|
"url": "https://suncalc.org/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Solar position calculator for estimating time and orientation from shadows in imagery.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Shadow-based time and location validation",
|
|
"input": "Date/time and coordinates",
|
|
"output": "Sun azimuth/elevation and daylight phase data"
|
|
},
|
|
{
|
|
"name": "GeoSpy",
|
|
"type": "url",
|
|
"url": "https://geospy.ai/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "AI-assisted image geolocation tool for estimating where a photo was taken.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Rapid initial geolocation hypotheses from photos",
|
|
"input": "Image file",
|
|
"output": "Likely geographic region or coordinate candidates"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Coordinates",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "GPSVisualizer",
|
|
"type": "url",
|
|
"url": "https://www.gpsvisualizer.com/geocode",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Coordinate and GPS utility for mapping, conversion, and geocoding operations.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Converting and visualizing GPS/coordinate inputs",
|
|
"input": "Coordinates, GPX/KML/CSV, or addresses",
|
|
"output": "Mapped tracks, converted coordinates, and geocode results"
|
|
},
|
|
{
|
|
"name": "Military Grid Reference System Coordinates",
|
|
"type": "url",
|
|
"url": "https://dominoc925-pages.appspot.com/mapplets/cs_mgrs.html",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "MGRS coordinate conversion utility for military-style grid references.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Converting MGRS values to lat/lon and back",
|
|
"input": "MGRS or decimal coordinate values",
|
|
"output": "Converted coordinates in requested format"
|
|
},
|
|
{
|
|
"name": "Batch Geocoding",
|
|
"type": "url",
|
|
"url": "https://www.doogal.co.uk/BatchGeocoding",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Bulk geocoding workflow that converts large address lists into latitude/longitude pairs.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Converting large address datasets to coordinates",
|
|
"input": "Address list (CSV/text)",
|
|
"output": "Coordinates with match quality metadata"
|
|
},
|
|
{
|
|
"name": "Batch Reverse Geocoding",
|
|
"type": "url",
|
|
"url": "https://www.doogal.co.uk/BatchReverseGeocoding",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Bulk reverse-geocoding workflow that converts coordinate lists into human-readable addresses.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Converting large coordinate sets into addresses",
|
|
"input": "Latitude/longitude list",
|
|
"output": "Address records, admin boundaries, and place labels"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Map Reporting Tools",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Hyperlapse (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/TeehanLax/Hyperlapse.js",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Open-source JavaScript library for creating Street View hyperlapse animations.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Generating time-lapse style Street View sequences",
|
|
"input": "Route coordinates and animation settings",
|
|
"output": "Embeddable hyperlapse animation"
|
|
},
|
|
{
|
|
"name": "Google Maps Streetview Player",
|
|
"type": "url",
|
|
"url": "https://brianfolts.com/driver/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Street View path playback utility for reviewing route-level imagery sequences.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Walking through street-level imagery along a route",
|
|
"input": "Street View route or map location",
|
|
"output": "Sequenced street-level imagery playback"
|
|
},
|
|
{
|
|
"name": "ScribbleMaps",
|
|
"type": "url",
|
|
"url": "https://www.scribblemaps.com/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Collaborative web map editor for annotations, overlays, and shared incident maps.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Producing and sharing annotated investigative maps",
|
|
"input": "Base map with custom markers/shapes/notes",
|
|
"output": "Shareable annotated maps and exportable map views"
|
|
},
|
|
{
|
|
"name": "Beholder",
|
|
"type": "url",
|
|
"url": "https://beholder.infragard.io/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Real-time global event map aggregating public-source signals for situational awareness.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Monitoring geolocated crisis and event signals in real time",
|
|
"input": "Map filters and geographic area",
|
|
"output": "Mapped events with source context and timelines"
|
|
},
|
|
{
|
|
"name": "LiveUaMap",
|
|
"type": "url",
|
|
"url": "https://liveuamap.com/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Conflict/event mapping platform that geolocates incidents from public reporting.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Conflict and crisis event geolocation tracking",
|
|
"input": "Region and event filters",
|
|
"output": "Mapped incidents with timeline and source context"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Mobile Coverage",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "OpenSignal",
|
|
"type": "url",
|
|
"url": "https://www.opensignal.com/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Crowdsourced mobile coverage and signal quality map from user telemetry.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Comparing cellular signal quality by carrier and location",
|
|
"input": "Location and carrier filters",
|
|
"output": "Coverage heatmaps, speed stats, and signal indicators"
|
|
},
|
|
{
|
|
"name": "AntennaSearch",
|
|
"type": "url",
|
|
"url": "https://www.antennasearch.com/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "FCC-backed lookup for antenna structure and tower records used in RF and telecom investigations.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Identifying nearby antenna structures and tower owners",
|
|
"input": "Location, address, or coordinates",
|
|
"output": "Antenna/tower records with ownership and registration details"
|
|
},
|
|
{
|
|
"name": "OpenCelliD",
|
|
"type": "url",
|
|
"url": "https://opencellid.org/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Collaborative global cell-tower database used for telecom-based geolocation.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Cell tower identification and approximate location triangulation",
|
|
"input": "Cell identifiers or coordinates",
|
|
"output": "Cell tower records and geographic positions"
|
|
},
|
|
{
|
|
"name": "beaconDB",
|
|
"type": "url",
|
|
"url": "https://beacondb.net/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Open geolocation database for Wi-Fi/Bluetooth/cell beacons used in location inference.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Beacon and AP-based geolocation without major platform lock-in",
|
|
"input": "BSSID/cell IDs or coordinates",
|
|
"output": "Geolocated beacon and network records"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Google Maps",
|
|
"type": "url",
|
|
"url": "https://www.google.com/maps/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Google web mapping suite with satellite, terrain, route, and place intelligence layers.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "General geolocation, routing, and POI correlation",
|
|
"input": "Address, coordinates, or place query",
|
|
"output": "Map views, directions, and POI results"
|
|
},
|
|
{
|
|
"name": "Bing Maps",
|
|
"type": "url",
|
|
"url": "https://www.bing.com/maps",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Microsoft web mapping service with road, aerial, and route layers for location analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "General geolocation and route context with Microsoft map data",
|
|
"input": "Address, place name, or coordinates",
|
|
"output": "Map views, routes, and nearby POI results"
|
|
},
|
|
{
|
|
"name": "HERE Maps",
|
|
"type": "url",
|
|
"url": "https://maps.here.com/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Enterprise-grade mapping platform with routing and global cartographic coverage.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Commercial-grade map and route analysis",
|
|
"input": "Address, coordinates, or route parameters",
|
|
"output": "Maps, directions, traffic, and location context"
|
|
},
|
|
{
|
|
"name": "Dual Maps",
|
|
"type": "url",
|
|
"url": "https://data.mashedworld.com/dualmaps/map.htm",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Dual-pane map viewer for side-by-side comparison of basemaps and imagery.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Comparing two map layers or providers at the same location",
|
|
"input": "Location or coordinates",
|
|
"output": "Synchronized side-by-side map views"
|
|
},
|
|
{
|
|
"name": "Instant Google Street View",
|
|
"type": "url",
|
|
"url": "https://www.instantstreetview.com/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Fast launcher for jumping directly into Google Street View at precise locations.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Quick street-level reconnaissance from an address or coordinate",
|
|
"input": "Address, place, or coordinates",
|
|
"output": "Direct Street View scene and navigable panorama"
|
|
},
|
|
{
|
|
"name": "Wikimapia",
|
|
"type": "url",
|
|
"url": "https://wikimapia.org/#lang=en&lat=40.078071&lon=-100.458984&z=5&m=b",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true,
|
|
"description": "Crowdsourced landmark annotation layer with uneven maintenance and stale coverage in some regions.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Supplementary user-labeled place context when newer sources are unavailable",
|
|
"input": "Location query",
|
|
"output": "User-labeled geographic features and notes"
|
|
},
|
|
{
|
|
"name": "OpenStreetMap",
|
|
"type": "url",
|
|
"url": "https://www.openstreetmap.org/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Open-source global map edited by the community and widely reused in OSINT workflows.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Open basemap and geospatial reference without vendor lock-in",
|
|
"input": "Location query or coordinates",
|
|
"output": "Map features, POIs, and open geodata layers"
|
|
},
|
|
{
|
|
"name": "Flash Earth",
|
|
"type": "url",
|
|
"url": "https://zoom.earth/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Zoom Earth interface for rapidly reviewing weather and satellite imagery timelines.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Fast satellite and weather imagery review",
|
|
"input": "Map position and time controls",
|
|
"output": "Recent satellite/weather imagery views"
|
|
},
|
|
{
|
|
"name": "Historic Aerials",
|
|
"type": "url",
|
|
"url": "https://www.historicaerials.com/?javascript=&",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Historical aerial imagery archive for property and infrastructure change analysis.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Comparing land and infrastructure changes over decades",
|
|
"input": "Location and year filters",
|
|
"output": "Time-series aerial imagery and map overlays"
|
|
},
|
|
{
|
|
"name": "Google Maps Update Alerts",
|
|
"type": "url",
|
|
"url": "https://followyourworld.appspot.com/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Follow Your World alert utility for notifications on map and imagery updates.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Tracking imagery refreshes for watched locations",
|
|
"input": "Selected map locations",
|
|
"output": "Email/location alerts when imagery updates occur"
|
|
},
|
|
{
|
|
"name": "Google Earth Overlays",
|
|
"type": "url",
|
|
"url": "https://www.mgmaps.com/kml/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Overlay workflow for layering KML/KMZ data onto Google Earth views.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Overlaying external KML/KMZ intelligence layers on earth imagery",
|
|
"input": "KML/KMZ overlay files and map position",
|
|
"output": "Composited imagery with custom overlay layers"
|
|
},
|
|
{
|
|
"name": "Yandex.Maps",
|
|
"type": "url",
|
|
"url": "https://yandex.com/maps/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Regional mapping service with strong coverage in Russia and surrounding regions.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Geolocation research in Russia/CIS where western maps are weaker",
|
|
"input": "Address/place query or coordinates",
|
|
"output": "Map imagery, routes, and regional POI context"
|
|
},
|
|
{
|
|
"name": "Google Earth",
|
|
"type": "url",
|
|
"url": "https://earth.google.com/web/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "3D globe and historical imagery platform for terrain and time-based visual analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Historical satellite and terrain review in 3D",
|
|
"input": "Location, polygons, and time slider controls",
|
|
"output": "3D imagery, overlays, and historical context"
|
|
},
|
|
{
|
|
"name": "Baidu Maps",
|
|
"type": "url",
|
|
"url": "https://map.baidu.com/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Major Chinese mapping platform with strong POI and routing coverage in mainland China.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Geolocation and POI discovery in mainland China",
|
|
"input": "Address, place name, or coordinates",
|
|
"output": "Map layers, routes, POIs, and location context"
|
|
},
|
|
{
|
|
"name": "Corona",
|
|
"type": "url",
|
|
"url": "https://corona.cast.uark.edu/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Access point for historical CORONA-era satellite imagery used in long-range change analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Cold War-era historical imagery analysis",
|
|
"input": "Location and archive filters",
|
|
"output": "Historical satellite imagery and metadata"
|
|
},
|
|
{
|
|
"name": "Naver (Korean)",
|
|
"type": "url",
|
|
"url": "https://map.naver.com/p/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Korea-focused mapping platform with strong local POI and transit coverage.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Geolocation and POI analysis in South Korea",
|
|
"input": "Address/place query or coordinates",
|
|
"output": "Map layers, routes, local business/POI data"
|
|
},
|
|
{
|
|
"name": "OpenStreetMap",
|
|
"type": "url",
|
|
"url": "https://www.openstreetmap.org/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Open-source global map edited by the community and widely reused in OSINT workflows.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Open basemap and geospatial reference without vendor lock-in",
|
|
"input": "Location query or coordinates",
|
|
"output": "Map features, POIs, and open geodata layers"
|
|
},
|
|
{
|
|
"name": "Overpass Turbo",
|
|
"type": "url",
|
|
"url": "https://overpass-turbo.eu/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Query interface for extracting targeted OpenStreetMap features via Overpass API.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Custom extraction of OSM entities by tags and geography",
|
|
"input": "Overpass query and map bounds",
|
|
"output": "Filtered OSM features (map/GeoJSON/KML)"
|
|
},
|
|
{
|
|
"name": "EarthExplorer",
|
|
"type": "url",
|
|
"url": "https://earthexplorer.usgs.gov/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "USGS portal for Landsat, Sentinel, and other earth observation datasets.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Downloading historical and multispectral satellite datasets",
|
|
"input": "AOI, date range, and dataset criteria",
|
|
"output": "Search results with downloadable geospatial scenes"
|
|
},
|
|
{
|
|
"name": "OpenStreetCam",
|
|
"type": "url",
|
|
"url": "https://kartaview.org/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "KartaView crowdsourced street-level imagery platform for geospatial verification.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Street-level image review outside mainstream Street View coverage",
|
|
"input": "Location and route filters",
|
|
"output": "Crowdsourced geotagged street imagery"
|
|
},
|
|
{
|
|
"name": "Travel by Drone",
|
|
"type": "url",
|
|
"url": "https://travelbydrone.com/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Drone-route and aerial exploration resource useful for planning vantage-aware terrain review.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Planning drone-oriented visual reconnaissance paths",
|
|
"input": "Location and route preferences",
|
|
"output": "Mapped route and aerial travel context"
|
|
},
|
|
{
|
|
"name": "Hivemapper",
|
|
"type": "url",
|
|
"url": "https://hivemapper.com/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Decentralized, crowdsourced street imagery map network with expanding coverage.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Street-level imagery in areas with limited mainstream coverage",
|
|
"input": "Location query",
|
|
"output": "Crowdsourced map and imagery tiles"
|
|
},
|
|
{
|
|
"name": "LandsatLook Viewer",
|
|
"type": "url",
|
|
"url": "https://landsatlook.usgs.gov/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "USGS viewer for browsing Landsat scenes and multispectral imagery.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Long-term environmental and infrastructure change detection",
|
|
"input": "Location/date filters and band selections",
|
|
"output": "Rendered Landsat scenes and metadata"
|
|
},
|
|
{
|
|
"name": "NEXRAD Data Inventory Search",
|
|
"type": "url",
|
|
"url": "https://www.ncdc.noaa.gov/nexradinv/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "NOAA/NCDC index for searching archived NEXRAD radar datasets.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Locating radar archives for weather-event correlation",
|
|
"input": "Radar station, date, and query filters",
|
|
"output": "Inventory records and radar dataset references"
|
|
},
|
|
{
|
|
"name": "MapQuest",
|
|
"type": "url",
|
|
"url": "https://www.mapquest.com/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Web mapping and routing platform supporting multi-stop route planning.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Route analysis and multi-stop planning",
|
|
"input": "Origin, destination, and stop list",
|
|
"output": "Turn-by-turn routes and distance metrics"
|
|
},
|
|
{
|
|
"name": "OpenRailwayMap",
|
|
"type": "url",
|
|
"url": "https://www.openrailwaymap.org/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Rail-specific map layer showing tracks, stations, and related rail infrastructure.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Rail network and station infrastructure mapping",
|
|
"input": "Location and zoom level",
|
|
"output": "Railway overlays, stations, and track details"
|
|
},
|
|
{
|
|
"name": "OpenInfrastructureMap",
|
|
"type": "url",
|
|
"url": "https://openinframap.org/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "OSM-derived map overlays for power, telecom, water, and industrial infrastructure.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Infrastructure mapping across energy and utility networks",
|
|
"input": "Location and layer toggles",
|
|
"output": "Infrastructure overlays on an interactive map"
|
|
},
|
|
{
|
|
"name": "Hiking & Biking Map",
|
|
"type": "url",
|
|
"url": "https://hikebikemap.org/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "OSM-based map optimized for trails, cycling routes, and terrain context.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Outdoor trail and route reconnaissance",
|
|
"input": "Location or route area",
|
|
"output": "Trail-focused map overlays and terrain context"
|
|
},
|
|
{
|
|
"name": "US Nav Guide Zip Code Data",
|
|
"type": "url",
|
|
"url": "https://www.usnaviguide.com/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Zip-code lookup resource for correlating US postal areas with map context.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Linking US zip codes to geographic lookup context",
|
|
"input": "US zip code or city/state query",
|
|
"output": "Zip-associated geographic and lookup reference data"
|
|
},
|
|
{
|
|
"name": "Wayback Imagery",
|
|
"type": "url",
|
|
"url": "https://livingatlas.arcgis.com/wayback/",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Esri Wayback archive for reviewing previous versions of world imagery basemaps.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Recent-era imagery change detection across archived basemap releases",
|
|
"input": "Location and imagery version selection",
|
|
"output": "Historical basemap snapshots by release date"
|
|
},
|
|
{
|
|
"name": "SkyFi.com - Satellite Open Data (R)",
|
|
"type": "url",
|
|
"url": "https://app.skyfi.com/explore/open",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses open-source mapping/geospatial data and does not directly interact with the target.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false,
|
|
"description": "Satellite imagery marketplace and open-data discovery interface for earth observation assets.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Finding open and commercial satellite scenes from one interface",
|
|
"input": "AOI, date range, and scene filters",
|
|
"output": "Scene search results with preview and ordering options"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Search Engines",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "General Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Google",
|
|
"type": "url",
|
|
"url": "https://www.google.com/?gws_rd=ssl",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "World's most popular search engine with advanced indexing capabilities and support for extensive search operators (Google dorks). Used for passive OSINT research with broad web coverage.",
|
|
"bestFor": "General web OSINT, historical information via cache, broad searches with operators",
|
|
"input": "Keywords, search operators (site:, intitle:, inurl:, filetype:, cache:, etc.)",
|
|
"output": "Ranked web pages, snippets, images, news, cached pages",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive reconnaissance technique; widely monitored by targets; Google tracks all searches if logged in; extensively documented for OSINT use",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Bing",
|
|
"type": "url",
|
|
"url": "https://www.bing.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Microsoft's search engine with advanced search operators and API capabilities. Supports many of the same operators as Google, providing alternative search coverage.",
|
|
"bestFor": "Alternative to Google, regional results, academic content, supplementary searches",
|
|
"input": "Keywords, search operators (site:, intitle:, filetype:, inurl:, AND, NOT, etc.)",
|
|
"output": "Ranked web pages, images, news, videos, answers",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive OSINT; Bing Search API is being retired by Microsoft on August 11, 2026; limited future API availability",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DuckDuckGo",
|
|
"type": "url",
|
|
"url": "https://duckduckgo.com/",
|
|
"status": "live",
|
|
"pricing": "free/freemium",
|
|
"description": "Privacy-focused search engine that doesn't track users or store personal data. Processes ~3 billion queries monthly with enhanced privacy protections and tracker blocking.",
|
|
"bestFor": "Privacy-preserving searches, tracking-free OSINT research, European results",
|
|
"input": "Keywords, basic search operators (site:, intitle:, filetype:), natural language",
|
|
"output": "Ranked web pages with privacy-protecting anonymous view option",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive OSINT with enhanced privacy; proxies results to prevent tracking by destination sites; no user profiling",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Yahoo Advanced Web Search",
|
|
"type": "url",
|
|
"url": "https://search.yahoo.com/web/advanced",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Yahoo's advanced search interface with support for search operators including site:, intitle:, filetype:, AND, OR, NOT. Provides real-time search results data with location filtering.",
|
|
"bestFor": "Alternative to Google/Bing, specialized searches, location-based results",
|
|
"input": "Keywords, search operators (+, -, site:, intitle:, filetype:, exact phrases in quotes)",
|
|
"output": "Ranked web pages, news, images, location-specific results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive OSINT technique; Yahoo Search API still active as of 2026; provides alternative result set",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "StartPage",
|
|
"type": "url",
|
|
"url": "https://www.startpage.com/",
|
|
"status": "live",
|
|
"pricing": "free/freemium",
|
|
"description": "Privacy-centric proxy search engine that strips identifying data before querying Google/Bing and provides anonymous view to visited websites through proxy servers.",
|
|
"bestFor": "Privacy-preserving Google searches, anonymous browsing through proxy",
|
|
"input": "Keywords, Google operators (forwarded through proxy)",
|
|
"output": "Google/Bing results returned anonymously without trackers",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive OSINT with added anonymity layer; completely hides identity from destination sites via proxy servers",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Yandex",
|
|
"type": "url",
|
|
"url": "https://yandex.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Russian search engine with excellent coverage of post-Soviet digital spaces. Supports 20+ advanced operators and provides faster indexing of Russian forums and breach boards than Google.",
|
|
"bestFor": "Russian/post-Soviet OSINT, faster breach board indexing, regional coverage",
|
|
"input": "Keywords, advanced operators (inurl:, url:, \"\", *, |, lang:, mime:, etc.)",
|
|
"output": "Ranked web pages with regional focus, Russian content prioritized",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive OSINT; valuable for Russian-language sources not well-indexed by Google; extensive operator support",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Baidu",
|
|
"type": "url",
|
|
"url": "https://www.baidu.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "China's dominant search engine with support for advanced search operators and knowledge graph data. Used for Chinese language and regional OSINT research.",
|
|
"bestFor": "Chinese language OSINT, Chinese market research, regional search coverage",
|
|
"input": "Keywords, operators (inurl:, intitle:, site:, filetype:), language and time filters",
|
|
"output": "Ranked web pages, images, news, knowledge graph, trending queries",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive OSINT with emphasis on Chinese content; government monitoring potential within China; broader regional coverage",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Advanced Search",
|
|
"type": "url",
|
|
"url": "https://www.google.com/advanced_search",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Dedicated interface to Google's advanced search operators. Makes complex queries easier to construct without memorizing dork syntax through visual form-based interface.",
|
|
"bestFor": "Guided advanced searches, learning Google operators, constructing complex queries visually",
|
|
"input": "Form-based parameters (date range, language, file type, domain, safe search, reading level)",
|
|
"output": "Ranked web pages matching advanced filters",
|
|
"opsec": "passive",
|
|
"opsecNote": "Same passive OSINT as Google; educational tool for learning operator syntax; helps build effective dork queries",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "iZito",
|
|
"type": "url",
|
|
"url": "https://www.izito.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Metasearch engine aggregating results from multiple sources including Wikipedia, videos, news, and products. Designed to support non-linear search behavior with multi-column display.",
|
|
"bestFor": "Multi-type searches (web, video, news, products in one overview), quick result aggregation",
|
|
"input": "Keywords, basic operators",
|
|
"output": "Web results, videos, news, products, Wikipedia entries in multi-column layout",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive aggregation of public search results; combines multiple result types",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Advangle",
|
|
"type": "url",
|
|
"url": "https://advangle.com/",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"description": "Advanced search query builder for Google and Bing. Allows construction of complex multi-parameter search queries without memorizing operator syntax.",
|
|
"bestFor": "Building complex search queries with multiple filters (domain, language, date published)",
|
|
"input": "Visual form-based query builder parameters (domain, language, date, region)",
|
|
"output": "Complex search queries executed in Google or Bing with multiple parameters",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive OSINT tool; site lacks SSL certificate (HTTP only), domain expires March 5, 2026; functionality may be compromised",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Instya",
|
|
"type": "url",
|
|
"url": "https://www.instya.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "eCommerce product search engine and shopping discovery platform. NOT suitable for general web OSINT research - category mismatch with Search Engines.",
|
|
"bestFor": "Product research, shopping comparisons, eCommerce OSINT only",
|
|
"input": "Product names, shopping categories",
|
|
"output": "Product listings across eCommerce sites with curated buying guides",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Category mismatch - primarily an eCommerce/shopping search engine, not general web OSINT; consider moving to commerce category",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Hulbee",
|
|
"type": "url",
|
|
"url": "https://hulbee.com/de",
|
|
"status": "live",
|
|
"pricing": "free/freemium",
|
|
"description": "Corporate site and product page for Hulbee AG. NOT a search engine itself - Hulbee is the company behind Swisscows. URL/category mismatch issue.",
|
|
"bestFor": "Corporate information only, NOT for web search OSINT",
|
|
"input": "Company information",
|
|
"output": "Corporate website content",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Category mismatch - this is a company website, not a search engine. Swisscows is the actual search product (already listed separately)",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Mojeek",
|
|
"type": "url",
|
|
"url": "https://mojeek.com/",
|
|
"status": "live",
|
|
"pricing": "free/freemium",
|
|
"description": "Independent UK-based search engine with its own crawler and index. Privacy-focused with no user tracking since 2006. Supports advanced search operators.",
|
|
"bestFor": "Privacy-preserving searches, independent index not reliant on Google/Bing",
|
|
"input": "Keywords, advanced operators (site:, intitle:, inurl:, etc.)",
|
|
"output": "Web results from independent Mojeek index in JSON/XML via API",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive OSINT with strong privacy guarantees - no IP tracking, no search history, no personalization; truly independent index",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Swisscows",
|
|
"type": "url",
|
|
"url": "https://swisscows.com/en",
|
|
"status": "live",
|
|
"pricing": "free/freemium",
|
|
"description": "Swiss privacy-focused search engine using semantic AI. Stores all data in Swiss Alps facility. No cookies, no tracking, no user profiles. Includes family-safe filtering.",
|
|
"bestFor": "Privacy-conscious searches, family-safe content filtering, Swiss data residency requirement",
|
|
"input": "Keywords, natural language queries with semantic understanding",
|
|
"output": "Ranked web results with optional content filtering, image/video search with filtering",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive OSINT with maximum privacy; data stored in Switzerland outside EU/USA; permanent family-safe filtering cannot be disabled",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Brave",
|
|
"type": "url",
|
|
"url": "https://search.brave.com/",
|
|
"status": "live",
|
|
"pricing": "free/freemium",
|
|
"description": "Privacy-focused search engine with independent index. Offers Goggles for custom search result ranking. First search API with zero data retention option.",
|
|
"bestFor": "Privacy-preserving searches, custom filtering via Goggles, enterprises needing zero data retention",
|
|
"input": "Keywords, Goggle rules for custom filtering",
|
|
"output": "Ranked web results with optional custom filtering via Goggles",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive OSINT with zero data retention option for API; 90-day query log retention for billing purposes only",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Stract",
|
|
"type": "url",
|
|
"url": "https://stract.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Open source search engine built by developers for developers. Features customizable Optics for result filtering and ranking. Independent index with web crawler.",
|
|
"bestFor": "Developers, transparency enthusiasts, customizable search, filtering by content type (blogs, indieweb, educational)",
|
|
"input": "Keywords, custom Optics rules for filtering",
|
|
"output": "Customized ranked results with filtering options",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive OSINT with complete code transparency; open source project suitable for security research; can be self-hosted",
|
|
"localInstall": true,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Meta Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "iSEEK",
|
|
"type": "url",
|
|
"url": "https://iseek.com/iseek/home.page",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"description": "Meta search engine that aggregated results from multiple sources. Service offline - URL returns 404 error. No longer operational.",
|
|
"bestFor": "Historical reference only - service no longer operational",
|
|
"input": "N/A",
|
|
"output": "N/A",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Deprecated - service offline; URL returns 404 error; recommend removal or archival only",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "eTools.ch",
|
|
"type": "url",
|
|
"url": "https://www.etools.ch/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Swiss privacy-focused metasearch engine aggregating 14+ sources (Google, Bing, Brave, DuckDuckGo, Yandex, etc.) simultaneously. Fast results averaging 0.83 seconds.",
|
|
"bestFor": "Privacy-preserving meta searches, quick result aggregation from multiple engines",
|
|
"input": "Keywords, basic search operators",
|
|
"output": "Aggregated results from 14 sources in parallel",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive OSINT; meta-search aggregator does not store personal data or collect identifying information",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Code Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "PublicWWW",
|
|
"type": "url",
|
|
"url": "https://publicwww.com/",
|
|
"status": "live",
|
|
"pricing": "free/freemium",
|
|
"description": "Source code search engine for HTML, JavaScript, CSS, and plaintext across 509+ million web pages. Find websites using specific analytics IDs, ad accounts, or code snippets.",
|
|
"bestFor": "Finding websites with specific code/analytics IDs, competitive intelligence, security research",
|
|
"input": "Code snippets, regular expressions, analytics IDs (Google Analytics, AdSense, etc.), JavaScript libraries",
|
|
"output": "Web pages containing matching code with download/export to CSV",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive reconnaissance of publicly indexed source code; valuable for security research and competitive intelligence analysis",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Searchcode",
|
|
"type": "url",
|
|
"url": "https://searchcode.com/",
|
|
"description": "Code search engine that indexes public source code from GitHub, GitLab, Bitbucket, and other repositories; useful for finding code examples and identifying technology usage patterns.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Source code snippet and function discovery across public repositories",
|
|
"input": "Code snippet, function name, or keyword",
|
|
"output": "Matching source code files with context and repository links",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are routed through Searchcode's servers; no direct contact with target repositories.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "NerdyData",
|
|
"type": "url",
|
|
"url": "https://www.nerdydata.com/reports/new",
|
|
"description": "Source code search engine for website technology reconnaissance that indexes HTML, CSS, and JavaScript across millions of live websites to identify technology and library usage.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Identifying websites using specific technologies, libraries, or code patterns",
|
|
"input": "Code snippet, library name, or technology string",
|
|
"output": "List of websites containing matching source code",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches NerdyData's pre-built index; no direct contact with target websites.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Gitrob (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/michenriksen/gitrob",
|
|
"description": "CLI tool for reconnaissance on GitHub organizations and users; clones repositories and scans commit history for sensitive files, exposed credentials, and configuration data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "GitHub organization reconnaissance for exposed secrets and sensitive files in commit history",
|
|
"input": "GitHub username or organization name",
|
|
"output": "List of potentially sensitive files and paths found across repositories",
|
|
"opsec": "active",
|
|
"opsecNote": "Directly queries the GitHub API and clones repositories; API activity is logged and may alert security monitoring.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Github-Dorks (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/techgaun/github-dorks",
|
|
"description": "Collection of GitHub advanced search operators and a CLI tool that automates searching GitHub for exposed credentials, API keys, configuration files, and other sensitive information.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding exposed credentials and sensitive files on GitHub via advanced search dorks",
|
|
"input": "Target username, organization, or domain",
|
|
"output": "GitHub search results matching dork patterns for sensitive data exposure",
|
|
"opsec": "active",
|
|
"opsecNote": "Queries the GitHub search API; activity is logged by GitHub and may trigger alerts for repository owners.",
|
|
"localInstall": true,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "GitLeaks",
|
|
"type": "url",
|
|
"url": "https://github.com/gitleaks/gitleaks",
|
|
"description": "Open-source SAST tool for detecting hardcoded secrets, API keys, passwords, and credentials in git repositories and file systems using customizable regex-based detection rules.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Scanning git repositories for hardcoded secrets, API keys, and leaked credentials",
|
|
"input": "Git repository path, remote URL, or file system path",
|
|
"output": "Report of detected secrets with file location, matched rule, commit hash, and line context",
|
|
"opsec": "active",
|
|
"opsecNote": "Remote scans require cloning the target repository; clone activity may be logged by the hosting platform.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "FTP Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "GlobalFile",
|
|
"type": "url",
|
|
"url": "https://globalfilesearch.com/",
|
|
"description": "FTP file search engine that indexes publicly accessible FTP servers; allows searching for specific file types including images, videos, software, and archives.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Discovering publicly accessible files on FTP servers by filename or file type",
|
|
"input": "Filename, file extension, or keyword",
|
|
"output": "List of matching files with FTP server addresses and paths",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches GlobalFile's pre-built index of FTP servers; no direct connection to target FTP servers.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FTP Google Dork (D)",
|
|
"type": "url",
|
|
"url": "https://www.google.com/search?q=inurl%3Aftp+-inurl%3Ahttp+-inurl%3Ahttps+ftpsearchterm",
|
|
"description": "Google dork technique using inurl:ftp operators to discover publicly indexed FTP server directories and files through Google's web index.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Discovering publicly indexed FTP server directories and files via Google dorking",
|
|
"input": "Search term appended to the dork URL",
|
|
"output": "Google search results showing indexed FTP server directories",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are routed through Google; no direct contact with target FTP servers.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Napalm FTP",
|
|
"type": "url",
|
|
"url": "https://www.searchftps.net/",
|
|
"description": "FTP indexer and search engine with over 329 million files indexed across 1,200+ FTP servers; supports advanced filtering by file type, size, and server location.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Large-scale FTP file discovery across hundreds of indexed public servers",
|
|
"input": "Filename, file type, or keyword",
|
|
"output": "Matching files with FTP server address, path, file size, and date",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches Napalm FTP's index; no direct connection to target FTP servers during search.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Academic / Publication Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "PubPeer",
|
|
"type": "url",
|
|
"url": "https://pubpeer.com/",
|
|
"description": "Post-publication peer review platform where researchers comment on and flag issues with published scientific papers; useful for identifying retracted or problematic research.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Verifying scientific publication credibility and finding post-publication corrections or retractions",
|
|
"input": "DOI, paper title, or author name",
|
|
"output": "Peer comments, flags, and discussion threads attached to the publication",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries PubPeer's public database; searches are not disclosed to paper authors.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Bielefeld Academic Search Engine",
|
|
"type": "url",
|
|
"url": "https://www.base-search.net/Search/Advanced",
|
|
"description": "Academic search engine indexing over 400 million documents from 12,000+ content providers including institutional repositories, open-access journals, and research databases worldwide.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Broad academic literature search across open-access and institutional repositories",
|
|
"input": "Author, title, keyword, DOI, or subject",
|
|
"output": "Academic papers, theses, and research documents with metadata and links",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches BASE's aggregated index; no direct contact with source institutions.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Scholar",
|
|
"type": "url",
|
|
"url": "https://scholar.google.com/",
|
|
"description": "Multidisciplinary academic search engine indexing journal articles, theses, books, conference papers, and patents; includes citation counts and related work discovery.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Comprehensive academic literature discovery with citation tracking across all disciplines",
|
|
"input": "Author, paper title, keyword, or institution",
|
|
"output": "Academic publications with citation counts, links to full text, and related work",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are logged by Google; results reflect Google's index with no direct contact to journals or authors.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "PubMed - National Center for Biotechnology Information",
|
|
"type": "url",
|
|
"url": "https://pubmed.ncbi.nlm.nih.gov/",
|
|
"description": "Free biomedical and life sciences literature database maintained by the NCBI with over 40 million citations; includes abstracts and links to full-text articles.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Biomedical, clinical, and life sciences literature research with high-quality metadata",
|
|
"input": "Author, MeSH term, keyword, PMID, or DOI",
|
|
"output": "Citation records with abstracts, MeSH terms, and links to full-text sources",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are routed through NCBI servers; queries are subject to NCBI's usage policies.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Open Library",
|
|
"type": "url",
|
|
"url": "https://openlibrary.org/",
|
|
"description": "Internet Archive's open catalog of over 3 million books with borrowable digital editions; provides bibliographic data and full-text access for many out-of-print titles.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding and borrowing digitized books, especially out-of-print or historical publications",
|
|
"input": "Title, author, ISBN, or subject",
|
|
"output": "Book records with metadata, cover images, and links to borrowable or readable editions",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public searches require no account; borrowing requires free registration which logs activity.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "JURN",
|
|
"type": "url",
|
|
"url": "https://www.jurn.org/",
|
|
"description": "Multidisciplinary search engine indexing freely accessible academic articles; covers arts, humanities, ecology, and social sciences with a focus on open-access content.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Open-access academic article discovery in arts, humanities, and social sciences",
|
|
"input": "Keyword, author, or subject",
|
|
"output": "Links to freely accessible academic articles across indexed journals",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches via JURN's Google Custom Search integration; queries are processed by Google.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "UK National Archives",
|
|
"type": "url",
|
|
"url": "https://discovery.nationalarchives.gov.uk/",
|
|
"description": "Official online catalog for the UK National Archives providing access to over 32 million records spanning 1,000 years of UK government, legal, and historical documents.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "UK historical records, government documents, and legal archives research",
|
|
"input": "Person name, place, date, or record reference",
|
|
"output": "Archive catalog entries with descriptions, dates, and ordering information for physical or digital access",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches the public catalog; no account required for browsing though some documents require in-person access.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OpenGrey EU Papers",
|
|
"type": "url",
|
|
"url": "https://opengrey.eu/",
|
|
"description": "Former European grey literature database maintained by INIST-CNRS that indexed non-conventional scientific and technical documents; archived in 2020 and no longer updated.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Historical European grey literature and non-conventional scientific documents (pre-2020)",
|
|
"input": "Keyword, author, or subject",
|
|
"output": "Grey literature records including reports, theses, and technical documents",
|
|
"opsec": "passive",
|
|
"opsecNote": "Static archive; no active data collection occurs during searches.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "US Gov Publishing Office - FDsys",
|
|
"type": "url",
|
|
"url": "https://www.gpo.gov/fdsys/",
|
|
"description": "Legacy US Government Publishing Office document system (FDsys) that has been superseded by GovInfo (govinfo.gov); the URL now redirects to the modernized GovInfo platform.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "US federal government publications, congressional records, and regulatory documents (use GovInfo instead)",
|
|
"input": "Document title, agency, or collection name",
|
|
"output": "US government publications in PDF, XML, and other formats",
|
|
"opsec": "passive",
|
|
"opsecNote": "Government-operated service; searches are logged per federal government policies.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "OpenDOAR",
|
|
"type": "url",
|
|
"url": "https://www.opendoar.org/search.php",
|
|
"description": "Global directory of open-access repositories with over 6,000 academic repositories from 130+ countries; useful for locating institutional repositories and discipline-specific archives.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding open-access repositories by institution, country, or subject discipline",
|
|
"input": "Institution name, country, or subject area",
|
|
"output": "List of matching open-access repositories with metadata and direct links",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches OpenDOAR's directory; no direct contact with listed repositories.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Microsoft Academic",
|
|
"type": "url",
|
|
"url": "https://academic.microsoft.com/",
|
|
"description": "Microsoft's academic search service indexing hundreds of millions of research papers; note that the original Microsoft Academic service was discontinued in December 2021 and this URL may redirect.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Academic paper discovery with author disambiguation and citation graph analysis",
|
|
"input": "Author, title, keyword, or institution",
|
|
"output": "Research paper records with metadata, citations, and author profiles",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are processed by Microsoft servers; activity may be subject to Microsoft's privacy policy.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Science Direct",
|
|
"type": "url",
|
|
"url": "https://www.sciencedirect.com/",
|
|
"description": "Elsevier's platform for peer-reviewed scientific literature with access to over 2,900 journals and 30,000 e-books; freely searchable with full-text access requiring subscription or institutional access.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Scientific and technical literature search across Elsevier's extensive journal catalog",
|
|
"input": "Author, title, keyword, DOI, or journal name",
|
|
"output": "Article records with abstracts; full text requires subscription or per-article purchase",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are logged by Elsevier; institutional access requires login which creates an activity record.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Think Tank Search",
|
|
"type": "url",
|
|
"url": "https://guides.library.harvard.edu/hks/think_tank_search",
|
|
"description": "Harvard Kennedy School Library guide for searching think tank research and policy reports; the referenced Think Tank Search service was deprecated in February 2025.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Policy research and think tank report discovery (see Policy Commons as current alternative)",
|
|
"input": "Topic, organization, or keyword",
|
|
"output": "Links to think tank research guides and policy report databases",
|
|
"opsec": "passive",
|
|
"opsecNote": "Accesses a public library guide page; no tracking beyond standard web server logs.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Library Databases",
|
|
"type": "url",
|
|
"url": "https://guides.uflib.ufl.edu/az.php",
|
|
"description": "University of Florida Library's A-Z database directory providing access to hundreds of academic databases covering all disciplines; useful as a reference for locating specialized research databases.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Identifying specialized academic databases by subject for deep literature research",
|
|
"input": "Subject area or database name",
|
|
"output": "List of academic databases with descriptions and access links",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public library guide; no account required for browsing the directory.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Copyscape Plagiarism Checker",
|
|
"type": "url",
|
|
"url": "https://www.copyscape.com/",
|
|
"description": "Online plagiarism detection service that searches the web for copies of submitted text or URLs; useful for verifying content originality or tracing where text has been republished.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Detecting plagiarism and tracing where specific text or content has been copied or republished online",
|
|
"input": "URL or pasted text",
|
|
"output": "List of web pages containing matching or similar text with percentage match scores",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches are processed by Copyscape's servers; submitted text is sent to Copyscape for comparison.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Lazy Scholar (T)",
|
|
"type": "url",
|
|
"url": "https://lazyscholar.org/",
|
|
"description": "Browser extension that automatically finds free legal full-text versions of academic papers when viewing paywalled content; checks open-access repositories and PubMed Central.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding free full-text access to paywalled academic papers without institutional subscription",
|
|
"input": "Paywalled journal article URL or DOI (via browser extension)",
|
|
"output": "Links to free legal full-text versions of the paper from open-access sources",
|
|
"opsec": "passive",
|
|
"opsecNote": "Extension queries open-access databases in the background; no personal data sent to external servers.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Open Access Scholarly Journals",
|
|
"type": "url",
|
|
"url": "https://www.pagepress.org/",
|
|
"description": "PAGEPress open-access publisher hosting peer-reviewed journals across biomedical, natural, and social sciences; provides free access to published research articles.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Accessing open-access peer-reviewed research in biomedical and natural sciences",
|
|
"input": "Article title, author, or journal name",
|
|
"output": "Freely accessible full-text research articles in PDF and HTML formats",
|
|
"opsec": "passive",
|
|
"opsecNote": "Publicly accessible journal platform; no account required to read articles.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "The Open Syllabus Project",
|
|
"type": "url",
|
|
"url": "https://www.opensyllabus.org/"
|
|
},
|
|
{
|
|
"name": "Science Publications",
|
|
"type": "url",
|
|
"url": "https://www.thescipub.com/"
|
|
},
|
|
{
|
|
"name": "arXiv.org",
|
|
"type": "url",
|
|
"url": "https://arxiv.org/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "News Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Google News Search",
|
|
"type": "url",
|
|
"url": "https://news.google.com/news/advanced_news_search?"
|
|
},
|
|
{
|
|
"name": "Flipboard",
|
|
"type": "url",
|
|
"url": "https://flipboard.com/"
|
|
},
|
|
{
|
|
"name": "YouGotTheNews",
|
|
"type": "url",
|
|
"url": "https://yougotthenews.com/"
|
|
},
|
|
{
|
|
"name": "NewspaperARCHIVE.com",
|
|
"type": "url",
|
|
"url": "https://newspaperarchive.com/"
|
|
},
|
|
{
|
|
"name": "PressReader.com",
|
|
"type": "url",
|
|
"url": "https://www.pressreader.com/"
|
|
},
|
|
{
|
|
"name": "Newspaper Map",
|
|
"type": "url",
|
|
"url": "https://newspapermap.com/"
|
|
},
|
|
{
|
|
"name": "NewsBrief",
|
|
"type": "url",
|
|
"url": "https://emm.newsbrief.eu/NewsBrief/clusteredition/en/latest.html"
|
|
},
|
|
{
|
|
"name": "AllYouCanRead.com",
|
|
"type": "url",
|
|
"url": "https://www.allyoucanread.com/"
|
|
},
|
|
{
|
|
"name": "World News",
|
|
"type": "url",
|
|
"url": "https://wn.com/#/search"
|
|
},
|
|
{
|
|
"name": "NewsNow.co.uk",
|
|
"type": "url",
|
|
"url": "https://www.newsnow.co.uk/h/"
|
|
},
|
|
{
|
|
"name": "Hubii",
|
|
"type": "url",
|
|
"url": "https://hubii.com/"
|
|
},
|
|
{
|
|
"name": "Inshorts",
|
|
"type": "url",
|
|
"url": "https://inshorts.com/en/read"
|
|
},
|
|
{
|
|
"name": "NewsBot",
|
|
"type": "url",
|
|
"url": "https://getnewsbot.com/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Other Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Colossus International Engine List",
|
|
"type": "url",
|
|
"url": "https://www.searchenginecolossus.com/"
|
|
},
|
|
{
|
|
"name": "Zenodo",
|
|
"type": "url",
|
|
"url": "https://zenodo.org/"
|
|
},
|
|
{
|
|
"name": "EntityCube",
|
|
"type": "url",
|
|
"url": "https://entitycube.research.microsoft.com/"
|
|
},
|
|
{
|
|
"name": "FindTheData A Research Engine",
|
|
"type": "url",
|
|
"url": "https://www.findthedata.com/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Search Tools",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "wayparam",
|
|
"type": "url",
|
|
"url": "https://github.com/aleff-github/wayparam"
|
|
},
|
|
{
|
|
"name": "SearchDiggity (T)",
|
|
"type": "url",
|
|
"url": "https://bishopfox.com/resources"
|
|
},
|
|
{
|
|
"name": "Scanner-inurlbr (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/googleinurl/SCANNER-INURLBR"
|
|
},
|
|
{
|
|
"name": "Google Alerts",
|
|
"type": "url",
|
|
"url": "https://www.google.com/alerts"
|
|
},
|
|
{
|
|
"name": "Google Custom Search Engine",
|
|
"type": "url",
|
|
"url": "https://cse.google.com/cse/"
|
|
},
|
|
{
|
|
"name": "pagodo - Passive Google Dork (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/opsdisk/pagodo",
|
|
"description": "Python CLI tool that automates passive Google dork searches using the Google Hacking Database (GHDB), supporting HTTP/SOCKS5 proxies to avoid rate-limiting.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Automated passive Google dork enumeration from GHDB",
|
|
"input": "GHDB dork categories, target domain",
|
|
"output": "Google search result URLs matching dork patterns",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public Google search only; supports proxy configuration to reduce exposure. No direct target system contact.",
|
|
"localInstall": true,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Trends",
|
|
"type": "url",
|
|
"url": "https://trends.google.com/trends/",
|
|
"description": "Google's free tool for analyzing search interest trends over time and by geography, providing anonymized and aggregated data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Tracking topic interest, comparing search terms, identifying trend patterns",
|
|
"input": "Search term or topic",
|
|
"output": "Trend graphs, regional interest data, related queries",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries Google's anonymized aggregated data; no personal data exposure and no direct target contact.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "dorksearch.com",
|
|
"type": "url",
|
|
"url": "https://www.dorksearch.com/",
|
|
"description": "Web-based Google dork builder and search tool that integrates with Shodan, Censys, and GitHub for comprehensive OSINT searches.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Building complex Google dorks with API cross-referencing",
|
|
"input": "Target domain, keywords, dork parameters",
|
|
"output": "Google search queries with optional Shodan/Censys/GitHub results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Constructs and executes Google dork queries; API integrations may send queries to third-party services.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "dorkgenerator.pages.dev",
|
|
"type": "url",
|
|
"url": "https://dorkgenerator.pages.dev/",
|
|
"description": "Online dork generator for creating custom Google search parameter queries to assist in OSINT and security research.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick generation of custom Google dork queries",
|
|
"input": "Target, search parameters, dork type",
|
|
"output": "Constructed Google dork search URL",
|
|
"opsec": "passive",
|
|
"opsecNote": "Generates query strings locally; executing the dork in Google is passive public search.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "dorksearch.netlify.app",
|
|
"type": "url",
|
|
"url": "https://dorksearch.netlify.app/",
|
|
"description": "Lightweight web interface for building and executing Google dork searches with minimal dependencies.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Fast, simple Google dork query generation",
|
|
"input": "Keywords and dork operators",
|
|
"output": "Google dork search URL",
|
|
"opsec": "passive",
|
|
"opsecNote": "Generates and redirects to Google search queries; passive public search only.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Search Engine Guides",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Google Hacking Database",
|
|
"type": "url",
|
|
"url": "https://www.exploit-db.com/google-hacking-database",
|
|
"description": "Offensive Security's curated database of Google dork queries, organized by category, used for finding sensitive information exposed on the web.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding proven dork queries by category for security research",
|
|
"input": "Category or keyword search within GHDB",
|
|
"output": "Curated Google dork queries with descriptions",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reference database only; executing dorks against Google is passive public search with no direct target contact.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Search Operators Guide",
|
|
"type": "url",
|
|
"url": "https://www.googleguide.com/advanced_operators_reference.html",
|
|
"description": "Official Google documentation covering all supported search operators, syntax, and advanced search techniques.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Reference for Google search operator syntax and capabilities",
|
|
"input": "N/A (reference document)",
|
|
"output": "Documentation on operators, syntax, and examples",
|
|
"opsec": "passive",
|
|
"opsecNote": "Static reference documentation; no data is submitted or queries executed.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Guide Cheat Sheet",
|
|
"type": "url",
|
|
"url": "https://www.googleguide.com/help/calculator.html",
|
|
"description": "Quick-reference cheat sheet for Google search operators and advanced search syntax from Google Guide.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick lookup of Google search operator syntax",
|
|
"input": "N/A (reference document)",
|
|
"output": "Tabular reference of operators with examples",
|
|
"opsec": "passive",
|
|
"opsecNote": "Static reference page; no queries executed or data submitted.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Online Communities",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Blog Search Engines",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Live Journal Seek",
|
|
"type": "url",
|
|
"url": "https://ljseek.com/",
|
|
"description": "Search tool for LiveJournal journals and communities across public entries that are indexed.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding public LiveJournal entries and historical community discussions",
|
|
"input": "Keywords and search terms",
|
|
"output": "Matching journal entries with author, date, and snippets",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches publicly indexed content and does not contact journal owners directly; queries are likely logged.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Blog Search Engine",
|
|
"type": "url",
|
|
"url": "https://www.blogsearchengine.org/",
|
|
"description": "Blog-focused search engine for discovering blog posts, directories, and RSS-connected content.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Blog discovery and topic-focused blog post searching",
|
|
"input": "Keywords and blog topics",
|
|
"output": "Matching blog posts, listings, and feed-linked results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregates publicly indexed blog data without direct user contact to target blogs; queries are logged.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Discord Servers",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Discord Bot List",
|
|
"type": "url",
|
|
"url": "https://discord.bots.gg/",
|
|
"description": "Searchable directory of Discord bots with listings, categories, and discovery metadata.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Discord bot discovery and ecosystem mapping",
|
|
"input": "Bot names, keywords, and categories",
|
|
"output": "Bot profiles with descriptions, ratings, and invite metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Enumerates publicly listed bots and does not require direct Discord account interaction for browsing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ReconXplorer (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/root7am/ReconXplorer",
|
|
"description": "Open-source reconnaissance toolkit with modules for IP, email, and Discord-focused lookups.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Multi-input OSINT checks from a local scriptable toolkit",
|
|
"input": "IP addresses, emails, Discord tokens, and host data",
|
|
"output": "Recon results including geolocation, service, and account-related metadata",
|
|
"opsec": "active",
|
|
"opsecNote": "Runs direct external queries from the operator environment and may trigger service-side detection or logging.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Top.gg",
|
|
"type": "url",
|
|
"url": "https://top.gg/",
|
|
"description": "Large Discord bot and app discovery platform with ranking, filtering, and listing data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Discord bot ranking analysis and app discovery",
|
|
"input": "Bot names, tags, and search filters",
|
|
"output": "Bot listings with popularity, server counts, and profile details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses public listing data and does not require direct target interaction for standard browsing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Forum Search Engines",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "BoardReader",
|
|
"type": "url",
|
|
"url": "https://boardreader.com/",
|
|
"description": "Forum search engine that indexes discussions across message boards and community platforms.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding forum threads and topic-centric discussion history",
|
|
"input": "Keywords, forum names, and topical queries",
|
|
"output": "Indexed posts and thread references with source links",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches indexed forum content and avoids direct interaction with target forum users.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Omgili",
|
|
"type": "url",
|
|
"url": "https://webz.io/",
|
|
"description": "Forum and discussion search capability operated through Webz.io infrastructure and data products.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Forum discussion discovery with optional API-driven workflows",
|
|
"input": "Keywords and Boolean-style forum queries",
|
|
"output": "Discussion posts and thread-level matching results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses indexed discussion datasets from a third-party provider; user-side browsing is passive.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Craigslist Forums",
|
|
"type": "url",
|
|
"url": "https://forums.craigslist.org/",
|
|
"description": "Craigslist-hosted forum system for public community discussions and region-oriented threads.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Reviewing Craigslist community discussions and regional forum activity",
|
|
"input": "Forum categories, keywords, and regional navigation",
|
|
"output": "Forum threads, post content, and timing context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reads publicly visible forum content and does not require direct messaging or contact with users.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Delphi Forum Search",
|
|
"type": "url",
|
|
"url": "https://www.delphiforums.com/",
|
|
"description": "Forum platform with searchable user communities across niche interest categories.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Niche forum discovery and historical community thread review",
|
|
"input": "Forum names, categories, and keywords",
|
|
"output": "Forum listings, thread titles, and message pages",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public forum browsing is passive; some communities may require registration for deeper access.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Groups Search",
|
|
"type": "url",
|
|
"url": "https://groups.google.com/forum/#!overview",
|
|
"description": "Search interface for Google Groups and archived discussion content, including historical threads.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Researching archived mailing-list and discussion-group content",
|
|
"input": "Keywords, group names, authors, and date ranges",
|
|
"output": "Thread messages and group-level discussion results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Searches archived public discussions through Google-hosted infrastructure where activity is logged.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "IRC Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Mibbit",
|
|
"type": "url",
|
|
"url": "https://search.mibbit.com/",
|
|
"description": "Former web IRC client and channel search service that is no longer operational.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Legacy reference for historical IRC channel search workflows",
|
|
"input": "Channel or keyword queries (historical behavior)",
|
|
"output": "No current output; service is discontinued",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "Service shut down on August 30, 2024 and cannot be relied on for active workflows.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "IRCP (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/internet-relay-chat/IRCP",
|
|
"description": "Python-based IRC probing utility for scanning servers and collecting network/channel metadata.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IRC server enumeration and protocol-level reconnaissance",
|
|
"input": "Target ranges, IRC ports, and server parameters",
|
|
"output": "Server and channel metadata in machine-readable output",
|
|
"opsec": "active",
|
|
"opsecNote": "Actively connects to IRC services and may be detectable by network monitoring and server logs.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ircsnapshot (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/bwall/ircsnapshot",
|
|
"description": "IRC data collection tool that connects bots to servers for user and channel mapping.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IRC topology mapping and user/channel relationship analysis",
|
|
"input": "IRC server details, bot config, and channel targets",
|
|
"output": "Collected user, hostmask, and channel affiliation data",
|
|
"opsec": "active",
|
|
"opsecNote": "Requires active network participation via bot accounts and is likely visible to channel operators.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "netsplit.de",
|
|
"type": "url",
|
|
"url": "https://netsplit.de/channels/search.php",
|
|
"description": "IRC directory and search portal for channel listings, network stats, and discovery workflows.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Passive IRC channel discovery and network trend checks",
|
|
"input": "Channel names, keywords, and network filters",
|
|
"output": "Channel listings with network and user-count context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses aggregated indexed IRC data and does not require direct IRC server interaction for searches.",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Reddit Communities",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Arctic Shift",
|
|
"type": "url",
|
|
"url": "https://arctic-shift.photon-reddit.com/",
|
|
"description": "Search and access layer for Reddit datasets with tools for historical content retrieval and analysis.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Historical Reddit dataset analysis and subreddit research",
|
|
"input": "Search terms, dataset queries, or API-style requests",
|
|
"output": "Matching Reddit posts, comments, and metadata from indexed datasets",
|
|
"opsec": "passive",
|
|
"opsecNote": "Works against archived or indexed data sources without requiring direct engagement with target accounts.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Cama's Reddit Search",
|
|
"type": "url",
|
|
"url": "https://camas.github.io/reddit-search/",
|
|
"description": "Web tool for searching Reddit posts and comments by author, subreddit, text, and time filters.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Reddit user and subreddit content discovery",
|
|
"input": "Usernames, subreddits, keywords, and date constraints",
|
|
"output": "Filtered post/comment search results with metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses public data indexing paths; original GitHub hosting was discontinued but alternative hosting remains available.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Reveddit",
|
|
"type": "url",
|
|
"url": "https://www.reveddit.com/",
|
|
"description": "Interface for viewing Reddit content removals using archived and moderation-related visibility signals.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Investigating deleted or removed Reddit discussions",
|
|
"input": "Reddit URLs, usernames, or subreddit paths",
|
|
"output": "Recovered or flagged removed-content views with moderation indicators",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries archive-backed sources and public content pathways without direct contact to target users.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Archives",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Web",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Anna's Archive",
|
|
"type": "url",
|
|
"url": "https://annas-archive.org/",
|
|
"description": "Meta-search index for books and papers that aggregates links from multiple shadow libraries.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Locating mirrored copies of books and papers from multiple sources",
|
|
"input": "Book title, author, ISBN, DOI, or keyword",
|
|
"output": "Indexed records with download and mirror links",
|
|
"opsec": "active",
|
|
"opsecNote": "Searches are query-based and may be logged; accessing mirrored content can carry legal and operational risk.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Archive.is",
|
|
"type": "url",
|
|
"url": "https://archive.is/",
|
|
"description": "On-demand web snapshot service that preserves point-in-time copies of pages and shortens archive links.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Capturing and retrieving snapshots of volatile web pages",
|
|
"input": "URL",
|
|
"output": "Archived page copy with permanent archive URL",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reading existing snapshots is passive; submitting new captures is visible to the archive provider.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Browsershots",
|
|
"type": "url",
|
|
"url": "https://browsershots.org/",
|
|
"description": "Legacy cross-browser screenshot service historically used to render pages in multiple browser/OS combinations.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference for legacy browser rendering captures",
|
|
"input": "URL and browser configuration",
|
|
"output": "Rendered webpage screenshots",
|
|
"opsec": "passive",
|
|
"opsecNote": "Service is effectively discontinued; requests are unlikely to complete.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Cached Pages",
|
|
"type": "url",
|
|
"url": "https://www.cachedpages.com/",
|
|
"description": "Web cache lookup utility that surfaces archived and cached versions of a target page from multiple sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding recent cached copies of pages that changed or disappeared",
|
|
"input": "URL",
|
|
"output": "Links to cached or archived snapshots",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries third-party caches and archives without contacting the target site directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Cached View",
|
|
"type": "url",
|
|
"url": "https://cachedview.com/",
|
|
"description": "Simple cache-checking service that retrieves copies of pages from search engine and archive caches.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick verification of whether a removed page still exists in cache",
|
|
"input": "URL",
|
|
"output": "Cached page links from available providers",
|
|
"opsec": "passive",
|
|
"opsecNote": "Lookup activity is handled by the cache service and does not interact with the target host directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Common Crawl",
|
|
"type": "url",
|
|
"url": "https://commoncrawl.org/",
|
|
"description": "Open repository of large-scale web crawl data published as monthly WARC datasets.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Large-scale historical web content mining and corpus analysis",
|
|
"input": "CC index query, URL, domain, or WARC request",
|
|
"output": "Raw crawl records, metadata indexes, and extracted web content",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reads published crawl datasets and indexes; no direct interaction with target systems.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Internet Archive: Wayback Machine",
|
|
"type": "url",
|
|
"url": "https://web.archive.org/",
|
|
"description": "Web archive providing historical snapshots of websites captured over time.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Historical website analysis and deleted content recovery",
|
|
"input": "URL or domain",
|
|
"output": "Archived web page snapshots with timestamps",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries archived data. Does not contact the target. Searches may be logged by the Internet Archive.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "PDF My URL",
|
|
"type": "url",
|
|
"url": "https://pdfmyurl.com/",
|
|
"description": "Converts web pages into downloadable PDF captures for documentation and evidence preservation.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Generating quick PDF evidence captures of web pages",
|
|
"input": "URL",
|
|
"output": "PDF snapshot of page content",
|
|
"opsec": "passive",
|
|
"opsecNote": "Third-party conversion service processes submitted URLs; target is typically fetched by the service backend.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Screenshots.com",
|
|
"type": "url",
|
|
"url": "https://www.screenshots.com/",
|
|
"description": "Website screenshot archive and capture service for viewing historical or current rendered page images.",
|
|
"status": "degraded",
|
|
"pricing": "freemium",
|
|
"bestFor": "Visual timeline checks of website appearance changes",
|
|
"input": "Domain or URL",
|
|
"output": "Stored website screenshots and capture previews",
|
|
"opsec": "passive",
|
|
"opsecNote": "Operational status requires follow-up verification; treat availability as uncertain.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Wayback Machine Chrome Extension",
|
|
"type": "url",
|
|
"url": "https://chrome.google.com/webstore/detail/wayback-machine/fpnmgdkabkmnadcjpehmlllkndpkmiak",
|
|
"description": "Browser extension that detects missing pages and loads historical versions from the Wayback Machine.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Fast archive lookups while browsing dead or changed pages",
|
|
"input": "Current tab URL or missing page request",
|
|
"output": "Direct Wayback snapshot links from browser context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Extension requests archive data through Internet Archive endpoints and may log usage telemetry.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Textfiles.com",
|
|
"type": "url",
|
|
"url": "https://textfiles.com/",
|
|
"description": "Historic repository preserving early internet text artifacts including BBS files, documents, and underground zines.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Researching legacy digital culture and historical text archives",
|
|
"input": "Keyword, directory path, or file browsing",
|
|
"output": "Archived plain-text files and scanned historical documents",
|
|
"opsec": "passive",
|
|
"opsecNote": "Read-only archive browsing; minimal operational exposure beyond normal web access logging.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "UK Web Archive",
|
|
"type": "url",
|
|
"url": "https://www.webarchive.org.uk/ukwa/",
|
|
"description": "British Library-led archive preserving selected UK websites and related national web heritage content.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Accessing preserved UK web content and historical domain captures",
|
|
"input": "URL, title, topic, or keyword",
|
|
"output": "Archived UK website records and preserved snapshots",
|
|
"opsec": "passive",
|
|
"opsecNote": "Service availability has been unstable following cyberattack-related disruptions.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Waybackpack (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/jsvine/waybackpack",
|
|
"description": "Command-line tool for bulk downloading archived captures from the Internet Archive Wayback Machine.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Batch export of historical snapshots for offline analysis",
|
|
"input": "Domain/URL and optional date filters",
|
|
"output": "Downloaded archive files and URL/capture lists",
|
|
"opsec": "passive",
|
|
"opsecNote": "Automated queries hit archive APIs and can generate identifiable traffic patterns if used at scale.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Web Archive-RU",
|
|
"type": "url",
|
|
"url": "https://web-arhive.ru/",
|
|
"description": "Regional web archiving service focused on preserving and browsing snapshots of selected websites.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Supplemental archive checks when mainstream archives lack coverage",
|
|
"input": "URL or keyword",
|
|
"output": "Available archived pages and snapshot listings",
|
|
"opsec": "passive",
|
|
"opsecNote": "Operational status requires follow-up verification; use as secondary source until confirmed.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "WebCite",
|
|
"type": "url",
|
|
"url": "https://www.webcitation.org:443/query",
|
|
"description": "Citation-focused web preservation service with legacy archived records and limited query capabilities.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Retrieving historical citation captures that still remain accessible",
|
|
"input": "Archived URL, DOI, or query string",
|
|
"output": "Stored citation snapshots and metadata records",
|
|
"opsec": "passive",
|
|
"opsecNote": "Service appears read-only and partially unavailable; expect incomplete retrieval.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Data Leaks",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Cryptome",
|
|
"type": "url",
|
|
"url": "https://cryptome.org/",
|
|
"description": "Long-running disclosure archive hosting leaked or hard-to-find government, intelligence, and policy documents.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Searching historical leaked documents and primary-source disclosures",
|
|
"input": "Keyword or document browsing",
|
|
"output": "Published leak archives and document files",
|
|
"opsec": "passive",
|
|
"opsecNote": "Read-only document access with standard web logging by host infrastructure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Databases.Today",
|
|
"type": "url",
|
|
"url": "https://databases.today/",
|
|
"description": "Breach data discovery portal indexing exposed databases and leaked credential collections.",
|
|
"status": "degraded",
|
|
"pricing": "freemium",
|
|
"bestFor": "Identifying whether target identifiers appear in known breach dumps",
|
|
"input": "Email, username, domain, or keyword",
|
|
"output": "Indexed breach hit results and source references",
|
|
"opsec": "active",
|
|
"opsecNote": "Operational status requires verification; querying breach portals can create attribution and compliance risk.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "WikiLeaks",
|
|
"type": "url",
|
|
"url": "https://wikileaks.org/",
|
|
"description": "Global document leak publication platform containing diplomatic, military, and corporate disclosures.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Searching high-impact leaked document collections for historical context",
|
|
"input": "Keyword, topic, date range, or document identifier",
|
|
"output": "Leaked document pages, files, and related publication context",
|
|
"opsec": "active",
|
|
"opsecNote": "Platform reliability is partial and interactions may carry legal, policy, and attribution exposure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Public Datasets",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Labeled Faces in the Wild DB",
|
|
"type": "url",
|
|
"url": "https://vis-www.cs.umass.edu/lfw/",
|
|
"description": "Academic benchmark dataset of labeled face photographs collected from the public web.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Facial recognition benchmarking and person-image research baselines",
|
|
"input": "Dataset download request",
|
|
"output": "Labeled face image dataset files and metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Static academic dataset retrieval with no direct target interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Stanford Large Network Dataset Collection",
|
|
"type": "url",
|
|
"url": "https://snap.stanford.edu/data/#amazon",
|
|
"description": "SNAP repository of graph/network datasets spanning social networks, web graphs, and communication systems.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Network analysis modeling and graph-based OSINT experimentation",
|
|
"input": "Dataset selection request",
|
|
"output": "Downloadable graph datasets and documentation",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public academic data access only; no interaction with investigation targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "UCI Spambase Data Set",
|
|
"type": "url",
|
|
"url": "https://archive.ics.uci.edu/dataset/94/spambase",
|
|
"description": "Classic UCI machine-learning dataset for spam classification and email feature analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Email spam model benchmarking and feature-engineering practice",
|
|
"input": "Dataset page access or download request",
|
|
"output": "Tabular spam classification dataset and metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public dataset retrieval only with negligible operational exposure.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Visual Genome",
|
|
"type": "url",
|
|
"url": "https://visualgenome.org/",
|
|
"description": "Structured image dataset linking objects, attributes, and scene graph relationships for visual understanding research.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Image relationship analysis and multimodal data research",
|
|
"input": "Dataset query or download request",
|
|
"output": "Annotated image corpus with objects, regions, and relation graphs",
|
|
"opsec": "passive",
|
|
"opsecNote": "Academic dataset access with no direct investigative target interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Other Media",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "TV Closed Caption Search",
|
|
"type": "url",
|
|
"url": "https://archive.org/details/tv",
|
|
"description": "Internet Archive TV News collection for searching closed-caption text across broadcast recordings.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding broadcast mentions by keyword and time period",
|
|
"input": "Keyword, program, channel, or date range",
|
|
"output": "Matching TV clips, transcripts, and broadcast metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Queries public archived broadcasts without interacting with monitored subjects.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Language Translation",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Text",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Bing Translate",
|
|
"type": "url",
|
|
"url": "https://translator.bing.com/",
|
|
"description": "Microsoft's neural translation service for text and web content across 100+ languages.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick translation of text and webpages",
|
|
"input": "Text or website URL",
|
|
"output": "Translated text or translated webpage content",
|
|
"opsec": "active",
|
|
"opsecNote": "Submitted text is processed on Microsoft servers.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Cambridge Dictionary",
|
|
"type": "url",
|
|
"url": "https://dictionary.cambridge.org/",
|
|
"description": "Dictionary and learner reference platform with translation support across multiple language pairs.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Word-level translation and bilingual dictionary lookups",
|
|
"input": "Words and short phrases",
|
|
"output": "Definitions, pronunciations, and translated equivalents",
|
|
"opsec": "passive",
|
|
"opsecNote": "Lookup requests are standard dictionary queries and do not contact investigation targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DeepL Translator",
|
|
"type": "url",
|
|
"url": "https://www.deepl.com/en/translator",
|
|
"description": "AI-powered machine translation service focused on high-quality translation with document support.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "High-accuracy translation of documents and technical text",
|
|
"input": "Text or supported documents",
|
|
"output": "Translated text or translated document",
|
|
"opsec": "active",
|
|
"opsecNote": "Submitted content is transmitted to DeepL infrastructure for processing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Free Translation",
|
|
"type": "url",
|
|
"url": "https://translation2.paralink.com/",
|
|
"description": "Multi-provider web translator for quick text translation across many language pairs.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Fast multi-language text translation in a browser",
|
|
"input": "Text",
|
|
"output": "Translated text",
|
|
"opsec": "active",
|
|
"opsecNote": "Text is sent to backend translation providers for processing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Input Tools",
|
|
"type": "url",
|
|
"url": "https://www.google.com/inputtools/",
|
|
"description": "Google input method utility for typing and transliteration across many scripts and languages.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Typing non-Latin scripts and transliterated input",
|
|
"input": "Keyboard text and transliteration input",
|
|
"output": "Text in target language script",
|
|
"opsec": "passive",
|
|
"opsecNote": "Used as an input method helper and not for target-facing interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Google Translate",
|
|
"type": "url",
|
|
"url": "https://translate.google.com/",
|
|
"description": "Google's web translation platform covering hundreds of languages for text and website translation.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick translation across broad language coverage",
|
|
"input": "Text, documents, speech, or website URL",
|
|
"output": "Translated text, speech output, or translated webpage",
|
|
"opsec": "active",
|
|
"opsecNote": "Submitted content is processed by Google services.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Slang Dictionary & Translator",
|
|
"type": "url",
|
|
"url": "https://www.noslang.com/",
|
|
"description": "NoSlang provides internet slang definitions and reverse translation for common texting shorthand.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Decoding internet slang and text abbreviations",
|
|
"input": "Slang terms or plain-language text",
|
|
"output": "Definitions or slang-style equivalents",
|
|
"opsec": "passive",
|
|
"opsecNote": "Lookup-based dictionary usage without direct interaction with investigation targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Slangit - The Slang Dictionary",
|
|
"type": "url",
|
|
"url": "https://slang.net/",
|
|
"description": "Online slang dictionary focused on modern internet and texting terminology with usage context.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Understanding current online slang and acronym usage",
|
|
"input": "Slang term or abbreviation",
|
|
"output": "Definition and usage context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Read-only dictionary queries routed to the provider site.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Urban Dictionary",
|
|
"type": "url",
|
|
"url": "https://www.urbandictionary.com/",
|
|
"description": "Crowdsourced slang reference that tracks contemporary colloquialisms and culture-specific definitions.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Interpreting emerging slang and culture-driven terms",
|
|
"input": "Slang terms or phrases",
|
|
"output": "Community-submitted definitions and examples",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public dictionary browsing; no direct contact with target entities.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Wiktionary",
|
|
"type": "url",
|
|
"url": "https://en.wiktionary.org/",
|
|
"description": "Collaborative multilingual dictionary and translation reference hosted by the Wikimedia ecosystem.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Word definitions, etymology, and multilingual term translation",
|
|
"input": "Words and phrases",
|
|
"output": "Definitions, pronunciations, etymology, and translation sections",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public lookup traffic only; occasional access friction was observed during automated checks.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Word Reference",
|
|
"type": "url",
|
|
"url": "https://www.wordreference.com/",
|
|
"description": "Bilingual dictionary platform with conjugation tables, forum context, and language-pair references.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Word-level translation with conjugation and usage context",
|
|
"input": "Words and short phrases",
|
|
"output": "Translations, definitions, conjugation tables, and examples",
|
|
"opsec": "passive",
|
|
"opsecNote": "Dictionary lookups are passive requests and do not engage targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Pictures",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "i2OCR",
|
|
"type": "url",
|
|
"url": "https://www.i2ocr.com/",
|
|
"description": "Free browser OCR service with broad multilingual support for extracting text from image and document files.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Multilingual OCR extraction without account creation",
|
|
"input": "Images and PDFs",
|
|
"output": "Extracted text and converted document output",
|
|
"opsec": "active",
|
|
"opsecNote": "Files are uploaded to a third-party OCR service for processing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "New OCR",
|
|
"type": "url",
|
|
"url": "https://www.newocr.com/",
|
|
"description": "Web OCR utility powered by Tesseract for text extraction from multiple file formats and scanned images.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "General-purpose OCR from scanned pages and images",
|
|
"input": "Images and PDF files",
|
|
"output": "Machine-readable extracted text",
|
|
"opsec": "active",
|
|
"opsecNote": "Uploaded files are processed on remote servers.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Online OCR (SodaPDF)",
|
|
"type": "url",
|
|
"url": "https://www.sodapdf.com/pdf-tools/ocr-pdf/",
|
|
"description": "SodaPDF's online OCR workflow for converting scanned PDFs and images into searchable text output.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "OCR conversion of scanned PDFs for editing",
|
|
"input": "PDF and image files",
|
|
"output": "Searchable PDF and extracted text",
|
|
"opsec": "active",
|
|
"opsecNote": "Document files are uploaded to SodaPDF infrastructure for OCR conversion.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Online OCR (onlineocr.net)",
|
|
"type": "url",
|
|
"url": "https://www.onlineocr.net/",
|
|
"description": "Browser OCR service for converting scanned images and PDFs to editable document formats.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Quick OCR to Word, Excel, or plain text",
|
|
"input": "Image files and PDFs",
|
|
"output": "DOCX, XLSX, and plain-text conversions",
|
|
"opsec": "active",
|
|
"opsecNote": "User files are uploaded for cloud-side OCR processing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Videos",
|
|
"type": "folder",
|
|
"children": []
|
|
},
|
|
{
|
|
"name": "Analysis",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "WhatTheFont",
|
|
"type": "url",
|
|
"url": "https://www.myfonts.com/pages/whatthefont/",
|
|
"description": "Image-based font identification service that matches uploaded text images against a large commercial font catalog.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Identifying unknown fonts from screenshots or photos",
|
|
"input": "Image containing text glyphs",
|
|
"output": "Likely font matches and related font-family suggestions",
|
|
"opsec": "passive",
|
|
"opsecNote": "Only uploaded imagery is analyzed; no interaction with investigation targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Mobile OSINT",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Android",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Emulation Tools",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Genymotion (T)",
|
|
"type": "url",
|
|
"url": "https://www.genymotion.com/",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"description": "Cloud-based and desktop Android emulator platform for app testing and forensic analysis. Supports multi-instance deployment and integration with security testing tools.",
|
|
"bestFor": "Testing mobile apps, forensic analysis, multi-device simulation",
|
|
"input": "APK files, app bundles",
|
|
"output": "Runtime behavior, app data artifacts, system logs",
|
|
"opsec": "active",
|
|
"opsecNote": "Genymotion generates detectable device signatures; fingerprinting tools may identify it as emulated",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "BlueStacks 2 (T)",
|
|
"type": "url",
|
|
"url": "https://www.bluestacks.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Free, lightweight Android emulator for desktop. Includes built-in forensic capabilities for data extraction from installed apps.",
|
|
"bestFor": "Quick Android testing, forensic artifact extraction, app analysis",
|
|
"input": "APK files, installed apps",
|
|
"output": "App data, SQLite databases, shared preferences, file system artifacts",
|
|
"opsec": "active",
|
|
"opsecNote": "Emulator detection possible via device properties and system checks",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Nox App Player",
|
|
"type": "url",
|
|
"url": "https://www.bignox.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Free Android emulator with support for multiple Android versions and root access. Used for app analysis and testing.",
|
|
"bestFor": "Android version testing, app analysis, rooted device simulation",
|
|
"input": "APK files, apps",
|
|
"output": "App behavior, system-level data, rooted access artifacts",
|
|
"opsec": "active",
|
|
"opsecNote": "Detectable via emulator checks; includes obvious emulator markers",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Apk Online",
|
|
"type": "url",
|
|
"url": "https://apk.online/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Browser-based tool for analyzing and downloading APK files. Allows viewing app permissions, features, and metadata without installation.",
|
|
"bestFor": "Quick APK analysis, permission review, app feature reconnaissance",
|
|
"input": "App package names or APK files",
|
|
"output": "APK downloads, permission lists, app metadata, manifest data",
|
|
"opsec": "passive",
|
|
"opsecNote": "No installation required; passive reconnaissance only",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Apps",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Social Networking",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Facebook (T)",
|
|
"type": "url",
|
|
"url": "https://www.facebook.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Major social network with over 2 billion users. Primary target for social OSINT and profile reconnaissance.",
|
|
"bestFor": "Profile reconnaissance, relationship mapping, photo analysis, location tracking",
|
|
"input": "Usernames, profile URLs, phone numbers, email addresses",
|
|
"output": "Profile data, friend networks, photos, location history, activity timeline",
|
|
"opsec": "active",
|
|
"opsecNote": "Facebook monitors and blocks suspicious activity patterns; tool-based scraping is easily detected",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "LinkedIn (T)",
|
|
"type": "url",
|
|
"url": "https://www.linkedin.com/",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"description": "Professional social network with 900M+ users. Key source for professional identity verification and corporate structure mapping.",
|
|
"bestFor": "Professional background verification, corporate reconnaissance, employment history research",
|
|
"input": "Usernames, email domains, company names",
|
|
"output": "Professional profiles, employment history, connections, company structure",
|
|
"opsec": "active",
|
|
"opsecNote": "LinkedIn actively blocks scraping tools and monitors for bulk data collection",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Twitter (T)",
|
|
"type": "url",
|
|
"url": "https://www.twitter.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Microblogging platform with 500M+ users. Extensive public data, real-time information, and relationship networks.",
|
|
"bestFor": "Real-time monitoring, account verification, relationship mapping, sentiment analysis",
|
|
"input": "Usernames, hashtags, keywords, user IDs",
|
|
"output": "Tweets, user profiles, follower networks, location data, media",
|
|
"opsec": "passive",
|
|
"opsecNote": "Mostly passive; API-based tools are rate-limited but account scraping can be detected",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Pinterest (T)",
|
|
"type": "url",
|
|
"url": "https://www.pinterest.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Visual discovery platform with 460M+ users. Used for lifestyle, location, and interest-based profiling.",
|
|
"bestFor": "Interest profiling, location discovery, lifestyle analysis, image reverse search",
|
|
"input": "Usernames, pins, boards, images",
|
|
"output": "User profiles, boards, pins, location metadata, follower networks",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive reconnaissance; less aggressively monitored than Facebook or LinkedIn",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Instant Messaging",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Signal Private Messenger (T)",
|
|
"type": "url",
|
|
"url": "https://signal.org/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "End-to-end encrypted messaging app with 40M+ users. Limited OSINT value due to privacy-first design.",
|
|
"bestFor": "Identity verification, account discovery via phone/email, community research",
|
|
"input": "Phone numbers, email addresses, usernames",
|
|
"output": "Account existence, profile names, avatar images",
|
|
"opsec": "passive",
|
|
"opsecNote": "Very limited information exposure; encrypted content not accessible",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Riot.im - Communicate, your way (T)",
|
|
"type": "url",
|
|
"url": "https://riot.im/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Open-source Matrix client for decentralized messaging. Limited public data but useful for community monitoring.",
|
|
"bestFor": "Open community monitoring, channel discovery, user verification",
|
|
"input": "Usernames, community names, room IDs",
|
|
"output": "Community membership, user profiles, message history (if public), user activity",
|
|
"opsec": "passive",
|
|
"opsecNote": "Privacy depends on server configuration; public rooms and communities are openly accessible",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Telegram (T)",
|
|
"type": "url",
|
|
"url": "https://telegram.org/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Messaging platform with 700M+ users. Extensive public data through public channels, groups, and user searches.",
|
|
"bestFor": "User discovery, channel monitoring, group reconnaissance, bot creation for data collection",
|
|
"input": "Usernames, user IDs, chat links, phone numbers",
|
|
"output": "User profiles, channel data, group membership, message history, media",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public channels and users are accessible without authentication; bot development requires API key",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Snapchat (T)",
|
|
"type": "url",
|
|
"url": "https://www.snapchat.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Ephemeral messaging app with 400M+ users. Limited historical data due to auto-deletion, but real-time activity visible.",
|
|
"bestFor": "User verification, story analysis, location tracking via snap maps, relationship mapping",
|
|
"input": "Usernames, Snapcodes, phone numbers",
|
|
"output": "User profiles, story content, snap maps, friend networks",
|
|
"opsec": "active",
|
|
"opsecNote": "Snapchat actively detects and blocks third-party clients; API access is restricted",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "WhatsApp Messenger (T)",
|
|
"type": "url",
|
|
"url": "https://www.whatsapp.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Messaging platform with 2B+ users. End-to-end encrypted, but profile data and metadata are accessible.",
|
|
"bestFor": "User verification, profile discovery, status updates, contact verification",
|
|
"input": "Phone numbers, WhatsApp IDs",
|
|
"output": "User profiles, status messages, profile pictures, last-seen timestamps, online status",
|
|
"opsec": "passive",
|
|
"opsecNote": "No official API for OSINT; third-party tools easily detected and account-banned",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Kik (T)",
|
|
"type": "url",
|
|
"url": "https://www.kik.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Messaging app with 300M+ registered users. Public username search and profile visibility.",
|
|
"bestFor": "User discovery, profile analysis, public username search",
|
|
"input": "Usernames, user handles",
|
|
"output": "User profiles, status, profile pictures, user discovery",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public search available; less monitored than major platforms",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Yik Yak (T)",
|
|
"type": "url",
|
|
"url": "https://www.yikyak.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Anonymous location-based social network. Public posts visible by location, useful for community sentiment and event tracking.",
|
|
"bestFor": "Location-based event monitoring, community sentiment analysis, anonymity assessment",
|
|
"input": "Location coordinates, proximity radius",
|
|
"output": "Anonymous posts, location data, user engagement, community trends",
|
|
"opsec": "passive",
|
|
"opsecNote": "Designed for anonymity; minimal PII exposure, but location data and timing can reveal patterns",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "LINE (T)",
|
|
"type": "url",
|
|
"url": "https://line.me/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Messaging app with 200M+ users, dominant in Asia. User search and public profile visibility.",
|
|
"bestFor": "Asian market user discovery, profile analysis, account verification",
|
|
"input": "User IDs, phone numbers, LINE accounts",
|
|
"output": "User profiles, status messages, timeline data, friends list",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public profile search available; varies by region and privacy settings",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Pictures",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Instagram (T)",
|
|
"type": "url",
|
|
"url": "https://www.instagram.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Photo and video sharing platform with 2B+ users. Extensive visual OSINT and metadata analysis.",
|
|
"bestFor": "Visual reconnaissance, metadata analysis, location tracking via geotagging, relationship mapping",
|
|
"input": "Usernames, hashtags, locations, profile URLs",
|
|
"output": "User profiles, photos, videos, captions, location data, follower networks",
|
|
"opsec": "active",
|
|
"opsecNote": "Instagram aggressively blocks scraping tools; bulk data collection easily detected",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Flickr (T)",
|
|
"type": "url",
|
|
"url": "https://www.flickr.com/",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"description": "Photo hosting and sharing platform with 200M+ photos. Extensive metadata and location data.",
|
|
"bestFor": "Photo metadata analysis, EXIF data extraction, location tracking, photographer identification",
|
|
"input": "Usernames, tags, locations, URLs",
|
|
"output": "Photos, metadata, EXIF data, location coordinates, user profiles",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive access to public photos; metadata freely available",
|
|
"localInstall": false,
|
|
"googleDork": true,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Streaming Video",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Periscope (T)",
|
|
"type": "url",
|
|
"url": "https://www.periscope.tv/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Live video streaming app merged into Twitter. Limited standalone value; functionality integrated into Twitter.",
|
|
"bestFor": "Live event monitoring, real-time location tracking (via broadcast metadata), community monitoring",
|
|
"input": "Broadcast URLs, user handles, search keywords",
|
|
"output": "Broadcast data, viewer information, location metadata, broadcast archives",
|
|
"opsec": "passive",
|
|
"opsecNote": "Functionality largely superseded by Twitter; limited independent OSINT utility",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Meerkat (T)",
|
|
"type": "url",
|
|
"url": "https://meerkatapp.co/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Live streaming social app. Currently dormant with minimal active users; historical value for archived streams.",
|
|
"bestFor": "Legacy stream archives, historical event analysis",
|
|
"input": "Stream URLs, user profiles, timestamps",
|
|
"output": "Archived streams, viewer data, user activity logs",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Service is largely dormant; limited active OSINT value",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Vine (T)",
|
|
"type": "url",
|
|
"url": "https://vine.co/",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"description": "Short-form video platform shut down by Twitter in January 2017. No longer operational.",
|
|
"bestFor": "Historical video archives only (via archive services)",
|
|
"input": "Archived Vine URLs, video IDs",
|
|
"output": "Historical video data via Internet Archive or similar services",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Platform is defunct; only accessible via web archives",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Truecaller (T)",
|
|
"type": "url",
|
|
"url": "https://www.truecaller.com/",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"description": "Phone and contact verification app with 500M+ users. Reverse phone lookup and caller ID identification.",
|
|
"bestFor": "Phone number verification, caller ID lookup, spam detection, contact validation",
|
|
"input": "Phone numbers, contact names",
|
|
"output": "Caller name, carrier info, location data, spam reports, contact validation",
|
|
"opsec": "passive",
|
|
"opsecNote": "Requires app or web access; limited free tier for bulk lookups",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "App Analysis",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "APKLeaks",
|
|
"type": "url",
|
|
"url": "https://github.com/dwisiswant0/apkleaks",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Open-source tool that scans APK files for hardcoded secrets, API endpoints, and sensitive information.",
|
|
"bestFor": "API endpoint discovery, hardcoded credential detection, sensitive data extraction from APKs",
|
|
"input": "APK files",
|
|
"output": "Discovered secrets, API endpoints, hardcoded strings, configuration data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local analysis only; no network communication required",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "APKtool",
|
|
"type": "url",
|
|
"url": "https://apktool.org/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Open-source tool for reverse engineering Android apps. Decompiles APKs to extract resources and bytecode.",
|
|
"bestFor": "APK decompilation, resource extraction, smali code analysis, app structure analysis",
|
|
"input": "APK files",
|
|
"output": "Decompiled source code, resources, manifest data, smali bytecode",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local analysis only; operates offline on APK files",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "JADX",
|
|
"type": "url",
|
|
"url": "https://github.com/skylot/jadx",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Open-source decompiler (47k+ GitHub stars) that converts DEX bytecode to Java source code. GUI and CLI available.",
|
|
"bestFor": "Java source code recovery, app logic analysis, vulnerability assessment, code review",
|
|
"input": "APK files, DEX files, class files",
|
|
"output": "Java source code, code structure, method signatures, data flow",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local analysis tool; no network communication",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MobSF",
|
|
"type": "url",
|
|
"url": "https://github.com/MobSF/Mobile-Security-Framework-MobSF",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Open-source mobile security framework for static and dynamic analysis. Comprehensive vulnerability scanning and artifact extraction.",
|
|
"bestFor": "Comprehensive mobile app security analysis, vulnerability assessment, artifact extraction, compliance testing",
|
|
"input": "APK files, IPA files, source code",
|
|
"output": "Security vulnerabilities, permissions analysis, data flow analysis, forensic artifacts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Can be deployed locally or on private infrastructure for analysis",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Device Forensics",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Autopsy",
|
|
"type": "url",
|
|
"url": "https://www.autopsy.com/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Open-source digital forensics platform. Extracts and analyzes data from mobile devices and disk images.",
|
|
"bestFor": "Mobile forensic artifact extraction, database analysis, file system recovery, evidence analysis",
|
|
"input": "Device backups, disk images, app databases, file systems",
|
|
"output": "SQLite databases, app data, deleted files, timeline analysis, forensic artifacts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Works on forensic images and backups; no interaction with live devices",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Frida",
|
|
"type": "url",
|
|
"url": "https://frida.re/",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "Open-source dynamic instrumentation toolkit. Injects JavaScript to intercept and modify app behavior at runtime.",
|
|
"bestFor": "Runtime behavior analysis, API call interception, encryption bypass, behavior modification",
|
|
"input": "Running app processes, method signatures, target functions",
|
|
"output": "Intercepted method calls, API parameters, return values, runtime state",
|
|
"opsec": "active",
|
|
"opsecNote": "Requires rooted/jailbroken device or emulator; app-level detection is possible",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "iOS",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Charles Proxy",
|
|
"type": "url",
|
|
"url": "https://www.charlesproxy.com/",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"description": "Commercial HTTP/HTTPS proxy for traffic analysis. Captures and analyzes network traffic between apps and servers.",
|
|
"bestFor": "Network traffic interception, API endpoint mapping, parameter analysis, encryption analysis",
|
|
"input": "Network traffic, SSL/TLS sessions",
|
|
"output": "HTTP requests/responses, SSL certificates, decoded payloads, traffic analysis",
|
|
"opsec": "active",
|
|
"opsecNote": "HTTPS interception requires certificate pinning bypass; easily detected by security-aware apps",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Lynxio OSINT",
|
|
"type": "url",
|
|
"url": "https://lynxio.io/",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"description": "Mobile OSINT search tool for multi-identifier reconnaissance. Searches across phone numbers, email addresses, usernames, and social platforms.",
|
|
"bestFor": "Multi-identifier search, quick reconnaissance, phone number lookup, email verification",
|
|
"input": "Phone numbers, email addresses, usernames, URLs",
|
|
"output": "Associated identifiers, social media profiles, verification results, relationship mapping",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregates public data from multiple sources; passive only",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OSINT Researcher",
|
|
"type": "url",
|
|
"url": "https://apps.apple.com/us/app/osint-researcher/id6747302251",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"description": "iOS app for GitHub organization reconnaissance and open-source intelligence. Limited to App Store distribution.",
|
|
"bestFor": "GitHub OSINT, organization structure analysis, open-source project discovery, team reconnaissance",
|
|
"input": "Organization names, GitHub URLs, repository URLs",
|
|
"output": "Organization members, repository lists, contribution history, project metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "App Store only; limited availability and distribution",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Dark Web",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "General Info",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Reddit Deep Web",
|
|
"type": "url",
|
|
"url": "https://www.reddit.com/r/deepweb/",
|
|
"description": "Subreddit focused on dark web discussions, beginner guidance, and community-sourced OSINT references.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Community discussion on dark web OSINT topics",
|
|
"input": "Posts, comments, and search queries",
|
|
"output": "Community-shared links, advice, and discussion threads",
|
|
"opsec": "passive",
|
|
"opsecNote": "Browsing is passive but account activity is logged by Reddit.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Reddit Onions",
|
|
"type": "url",
|
|
"url": "https://www.reddit.com/r/onions/",
|
|
"description": "Subreddit for .onion service discussion, availability reports, and tool recommendations.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Tracking .onion ecosystem changes via community reports",
|
|
"input": "Posts, comments, and subreddit search terms",
|
|
"output": "User-reported onion links and operational status discussions",
|
|
"opsec": "passive",
|
|
"opsecNote": "Content consumption is passive; authenticated interactions are attributable to Reddit accounts.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Reddit Darknet",
|
|
"type": "url",
|
|
"url": "https://www.reddit.com/r/darknet/",
|
|
"description": "Community forum discussing darknet marketplaces, ecosystem events, and related threat activity.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Market ecosystem pulse and discussion-driven lead generation",
|
|
"input": "Posts, comments, and subreddit search terms",
|
|
"output": "Discussion intelligence, incident chatter, and directional leads",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive reading is low-risk, but participation creates account-linked activity trails.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Clients",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Tor Download (T)",
|
|
"type": "url",
|
|
"url": "https://www.torproject.org/download/",
|
|
"description": "Official Tor Project distribution page for Tor Browser and related anonymity tooling.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Obtaining trusted Tor Browser binaries",
|
|
"input": "Platform selection and download request",
|
|
"output": "Official Tor Browser installer packages",
|
|
"opsec": "passive",
|
|
"opsecNote": "Download activity is visible to network observers unless additional transport protections are used.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Freenet Project (T)",
|
|
"type": "url",
|
|
"url": "https://www.hyphanet.org/",
|
|
"description": "Hyphanet (formerly Freenet) is a decentralized, privacy-oriented network for anonymous publishing and file sharing.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Anonymous peer-to-peer content distribution",
|
|
"input": "Locally hosted or requested content within the network",
|
|
"output": "Distributed content retrieval and sharing",
|
|
"opsec": "passive",
|
|
"opsecNote": "Traffic is routed through a decentralized overlay, reducing direct source attribution.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "I2P Anonymous Network (T)",
|
|
"type": "url",
|
|
"url": "https://i2p.net/",
|
|
"description": "I2P is an anonymous overlay network supporting eepsites, messaging, and peer-to-peer services.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Accessing and hosting services inside the I2P anonymity network",
|
|
"input": "Local I2P router traffic and destination lookups",
|
|
"output": "Anonymized in-network service access",
|
|
"opsec": "passive",
|
|
"opsecNote": "Garlic routing and distributed peers obscure endpoint relationships.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Discovery",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "OnionScan",
|
|
"type": "url",
|
|
"url": "https://github.com/s-rah/onionscan",
|
|
"description": "Open-source scanner for .onion services that identifies metadata leaks and potential OPSEC weaknesses.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Assessing exposed metadata and weak configurations on hidden services",
|
|
"input": ".onion targets",
|
|
"output": "Scan findings and metadata leak indicators",
|
|
"opsec": "active",
|
|
"opsecNote": "Direct probing of hidden services can be logged and may alert target operators.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "TorBot",
|
|
"type": "url",
|
|
"url": "https://github.com/DedSecInside/TorBot",
|
|
"description": "Python-based crawler for discovering and indexing .onion links and related metadata.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Automated dark web crawling and onion link collection",
|
|
"input": "Seed onion links and crawl configuration",
|
|
"output": "Crawled onion pages, discovered links, and metadata",
|
|
"opsec": "active",
|
|
"opsecNote": "Crawling generates repeated target requests that can be detected by destination services.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Tor Scan",
|
|
"type": "url",
|
|
"url": "https://www.torscan.io/",
|
|
"description": "Legacy or ambiguous dark web scanning entry with unclear maintenance and uncertain distinction from OnionScan.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Legacy reference for Tor scanning workflows pending mapping cleanup",
|
|
"input": ".onion targets",
|
|
"output": "Potential scan intelligence when service is available",
|
|
"opsec": "active",
|
|
"opsecNote": "Any scan-style use is active probing and may expose investigator patterns.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Onioff",
|
|
"type": "url",
|
|
"url": "https://github.com/k4m4/onioff",
|
|
"description": "Onion URL inspection utility for checking reachability and extracting metadata from hidden service links.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick inspection of onion links and service metadata",
|
|
"input": ".onion URLs",
|
|
"output": "Link metadata and availability information",
|
|
"opsec": "active",
|
|
"opsecNote": "Inspection requests contact target onion services through Tor and can be observed by targets.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Hunchly Hidden Services Report",
|
|
"type": "url",
|
|
"url": "https://darkweb.hunch.ly/",
|
|
"description": "Daily feed of newly observed hidden services and associated monitoring data from Hunchly.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Monitoring new hidden-service discovery trends",
|
|
"input": "Feed queries and subscription requests",
|
|
"output": "Hidden service report data and update feeds",
|
|
"opsec": "passive",
|
|
"opsecNote": "Primarily consumes third-party aggregated reporting rather than probing targets directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "docker-onion-nmap (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/milesrichardson/docker-onion-nmap",
|
|
"description": "Dockerized nmap/proxychains workflow for enumerating exposed ports on onion services through Tor.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Containerized port enumeration of hidden services",
|
|
"input": ".onion hosts",
|
|
"output": "Network scan results and open-port findings",
|
|
"opsec": "active",
|
|
"opsecNote": "Port scanning is high-signal active probing and is likely visible to target operators.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Onion Investigator",
|
|
"type": "url",
|
|
"url": "https://oint.ctrlbox.com/",
|
|
"description": "Ambiguous investigation entry with limited current validation and unclear relation to other onion analysis tools.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Legacy onion investigation reference pending mapping decision",
|
|
"input": "Unknown",
|
|
"output": "Unknown",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Insufficient current evidence on operating model; treat as potentially active until clarified.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "TOR Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Onion Cab",
|
|
"type": "url",
|
|
"url": "https://onion.cab/",
|
|
"description": "Dark web search/directory endpoint with intermittent reliability and limited contemporary documentation.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Supplemental onion discovery when primary search tools miss coverage",
|
|
"input": "Keywords and category browsing",
|
|
"output": "Directory-style onion link listings",
|
|
"opsec": "passive",
|
|
"opsecNote": "Directory browsing is generally passive, but gateway logging policies are often opaque.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Ahmia",
|
|
"type": "url",
|
|
"url": "https://ahmia.fi/",
|
|
"description": "Well-known Tor search engine indexing onion services with clearnet accessibility for discovery workflows.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Primary onion search and service discovery",
|
|
"input": "Search keywords",
|
|
"output": "Indexed onion search results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Query activity is mediated by Ahmia rather than direct probing of each destination.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "TOR Directories",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Hidden Wiki",
|
|
"type": "url",
|
|
"url": "https://thehiddenwiki.org/",
|
|
"description": "Historically popular onion directory with variable trustworthiness, mirror churn, and high link rot.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference for onion directory structures",
|
|
"input": "Category browsing",
|
|
"output": "Curated onion link lists when accessible",
|
|
"opsec": "passive",
|
|
"opsecNote": "Directory browsing is passive, but listed links often carry high operational risk.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Web O Proxy",
|
|
"type": "url",
|
|
"url": "https://weboproxy.com/",
|
|
"description": "Web-based onion proxy/gateway style entry with uncertain current reliability and attribution risk.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Legacy gateway access reference for onion destinations",
|
|
"input": ".onion URLs",
|
|
"output": "Gateway-mediated onion page access",
|
|
"opsec": "unknown",
|
|
"opsecNote": "Gateway models can expose user IP/activity to operators; treat as high-risk unless verified.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "IACA Dark Web Investigation Support",
|
|
"type": "url",
|
|
"url": "https://iaca-darkweb-tools.com/",
|
|
"description": "International Anti Crime Academy dark web investigation support portal for federated search workflows.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Federated dark web investigation support and discovery",
|
|
"input": "Keywords and investigative query terms",
|
|
"output": "Aggregated search intelligence",
|
|
"opsec": "passive",
|
|
"opsecNote": "Primarily query-mediated discovery; avoid entering sensitive operational indicators into shared portals.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Disinformation & Media Verification",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Deepfake Detection",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "DeepFake-Detect",
|
|
"type": "url",
|
|
"url": "https://github.com/dessa-oss/DeepFake-Detection",
|
|
"description": "Open-source deepfake detection project built with PyTorch and ResNet18 for classifying manipulated media.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Research-grade deepfake detection model experimentation",
|
|
"input": "Image or video files",
|
|
"output": "Real/fake classification scores",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local/open-source workflow can run fully offline when self-hosted.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DeepFake-Image-Detection",
|
|
"type": "url",
|
|
"url": "https://github.com/rmkemker/DeepFake-Image-Detection",
|
|
"description": "Archived deepfake image detection repository previously used for forensic model experimentation.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference for legacy deepfake image detection approaches",
|
|
"input": "Image datasets",
|
|
"output": "Legacy model outputs and experiment artifacts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Repository currently unavailable; no active service to query.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "DeepSafe",
|
|
"type": "url",
|
|
"url": "https://github.com/siddharthksah/DeepSafe",
|
|
"description": "Containerized deepfake detection suite combining multiple models with both web and extension interfaces.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Ensemble deepfake detection for image and video investigations",
|
|
"input": "Image and video files",
|
|
"output": "Detection verdicts with confidence metrics",
|
|
"opsec": "active",
|
|
"opsecNote": "Hosted mode uploads media externally; local Docker deployment reduces exposure.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DeepfakeBench",
|
|
"type": "url",
|
|
"url": "https://github.com/SCLBD/DeepfakeBench",
|
|
"description": "Benchmark framework for deepfake detection with multiple datasets and standardized evaluation pipelines.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Comparing deepfake detector performance across common benchmarks",
|
|
"input": "Deepfake datasets and benchmark configs",
|
|
"output": "Evaluation metrics such as AUC and model comparisons",
|
|
"opsec": "passive",
|
|
"opsecNote": "Research framework executed locally without required external submissions.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "DeepfakeDetector",
|
|
"type": "url",
|
|
"url": "https://github.com/TRahulsingh/DeepfakeDetector",
|
|
"description": "Open-source deepfake detector with EfficientNet-based models and a web-facing analysis workflow.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Rapid deepfake checks with optional self-hosted deployment",
|
|
"input": "Image/video files or media URLs",
|
|
"output": "Detection results with confidence scoring",
|
|
"opsec": "active",
|
|
"opsecNote": "Public web deployments may log submitted content; local hosting is safer for sensitive media.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FaceForensics++",
|
|
"type": "url",
|
|
"url": "https://www.faceforensics.com/",
|
|
"description": "Academic deepfake forensics dataset with manipulated video samples, masks, and aligned benchmarks.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Training and benchmarking deepfake detection models",
|
|
"input": "Registration request and dataset usage context",
|
|
"output": "Curated deepfake datasets with annotations and metadata",
|
|
"opsec": "passive",
|
|
"opsecNote": "Dataset access requires form submission but does not require uploading investigative targets.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "InVID-WeVerify Verification Plugin",
|
|
"type": "url",
|
|
"url": "https://www.invid-project.eu/tools-and-services/invid-verification-plugin/",
|
|
"description": "Journalist-focused browser plugin for media verification, reverse image search, metadata checks, and video keyframe analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Social media image/video verification workflows",
|
|
"input": "Web pages, social posts, images, and videos",
|
|
"output": "Verification artifacts, reverse-search pivots, and extracted media context",
|
|
"opsec": "active",
|
|
"opsecNote": "Extension-driven workflows query external platforms and search engines, creating third-party telemetry.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "TruthScan Deepfake Detector",
|
|
"type": "url",
|
|
"url": "https://truthscan.com/",
|
|
"description": "Cloud-based deepfake detection platform offering forensic analysis for manipulated video and audio.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Operational deepfake triage with enterprise-grade reporting",
|
|
"input": "Uploaded audio/video files",
|
|
"output": "Probability scores, forensic indicators, and analysis reports",
|
|
"opsec": "active",
|
|
"opsecNote": "Media must be uploaded to a third-party cloud platform for processing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Fact-checking Tools",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Duke Reporters' Lab",
|
|
"type": "url",
|
|
"url": "https://reporterslab.org/",
|
|
"description": "Duke University journalism lab tracking global fact-checking initiatives, tools, and ecosystem trends.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Finding and benchmarking fact-checking organizations worldwide",
|
|
"input": "Research queries on fact-checking organizations and projects",
|
|
"output": "Directories, datasets, and reports on fact-checking initiatives",
|
|
"opsec": "passive",
|
|
"opsecNote": "Read-only research portal with standard website analytics.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Hoaxy",
|
|
"type": "url",
|
|
"url": "https://hoaxy.osome.iu.edu/",
|
|
"description": "Visualization platform for tracking how claims and fact-checking spread through social media networks.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Historical social diffusion analysis of misinformation and debunks",
|
|
"input": "Keywords, URLs, and social media topics",
|
|
"output": "Network graphs and timeline views of information spread",
|
|
"opsec": "active",
|
|
"opsecNote": "Service appears offline; historical design required querying social-platform data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "PolitiFact",
|
|
"type": "url",
|
|
"url": "https://www.politifact.com/",
|
|
"description": "Fact-checking publication that rates political claims and documents supporting evidence.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Verifying political statements and tracing source-backed ratings",
|
|
"input": "Public claims from politicians and media figures",
|
|
"output": "Structured fact-check articles and truth ratings",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public read-only use does not interact with targets directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "SciCheck",
|
|
"type": "url",
|
|
"url": "https://factcheck.org/scicheck/",
|
|
"description": "FactCheck.org section dedicated to scientific and health misinformation analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Validating scientific and medical claims in public discourse",
|
|
"input": "Scientific or health-related claims",
|
|
"output": "Evidence-backed explanatory fact-check articles",
|
|
"opsec": "passive",
|
|
"opsecNote": "Standard web consumption with no required interaction with investigated subjects.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Snopes",
|
|
"type": "url",
|
|
"url": "https://www.snopes.com/",
|
|
"description": "Long-running debunking site covering rumors, hoaxes, and viral misinformation claims.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Rapid validation of widely shared rumors and internet folklore",
|
|
"input": "Rumors, claims, memes, and circulating stories",
|
|
"output": "Investigative write-ups with verdicts and citation trails",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public resource; user activity is limited to normal web browsing telemetry.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Stop Fake Tools",
|
|
"type": "url",
|
|
"url": "http://www.stopfake.org/",
|
|
"description": "Ukrainian anti-disinformation initiative publishing fact-checks, analysis, and media literacy resources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Investigating Ukraine-focused propaganda and disinformation narratives",
|
|
"input": "Claims, narratives, and media artifacts related to regional information operations",
|
|
"output": "Debunks, context analysis, and educational guidance",
|
|
"opsec": "passive",
|
|
"opsecNote": "Read-only consumption of published reporting and educational content.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Reverse Media Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "ImgOps",
|
|
"type": "url",
|
|
"url": "https://imgops.com/",
|
|
"description": "Meta-search utility that routes an image to multiple reverse search and forensic services.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Fast multi-engine reverse image analysis from one entry point",
|
|
"input": "Image URL, uploaded file, or pasted image",
|
|
"output": "Pivot links and results across reverse-search and image-analysis engines",
|
|
"opsec": "active",
|
|
"opsecNote": "Routes images to third-party services, which may log content and request metadata.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "TinEye Reverse Image Search",
|
|
"type": "url",
|
|
"url": "https://tineye.com/",
|
|
"description": "Reverse image search engine that finds where an image appears online and identifies modified versions.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Tracing original publication and reuse of visual media",
|
|
"input": "Uploaded image or direct image URL",
|
|
"output": "Matched occurrences, oldest-known instances, and related variants",
|
|
"opsec": "active",
|
|
"opsecNote": "Image queries are processed on TinEye infrastructure and may be logged.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Source Verification",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "FotoForensics",
|
|
"type": "url",
|
|
"url": "https://fotoforensics.com/",
|
|
"description": "Image forensics platform with error level analysis and metadata-oriented integrity checks.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Detecting likely image manipulation and compression artifacts",
|
|
"input": "Image upload or image URL",
|
|
"output": "Forensic visualizations and manipulation indicators",
|
|
"opsec": "active",
|
|
"opsecNote": "Uploaded files are processed by a third-party online service.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Verification Handbook",
|
|
"type": "url",
|
|
"url": "https://verificationhandbook.com/",
|
|
"description": "Reference handbook for journalists covering verification methodologies for digital investigations.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Learning repeatable verification workflows for UGC and breaking news",
|
|
"input": "Verification learning needs and workflow questions",
|
|
"output": "Structured guidance, case studies, and checklists",
|
|
"opsec": "passive",
|
|
"opsecNote": "Static documentation site with no investigative target interaction.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Verification Junkie",
|
|
"type": "url",
|
|
"url": "https://verificationjunkie.com/",
|
|
"description": "Curated directory of verification resources, tools, and training materials for journalists.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Discovering verification tools and practitioner-oriented references",
|
|
"input": "Category browsing and keyword searches",
|
|
"output": "Collections of linked tools and verification guidance",
|
|
"opsec": "passive",
|
|
"opsecNote": "Site has certificate issues; treat access as unstable and verify links before relying on them.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Blockchain & Cryptocurrency",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Bitcoin",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Bitcoin Who's Who",
|
|
"type": "url",
|
|
"url": "https://www.bitcoinwhoswho.com/",
|
|
"description": "Bitcoin address profiling and scam reporting platform with community-driven address tagging for fraud detection and wallet identification.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Bitcoin address scam reports and community tagging",
|
|
"input": "Bitcoin address, wallet identifier, or transaction hash",
|
|
"output": "Address profile, transaction history, scam reports, community tags",
|
|
"opsec": "passive",
|
|
"opsecNote": "Direct lookup of public blockchain data; no registration required for basic queries.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "BitRef",
|
|
"type": "url",
|
|
"url": "https://bitref.com/",
|
|
"description": "Bitcoin address balance checker and transaction analyzer supporting address clustering, mempool data, mining statistics, and developer API.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Bitcoin address balance lookup and transaction analysis",
|
|
"input": "Bitcoin address, transaction ID, or block hash",
|
|
"output": "Current balance, transaction history, block data, mempool status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public blockchain query via web interface; no account required for basic lookups.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Blockonomics",
|
|
"type": "url",
|
|
"url": "https://www.blockonomics.co/",
|
|
"description": "Bitcoin payment API and OSINT platform providing address monitoring, wallet balance tracking, and transaction alerts for developers and enterprises.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Bitcoin payment integration and address monitoring for developers",
|
|
"input": "Bitcoin address, webhook configuration, or payment tracking setup",
|
|
"output": "Balance notifications, transaction alerts via email/webhook, payment confirmations",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uses public blockchain data; API keys required for monitoring features but basic lookups are unrestricted.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Blockr.io",
|
|
"type": "url",
|
|
"url": "https://blockr.io/",
|
|
"description": "Legacy Bitcoin blockchain explorer acquired by Coinbase in August 2014 and no longer maintained as standalone service.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference only (service discontinued)",
|
|
"input": "Bitcoin address or transaction hash (legacy)",
|
|
"output": "Service unavailable; rebranded to Coinbase services",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "Original service is defunct. Users should migrate to Blockchair, Blockchain.com, or Etherscan.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Blocktrail",
|
|
"type": "url",
|
|
"url": "https://www.blocktrail.com/BTC",
|
|
"description": "Bitcoin transaction analysis platform acquired by Bitmain in July 2016 and rebranded to BTC.com; original service no longer operational.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference only (rebranded to BTC.com)",
|
|
"input": "Bitcoin address or transaction (legacy)",
|
|
"output": "Service migrated; use BTC.com instead",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "Original blocktrail.com service is deprecated. Some wallet recovery tools remain but core blockchain explorer moved to BTC.com.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Orbit (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/s0md3v/Orbit",
|
|
"description": "Python CLI tool for Bitcoin wallet network analysis that visualizes transaction relationships through recursive crawling and graph rendering.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Bitcoin transaction network visualization and wallet relationship mapping",
|
|
"input": "Bitcoin address(es) via command line; supports single or multiple wallet analysis",
|
|
"output": "Interactive graph visualization showing fund flows, transaction frequency, node connections",
|
|
"opsec": "active",
|
|
"opsecNote": "Makes direct queries to blockchain APIs (configurable). Graph output may leak investigation scope to observers.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Wallet Explorer",
|
|
"type": "url",
|
|
"url": "https://www.walletexplorer.com/",
|
|
"description": "Bitcoin address clustering and wallet linking tool using multi-input heuristics to identify related addresses and track entity-level transaction patterns.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Bitcoin address clustering and entity wallet identification",
|
|
"input": "Bitcoin address, transaction hash, or entity name search",
|
|
"output": "Clustered wallet addresses, transaction patterns, entity profiles, balance summaries",
|
|
"opsec": "passive",
|
|
"opsecNote": "Analyzes public blockchain data; no registration required for basic lookups.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Chain Analysis Platforms",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Bitcoin Abuse Database",
|
|
"type": "url",
|
|
"url": "https://bitcoinabuse.com/",
|
|
"description": "Community-curated Bitcoin address abuse database tracking addresses associated with ransomware, fraud, scams, and illicit activities.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Identifying Bitcoin addresses linked to scams and ransomware",
|
|
"input": "Bitcoin address to search against abuse reports",
|
|
"output": "Abuse reports, report dates, reporter comments, associated crime type classifications",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public abuse reports from community; service noted to have received 75% spam in past operations. Use with caution for investigative confidence.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Bitcoin Who's Who",
|
|
"type": "url",
|
|
"url": "https://www.bitcoinwhoswho.com/",
|
|
"description": "Bitcoin address profiling and scam reporting platform with community-driven address tagging for fraud detection and wallet identification.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Bitcoin address scam reports and community tagging",
|
|
"input": "Bitcoin address, wallet identifier, or transaction hash",
|
|
"output": "Address profile, transaction history, scam reports, community tags",
|
|
"opsec": "passive",
|
|
"opsecNote": "Direct lookup of public blockchain data; no registration required for basic queries.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "BitRef",
|
|
"type": "url",
|
|
"url": "https://bitref.com/",
|
|
"description": "Bitcoin address balance checker and transaction analyzer supporting address clustering, mempool data, mining statistics, and developer API.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Bitcoin address balance lookup and transaction analysis",
|
|
"input": "Bitcoin address, transaction ID, or block hash",
|
|
"output": "Current balance, transaction history, block data, mempool status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public blockchain query via web interface; no account required for basic lookups.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Blockchair",
|
|
"type": "url",
|
|
"url": "https://blockchair.com/",
|
|
"description": "Multi-chain blockchain explorer supporting 48+ blockchains (Bitcoin, Ethereum, Litecoin, Solana, etc.) with advanced search, SQL-like queries, and privacy-focused design (Tor accessible, no tracking).",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Cross-chain address and transaction search with privacy-friendly interface",
|
|
"input": "Blockchain address, transaction hash, or advanced SQL-like query across chains",
|
|
"output": "Transaction history, balance data, token transfers, smart contract events, cross-chain analytics",
|
|
"opsec": "passive",
|
|
"opsecNote": "Accessible via Tor; does not require registration; minimal tracking or logging. Privacy-oriented design.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Blockscan",
|
|
"type": "url",
|
|
"url": "https://blockscan.com/",
|
|
"description": "Multichain EVM blockchain explorer aggregating 25+ EVM-compatible chains with portfolio tracking, real-time data, and in-depth analytics.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "EVM-chain portfolio aggregation and cross-chain transaction tracking",
|
|
"input": "Wallet address across EVM chains or transaction hash",
|
|
"output": "Portfolio balances across chains, transaction history, token holdings, DeFi position tracking",
|
|
"opsec": "passive",
|
|
"opsecNote": "Aggregates data from public blockchain APIs; no account required for basic lookups.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Etherscan",
|
|
"type": "url",
|
|
"url": "https://etherscan.io/",
|
|
"description": "Leading blockchain explorer, analytics, and API platform for Ethereum and 60+ EVM-compatible chains with comprehensive smart contract interaction tracking and developer tools.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Ethereum and EVM transaction analysis, smart contract inspection, token tracking",
|
|
"input": "Ethereum address, transaction hash, smart contract address, token contract",
|
|
"output": "Transaction details, smart contract source code, token transfers, holder lists, gas analytics",
|
|
"opsec": "passive",
|
|
"opsecNote": "Query via web interface or free API (rate-limited); no registration required for basic lookup. API keys enable higher rate limits.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OXT.me",
|
|
"type": "url",
|
|
"url": "https://oxt.me/",
|
|
"description": "Bitcoin blockchain analysis platform providing address probability scoring, transaction graph visualization, and timeline-based balance analysis for privacy research.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Bitcoin address privacy analysis and transaction probability scoring",
|
|
"input": "Bitcoin address or transaction hash",
|
|
"output": "Address summary, transaction timeline, balance history, probability-linked wallet analysis, transaction graph",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public blockchain analysis without registration; part of Samourai Wallet ecosystem.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Wallet Explorer",
|
|
"type": "url",
|
|
"url": "https://www.walletexplorer.com/",
|
|
"description": "Bitcoin address clustering and wallet linking tool using multi-input heuristics to identify related addresses and track entity-level transaction patterns.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Bitcoin address clustering and entity wallet identification",
|
|
"input": "Bitcoin address, transaction hash, or entity name search",
|
|
"output": "Clustered wallet addresses, transaction patterns, entity profiles, balance summaries",
|
|
"opsec": "passive",
|
|
"opsecNote": "Analyzes public blockchain data; no registration required for basic lookups.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "DeFi & DEX Tracing",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "DefiLlama",
|
|
"type": "url",
|
|
"url": "https://defillama.com/",
|
|
"description": "DeFi analytics platform aggregating Total Value Locked (TVL), yields, protocol revenue, and fees across 7000+ protocols on 500+ chains.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "DeFi protocol TVL comparison and yield aggregation across chains",
|
|
"input": "Protocol name, chain identifier, or yield pool search",
|
|
"output": "TVL rankings, historical TVL charts, protocol fees, revenue data, yield opportunities, stablecoin supply",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public DeFi data aggregation; no registration required for dashboard viewing. API access available for extended queries.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Dune Analytics",
|
|
"type": "url",
|
|
"url": "https://dune.com/",
|
|
"description": "Onchain data analytics platform enabling SQL queries against indexed blockchain data for 100+ blockchains with interactive dashboard and visualization tools.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Custom blockchain data analysis and dashboard creation via SQL queries",
|
|
"input": "SQL queries against blockchain tables; custom dashboard specifications",
|
|
"output": "Query results, custom visualizations, shareable dashboards, blockchain analytics insights",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public web platform; free tier supports publishing dashboards. Queries are indexed by Dune but individual data lookups are transparent.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Ethereum",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Etherscan",
|
|
"type": "url",
|
|
"url": "https://etherscan.io/",
|
|
"description": "Leading blockchain explorer, analytics, and API platform for Ethereum and 60+ EVM-compatible chains with comprehensive smart contract interaction tracking and developer tools.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Ethereum and EVM transaction analysis, smart contract inspection, token tracking",
|
|
"input": "Ethereum address, transaction hash, smart contract address, token contract",
|
|
"output": "Transaction details, smart contract source code, token transfers, holder lists, gas analytics",
|
|
"opsec": "passive",
|
|
"opsecNote": "Query via web interface or free API (rate-limited); no registration required for basic lookup. API keys enable higher rate limits.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Mixer Tracking",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Arkham Intelligence",
|
|
"type": "url",
|
|
"url": "https://intel.arkm.com/",
|
|
"description": "AI-powered blockchain intelligence platform mapping 300+ million address labels and 150K+ entity pages using proprietary Ultra system for entity deanonymization and fund-flow tracking.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Institutional-grade cryptocurrency entity mapping and fund-flow analysis",
|
|
"input": "Cryptocurrency address, entity name, or organization identifier",
|
|
"output": "Entity profile pages, address labels, transaction network visualization, fund-flow tracking, counterparty analysis",
|
|
"opsec": "active",
|
|
"opsecNote": "Aggregates on-chain and off-chain intelligence; registered users leave account footprint. Government and institutional adoption.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Breadcrumbs.app",
|
|
"type": "url",
|
|
"url": "https://www.breadcrumbs.app/",
|
|
"description": "Community-powered blockchain analytics platform with fund-flow visualization (PathFinder), address investigation, and crypto transaction network mapping.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Crypto fund-flow visualization and transaction relationship mapping",
|
|
"input": "Cryptocurrency address (Bitcoin, Ethereum, or other supported chains)",
|
|
"output": "Interactive fund-flow graph, incoming/outgoing transaction patterns, related address recommendations, balance summaries",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public blockchain data visualization; graph relationships may indicate investigation interest to observers.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MetaSleuth",
|
|
"type": "url",
|
|
"url": "https://metasleuth.io/",
|
|
"description": "Cross-chain cryptocurrency tracking and AML platform supporting 13 blockchains with fund-tracing through mixers using time/amount heuristics and network analysis.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Cross-chain fund tracking and mixer analysis for compliance investigations",
|
|
"input": "Cryptocurrency address across supported chains (Bitcoin, Ethereum, Solana, TRON, Polygon, etc.)",
|
|
"output": "Traced fund paths, mixer exit point detection, heuristic-based wallet linking, transaction timeline, compliance risk scoring",
|
|
"opsec": "active",
|
|
"opsecNote": "Active investigation platform; registered use may be logged. Used by compliance teams and law enforcement.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MistTrack",
|
|
"type": "url",
|
|
"url": "https://misttrack.io/",
|
|
"description": "Comprehensive AML and fund-tracing platform with 400M+ labeled wallet addresses, compliance database integration (OFAC, NBCTF, UK HMT), and real-time monitoring for 100K+ users.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Institutional AML compliance and suspicious transaction flagging",
|
|
"input": "Wallet address across Bitcoin, Ethereum, BNB, and other supported chains",
|
|
"output": "AML risk scoring, address labels from sanctions lists, transaction monitoring alerts, compliance reports, entity investigation",
|
|
"opsec": "active",
|
|
"opsecNote": "Enterprise compliance platform used by exchanges and regulators; addresses are actively monitored and investigations may be logged.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OFAC Sanctions List Search",
|
|
"type": "url",
|
|
"url": "https://sanctionssearch.ofac.treas.gov/",
|
|
"description": "Official U.S. Treasury Department tool for searching the Specially Designated Nationals (SDN) list and consolidated sanctions lists using fuzzy-logic name matching.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Checking against U.S. government sanctions list (SDN and consolidated lists)",
|
|
"input": "Individual or entity name (fuzzy-matched), alias variations",
|
|
"output": "SDN list matches, alternate names, addresses, dates of birth (when available), designation details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Official government database; searches are not logged against user identity but accessing the government website may be monitored.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Monero",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Monero Blocks",
|
|
"type": "url",
|
|
"url": "https://localmonero.co/blocks/",
|
|
"description": "Monero blockchain explorer displaying blocks, transactions, and network statistics for the privacy-focused Monero cryptocurrency.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Monero block and transaction lookup with basic privacy-coin exploration",
|
|
"input": "Monero block hash, block height, or transaction ID",
|
|
"output": "Block details, transaction count, network hashrate, difficulty, emission rate",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public Monero blockchain browsing; inherent privacy from Monero's ring signature design limits address-level tracing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "XMRChain.net",
|
|
"type": "url",
|
|
"url": "https://xmrchain.net/",
|
|
"description": "Minimal Monero blockchain explorer with no JavaScript, cookies, or tracking; available via Tor with focus on privacy and open-source design.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Monero transaction lookup with privacy-first design (Tor-accessible)",
|
|
"input": "Monero transaction ID, block height, or block hash",
|
|
"output": "Transaction details, block information, network statistics, Monero emission data",
|
|
"opsec": "passive",
|
|
"opsecNote": "No tracking or analytics; Tor-accessible for anonymous browsing. Inherent Monero privacy limits address tracing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Multi-Chain Explorers",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Bitquery Explorer",
|
|
"type": "url",
|
|
"url": "https://explorer.bitquery.io/",
|
|
"description": "Multi-chain blockchain explorer with GraphQL API supporting 40+ blockchains, real-time streaming, and advanced querying for token trades, transfers, and smart contract events.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Advanced cross-chain data querying and real-time blockchain event tracking",
|
|
"input": "Blockchain query via GraphQL (address, transaction, token, smart contract), or web interface search",
|
|
"output": "Transaction data, token transfer history, DEX trades, smart contract events, real-time streaming via WebSocket",
|
|
"opsec": "passive",
|
|
"opsecNote": "API-first platform; queries are processed by Bitquery servers. Free tier available with rate limits.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Blockchair",
|
|
"type": "url",
|
|
"url": "https://blockchair.com/",
|
|
"description": "Multi-chain blockchain explorer supporting 48+ blockchains (Bitcoin, Ethereum, Litecoin, Solana, etc.) with advanced search, SQL-like queries, and privacy-focused design (Tor accessible, no tracking).",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Cross-chain address and transaction search with privacy-friendly interface",
|
|
"input": "Blockchain address, transaction hash, or advanced SQL-like query across chains",
|
|
"output": "Transaction history, balance data, token transfers, smart contract events, cross-chain analytics",
|
|
"opsec": "passive",
|
|
"opsecNote": "Accessible via Tor; does not require registration; minimal tracking or logging. Privacy-oriented design.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "NFT Provenance",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Etherscan NFT Tracker",
|
|
"type": "url",
|
|
"url": "https://etherscan.io/nft",
|
|
"description": "NFT-specific section of Etherscan for tracking ERC-721 and ERC-1155 token transfers, marketplace activities, and collection-level statistics.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Ethereum NFT transaction tracking and collection analysis",
|
|
"input": "NFT contract address, collection name, or transaction hash",
|
|
"output": "NFT transaction history, collection floor prices, holder distribution, trading volume, minting data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Subset of Etherscan; same passive analysis of public Ethereum NFT data.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OpenSea",
|
|
"type": "url",
|
|
"url": "https://opensea.io/",
|
|
"description": "Multi-chain NFT marketplace supporting 22+ blockchains (Ethereum, Solana, Arbitrum, Optimism, etc.) with transaction history, collection analytics, and trading data.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Multi-chain NFT trading history and collection-level analysis",
|
|
"input": "NFT collection address, wallet address, or transaction search",
|
|
"output": "Trading history, collection floor prices, holder analysis, transaction data, offer history",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public marketplace; wallet connections identify users for OpenSea platform (not blockchain-level deanonymization).",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Privacy Coin Analysis",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "XMRChain.net (Monero)",
|
|
"type": "url",
|
|
"url": "https://xmrchain.net/",
|
|
"description": "Minimal Monero blockchain explorer with no JavaScript, cookies, or tracking; available via Tor with focus on privacy and open-source design.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Monero transaction lookup with privacy-first design (Tor-accessible)",
|
|
"input": "Monero transaction ID, block height, or block hash",
|
|
"output": "Transaction details, block information, network statistics, Monero emission data",
|
|
"opsec": "passive",
|
|
"opsecNote": "No tracking or analytics; Tor-accessible for anonymous browsing. Inherent Monero privacy limits address tracing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Zcash Block Explorer",
|
|
"type": "url",
|
|
"url": "https://blockchair.com/zcash",
|
|
"description": "Zcash blockchain explorer (hosted on Blockchair) supporting transparent and shielded transaction analysis for privacy-coin OSINT with transaction filtering and address lookup.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Zcash transparent transaction tracking (limited privacy-coin OSINT)",
|
|
"input": "Zcash address (transparent), transaction hash, or block height",
|
|
"output": "Transaction details, address balance (transparent addresses only), block information, mining statistics",
|
|
"opsec": "passive",
|
|
"opsecNote": "Only transparent Zcash transactions are traceable; shielded transactions provide privacy beyond analysis capability.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Wallet Clustering & Address Analysis",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Blockchair",
|
|
"type": "url",
|
|
"url": "https://blockchair.com/",
|
|
"description": "Multi-chain blockchain explorer supporting 48+ blockchains (Bitcoin, Ethereum, Litecoin, Solana, etc.) with advanced search, SQL-like queries, and privacy-focused design (Tor accessible, no tracking).",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Cross-chain address and transaction search with privacy-friendly interface",
|
|
"input": "Blockchain address, transaction hash, or advanced SQL-like query across chains",
|
|
"output": "Transaction history, balance data, token transfers, smart contract events, cross-chain analytics",
|
|
"opsec": "passive",
|
|
"opsecNote": "Accessible via Tor; does not require registration; minimal tracking or logging. Privacy-oriented design.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Wallet Explorer",
|
|
"type": "url",
|
|
"url": "https://www.walletexplorer.com/",
|
|
"description": "Bitcoin address clustering and wallet linking tool using multi-input heuristics to identify related addresses and track entity-level transaction patterns.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Bitcoin address clustering and entity wallet identification",
|
|
"input": "Bitcoin address, transaction hash, or entity name search",
|
|
"output": "Clustered wallet addresses, transaction patterns, entity profiles, balance summaries",
|
|
"opsec": "passive",
|
|
"opsecNote": "Analyzes public blockchain data; no registration required for basic lookups.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Classifieds",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Craigslist",
|
|
"type": "url",
|
|
"url": "https://charlotte.craigslist.org/"
|
|
},
|
|
{
|
|
"name": "Kijiji - Canada Classifieds",
|
|
"type": "url",
|
|
"url": "https://www.kijiji.ca:443/"
|
|
},
|
|
{
|
|
"name": "Quikr - India Classifieds",
|
|
"type": "url",
|
|
"url": "https://www.quikr.com/"
|
|
},
|
|
{
|
|
"name": "eBay",
|
|
"type": "url",
|
|
"url": "https://www.ebay.com/"
|
|
},
|
|
{
|
|
"name": "OfferUp",
|
|
"type": "url",
|
|
"url": "https://offerup.com/"
|
|
},
|
|
{
|
|
"name": "Goofbid",
|
|
"type": "url",
|
|
"url": "https://www.goofbid.com/"
|
|
},
|
|
{
|
|
"name": "SearchAllJunk",
|
|
"type": "url",
|
|
"url": "https://www.searchalljunk.com/"
|
|
},
|
|
{
|
|
"name": "TotalCraigSearch",
|
|
"type": "url",
|
|
"url": "https://www.totalcraigsearch.com/"
|
|
},
|
|
{
|
|
"name": "Search Tempest",
|
|
"type": "url",
|
|
"url": "https://www.searchtempest.com/"
|
|
},
|
|
{
|
|
"name": "francais-a-londres.org - French Classifieds",
|
|
"type": "url",
|
|
"url": "https://francaisalondres.com/"
|
|
},
|
|
{
|
|
"name": "Kleinanzeigen.de",
|
|
"type": "url",
|
|
"url": "https://www.kleinanzeigen.de/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Encoding / Decoding",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Barcodes / QR",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "ClearImage Barcode Reader",
|
|
"type": "url",
|
|
"url": "https://online-barcode-reader.inliteresearch.com/",
|
|
"description": "Web-based barcode and QR code recognition tool using Inlite Research ClearImage technology for common image and document formats.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Barcode and QR code decoding from uploaded files",
|
|
"input": "Image files and PDFs containing barcode or QR symbols",
|
|
"output": "Decoded barcode and QR payload values",
|
|
"opsec": "active",
|
|
"opsecNote": "Uploaded files are processed by a third-party web service and may be logged.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Javascript",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "JS Beautifier",
|
|
"type": "url",
|
|
"url": "https://beautifier.io/",
|
|
"description": "Open-source JavaScript formatter that rewrites minified or obfuscated code into readable, consistently indented source.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Fast readability improvements for packed JavaScript",
|
|
"input": "Minified or obfuscated JavaScript source text",
|
|
"output": "Formatted JavaScript with normalized structure and spacing",
|
|
"opsec": "passive",
|
|
"opsecNote": "Typical use is low-risk code formatting through a public web interface.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "JS NICE",
|
|
"type": "url",
|
|
"url": "https://jsnice.org/",
|
|
"description": "Legacy JavaScript reverse-engineering service that previously improved variable names and recovered structure from minified code.",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Historical reference for JavaScript decompilation workflows",
|
|
"input": "Obfuscated or minified JavaScript code",
|
|
"output": "No current output because the public service is unavailable",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "Service is currently unreachable and should be treated as defunct until replaced.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Firebug (T)",
|
|
"type": "url",
|
|
"url": "https://getfirebug.com/downloads/",
|
|
"description": "Former Firefox debugging extension that has been retired, with core functionality absorbed into modern Firefox Developer Tools.",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Historical context for legacy JavaScript debugging references",
|
|
"input": "Legacy Firefox extension workflows and old debugging material",
|
|
"output": "Archived documentation and obsolete download artifacts",
|
|
"opsec": "Unknown",
|
|
"opsecNote": "Tool is unmaintained and not suitable for active investigative workflows.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "SpiderMonkey (T)",
|
|
"type": "url",
|
|
"url": "https://developer.mozilla.org/en-US/docs/Mozilla/Projects/SpiderMonkey",
|
|
"description": "Mozilla JavaScript engine used by Firefox and available for standalone execution and analysis in local environments.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Local JavaScript execution and behavior testing without browser UI",
|
|
"input": "JavaScript source code",
|
|
"output": "Execution results, runtime behavior, and script output",
|
|
"opsec": "passive",
|
|
"opsecNote": "Runs locally and avoids sending samples to third-party analysis services.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Kahu Revelo (T)",
|
|
"type": "url",
|
|
"url": "https://www.kahusecurity.com/tools/",
|
|
"description": "Windows-focused JavaScript deobfuscation utility that executes scripts in a controlled environment to reveal hidden logic.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Unpacking heavily obfuscated JavaScript samples on Windows",
|
|
"input": "Obfuscated JavaScript files or script text",
|
|
"output": "Deobfuscated code and decoded runtime content",
|
|
"opsec": "active",
|
|
"opsecNote": "Tool executes suspect code paths, so sandbox or VM isolation is recommended.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "JavaScript Deobfuscator (T)",
|
|
"type": "url",
|
|
"url": "https://addons.mozilla.org/en-US/firefox/addon/javascript-deobfuscator/",
|
|
"description": "Firefox add-on for inspecting and deobfuscating JavaScript in-browser during page analysis and script review.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Browser-native JavaScript deobfuscation during web investigations",
|
|
"input": "JavaScript loaded in Firefox pages or pasted script content",
|
|
"output": "Readable deobfuscated script output in browser tooling",
|
|
"opsec": "active",
|
|
"opsecNote": "Browser execution context can run page scripts and trackers while analyzing content.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "PHP",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "DDecode - PHP Decoder",
|
|
"type": "url",
|
|
"url": "https://ddecode.com/phpdecoder/",
|
|
"description": "Online decoder for layered PHP obfuscation chains such as eval, base64, gzinflate, and related encoding wrappers.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Rapid decoding of obfuscated PHP webshell and malware snippets",
|
|
"input": "Encoded or obfuscated PHP code",
|
|
"output": "Decoded and expanded PHP source text",
|
|
"opsec": "active",
|
|
"opsecNote": "Submitted samples are processed by a third-party server, so sensitive code should be sanitized first.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "XOR",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Unix",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "XORSearch & XORStrings (T)",
|
|
"type": "url",
|
|
"url": "https://blog.didierstevens.com/programs/xorsearch/",
|
|
"description": "Didier Stevens command-line utilities for locating XOR, ROL, ROT, and SHIFT-encoded strings in suspicious binaries.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "String extraction and key hunting in encoded malware payloads",
|
|
"input": "Binary files and encoded byte streams",
|
|
"output": "Decoded candidate strings across transformation and key ranges",
|
|
"opsec": "passive",
|
|
"opsecNote": "Runs locally on analyst systems and does not require online submission.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "xortool (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/hellman/xortool",
|
|
"description": "Python-based XOR analysis tool that estimates key lengths and recovers likely multi-byte keys via frequency analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Recovering repeating XOR keys from encoded files",
|
|
"input": "XOR-encrypted text or binary data",
|
|
"output": "Likely XOR keys and candidate decrypted output",
|
|
"opsec": "passive",
|
|
"opsecNote": "Pure local processing with no required external service calls.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "unxor (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/tomchop/unxor",
|
|
"description": "Known-plaintext XOR analysis utility for deriving keystreams and recovering original content from encoded samples.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Known-plaintext XOR cracking against malware and encoded artifacts",
|
|
"input": "XOR-encoded file plus known plaintext fragments",
|
|
"output": "Recovered keystream segments and decoded content",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local command-line analysis avoids submitting artifacts to remote services.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Windows",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Kahu Converter Utilities (T)",
|
|
"type": "url",
|
|
"url": "https://www.kahusecurity.com/tools/",
|
|
"description": "Windows utility collection for format conversion, hex/binary transforms, and XOR-related decoding workflows.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Mixed conversion and XOR utility operations on Windows",
|
|
"input": "Binary blobs, hex strings, and text samples",
|
|
"output": "Converted data and decoded intermediate representations",
|
|
"opsec": "passive",
|
|
"opsecNote": "Runs locally on analyst systems without mandatory cloud processing.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Python",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "iheartxor.py (T)",
|
|
"type": "url",
|
|
"url": "https://hooked-on-mnemonics.blogspot.com/p/iheartxor.html",
|
|
"description": "Python script for brute-forcing XOR-obfuscated strings within defined boundaries to reveal hidden text in malware samples.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Targeted extraction of XOR-obfuscated strings from binaries",
|
|
"input": "Binary data, dumps, or encoded string segments",
|
|
"output": "Recovered candidate strings and associated key bytes",
|
|
"opsec": "passive",
|
|
"opsecNote": "Offline local script execution keeps sample handling under analyst control.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "XORBruteForcer.py (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/jesparza/scripts/blob/master/xorBruteForcer.py",
|
|
"description": "Single-byte XOR brute-force Python script that iterates candidate key values and surfaces matching decoded output.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Single-byte XOR key brute-forcing and quick validation",
|
|
"input": "Encoded file or byte sequence",
|
|
"output": "Decoded candidates mapped to tested XOR key values",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local script analysis avoids artifact upload and minimizes external exposure.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "NoMoreXOR.py (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/hiddenillusion/NoMoreXOR",
|
|
"description": "Python utility for recovering long XOR keys using character frequency heuristics and YARA-assisted pattern matching.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Recovering long XOR keys in malware binaries",
|
|
"input": "Malware sample or obfuscated binary content",
|
|
"output": "Likely keys, decoded streams, and extraction hints",
|
|
"opsec": "passive",
|
|
"opsecNote": "Operates locally and is suitable for isolated malware analysis environments.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Balbuzard (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/decalage2/balbuzard",
|
|
"description": "Python malware analysis toolkit that extracts indicators and brute-forces common obfuscation patterns including XOR and rotation transforms.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Automated deobfuscation and indicator extraction from suspicious files",
|
|
"input": "Suspicious binaries and encoded artifact files",
|
|
"output": "Decoded content, extracted IoCs, and pattern-analysis results",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local toolkit execution supports controlled analysis without remote sample submission.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "CyberChef",
|
|
"type": "url",
|
|
"url": "https://gchq.github.io/CyberChef/",
|
|
"description": "GCHQ-maintained browser workbench for chained encoding, decoding, hashing, crypto, and data transformation operations.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Building and replaying multi-step decode and transform recipes",
|
|
"input": "Text, binary, hex, Base64, and structured payloads",
|
|
"output": "Transformed output for each selected operation chain",
|
|
"opsec": "passive",
|
|
"opsecNote": "Public web app use is convenient, but locally hosted builds are preferred for sensitive data.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Functions Online",
|
|
"type": "url",
|
|
"url": "https://www.functions-online.com/",
|
|
"description": "PHP-oriented online utility suite for common encoding, decoding, hashing, and string-manipulation function tests.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick PHP-specific encoding and decoding checks in browser",
|
|
"input": "Function parameters and data strings for selected PHP routines",
|
|
"output": "Computed function results and transformed data values",
|
|
"opsec": "active",
|
|
"opsecNote": "Data is processed server-side, so avoid submitting sensitive payloads directly.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Tools",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "OSINT Automation",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Vector (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/thesaderror/vector"
|
|
},
|
|
{
|
|
"name": "DataSploit (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/datasploit/datasploit/"
|
|
},
|
|
{
|
|
"name": "Omnibus (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/InQuest/omnibus"
|
|
},
|
|
{
|
|
"name": "Photon (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/s0md3v/Photon"
|
|
},
|
|
{
|
|
"name": "ReconDog (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/s0md3v/ReconDog"
|
|
},
|
|
{
|
|
"name": "IFTTT",
|
|
"type": "url",
|
|
"url": "https://ifttt.com/"
|
|
},
|
|
{
|
|
"name": "Slash",
|
|
"type": "url",
|
|
"url": "https://github.com/redc86/slash"
|
|
},
|
|
{
|
|
"name": "Stringify",
|
|
"type": "url",
|
|
"url": "https://www.stringify.com/"
|
|
},
|
|
{
|
|
"name": "OSRFramework (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/i3visio/osrframework"
|
|
},
|
|
{
|
|
"name": "Inquisitor (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/penafieljlm/inquisitor"
|
|
},
|
|
{
|
|
"name": "AutoOSINT (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/bharshbarger/AutOSINT"
|
|
},
|
|
{
|
|
"name": "IntRec-Pack (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/NullArray/IntRec-Pack"
|
|
},
|
|
{
|
|
"name": "OSINT-SPY (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/SharadKumar97/OSINT-SPY"
|
|
},
|
|
{
|
|
"name": "Microsoft Flow",
|
|
"type": "url",
|
|
"url": "https://flow.microsoft.com/en-us/"
|
|
},
|
|
{
|
|
"name": "PhoneInfoga (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/sundowndev/PhoneInfoga"
|
|
},
|
|
{
|
|
"name": "IntelligenceX",
|
|
"type": "url",
|
|
"url": "https://intelx.io/"
|
|
},
|
|
{
|
|
"name": "Scrummage (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/matamorphosis/Scrummage"
|
|
},
|
|
{
|
|
"name": "Analyst Research Tools",
|
|
"type": "url",
|
|
"url": "https://analystresearchtools.com"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Graph Visualization",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "MIDINS TITAN",
|
|
"type": "url",
|
|
"url": "https://midins.net/titan"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Pentesting Recon",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Low Hanging Fruit (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/blindfuzzy/LHF"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Virtual Machines",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "VMware Workstation Player (T)",
|
|
"type": "url",
|
|
"url": "https://www.vmware.com/products/player/playerpro-evaluation.html"
|
|
},
|
|
{
|
|
"name": "VirtualBox (T)",
|
|
"type": "url",
|
|
"url": "https://www.virtualbox.org/"
|
|
},
|
|
{
|
|
"name": "Buscador OS (T)",
|
|
"type": "url",
|
|
"url": "https://inteltechniques.com/buscador/index.html"
|
|
},
|
|
{
|
|
"name": "Kali Linux OS (T)",
|
|
"type": "url",
|
|
"url": "https://www.kali.org/"
|
|
},
|
|
{
|
|
"name": "ParrotSec OS (T)",
|
|
"type": "url",
|
|
"url": "https://www.parrotsec.org/"
|
|
},
|
|
{
|
|
"name": "Microsoft Edge Development OS VMs (T)",
|
|
"type": "url",
|
|
"url": "https://developer.microsoft.com/en-us/microsoft-edge/tools/vms/"
|
|
},
|
|
{
|
|
"name": "Subgraph OS (T)",
|
|
"type": "url",
|
|
"url": "https://subgraph.com/index.en.html"
|
|
},
|
|
{
|
|
"name": "Tails Live OS (T)",
|
|
"type": "url",
|
|
"url": "https://tails.boum.org/"
|
|
},
|
|
{
|
|
"name": "Whonix (T)",
|
|
"type": "url",
|
|
"url": "https://www.whonix.org/wiki/Main_Page"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Wordlist",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "CeWL (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/digininja/CeWL"
|
|
},
|
|
{
|
|
"name": "Cupp (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/Mebus/cupp"
|
|
},
|
|
{
|
|
"name": "OWASP D4N155 (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/OWASP/D4N155"
|
|
},
|
|
{
|
|
"name": "W Generator",
|
|
"type": "url",
|
|
"url": "https://app.wgen.io/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Paterva / Maltego (T)",
|
|
"type": "url",
|
|
"url": "https://www.maltego.com/",
|
|
"description": "Visual link analysis tool for mapping relationships between people, companies, domains, and infrastructure.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Link analysis, relationship mapping, entity correlation",
|
|
"input": "Domain, email, IP, name, phone number",
|
|
"output": "Entity relationship graph, linked records, transform results",
|
|
"opsec": "active",
|
|
"opsecNote": "Transforms may query targets directly. Some data sources log lookups.",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Overview",
|
|
"type": "url",
|
|
"url": "https://www.overviewdocs.com/"
|
|
},
|
|
{
|
|
"name": "Online Nikto scanner",
|
|
"type": "url",
|
|
"url": "https://nikto.online/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "AI Tools",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "AI or Not",
|
|
"type": "url",
|
|
"url": "https://www.aiornot.com/"
|
|
},
|
|
{
|
|
"name": "Copyleaks",
|
|
"type": "url",
|
|
"url": "https://copyleaks.com/"
|
|
},
|
|
{
|
|
"name": "Decopy AI Image Detector",
|
|
"type": "url",
|
|
"url": "https://decopy.ai/ai-image-detector/"
|
|
},
|
|
{
|
|
"name": "DeepAI AI Image Detector",
|
|
"type": "url",
|
|
"url": "https://deepai.org/ai-image-detector"
|
|
},
|
|
{
|
|
"name": "DeepSeek",
|
|
"type": "url",
|
|
"url": "https://www.deepseek.com/"
|
|
},
|
|
{
|
|
"name": "DocMind AI",
|
|
"type": "url",
|
|
"url": "https://github.com/BjornMelin/docmind-ai-llm"
|
|
},
|
|
{
|
|
"name": "DuckDuckGo AI Chat",
|
|
"type": "url",
|
|
"url": "https://duckduckgo.com/aichat"
|
|
},
|
|
{
|
|
"name": "GPTZero",
|
|
"type": "url",
|
|
"url": "https://gptzero.me/"
|
|
},
|
|
{
|
|
"name": "Grammarly AI Detector",
|
|
"type": "url",
|
|
"url": "https://www.grammarly.com/ai-detector"
|
|
},
|
|
{
|
|
"name": "Hive AI Generated Content Detection",
|
|
"type": "url",
|
|
"url": "https://hivemoderation.com/ai-generated-content-detection"
|
|
},
|
|
{
|
|
"name": "Hugging Face AI Detector",
|
|
"type": "url",
|
|
"url": "https://huggingface.co/spaces/umm-maybe/AI_Detector"
|
|
},
|
|
{
|
|
"name": "Illuminarty",
|
|
"type": "url",
|
|
"url": "https://app.illuminarty.ai/"
|
|
},
|
|
{
|
|
"name": "Microsoft Copilot",
|
|
"type": "url",
|
|
"url": "https://copilot.microsoft.com/"
|
|
},
|
|
{
|
|
"name": "Ollama",
|
|
"type": "url",
|
|
"url": "https://ollama.com/"
|
|
},
|
|
{
|
|
"name": "OSINT Analyser",
|
|
"type": "url",
|
|
"url": "https://github.com/joestanding/osint-analyser"
|
|
},
|
|
{
|
|
"name": "TrueMedia",
|
|
"type": "url",
|
|
"url": "https://www.truemedia.org/"
|
|
},
|
|
{
|
|
"name": "WasItAI",
|
|
"type": "url",
|
|
"url": "https://wasitai.com/"
|
|
},
|
|
{
|
|
"name": "World Monitor",
|
|
"type": "url",
|
|
"url": "https://www.worldmonitor.app/"
|
|
},
|
|
{
|
|
"name": "You.com",
|
|
"type": "url",
|
|
"url": "https://you.com/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Malicious File Analysis",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Search",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Decalage Malware Search",
|
|
"type": "url",
|
|
"url": "https://decalage.info/en/mwsearch",
|
|
"description": "Custom metasearch engine that indexes malware analysis databases to find malware samples containing specific strings, filenames, hashes, or IOCs.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick metasearch across multiple malware analysis databases by hash, string, or filename",
|
|
"input": "IOC (hash, filename, string, yara rule, VT hash)",
|
|
"output": "Links to malware analysis reports from aggregated databases",
|
|
"opsec": "passive",
|
|
"opsecNote": "Search-only interface; no account required; queries are directed to indexed databases",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "VirusShare.com",
|
|
"type": "url",
|
|
"url": "https://virusshare.com/",
|
|
"description": "Repository of 111+ million live malware samples provided for security researchers, incident responders, forensic analysts, and researchers.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Bulk access to malware sample collections for research and analysis",
|
|
"input": "MD5 hash, account credentials",
|
|
"output": "Malware sample files (zip archives, password protected), related IOCs",
|
|
"opsec": "passive",
|
|
"opsecNote": "Registration required; no direct execution occurs; passive hash lookup available",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "#totalhash",
|
|
"type": "url",
|
|
"url": "https://totalhash.cymru.com/",
|
|
"description": "Malware Hash Registry that searches against 30+ antivirus databases to validate malware hashes with detection percentage results. Updated daily.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Hash validation against 30+ AV engines with detection percentages",
|
|
"input": "MD5 or SHA-1 hash",
|
|
"output": "Detection percentage, last seen timestamp, signature matches from AV databases",
|
|
"opsec": "passive",
|
|
"opsecNote": "No registration required; read-only hash lookups leave minimal traces",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "VX Vault",
|
|
"type": "url",
|
|
"url": "https://vxvault.net/ViriList.php",
|
|
"description": "Active collection of malware samples and related data shared among security researchers and malware analysts for threat intelligence.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Access to active malware sample collections",
|
|
"input": "Web interface browsing, malware sample queries",
|
|
"output": "Malware sample information, related indicators",
|
|
"opsec": "passive",
|
|
"opsecNote": "Web-based browsing interface; no registration typically required",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ID Ransomware",
|
|
"type": "url",
|
|
"url": "https://id-ransomware.malwarehunterteam.com/",
|
|
"description": "Free ransomware identification tool that analyzes ransom notes and encrypted file samples to identify variants and provide decryption guidance. Detects 1181+ ransomware types.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Ransomware identification and victim support",
|
|
"input": "Ransom note file, encrypted file sample, ransom email address",
|
|
"output": "Ransomware variant identification, decryption status, victim resources",
|
|
"opsec": "passive",
|
|
"opsecNote": "File uploads provide victim privacy options to protect personal data exposure",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "National Software Reference Library",
|
|
"type": "url",
|
|
"url": "https://nsrl.hashsets.com/national_software_reference_library1_search.php",
|
|
"description": "NIST-maintained repository of cryptographic hash values for known, legitimate software to identify known-good files during digital forensics investigations.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Eliminating known-good files in forensic investigations and digital triage",
|
|
"input": "File hash (MD5, SHA-1, SHA-256), software query",
|
|
"output": "Hash matches to known software, file metadata, product versioning",
|
|
"opsec": "passive",
|
|
"opsecNote": "No registration required; lookup-only service; government maintained",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Hosted Automated Analysis",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Office Files",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "TYLabs QuickSand Framework",
|
|
"type": "url",
|
|
"url": "https://scan.tylabs.com/",
|
|
"description": "Python-based malware analysis framework for analyzing Office documents and PDFs to identify exploits in decoded streams using YARA signatures.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Document and PDF malware analysis with exploit detection",
|
|
"input": "Office documents (.doc, .xls, .ppt), PDFs, emails, Postscript",
|
|
"output": "YARA signature matches, exploit detection, risk scoring, threat analysis",
|
|
"opsec": "active",
|
|
"opsecNote": "Hosted analysis requires file upload; local installation available for offline use",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "JoeSandbox Document Analyzer",
|
|
"type": "url",
|
|
"url": "https://www.joesandbox.com/",
|
|
"description": "Hosted automated malware analysis service that performs dynamic and static analysis of files including Office documents, PDFs, and executables with comprehensive behavioral reporting.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Comprehensive malware analysis with behavioral insights and threat scoring",
|
|
"input": "Executable files, documents, PDFs, URLs, APKs (Max 30MB free tier)",
|
|
"output": "Behavioral analysis, network IOCs, detection verdicts, MITRE ATT&CK mappings, export formats (JSON, XML, HTML, PDF)",
|
|
"opsec": "active",
|
|
"opsecNote": "File uploads are processed on external sandbox; free tier limited to 30 submissions/month",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "PDFs",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "TYLabs QuickSand Framework",
|
|
"type": "url",
|
|
"url": "https://scan.tylabs.com/",
|
|
"description": "Python-based malware analysis framework for analyzing Office documents and PDFs to identify exploits in decoded streams using YARA signatures.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Document and PDF malware analysis with exploit detection",
|
|
"input": "Office documents (.doc, .xls, .ppt), PDFs, emails, Postscript",
|
|
"output": "YARA signature matches, exploit detection, risk scoring, threat analysis",
|
|
"opsec": "active",
|
|
"opsecNote": "Hosted analysis requires file upload; local installation available for offline use",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Android",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Akana Android Malware",
|
|
"type": "url",
|
|
"url": "https://akana.mobiseclab.org/",
|
|
"description": "Online Android Interactive Analysis Environment with plugins for analyzing malicious Android applications and APKs for suspicious behavior and malware characteristics.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Android app malware analysis and interactive examination",
|
|
"input": "Android APK files",
|
|
"output": "Malware detection results, behavioral analysis, plugin-based threat assessment",
|
|
"opsec": "active",
|
|
"opsecNote": "File uploads required; external analysis service",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Joe APK Analyzer",
|
|
"type": "url",
|
|
"url": "https://www.apk-analyzer.net/",
|
|
"description": "Part of Joe Sandbox suite; performs dynamic and static analysis of Android Application Packages to detect malicious behavior and generate detailed analysis reports.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Android malware analysis with dynamic behavior monitoring",
|
|
"input": "Android APK files",
|
|
"output": "Malware detection, behavioral analysis, threat intelligence IOCs",
|
|
"opsec": "active",
|
|
"opsecNote": "File uploads to external sandbox; free tier has limitations",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "VirusTotal",
|
|
"type": "url",
|
|
"url": "https://www.virustotal.com/gui/",
|
|
"description": "Multi-engine file and URL scanner that aggregates results from 70+ antivirus engines and threat feeds.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Malware analysis, URL reputation, file hash lookups",
|
|
"input": "File, file hash, URL, domain, IP address",
|
|
"output": "Detection results, behavioral analysis, community comments, related indicators",
|
|
"opsec": "passive",
|
|
"opsecNote": "Uploaded files become visible to other VirusTotal users. Hash lookups are private.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OPSWAT Meta Defender",
|
|
"type": "url",
|
|
"url": "https://metadefender.opswat.com/#!/",
|
|
"description": "Multi-engine malware scanning service using 20+ antivirus engines with advanced threat analysis, content disarm & reconstruction, and emulation-based detection for zero-day threats.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Multi-engine malware detection with advanced threat analysis",
|
|
"input": "Files (all types), URLs",
|
|
"output": "Multi-engine scan results, threat verdicts, IOC extraction, file behavior analysis",
|
|
"opsec": "active",
|
|
"opsecNote": "File uploads required; free community version available with API limits",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Hybrid Analysis",
|
|
"type": "url",
|
|
"url": "https://hybrid-analysis.com/",
|
|
"description": "Free automated malware analysis service powered by CrowdStrike Falcon Sandbox. Combines runtime data with memory dump analysis to extract execution pathways and IOCs for evasive malware.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Advanced malware behavior analysis and evasion detection",
|
|
"input": "Files (30MB max free tier), URLs, APKs (up to 30 per month free)",
|
|
"output": "Hybrid behavioral analysis, memory dumps, disassembly, IOC extraction, behavioral indicators",
|
|
"opsec": "active",
|
|
"opsecNote": "Free tier limited to 30 uploads/month; file uploads to external sandbox infrastructure",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Malware Config",
|
|
"type": "url",
|
|
"url": "https://malwareconfig.com/",
|
|
"description": "Database for searching and analyzing extracted malware configurations by hash, domain, or IP address to track C2 infrastructure and malware attributes.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Malware configuration extraction and C2 server tracking",
|
|
"input": "SHA256 hash, domain, IP address, malware family",
|
|
"output": "Extracted malware configurations, C2 infrastructure, encrypted keys, command data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Search-only interface; no file uploads required; passive lookups",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MetaDefender",
|
|
"type": "url",
|
|
"url": "https://metadefender.opswat.com/",
|
|
"description": "OPSWAT's cloud-based multi-engine malware scanning platform with advanced threat detection using 30+ antivirus engines, CDR technology, and behavioral analysis.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Enterprise-grade multi-engine malware detection and advanced threat analysis",
|
|
"input": "Files, URLs, streams",
|
|
"output": "Multi-engine detection results, threat verdicts, behavioral analysis, IOC extraction",
|
|
"opsec": "active",
|
|
"opsecNote": "File uploads required; commercial and free tiers available",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Ether",
|
|
"type": "url",
|
|
"url": "https://ether.gtisc.gatech.edu/web_unpack/",
|
|
"description": "Georgia Tech malware analysis framework using Intel VT hardware virtualization for transparent, stealthy malware analysis resistant to anti-analysis techniques.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Transparent malware analysis resistant to anti-analysis evasion",
|
|
"input": "Executable files, malware samples",
|
|
"output": "Fine-grained execution traces, instruction-level analysis, unpacking results, behavior extraction",
|
|
"opsec": "active",
|
|
"opsecNote": "Hosted analysis service; academic research project from Georgia Institute of Technology",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Jotti's Malware Scanner",
|
|
"type": "url",
|
|
"url": "https://virusscan.jotti.org/en-US/scan-file",
|
|
"description": "Free multi-scanner malware analysis service that submits files for analysis against 14+ antivirus engines. No installation or account setup required.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Quick multi-engine scan without installation or account setup",
|
|
"input": "Files (up to 5 concurrent, 250MB per file)",
|
|
"output": "Detection results from 14+ AV engines, file metadata, scan reports",
|
|
"opsec": "active",
|
|
"opsecNote": "No account required; file uploads to external scanning service",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Valkyrie File Analysis",
|
|
"type": "url",
|
|
"url": "https://consumer.valkyrie.comodo.com/",
|
|
"description": "Cloud-based verdict-driven malware analysis platform from Comodo using static analysis (450+ unpackers), dynamic analysis, and optional human expert analysis for unknown files.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Advanced malware analysis with human expert review option",
|
|
"input": "Files (all types), URLs",
|
|
"output": "File verdict, behavioral analysis results, IOC extraction, confidence scores, expert analysis",
|
|
"opsec": "active",
|
|
"opsecNote": "File uploads required; expert analysis available for premium users",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "detux Linux Sandbox",
|
|
"type": "url",
|
|
"url": "https://detux.org/",
|
|
"description": "Open-source multiplatform Linux sandbox for analyzing Linux malware across multiple CPU architectures (x86, x86-64, ARM, MIPS) using QEMU emulation and traffic analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Linux malware analysis across multiple architectures",
|
|
"input": "Linux executable files, malware samples",
|
|
"output": "Static analysis strings, dynamic traffic capture, IOC extraction, architecture-specific analysis",
|
|
"opsec": "active",
|
|
"opsecNote": "Open-source tool; can be deployed locally or used as hosted service",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Joe File Analyzer",
|
|
"type": "url",
|
|
"url": "https://www.file-analyzer.net/",
|
|
"description": "Part of Joe Sandbox suite; performs hybrid code analysis of PE files on Windows with detailed behavioral and system interaction reporting.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "PE file malware analysis with system interaction tracking",
|
|
"input": "PE executable files (.exe, .dll, etc.)",
|
|
"output": "Hybrid behavioral analysis, system calls, network IOCs, threat scores",
|
|
"opsec": "active",
|
|
"opsecNote": "File uploads to Joe Sandbox infrastructure; free tier has submission limits",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Pikker.ee Cuckoo Sandbox",
|
|
"type": "url",
|
|
"url": "https://sandbox.pikker.ee/",
|
|
"description": "Public instance of Cuckoo Sandbox malware analysis system hosted in Estonia. Provides automated dynamic analysis with detailed result reporting for submitted files.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Free automated dynamic malware analysis with detailed behavioral reports",
|
|
"input": "Executable files, documents, archives",
|
|
"output": "Process monitoring, API calls, file system changes, network traffic, behavioral analysis",
|
|
"opsec": "active",
|
|
"opsecNote": "Public instance; files uploaded to external infrastructure; Estonian-hosted",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Koodous",
|
|
"type": "url",
|
|
"url": "https://koodous.com",
|
|
"description": "Collaborative platform for Android malware research and analysis with community-driven database of 70+ million Android applications with crowd-sourced malware detection.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Android malware analysis with community collaboration and threat intelligence",
|
|
"input": "Android APK files, package names, hashes",
|
|
"output": "Malware detection results, community analysis, threat indicators, sample sharing",
|
|
"opsec": "active",
|
|
"opsecNote": "Registration available; community platform with shared threat intelligence",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Any Run",
|
|
"type": "url",
|
|
"url": "https://app.any.run/",
|
|
"description": "Interactive malware analysis sandbox allowing real-time manual interaction with Windows, macOS, Linux, and Android environments. Fast report generation with MITRE ATT&CK mapping.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Interactive malware analysis with real-time system interaction",
|
|
"input": "Files, URLs, APKs, documents (platform-specific)",
|
|
"output": "Process graphs, behavioral analysis, MITRE ATT&CK TTPs, IOCs, customizable reports",
|
|
"opsec": "active",
|
|
"opsecNote": "Interactive analysis leaves traces; free tier limited to 3 public analyses/day; private mode in paid plans",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Uncover It",
|
|
"type": "url",
|
|
"url": "https://www.uncoverit.org/",
|
|
"description": "Static malware configuration extractor that quickly analyzes files without execution to extract malware configurations, C2 infrastructure, and IOCs in under 5 seconds.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Fast static malware configuration extraction",
|
|
"input": "Malware samples, executable files",
|
|
"output": "Extracted configurations, C2 servers, encryption keys, behavioral indicators",
|
|
"opsec": "passive",
|
|
"opsecNote": "Static analysis only; no code execution; quick analysis without external dependencies",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Office Files",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Office Mal Scanner (T)",
|
|
"type": "url",
|
|
"url": "https://www.reconstructer.org/",
|
|
"description": "Malicious Office document analysis tool for analyzing and reconstructing Office documents to identify exploits and malicious content.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Malicious Office document analysis and reconstruction",
|
|
"input": "Microsoft Office documents (.doc, .xls, .ppt)",
|
|
"output": "Document structure analysis, malicious content extraction, exploit identification",
|
|
"opsec": "active",
|
|
"opsecNote": "Document upload required; analysis service online",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OffVis (T)",
|
|
"type": "url",
|
|
"url": "https://download.microsoft.com/download/1/2/7/127ba59a-4fe1-4acd-ba47-513ceef85a85/OffVis.zip",
|
|
"description": "Microsoft Office Visualization Tool for analyzing Office binary files to identify exploits and malicious structures. Displays hex and object tree views.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Office binary file format analysis and exploit detection",
|
|
"input": "Office binary files (.doc, .xls, .ppt, .pps, .pot)",
|
|
"output": "File structure visualization, hex dump, object trees, vulnerability detection",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local desktop application; no file uploads; Microsoft-provided tool",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "PDFs",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "PDF Tools (T)",
|
|
"type": "url",
|
|
"url": "https://blog.didierstevens.com/programs/pdf-tools/",
|
|
"description": "Free suite of PDF analysis tools by Didier Stevens including pdfid (keyword scanning) and pdf-parser.py for analyzing malicious PDF documents and extracting embedded objects.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "PDF structure analysis and malicious object extraction",
|
|
"input": "PDF files",
|
|
"output": "PDF keyword identification, object parsing, embedded JavaScript detection, IOC extraction",
|
|
"opsec": "passive",
|
|
"opsecNote": "Command-line tools; local execution; open-source from reputable security researcher",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Origami Framework (T)",
|
|
"type": "url",
|
|
"url": "https://code.google.com/archive/p/origami-pdf/",
|
|
"description": "Ruby framework for parsing, analyzing, and forging PDF documents. Includes PDF Walker GUI and PDFcop heuristic checker for detecting dangerous PDF content.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "PDF parsing and manipulation for malicious PDF analysis",
|
|
"input": "PDF files, PDF objects, malicious content",
|
|
"output": "Parsed PDF structure, extracted objects, deobfuscated content, modified PDFs",
|
|
"opsec": "passive",
|
|
"opsecNote": "Open-source framework; local installation required; no file uploads",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "PCAPs",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Malware-Traffic-Analysis.net",
|
|
"type": "url",
|
|
"url": "https://www.malware-traffic-analysis.net/index.html",
|
|
"description": "Training resource and PCAP repository providing network traffic captures from malware infections since 2013. Includes tutorials and exercises for malware traffic analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Malware network behavior analysis and training exercises",
|
|
"input": "PCAP files, network traffic captures",
|
|
"output": "Network indicators (IPs, domains, C2 servers), behavioral analysis, post-exploitation patterns",
|
|
"opsec": "passive",
|
|
"opsecNote": "PCAP analysis is passive; no live malware execution; educational resource",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Ghidra (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/NationalSecurityAgency/ghidra",
|
|
"description": "Free and open-source reverse engineering framework from NSA for analyzing compiled software. Includes disassembly, decompilation, scripting, and interactive graphing for malware analysis.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Reverse engineering and static malware analysis",
|
|
"input": "Executable files (ELF, PE, Mach-O, raw binaries), multiple architectures",
|
|
"output": "Disassembly, decompiled code, control flow graphs, function analysis, custom scripts",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local desktop application; no file uploads; open-source from NSA",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Malware Analysis Tools",
|
|
"type": "url",
|
|
"url": "https://malwareanalysis.tools/",
|
|
"description": "Curated resource and reference guide for malware analysis tools with recommendations for virtualization, safety practices, and tool selection for analysis scenarios.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Malware analysis tool discovery and best practices reference",
|
|
"input": "Tool research, methodology guidance",
|
|
"output": "Tool recommendations, analysis methodologies, safety practices, learning resources",
|
|
"opsec": "passive",
|
|
"opsecNote": "Reference resource only; no file uploads or active analysis",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "virustotal",
|
|
"type": "url",
|
|
"url": "https://www.virustotal.com/gui/home/upload",
|
|
"description": "Free online service that analyzes files and URLs for viruses, trojans and malicious content detected by 70+ antivirus engines and URL/domain reputation services.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Multi-engine malware scanning and URL reputation lookup",
|
|
"input": "Files, URLs, domains, IP addresses, file hashes",
|
|
"output": "Detection results from 70+ AV engines, behavioral analysis, file insights, related samples",
|
|
"opsec": "passive",
|
|
"opsecNote": "File uploads are indexed and visible to other users; hash-only queries are private",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Security Intelligence",
|
|
"children": [
|
|
{
|
|
"name": "Advisories",
|
|
"children": [
|
|
{
|
|
"name": "Vulert: Updated Open Source Vulnerability Database",
|
|
"type": "url",
|
|
"url": "https://vulert.com/vuln-db"
|
|
},
|
|
{
|
|
"name": "SecurityFocus",
|
|
"type": "url",
|
|
"url": "https://www.securityfocus.com/bid"
|
|
},
|
|
{
|
|
"name": "NVD - NIST",
|
|
"type": "url",
|
|
"url": "https://nvd.nist.gov/"
|
|
},
|
|
{
|
|
"name": "OSV Vulnerability Library",
|
|
"type": "url",
|
|
"url": "https://osv.dev/list"
|
|
},
|
|
{
|
|
"name": "CVE Details",
|
|
"type": "url",
|
|
"url": "https://www.cvedetails.com/"
|
|
},
|
|
{
|
|
"name": "CVE - MITRE",
|
|
"type": "url",
|
|
"url": "https://www.cve.org/"
|
|
},
|
|
{
|
|
"name": "OWASP",
|
|
"type": "url",
|
|
"url": "https://www.owasp.org/index.php/Main_Page"
|
|
},
|
|
{
|
|
"name": "Secunia",
|
|
"type": "url",
|
|
"url": "https://secuniaresearch.flexerasoftware.com/community/research/"
|
|
},
|
|
{
|
|
"name": "Australian Cyber Security Centre",
|
|
"type": "url",
|
|
"url": "https://www.cyber.gov.au/"
|
|
},
|
|
{
|
|
"name": "Canadian Centre for Cyber Security",
|
|
"type": "url",
|
|
"url": "https://www.cyber.gc.ca/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Attack Surface / Security Testing",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "ImmuniWeb",
|
|
"type": "url",
|
|
"url": "https://www.immuniweb.com/",
|
|
"description": "AI-powered application security platform for web penetration testing and vulnerability scanning.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Web security testing and scanning",
|
|
"input": "Web application or target URL",
|
|
"output": "Vulnerability reports and risk assessment",
|
|
"opsec": "active",
|
|
"opsecNote": "Performs actual penetration testing and scanning - generates server logs",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Default Passwords",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Default Passwords DB",
|
|
"type": "url",
|
|
"url": "https://cirt.net/passwords/"
|
|
},
|
|
{
|
|
"name": "Default passwords list",
|
|
"type": "url",
|
|
"url": "https://default-password.info/"
|
|
},
|
|
{
|
|
"name": "Default Password Lookup Utility",
|
|
"type": "url",
|
|
"url": "https://fortypoundhead.com/tools_dpw.asp"
|
|
},
|
|
{
|
|
"name": "Phenoelit Default Password List",
|
|
"type": "url",
|
|
"url": "https://phenoelit.org/dpl/dpl.html"
|
|
},
|
|
{
|
|
"name": "Default Router Passwords",
|
|
"type": "url",
|
|
"url": "https://www.routerpasswords.com/"
|
|
},
|
|
{
|
|
"name": "Open Sez Me Default Passwords",
|
|
"type": "url",
|
|
"url": "https://open-sez.me/"
|
|
},
|
|
{
|
|
"name": "Hashes.org",
|
|
"type": "url",
|
|
"url": "https://hashes.org/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Exploits",
|
|
"children": [
|
|
{
|
|
"name": "Exploit DB",
|
|
"type": "url",
|
|
"url": "https://www.exploit-db.com/"
|
|
},
|
|
{
|
|
"name": "Packet Storm",
|
|
"type": "url",
|
|
"url": "https://packetstormsecurity.com/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "IOC Tools",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Jager",
|
|
"type": "url",
|
|
"url": "https://github.com/sroberts/jager",
|
|
"description": "Python IOC aggregation and analysis tool for collecting and organizing security indicators.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IOC collection and aggregation",
|
|
"input": "IOC feeds or indicator lists",
|
|
"output": "Aggregated IOC database in standardized format",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local processing of public feeds",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "IOC Parser",
|
|
"type": "url",
|
|
"url": "https://github.com/armbues/ioc_parser",
|
|
"description": "Python library for extracting and parsing IOCs from raw text and security reports.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IOC extraction from reports",
|
|
"input": "Raw text or security reports",
|
|
"output": "Parsed IOCs in structured format",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local text analysis without network interaction",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"invitationOnly": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Cacador",
|
|
"type": "url",
|
|
"url": "https://github.com/sroberts/cacador",
|
|
"description": "Python tool for indicator extraction and deduplication from threat intelligence documents.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Indicator extraction and deduplication",
|
|
"input": "Documents and threat feeds",
|
|
"output": "Extracted and deduplicated IOCs",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local processing tool for passive analysis",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"invitationOnly": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ThreatPinch Lookup",
|
|
"type": "url",
|
|
"url": "https://github.com/cloudtracer/ThreatPinchLookup",
|
|
"description": "Browser extension and Python tool for enriching IOCs with real-time threat intelligence.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Indicator enrichment",
|
|
"input": "IOC or domain/IP/hash",
|
|
"output": "Enriched threat intelligence from multiple sources",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of public threat intel APIs",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Mimir",
|
|
"type": "url",
|
|
"url": "https://github.com/NullArray/Mimir",
|
|
"description": "IOC extraction and validation tool from security reports (unmaintained).",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IOC extraction and validation",
|
|
"input": "Security reports and documents",
|
|
"output": "Validated IOCs in structured format",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local processing tool for passive extraction",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false
|
|
},
|
|
{
|
|
"name": "iocextract (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/InQuest/iocextract",
|
|
"description": "Python library and CLI tool for rapid IOC extraction with support for obfuscated indicators.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IOC extraction with deobfuscation",
|
|
"input": "Raw text with obfuscated indicators",
|
|
"output": "Extracted IOCs including decoded variants",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local text parsing without network interaction",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"invitationOnly": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "ThreatIngestor (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/InQuest/ThreatIngestor",
|
|
"description": "Modular IOC ingestion platform for automated threat indicator extraction from multiple sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Automated IOC collection and enrichment",
|
|
"input": "Multiple threat feeds and RSS sources",
|
|
"output": "Aggregated and enriched IOCs in repository",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive aggregation of public threat feeds",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Phishing",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "SecAI.ai",
|
|
"type": "url",
|
|
"url": "https://secai.ai/research",
|
|
"description": "Security research platform providing threat intelligence, vulnerability analysis, and cybersecurity insights with focus on emerging threats.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Security research and threat intelligence",
|
|
"input": "Threat indicator or research topic",
|
|
"output": "Research articles and threat analysis",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive threat intelligence platform",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"invitationOnly": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "https://openphish.com/feed.txt",
|
|
"type": "url",
|
|
"url": "https://openphish.com/feed.txt",
|
|
"description": "Real-time phishing URL feed providing confirmed malicious phishing sites updated continuously.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Phishing URL detection",
|
|
"input": "Feed subscription or URL lookup",
|
|
"output": "Phishing URLs and malicious domains",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive feed consumption of public phishing data",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "PhishTank",
|
|
"type": "url",
|
|
"url": "https://www.phishtank.com/",
|
|
"description": "Community-driven phishing URL database where users submit and verify suspected phishing sites.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Phishing site verification",
|
|
"input": "Phishing URL or suspected malicious site",
|
|
"output": "Phishing status and community verification votes",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of community-reported database",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"editUrl": true,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"registration": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "PhishStats",
|
|
"type": "url",
|
|
"url": "https://phishstats.info/",
|
|
"description": "Phishing detection and analysis platform providing statistics on campaigns and domain intelligence.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Phishing campaign analysis",
|
|
"input": "Domain, IP, or keyword",
|
|
"output": "Campaign tracking and threat profiles",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive querying of phishing statistics database",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Terrorism & Extremism",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Academic Research",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Global Terrorism Database",
|
|
"type": "url",
|
|
"url": "https://www.start.umd.edu/research-projects/global-terrorism-database-gtd",
|
|
"description": "Academic database of terrorist attacks maintained by START at University of Maryland.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Terrorism research and analysis",
|
|
"input": "Search by attack, group, or date",
|
|
"output": "Terrorist attack records and analysis data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive academic research database",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "START Consortium for the Study of Terrorism and Responses to Terrorism",
|
|
"type": "url",
|
|
"url": "https://www.start.umd.edu/",
|
|
"description": "National Consortium conducting research on terrorism causes, consequences, and responses.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Terrorism research and education",
|
|
"input": "Research topics and publications",
|
|
"output": "Academic research and threat intelligence",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive academic research access",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Research Centers",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "CSIS Warfare, Irregular Threats, and Terrorism Program",
|
|
"type": "url",
|
|
"url": "https://www.csis.org/programs/warfare-irregular-threats-and-terrorism-program",
|
|
"description": "Research program analyzing terrorism, cyber threats, and irregular warfare.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Terrorism and threat analysis research",
|
|
"input": "Research topics and reports",
|
|
"output": "Reports and analysis on terrorism and warfare",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive access to public research",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Institute for Strategic Dialogue",
|
|
"type": "url",
|
|
"url": "https://www.isdglobal.org/",
|
|
"description": "International research organization studying conflict, extremism, and social change.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Extremism and conflict research",
|
|
"input": "Research topics and publications",
|
|
"output": "Research reports and analysis",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive access to public research",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "RAND Terrorism Research",
|
|
"type": "url",
|
|
"url": "https://www.rand.org/topics/terrorism.html",
|
|
"description": "RAND Corporation's collection of research and analysis on terrorism topics.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Terrorism research and policy analysis",
|
|
"input": "Search for terrorism research",
|
|
"output": "Academic papers and research findings",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive access to public research",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Sanctions & Watchlists",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "OFAC Sanctions List Search",
|
|
"type": "url",
|
|
"url": "https://sanctionssearch.ofac.treas.gov/",
|
|
"description": "U.S. Treasury tool for searching SDN and sanctions lists with approximate string matching.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Sanctions list lookups",
|
|
"input": "Person or entity name",
|
|
"output": "Sanctions status and entity information",
|
|
"opsec": "passive",
|
|
"opsecNote": "Government database lookup with approximate matching",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": true,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "OpenSanctions",
|
|
"type": "url",
|
|
"url": "https://www.opensanctions.org/",
|
|
"description": "Platform aggregating global sanctions, watchlists, and PEP data from 329 sources.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Sanctions and compliance research",
|
|
"input": "Person, company, or entity name",
|
|
"output": "Sanctions status and entity details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of aggregated public data",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "UN Security Council Consolidated List",
|
|
"type": "url",
|
|
"url": "https://main.un.org/securitycouncil/en/content/un-sc-consolidated-list",
|
|
"description": "Official UN Security Council list of designated individuals and entities.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "UN sanctions verification",
|
|
"input": "Person or entity name",
|
|
"output": "UN designation status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of official UN data",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Terrorist Financing",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Terrorist Finance Tracking Program",
|
|
"type": "url",
|
|
"url": "https://home.treasury.gov/policy-issues/terrorism-and-illicit-finance/terrorist-finance-tracking-program-tftp",
|
|
"description": "U.S. Treasury program tracking terrorist financing and money laundering.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Terrorist financing intelligence",
|
|
"input": "Financial or entity information",
|
|
"output": "Financing intelligence and reports",
|
|
"opsec": "passive",
|
|
"opsecNote": "Government resource access",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Threat Feeds & Platforms",
|
|
"children": [
|
|
{
|
|
"name": "IBM X-Force Exchange",
|
|
"type": "url",
|
|
"url": "https://exchange.xforce.ibmcloud.com/",
|
|
"description": "Collaborative threat intelligence platform with malware, vulnerability, and campaign data.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Malware and threat intelligence",
|
|
"input": "IOC, domain, or malware sample",
|
|
"output": "Threat analysis and intelligence reports",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive querying of threat database",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Malware Information Sharing Platform",
|
|
"type": "url",
|
|
"url": "https://www.misp-project.org/",
|
|
"description": "Open-source platform for collecting, storing, and sharing cyber threat indicators and malware data.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Threat intelligence sharing",
|
|
"input": "Threat indicators and malware samples",
|
|
"output": "Structured threat intelligence and correlations",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local platform for passive sharing",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Malware Patrol",
|
|
"type": "url",
|
|
"url": "https://www.malwarepatrol.net/",
|
|
"description": "Threat intelligence feed service providing malware samples, URLs, domains, and IOC data.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Malware IOC and feed intelligence",
|
|
"input": "IOC queries or feed subscriptions",
|
|
"output": "Malware hashes, URLs, and threat intel",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive consumption of threat feeds",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "AlienVault OTX",
|
|
"type": "url",
|
|
"url": "https://otx.alienvault.com/",
|
|
"description": "Crowd-sourced threat intelligence platform with 180K+ participants sharing 19M+ daily threats.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Community threat intelligence",
|
|
"input": "IOC, domain, IP, or search query",
|
|
"output": "Community threat pulses and analysis",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive community threat data sharing",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "FireHOL IP Lists ",
|
|
"type": "url",
|
|
"url": "https://iplists.firehol.org/",
|
|
"description": "Collection of firewall-friendly IP blacklists for blocking malicious and spam sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IP reputation and blocking",
|
|
"input": "IP address or list subscription",
|
|
"output": "Blacklist membership status",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of public reputation lists",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Maltiverse",
|
|
"type": "url",
|
|
"url": "https://maltiverse.com/",
|
|
"description": "Threat intelligence platform aggregating 100+ sources with real-time IOC scoring.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "IOC aggregation and scoring",
|
|
"input": "IOC or threat indicator",
|
|
"output": "Threat scores and context",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive aggregation of threat data",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Malpedia",
|
|
"type": "url",
|
|
"url": "https://malpedia.caad.fkie.fraunhofer.de/",
|
|
"description": "Free collaborative malware database from Fraunhofer FKIE with 600+ malware families.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Malware family identification",
|
|
"input": "Malware sample or family name",
|
|
"output": "Malware family analysis and YARA rules",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive malware research database",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": true,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Project Honey Pot",
|
|
"type": "url",
|
|
"url": "https://www.projecthoneypot.org/",
|
|
"description": "Distributed honeypot project tracking email harvesters, spam servers, and malicious IPs.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Spam and harvester tracking",
|
|
"input": "IP address or email domain",
|
|
"output": "Harvester and spam activity records",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive honeypot intelligence",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Cymon Open Threat Intelligence",
|
|
"type": "url",
|
|
"url": "https://cymon.io/",
|
|
"description": "Largest open tracker of malware, phishing, botnets containing 6M+ malicious IPs.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "IP threat tracking",
|
|
"input": "IP address or threat indicator",
|
|
"output": "Malware and threat reports",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive threat database queries",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "mlsecproject / combine",
|
|
"type": "url",
|
|
"url": "https://github.com/mlsecproject/combine",
|
|
"description": "Tool for gathering and normalizing threat intelligence feeds from public sources.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Threat feed aggregation",
|
|
"input": "Multiple threat intelligence feeds",
|
|
"output": "Normalized IOC data in CSV or CRITs format",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local processing of public feeds",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "hostintel - keithjjones Github",
|
|
"type": "url",
|
|
"url": "https://github.com/keithjjones/hostintel",
|
|
"description": "Modular Python application to collect host and malicious IP intelligence.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Host intelligence gathering",
|
|
"input": "IP, FQDN, or domain name",
|
|
"output": "Intelligence data in CSV format",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local tool for passive host analysis",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "massive-octo-spice - csirtgadgets Github",
|
|
"type": "url",
|
|
"url": "https://github.com/csirtgadgets/massive-octo-spice",
|
|
"description": "CSIRT threat intelligence platform (deprecated - use bearded-avenger v3 instead).",
|
|
"status": "degraded",
|
|
"pricing": "free",
|
|
"bestFor": "Legacy CSIRT intelligence platform",
|
|
"input": "Threat intelligence feeds",
|
|
"output": "Aggregated threat data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Local platform for threat aggregation",
|
|
"localInstall": true,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Scam Database",
|
|
"type": "url",
|
|
"url": "https://www.scamdb.net/",
|
|
"description": "User-contributed database of scam reports searchable by phone, email, and website.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Scam and fraud reporting",
|
|
"input": "Phone, email, or website",
|
|
"output": "Unverified scam reports and details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup of community reports",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Bot Scout",
|
|
"type": "url",
|
|
"url": "https://botscout.com/",
|
|
"description": "Service tracking bot signatures (names, IPs, emails) to prevent automated spam and abuse.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Bot and spam detection",
|
|
"input": "IP, email, or username",
|
|
"output": "Bot activity and spam records",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive honeypot-based detection",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "APTnotes",
|
|
"type": "url",
|
|
"url": "https://github.com/aptnotes/data",
|
|
"description": "Repository of public documents, whitepapers, and articles about APT campaigns.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "APT research and threat analysis",
|
|
"input": "Search APT campaign documents",
|
|
"output": "Threat reports and analysis",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive access to public threat research",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "HoneyDB",
|
|
"type": "url",
|
|
"url": "https://honeydb.io/",
|
|
"description": "Honeypot network providing real-time IoT and server threat intelligence via REST API.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "IoT honeypot intelligence",
|
|
"input": "IP address or attack queries",
|
|
"output": "Honeypot interaction logs and threat data",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive honeypot-based intelligence",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Pulsedive",
|
|
"type": "url",
|
|
"url": "https://pulsedive.com/",
|
|
"description": "Free threat intelligence platform for enriching IPs, URLs, domains, and IOCs from OSINT feeds.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "IOC enrichment and risk scoring",
|
|
"input": "IP, URL, domain, or IOC",
|
|
"output": "Enriched threat intelligence and risk factors",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive querying of enrichment database",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Mr.Looquer IOC Feed - 1st Dual Stack Threat Feed",
|
|
"type": "url",
|
|
"url": "https://iocfeed.mrlooquer.com/",
|
|
"description": "Threat intelligence feed providing IOC data with IPv4/IPv6 dual stack support.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "IOC threat feed access",
|
|
"input": "Feed subscription",
|
|
"output": "IOC threat intelligence feed",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive threat feed consumption",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "REScure Cyber Threat Intelligence Project",
|
|
"type": "url",
|
|
"url": "https://rescure.me/",
|
|
"description": "Community-driven cyber threat intelligence project providing IOC feeds and research.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Threat intelligence feeds",
|
|
"input": "IOC feed subscription",
|
|
"output": "IOC threat intelligence",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive threat feed access",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "TTPs",
|
|
"children": [
|
|
{
|
|
"name": "Malware Exploit TTP Database",
|
|
"type": "url",
|
|
"url": "https://www.pwnmalw.re/",
|
|
"description": "Malware exploit database documenting security vulnerabilities in malware families (offline).",
|
|
"status": "down",
|
|
"pricing": "free",
|
|
"bestFor": "Malware exploit research",
|
|
"input": "Malware name or exploit query",
|
|
"output": "Exploit documentation and vulnerability details",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive lookup when functional",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": true
|
|
},
|
|
{
|
|
"name": "Mitre TTPs",
|
|
"type": "url",
|
|
"url": "https://attack.mitre.org/",
|
|
"description": "MITRE ATT&CK framework: globally-accessible knowledge base of adversary tactics and techniques.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Threat modeling and TTP analysis",
|
|
"input": "Search for tactics, techniques, or threat groups",
|
|
"output": "Technique descriptions and mitigation strategies",
|
|
"opsec": "passive",
|
|
"opsecNote": "Passive research of public threat intelligence",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "MITRE ATT&CK",
|
|
"type": "url",
|
|
"url": "https://attack.mitre.org/"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "OpSec",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Persona Creation",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Fake Name Generator",
|
|
"type": "url",
|
|
"url": "https://www.fakenamegenerator.com/"
|
|
},
|
|
{
|
|
"name": "Fake Identity Generator",
|
|
"type": "url",
|
|
"url": "https://backgroundchecks.org/justdeleteme/fake-identity-generator/"
|
|
},
|
|
{
|
|
"name": "This Person Does Not Exist",
|
|
"type": "url",
|
|
"url": "https://thispersondoesnotexist.com/"
|
|
},
|
|
{
|
|
"name": "Random User Generator",
|
|
"type": "url",
|
|
"url": "https://randomuser.me/"
|
|
},
|
|
{
|
|
"name": "Faker.js",
|
|
"type": "url",
|
|
"url": "https://cdn.rawgit.com/Marak/faker.js/master/examples/browser/index.html"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Anonymous Browsing",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "TOR",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Tor Download (T)",
|
|
"type": "url",
|
|
"url": "https://www.torproject.org/download/"
|
|
},
|
|
{
|
|
"name": "Freenet Project (T)",
|
|
"type": "url",
|
|
"url": "https://freenetproject.org/pages/download.html"
|
|
},
|
|
{
|
|
"name": "I2P Anonymous Network (T)",
|
|
"type": "url",
|
|
"url": "https://geti2p.net/en/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Anonymous VPNs",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "VPN Comparisons - That One Privacy Site",
|
|
"type": "url",
|
|
"url": "https://thatoneprivacysite.net/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Spoof User-Agent",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "UserAgentString.com",
|
|
"type": "url",
|
|
"url": "https://www.useragentstring.com/pages/useragentstring.php"
|
|
},
|
|
{
|
|
"name": "WhatIsMyBrowser.com",
|
|
"type": "url",
|
|
"url": "https://www.whatismybrowser.com/"
|
|
},
|
|
{
|
|
"name": "User Agent String Decoder",
|
|
"type": "url",
|
|
"url": "https://tools.tracemyip.org/user-agent-string-decoder/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "VPN Tests",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "IP / DNS Leak Detection",
|
|
"type": "url",
|
|
"url": "https://ipleak.net/"
|
|
},
|
|
{
|
|
"name": "JonDonym",
|
|
"type": "url",
|
|
"url": "https://ip-check.info/?lang=en"
|
|
},
|
|
{
|
|
"name": "DNS leak test",
|
|
"type": "url",
|
|
"url": "https://www.dnsleaktest.com/"
|
|
},
|
|
{
|
|
"name": "DNS Leak Tests",
|
|
"type": "url",
|
|
"url": "https://dnsleak.com/"
|
|
},
|
|
{
|
|
"name": "IPv6 Leak Tests",
|
|
"type": "url",
|
|
"url": "https://ipv6leak.com/"
|
|
},
|
|
{
|
|
"name": "Email Leak Tests",
|
|
"type": "url",
|
|
"url": "https://emailipleak.com/"
|
|
},
|
|
{
|
|
"name": "Perfect Privacy",
|
|
"type": "url",
|
|
"url": "https://www.perfect-privacy.com/check-ip/"
|
|
},
|
|
{
|
|
"name": "WebRTC Leak Test",
|
|
"type": "url",
|
|
"url": "https://www.perfect-privacy.com/webrtc-leaktest/"
|
|
},
|
|
{
|
|
"name": "LetMeCheck.it",
|
|
"type": "url",
|
|
"url": "https://letmecheck.it/"
|
|
},
|
|
{
|
|
"name": "Trace My IP",
|
|
"type": "url",
|
|
"url": "https://www.tracemyip.org/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Browser Tests",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Browser Statistics",
|
|
"type": "url",
|
|
"url": "https://www.w3schools.com/browsers/default.asp"
|
|
},
|
|
{
|
|
"name": "WhatsMyBrowser.org",
|
|
"type": "url",
|
|
"url": "https://www.whatsmybrowser.org/"
|
|
},
|
|
{
|
|
"name": "What browser am I using.co",
|
|
"type": "url",
|
|
"url": "https://www.whatbrowseramiusing.co/"
|
|
},
|
|
{
|
|
"name": "What Browser?",
|
|
"type": "url",
|
|
"url": "https://whatbrowser.org/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Proxy Tests",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "IP2Proxy",
|
|
"type": "url",
|
|
"url": "https://www.ip2proxy.com/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "NoScript (T)",
|
|
"type": "url",
|
|
"url": "https://noscript.net/"
|
|
},
|
|
{
|
|
"name": "Firefox-debloat",
|
|
"type": "url",
|
|
"url": "https://github.com/amq/firefox-debloat"
|
|
},
|
|
{
|
|
"name": "Browser Leaks",
|
|
"type": "url",
|
|
"url": "https://browserleaks.com/"
|
|
},
|
|
{
|
|
"name": "Self-Destructing Cookies (T)",
|
|
"type": "url",
|
|
"url": "https://addons.mozilla.org/en-US/firefox/addon/self-destructing-cookies/"
|
|
},
|
|
{
|
|
"name": "BrowserSpy.dk",
|
|
"type": "url",
|
|
"url": "https://browserspy.dk/"
|
|
},
|
|
{
|
|
"name": "LocaBrowser.com",
|
|
"type": "url",
|
|
"url": "https://www.locabrowser.com/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Privacy / Clean Up",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Privacy Guides",
|
|
"type": "url",
|
|
"url": "https://www.privacyguides.org/en/"
|
|
},
|
|
{
|
|
"name": "Just Delete Me",
|
|
"type": "url",
|
|
"url": "https://backgroundchecks.org/justdeleteme/"
|
|
},
|
|
{
|
|
"name": "OptOut Credit Prescreen",
|
|
"type": "url",
|
|
"url": "https://www.optoutprescreen.com/?rf=t"
|
|
},
|
|
{
|
|
"name": "Credit Freeze",
|
|
"type": "url",
|
|
"url": "https://inteltechniques.com/blog/2018/09/28/complete-credit-freeze-tutorial-update/"
|
|
},
|
|
{
|
|
"name": "Fake US Identities",
|
|
"type": "url",
|
|
"url": "https://xdd2.org/"
|
|
},
|
|
{
|
|
"name": "Social Media Fingerprint",
|
|
"type": "url",
|
|
"url": "https://robinlinus.github.io/socialmedia-leak/"
|
|
},
|
|
{
|
|
"name": "Privacy Tools",
|
|
"type": "url",
|
|
"url": "https://www.privacytools.io/"
|
|
},
|
|
{
|
|
"name": "Panopticlick",
|
|
"type": "url",
|
|
"url": "https://panopticlick.eff.org/"
|
|
},
|
|
{
|
|
"name": "Intel Techniques - Hiding from the Internet",
|
|
"type": "url",
|
|
"url": "https://inteltechniques.com/data/workbook.pdf"
|
|
},
|
|
{
|
|
"name": "The Many Hats Club - Privacy Resources",
|
|
"type": "url",
|
|
"url": "https://themanyhats.club/centralised-place-for-privacy-resources/"
|
|
},
|
|
{
|
|
"name": "The Hitchhiker\u2019s Guide to Online Anonymity",
|
|
"type": "url",
|
|
"url": "https://anonymousplanet.org/guide/"
|
|
},
|
|
{
|
|
"name": "Awesome Opt-Out Guide 2026",
|
|
"type": "url",
|
|
"url": "https://github.com/thumpersecure/opt-out-manual-2026"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Metadata / Style",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Anonymouth - Document Anonymization (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/psal/anonymouth"
|
|
},
|
|
{
|
|
"name": "MAT2 (T)",
|
|
"type": "url",
|
|
"url": "https://0xacab.org/jvoisin/mat2"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Documentation / Evidence Capture",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Web Browsing",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Forensic OSINT (T)",
|
|
"type": "url",
|
|
"url": "https://www.forensicosint.com/"
|
|
},
|
|
{
|
|
"name": "Fiddler (T)",
|
|
"type": "url",
|
|
"url": "https://www.telerik.com/download/fiddler"
|
|
},
|
|
{
|
|
"name": "Burp Suite (T)",
|
|
"type": "url",
|
|
"url": "https://portswigger.net/burp/download.html"
|
|
},
|
|
{
|
|
"name": "Page2Images (T)",
|
|
"type": "url",
|
|
"url": "https://www.page2images.com/URL-Live-Website-Screenshot-Generator"
|
|
},
|
|
{
|
|
"name": "Archive.is",
|
|
"type": "url",
|
|
"url": "https://archive.is/"
|
|
},
|
|
{
|
|
"name": "Web Page Saver",
|
|
"type": "url",
|
|
"url": "https://www.magnetforensics.com/resources/web-page-saver/"
|
|
},
|
|
{
|
|
"name": "Snapper (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/dxa4481/Snapper"
|
|
},
|
|
{
|
|
"name": "Full Page Screen Capture Chrome Extension (T)",
|
|
"type": "url",
|
|
"url": "https://github.com/mrcoles/full-page-screen-capture-chrome-extension"
|
|
},
|
|
{
|
|
"name": "EZR OSINT Sidebar (T)",
|
|
"type": "url",
|
|
"url": "https://chromewebstore.google.com/detail/ezr-osint-sidebar/joagbbgciboooipadijeaoidjjigdmof"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Screen Capture",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "FRAPS (T)",
|
|
"type": "url",
|
|
"url": "https://fraps.com/"
|
|
},
|
|
{
|
|
"name": "ShareX (T)",
|
|
"type": "url",
|
|
"url": "https://getsharex.com/"
|
|
},
|
|
{
|
|
"name": "Greenshot (T)",
|
|
"type": "url",
|
|
"url": "https://getgreenshot.org/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Map Locations",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Google Street View - Hyperlapse",
|
|
"type": "url",
|
|
"url": "https://github.com/TeehanLax/Hyperlapse.js"
|
|
},
|
|
{
|
|
"name": "ZeeMaps",
|
|
"type": "url",
|
|
"url": "https://www.zeemaps.com/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Timeline JS3",
|
|
"type": "url",
|
|
"url": "https://timeline.knightlab.com/"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Training",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "Games",
|
|
"type": "folder",
|
|
"children": [
|
|
{
|
|
"name": "GeoGuesser",
|
|
"type": "url",
|
|
"url": "https://www.geoguessr.com/",
|
|
"description": "Geography game for geolocation OSINT training; users observe visual clues in Street View panoramas to guess locations worldwide.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Geolocation skills, visual intelligence analysis, landmark identification",
|
|
"input": "Street View imagery, map interface",
|
|
"output": "Accuracy score, location guess feedback, player rankings",
|
|
"opsec": "passive",
|
|
"opsecNote": "No active reconnaissance; purely observational gameplay using public imagery.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": true,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Verif!cation Quiz Bot",
|
|
"type": "url",
|
|
"url": "https://x.com/quiztime",
|
|
"description": "Daily OSINT verification challenges posted on X (Twitter), using a community-driven quiz format for image geolocation and source verification.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Community OSINT challenges, image verification techniques, collaborative research",
|
|
"input": "Shared images and verification questions from quizmasters",
|
|
"output": "Community discussion threads, solution walkthroughs, and learning outcomes",
|
|
"opsec": "passive",
|
|
"opsecNote": "No active probing; public community engagement via social replies.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"name": "Forensic OSINT KB Guides",
|
|
"type": "url",
|
|
"url": "https://www.forensicosint.com/osint-guide",
|
|
"description": "Knowledge base of digital forensics guides for evidence capture and court-admissible documentation, including web capture and metadata analysis.",
|
|
"status": "live",
|
|
"pricing": "freemium",
|
|
"bestFor": "Digital evidence preservation, chain-of-custody documentation, court-ready OSINT reporting",
|
|
"input": "Target URLs or digital media requiring forensic capture",
|
|
"output": "Timestamped artifacts, metadata analysis guidance, preserved evidence workflows",
|
|
"opsec": "passive",
|
|
"opsecNote": "Evidence collection focus; requires proper methodology for investigative and legal contexts.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Open Source Intelligence Techniques",
|
|
"type": "url",
|
|
"url": "https://inteltechniques.com/",
|
|
"description": "Professional OSINT training and certification by IntelTechniques with extensive video modules, documentation, and practical investigative exercises.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Professional OSINT certification, structured curriculum, advanced investigative techniques",
|
|
"input": "Student participation in course modules, notes, and guided practical exercises",
|
|
"output": "Course completion, certification-track readiness, and advanced OSINT methodology",
|
|
"opsec": "passive",
|
|
"opsecNote": "Instructor-led educational platform focused on passive investigative methodology.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Plessas",
|
|
"type": "url",
|
|
"url": "https://plessas.net/online-training",
|
|
"description": "Expert-led OSINT training courses by Plessas Experts Network, from fundamentals to intensive hands-on investigation programs.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Professional investigative training, corporate intelligence, legal and compliance investigations",
|
|
"input": "Structured coursework, practical OSINT exercises, and instructor interaction",
|
|
"output": "Course completion outcomes, investigative skill development, and training credentials",
|
|
"opsec": "passive",
|
|
"opsecNote": "Educational environment centered on passive research techniques.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "The OSINTion",
|
|
"type": "url",
|
|
"url": "https://www.theosintion.com/courses",
|
|
"description": "Affordable OSINT training courses by Joe Gray, including people OSINT, business investigations, and blockchain-focused instruction.",
|
|
"status": "live",
|
|
"pricing": "paid",
|
|
"bestFor": "Accessible OSINT courses, CTF-style learning, people and business intelligence workflows",
|
|
"input": "Live or remote class participation, practical exercises, and case-study analysis",
|
|
"output": "Completed coursework, practical investigative techniques, and reusable OSINT workflows",
|
|
"opsec": "passive",
|
|
"opsecNote": "Training-focused environment without active network probing requirements.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": true,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
},
|
|
{
|
|
"name": "Smart Questions",
|
|
"type": "url",
|
|
"url": "https://www.catb.org/esr/faqs/smart-questions.html",
|
|
"description": "Foundational guide by Eric S. Raymond on asking effective technical questions in open-source and technical communities.",
|
|
"status": "live",
|
|
"pricing": "free",
|
|
"bestFor": "Research methodology, effective questioning, and stronger information-seeking habits",
|
|
"input": "Reader engagement with essay guidelines and practical examples",
|
|
"output": "Improved question framing, clearer research requests, and better community responses",
|
|
"opsec": "passive",
|
|
"opsecNote": "Pure methodology reference; no target interaction or probing.",
|
|
"localInstall": false,
|
|
"googleDork": false,
|
|
"registration": false,
|
|
"editUrl": false,
|
|
"api": false,
|
|
"invitationOnly": false,
|
|
"deprecated": false
|
|
}
|
|
]
|
|
}
|
|
]
|
|
} |