Early access: New content posts daily — updates are frequent and you may notice work in progress.
OSINTBench

Network Reconnaissance

73 tools

Network reconnaissance tools — internet-wide port scanners, IP intelligence, certificate transparency, DNS enumeration, and attack surface mapping.

Internet-wide scanningIP & ASN intelligenceDNS enumerationCertificate transparencyAttack surface mapping

Pricing

Min Rating

Top-Rated Tools

Comparisons & Buyer Guides

Guides & Techniques

Website Footprinting Methodology: WHOIS, Subdomains, and Certificate Transparency

Website footprinting methodology is the step-by-step process of expanding from a known domain into subdomains, certificates, IPs, and related internet-facing infrastructure. Its value is not in any one tool, but in the sequence: each stage creates the next pivot, helping investigators build a repeatable map of a target's external presence without confusing raw leads with validated assets.

osint-for-penetration-testers

Recon-ng is an open source reconnaissance framework that helps penetration testers collect, correlate, and export OSINT from public sources before any active testing begins. It is especially useful for organizing domains, infrastructure, people, leaks, and technology findings into a client-ready handoff.

Domain and IP Investigation with OSINT: A Complete Guide

A practical guide to investigating domains and IP addresses using open source tools — covering WHOIS, DNS history, IP geolocation, ASN analysis, and infrastructure pivoting.

Best OSINT GitHub Repositories in 2026

The top GitHub repositories for OSINT — curated lists, automation frameworks, username lookup, email investigation, phone OSINT, and threat intelligence tools. Stars verified April 2026.

How to Use SpiderFoot for Automated OSINT Reconnaissance

Step-by-step guide to running SpiderFoot scans, configuring modules, and reading results without alerting your target.

How to Use Shodan: A Beginner's Guide

A practical introduction to Shodan — what it is, how to search it, and how OSINT investigators and security practitioners use it to research internet-facing infrastructure.

More Network Reconnaissance Tools

VirusTotal

Multi-engine malware scanner and threat intelligence platform for files, URLs, IPs, and domains

4.5/5 freemium

httpx

A high-speed HTTP probing tool that turns raw host lists into triaged, fingerprinted web targets ready for investigation.

4.4/5 free

Nooelec NESDR SMArt v5

The RTL-SDR alternative with tighter frequency accuracy and a complete antenna bundle — better value than the V4 if you don't need shortwave.

4.4/5 paid

subfinder

Fast passive subdomain enumeration that gives pentesters a clean starting point for external recon.

4.4/5 free

Amass

Map an organization's full external attack surface — ASNs, domains, subdomains, and infrastructure relationships — through 50+ integrated data sources and a persistent graph database.

4.3/5 free

Awesome OSINT

A massive, investigator-friendly directory for finding the right OSINT tools before you waste time using the wrong ones.

4.3/5 free

C2 Tracker

A live C2 infrastructure feed that helps defenders hunt, block, and correlate active command-and-control servers by framework type.

4.3/5 free

crt.sh

Passive certificate transparency searches uncover subdomains and related infrastructure before you ever touch the target.

4.3/5 free

DorkSearch

889,000+ pre-built Google dorks with an AI dork builder for instant recon

4.3/5 free

Flightradar24

Real-time and historical flight tracking via a global ADS-B receiver network

4.3/5 freemium

reNgine

Run subfinder, amass, httpx, naabu, and nuclei as configurable YAML pipelines across multiple targets — with a persistent database, screenshot gallery, and notification integrations managed through a web UI.

4.3/5 free

Web Check

Paste a URL and get DNS records, SSL details, security headers, tech stack, WHOIS, and 100+ more domain intelligence checks in a single browser view — in under thirty seconds.

4.3/5 free

BuiltWith

Technology intelligence — find what any website is built with and who else uses it

4.2/5 freemium

Open-Asm

An open-source ASM platform that helps defenders turn scattered internet-facing assets into a trackable external inventory.

4.2/5 free

osmedeus

A recon orchestration engine that helps operators run complex attack surface discovery workflows with concurrency, dependencies, and structured output.

4.2/5 free

Penetration Testing Cheat Sheet

A command-first offensive security reference that helps testers find the exact syntax they need during active engagements.

4.2/5 free

r1cksec/cheatsheets

A compact infosec reference repository that gives pentesters fast command lookups for Active Directory, bash, and common offensive workflows.

4.2/5 free

scilla

An all-in-one recon tool that gives bug hunters a fast first-pass view of DNS, subdomains, ports, and web paths from one binary.

4.2/5 free

Scope

Pull public bug bounty scope data from one GitHub repository instead of checking every platform by hand.

4.2/5 free

secator

A CLI-first orchestration layer that standardizes how pentest teams run, chain, and store results from their security toolchain.

4.2/5 free

shuffleDNS

A fast DNS brute-force and validation tool that cleans passive subdomain results and extends coverage with wildcard-aware active discovery.

4.2/5 free

SpiderFoot

Map a target's full digital footprint automatically — domains, IPs, emails, names, and ASNs across 500+ sources.

4.2/5 freemium

Sucuri

Website security platform used by investigators to analyze site integrity, malware, and CDN infrastructure

4.2/5 freemium

TCM Security OSINT Course

Practical OSINT training for investigators and security professionals

4.2/5 paid

WebCheck-OSINT

A lightweight way to pull website infrastructure, DNS, TLS, and fingerprinting checks into one fast first-pass recon view.

4.2/5 free

Censys

Internet-wide scanner with certificate transparency coverage no other tool matches.

4.1/5 freemium

FOFA

A web-focused internet asset search engine that helps analysts pivot from one exposed fingerprint to broader infrastructure quickly.

4.1/5 free

GrayHatWarfare

Find exposed cloud storage faster by searching indexed public S3 buckets and blob containers tied to real targets.

4.1/5 free

LeakIX

Internet-wide scanner for exposed services and data leaks, with a focus on misconfigured databases and sensitive data exposure

4.1/5 freemium

nomore403

A fast 403 bypass automation tool that turns forbidden content discovery results into systematically tested access-control edge cases.

4.1/5 free

openSquat

An open source monitoring tool that helps defenders catch brand lookalike domains before phishing campaigns go live.

4.1/5 free

Photon

Crawl a target website once and walk away with internal URLs, email addresses, social media links, JavaScript files, and exposed secrets — all organized into separate files ready for downstream investigation.

4.1/5 free

reconFTW

A full-scope domain recon framework that chains proven CLI tools into one repeatable workflow for broad attack surface discovery.

4.1/5 free

Recorded Future

The leading threat intelligence platform for enterprise security teams

4.1/5 enterprise

SkyOSINT

Real-time satellite tracking and space intelligence platform combining orbital data with geopolitical analysis

4.1/5 freemium

Surfshark

VPN with built-in identity monitoring and anonymous browsing identity tools

4.1/5 paid

Ubikron

The OSINT browser extension that runs 200+ enrichments from any web page

4.1/5 freemium

WiGLE

Crowdsourced wireless network database mapping billions of Wi-Fi, Bluetooth, and cell networks globally

4.1/5 free

YARD Stick One

Sub-1 GHz wireless transceiver for 433/868 MHz IoT, key fob, and industrial protocol analysis — the dedicated tool for the RF bands that run smart devices.

4.1/5 paid

ADS-B Exchange

The only major flight tracker that refuses to filter opt-out aircraft

4/5 freemium

AirNav Radar FlightStick

A purpose-built ADS-B receiver with integrated filter and LNA — better 1090 MHz decode performance out of the box than any generic RTL-SDR dongle.

4/5 paid

cariddi

A fast Go web crawler that plugs cleanly into recon pipelines to uncover endpoints, JavaScript URLs, and exposed secrets at scale.

4/5 free

discover

A Kali-native bash automation wrapper that speeds up standard recon, scanning, and payload generation without forcing you into a heavyweight framework.

4/5 free

IVRE

Turn your Nmap and Masscan output into a persistent, queryable network intelligence database with Shodan-style query capabilities against your own infrastructure.

4/5 free

mihari

A rule-driven OSINT hunting engine that automates recurring infrastructure queries and alerts only on what is newly discovered.

4/5 free

Pulsedive

Community-driven threat intelligence platform with enriched IOC data and free analyst-grade lookups

4/5 freemium

SEMrush

Competitive intelligence and web footprint analysis for digital investigators

4/5 freemium

Adalanche

A single-binary Active Directory graph tool that helps operators find ACL-driven escalation paths without standing up a separate graph database.

3.9/5 free

Hacking Tools (aw-junaid)

A multi-language security tool collection that helps researchers study how offensive and analysis utilities are built across different ecosystems.

3.9/5 free

Criminal IP

IP and domain scanner that scores addresses by malicious activity and maps CVEs to exposed service banners.

3.9/5 freemium

Findomain

A fast passive subdomain enumerator that adds built-in monitoring, history, and alerting for newly exposed assets.

3.9/5 free

Netlas

Internet scanning platform with 8 billion+ indexed IP addresses for attack surface and infrastructure analysis

3.9/5 freemium

Recon-ng

CLI-based web reconnaissance framework modeled after Metasploit

3.9/5 free

Setapp

Curated Mac app subscription with several tools useful for investigators and security researchers

3.9/5 paid

theHarvester

Passively harvest emails, subdomains, and hostnames from public sources before you touch a single target system.

3.9/5 free

FlightAware

US commercial flight tracking with FAA data integration and a developer-friendly API

3.8/5 freemium

metabigor

A zero-configuration ASN and network scope discovery tool that helps hunters map organizational IP space without API setup.

3.8/5 free

Mitaka

A browser extension that turns highlighted indicators into instant OSINT and threat intelligence lookups without breaking analyst flow.

3.8/5 free

SecurityTrails

Historical DNS and domain intelligence database covering 10+ years of infrastructure changes

3.8/5 freemium

GreyNoise

Internet noise classifier that separates mass-scanning background traffic from targeted activity so you can stop chasing ghosts in your SIEM.

3.7/5 freemium

MarineTraffic

Real-time ship tracking via a global AIS receiver network — the default starting point for maritime OSINT

3.7/5 freemium

Onyphe

Cyber defense search engine indexing internet-wide scan data, threat intelligence feeds, and passive DNS

3.7/5 freemium

sitedorks

Run the same dork across multiple search engines and target site collections without rebuilding every query by hand.

3.6/5 free

Maltego

The gold standard for visual link analysis and OSINT pivoting

3.5/5 freemium

ZoomEye

Chinese-operated internet search engine for cyberspace — maps exposed services and devices globally

3.5/5 freemium

OpenSky Network

Free ADS-B flight tracking API with multi-year historical archive — the right tool when Flightradar24's history tier is too expensive.

3.4/5 free

VesselFinder

AIS-based ship tracking that earns its place as a cross-reference tool — and occasionally the primary one

3.4/5 freemium