Early access: New content posts daily — updates are frequent and you may notice work in progress.
OSINTBench

Cyber Threat Intelligence

76 tools

OSINT tools for threat analysis, threat hunting, detection engineering, SOC analysis, incident response, and digital forensics.

Threat analysisThreat huntingDetection engineeringIncident responseDigital forensics

Pricing

Min Rating

Top-Rated Tools

More Tools

VirusTotal

Threat Intelligence

Multi-engine malware scanner and threat intelligence platform for files, URLs, IPs, and domains

4.5/5 freemium

capa

Threat Intelligence

A malware triage tool that quickly tells analysts what an executable is capable of doing and where those behaviors appear.

4.4/5 free

Cortex Analyzers

Threat Intelligence

A modular enrichment engine that lets TheHive analysts analyze observables in place instead of pivoting across dozens of external CTI tools.

4.4/5 free

Cortex

Threat Intelligence

An enrichment and response engine that lets TheHive analysts analyze observables and trigger actions without leaving the case workflow.

4.4/5 free

destroylist

Threat Intelligence

A continuously updated phishing and scam domain feed that helps defenders block fraud infrastructure through DNS, hosts files, or API lookups.

4.4/5 free

Have I Been Pwned

Identity Investigation

The fastest way to confirm whether an email address appears in known data breaches — free, accurate, and maintained by a single researcher who vets every dataset.

4.4/5 freemium

httpx

Network Recon

A high-speed HTTP probing tool that turns raw host lists into triaged, fingerprinted web targets ready for investigation.

4.4/5 free

MISP Galaxy

Threat Intelligence

A structured cluster library that gives threat intelligence events actor, malware, and technique context instead of leaving them as unlabeled IOC collections.

4.4/5 free

MISP

Threat Intelligence

An open source threat intelligence platform built for structured IOC management, community sharing, and fast operational distribution.

4.4/5 free

subfinder

Network Recon

Fast passive subdomain enumeration that gives pentesters a clean starting point for external recon.

4.4/5 free

Amass

Network Recon

Map an organization's full external attack surface — ASNs, domains, subdomains, and infrastructure relationships — through 50+ integrated data sources and a persistent graph database.

4.3/5 free

Anthropic Cybersecurity Skills

Threat Intelligence

A structured open skill library that gives AI agents concrete cybersecurity workflows mapped to ATT&CK, D3FEND, ATLAS, and NIST frameworks.

4.3/5 free

C2 Tracker

Threat Intelligence

A live C2 infrastructure feed that helps defenders hunt, block, and correlate active command-and-control servers by framework type.

4.3/5 free

crt.sh

Network Recon

Passive certificate transparency searches uncover subdomains and related infrastructure before you ever touch the target.

4.3/5 free

DorkSearch

Network Recon

889,000+ pre-built Google dorks with an AI dork builder for instant recon

4.3/5 free

Awesome Lists (mthcht)

Threat Intelligence

A blue-team-first security directory that helps SOC and CTI teams find relevant feeds, rule sources, and detection references without wading through offensive tooling.

4.3/5 free

OpenCTI

Threat Intelligence

Store, correlate, and visualize structured threat intelligence using STIX2 as the native data model — with a 150+ connector ecosystem and graph-based investigation workflows designed for serious TI programs.

4.3/5 free

Web Check

Network Recon

Paste a URL and get DNS records, SSL details, security headers, tech stack, WHOIS, and 100+ more domain intelligence checks in a single browser view — in under thirty seconds.

4.3/5 free

WorldMonitor

Geospatial

Correlated multi-domain intelligence across conflicts, maritime, aviation, infrastructure, finance, and climate on a single open source map surface.

4.3/5 free

BuiltWith

Network Recon

Technology intelligence — find what any website is built with and who else uses it

4.2/5 freemium

IntelOwl

Threat Intelligence

Orchestrate IOC enrichment across 100+ threat intelligence sources through a single API — with automated multi-hop correlation and direct output to MISP, OpenCTI, or DFIR-IRIS.

4.2/5 free

ProtonVPN

Identity Investigation

Swiss-based VPN with open-source client and strong jurisdiction for journalists and investigators

4.2/5 freemium

SpiderFoot

Network Recon

Map a target's full digital footprint automatically — domains, IPs, emails, names, and ASNs across 500+ sources.

4.2/5 freemium

Sucuri

Network Recon

Website security platform used by investigators to analyze site integrity, malware, and CDN infrastructure

4.2/5 freemium

Awesome Incident Response

Threat Intelligence

A categorized DFIR directory that helps responders discover forensic, malware, and case-management tools with added adoption signals from GitHub metadata.

4.1/5 free

Censys

Network Recon

Internet-wide scanner with certificate transparency coverage no other tool matches.

4.1/5 freemium

cyberbro

Threat Intelligence

A paste-and-submit IOC triage tool that extracts indicators from messy text and checks their reputation across multiple CTI services.

4.1/5 free

FOFA

Network Recon

A web-focused internet asset search engine that helps analysts pivot from one exposed fingerprint to broader infrastructure quickly.

4.1/5 free

GrayHatWarfare

Network Recon

Find exposed cloud storage faster by searching indexed public S3 buckets and blob containers tied to real targets.

4.1/5 free

Hudson Rock

Threat Intelligence

Infostealer intelligence platform exposing compromised credentials from malware-infected machines worldwide

4.1/5 freemium

LeakIX

Network Recon

Internet-wide scanner for exposed services and data leaks, with a focus on misconfigured databases and sensitive data exposure

4.1/5 freemium

nomore403

Network Recon

A fast 403 bypass automation tool that turns forbidden content discovery results into systematically tested access-control edge cases.

4.1/5 free

NordVPN

Identity Investigation

Encrypted tunnel and threat protection for OSINT investigators working in hostile environments

4.1/5 paid

openSquat

Threat Intelligence

An open source monitoring tool that helps defenders catch brand lookalike domains before phishing campaigns go live.

4.1/5 free

Ransomware Tool Matrix

Threat Intelligence

A group-centric ransomware reference that helps defenders translate gang attribution into concrete tools, hunt leads, and detection priorities.

4.1/5 free

reconFTW

Network Recon

A full-scope domain recon framework that chains proven CLI tools into one repeatable workflow for broad attack surface discovery.

4.1/5 free

Recorded Future

Threat Intelligence

The leading threat intelligence platform for enterprise security teams

4.1/5 enterprise

Surfshark

Identity Investigation

VPN with built-in identity monitoring and anonymous browsing identity tools

4.1/5 paid

WiGLE

Geospatial

Crowdsourced wireless network database mapping billions of Wi-Fi, Bluetooth, and cell networks globally

4.1/5 free

YARD Stick One

Network Recon

Sub-1 GHz wireless transceiver for 433/868 MHz IoT, key fob, and industrial protocol analysis — the dedicated tool for the RF bands that run smart devices.

4.1/5 paid

Awesome Forensics

Threat Intelligence

A curated DFIR resource directory that helps investigators find relevant forensic tools quickly when unfamiliar evidence types appear.

4/5 free

cariddi

Network Recon

A fast Go web crawler that plugs cleanly into recon pipelines to uncover endpoints, JavaScript URLs, and exposed secrets at scale.

4/5 free

DFIRTrack

Threat Intelligence

A focused incident response tracking app that helps teams manage systems, artifacts, tasks, and timelines without relying on spreadsheets.

4/5 free

discover

Network Recon

A Kali-native bash automation wrapper that speeds up standard recon, scanning, and payload generation without forcing you into a heavyweight framework.

4/5 free

IVRE

Network Recon

Turn your Nmap and Masscan output into a persistent, queryable network intelligence database with Shodan-style query capabilities against your own infrastructure.

4/5 free

mihari

Threat Intelligence

A rule-driven OSINT hunting engine that automates recurring infrastructure queries and alerts only on what is newly discovered.

4/5 free

NordPass

Identity Investigation

Password manager with breach monitoring built for secure credential hygiene

4/5 freemium

Open Source Threat Intel Feeds

Threat Intelligence

A practical reference directory for finding, comparing, and operationalizing free IOC feeds across MISP, SIEM, and enrichment pipelines.

4/5 free

Pulsedive

Threat Intelligence

Community-driven threat intelligence platform with enriched IOC data and free analyst-grade lookups

4/5 freemium

SEMrush

Network Recon

Competitive intelligence and web footprint analysis for digital investigators

4/5 freemium

Sploitus

Threat Intelligence

A centralized exploit search engine that helps analysts check public exploit availability across multiple sources in one place.

4/5 free

Adalanche

Network Recon

A single-binary Active Directory graph tool that helps operators find ACL-driven escalation paths without standing up a separate graph database.

3.9/5 free

Avilla Forensics

Threat Intelligence

A free Android forensic utility that simplifies ADB-based extraction and app analysis for investigators without a commercial mobile suite.

3.9/5 free

Hacking Tools (aw-junaid)

Network Recon

A multi-language security tool collection that helps researchers study how offensive and analysis utilities are built across different ecosystems.

3.9/5 free

Criminal IP

Network Recon

IP and domain scanner that scores addresses by malicious activity and maps CVEs to exposed service banners.

3.9/5 freemium

deepdarkCTI

Threat Intelligence

A structured reference of dark web and deep web CTI sources — ransomware tracking sites, IOC feeds, paste monitors, and threat actor Telegram channels — organized for feed coverage auditing.

3.9/5 free

Findomain

Network Recon

A fast passive subdomain enumerator that adds built-in monitoring, history, and alerting for newly exposed assets.

3.9/5 free

Netlas

Network Recon

Internet scanning platform with 8 billion+ indexed IP addresses for attack surface and infrastructure analysis

3.9/5 freemium

Norton Small Business

Threat Intelligence

Endpoint protection and threat detection for small OSINT teams and security firms

3.9/5 paid

Recon-ng

Network Recon

CLI-based web reconnaissance framework modeled after Metasploit

3.9/5 free

theHarvester

Network Recon

Passively harvest emails, subdomains, and hostnames from public sources before you touch a single target system.

3.9/5 free

metabigor

Network Recon

A zero-configuration ASN and network scope discovery tool that helps hunters map organizational IP space without API setup.

3.8/5 free

Mitaka

Threat Intelligence

A browser extension that turns highlighted indicators into instant OSINT and threat intelligence lookups without breaking analyst flow.

3.8/5 free

SecurityTrails

Network Recon

Historical DNS and domain intelligence database covering 10+ years of infrastructure changes

3.8/5 freemium

TorBot

Threat Intelligence

A Tor-routed OSINT crawler that helps analysts map .onion infrastructure, collect contact details, and preserve volatile dark web content.

3.8/5 free

GreyNoise

Network Recon

Internet noise classifier that separates mass-scanning background traffic from targeted activity so you can stop chasing ghosts in your SIEM.

3.7/5 freemium

Onyphe

Threat Intelligence

Cyber defense search engine indexing internet-wide scan data, threat intelligence feeds, and passive DNS

3.7/5 freemium

sitedorks

Network Recon

Run the same dork across multiple search engines and target site collections without rebuilding every query by hand.

3.6/5 free

Maltego

Network Recon

The gold standard for visual link analysis and OSINT pivoting

3.5/5 freemium

ZoomEye

Network Recon

Chinese-operated internet search engine for cyberspace — maps exposed services and devices globally

3.5/5 freemium