r/osinttools

Image 1 — OPEN SOURCE INTELLIGENCE CENTER
Image 2 — OPEN SOURCE INTELLIGENCE CENTER
Image 3 — OPEN SOURCE INTELLIGENCE CENTER
Image 4 — OPEN SOURCE INTELLIGENCE CENTER
▲ 69 r/osinttools+2 crossposts

OPEN SOURCE INTELLIGENCE CENTER

It's called OSIRIS.

You open a 3D globe in your browser and see, in real time:

→ +10,000 planes in the air
→ +2,000 satellites
→ CCTV cameras from around the world
→ fires, earthquakes, maritime traffic
→ 13 active conflict zones

all on a single screen.

and it doesn't stop there.

it comes with an OSINT toolkit inside:
port scanner, DNS, WHOIS, domain analysis.

This is:

→ open source
→ MIT
→ docker compose up
→ ready

most sources work without entering even a single API key.

why it matters to you:

the kind of intelligence that governments used to have exclusively...

now you can set it up on your laptop in 5 minutes.

ideal for journalism, security, or verification.

Live Site : https://osirisai.live/

Github : https://github.com/simplifaisoul/osiris

u/Gold-Comfortable-340 — 22 hours ago
▲ 26 r/osinttools+4 crossposts

I built my childhood dream: an open-source intelligence workspace inspired by platforms like Palantir

Ever since I was a kid, I was fascinated by spy movies, hacker movies, and the huge intelligence maps you always saw on screen.

As I got older, I realized there are real platforms that solve similar problems, but they're generally proprietary and out of reach for most developers.

I kept wondering what an open-source version could look like.

So over the past few weeks I've been building Akashic.

Akashic is a self-hosted intelligence workspace that brings together aircraft, satellites, earthquakes, weather, public radio, infrastructure, country intelligence, public cameras, and other OSINT sources onto a single interactive map.

The goal isn't to replace every existing service.

It's to make exploration easier.

Instead of switching between multiple websites, you can combine layers, inspect entities directly on the map, and correlate information from different public sources in one workspace.

Current highlights:

• Open source (MIT)

• Self-hosted

• No mandatory API keys

• Built in public

This is still an early project, so I'd genuinely appreciate feedback on the direction, missing features, or things you'd like to see.

GitHub:

https://github.com/caviraoss/akashic

Demo:

https://www.youtube.com/watch?v=qsWHhuIwR8c

u/nullure — 1 day ago

mapped every public camera and sensor feed I could find. Free, no login, AGPL. Would like it torn apart.

I'm a CS student and I've spent the last few months building this.

It's a live map of public sensor feeds, the stuff governments already publish and almost nobody reads, because it comes out as XML on a page from 2011.

It's free, there's no account, no API key and nothing to install. The source is AGPL-3.0 and public:

https://provenance-online.vercel.app/ https://github.com/011-sam-110/Provenance

What's actually on it right now (measured today, these numbers move quickly as I continue to work on it):

- 19,748 road cameras: across 12 networks: Castle Rock 511 (13,136), Oregon TripCheck (1,141), DriveBC (1,060), TfL London (882), Caltrans (863), Finland Digitraffic (809), South Carolina DOT (768), Traffic Scotland (415), NZTA (319), Estonia (179), Iceland (165), CET São Paulo (11). Every one sits at its real coordinates, links back to its own source, and shows when it was last sampled.

- 37 signal layers: USGS and EMSC earthquakes, NASA FIRMS active fires, GDACS disaster alerts, NOAA cyclones and space weather, IODA internet outages, 702 TeleGeography submarine cables, UNHCR displacement, GDELT conflict and protest coding, abuse.ch C2 infrastructure, and others. All off by default. You turn on what you want.

The part I actually want feedback on.

I took an earlier build into an OSINT Discord last week and got taken apart, fairly. The short version was: "we've seen hundreds of these, they're all the same project, and we can't rely on the data anyway, because verification is the work". Kind of heart shattering but I'll move on and improve what needs improving.

I don't think a dashboard answers this issue, and I've stopped believing it will. But one thing did come out of it that I've been building around since:

- Observations: a camera frame, an ADS-B ping, a seismometer reading. A machine can be trusted to carry these.

- Interpretations: "this protest is left-wing", "this aircraft is military", "this country is unstable". A machine is bad at these and shouldn't render them at the same visual weight as a fact.

Nearly every complaint I can find about tools in this category is really about the second class being dressed up as the first. So I'm labelling every layer by which one it is, and demoting the ones that are somebody's static claim about a place rather than a live reading. That's the actual project now; the map is just how you look at it.

What's broken right now, so you don't have to find it:

- The aircraft layer is capped, not empty. It's showing 3,000 aircraft against 5,108 available, because I cap the response. It comes from community ADS-B receivers and it's thin outside North America and Europe, so treat the count as a lower bound rather than a world total.

- 4 of the 37 layers need API keys I don't have and sit dormant (ACLED, AIS, ENTSO-E grid load, ReliefWeb). The other 33 are returning data. They're marked, but marked isn't fixed.

It's an upcoming tool rather than a finished one, and I'd rather have criticism than traffic, especially on: whether the observation/interpretation split is the right line to draw, and which feeds I'm obviously missing.

Thanks for any input!

Best,
Sam

https://provenance-online.vercel.app/ https://github.com/011-sam-110/Provenance

u/Practical-Toe5390 — 2 days ago
▲ 1 r/osinttools+1 crossposts

Problème familiaux

J ai actuellement ma nièce une asulescente qui fait connerie sur connerie . J'aimerais trouver un outil pour en savoir plus sans envahir sa vie privée. Histoire d être sur qu'elle soit safe malgré tout

reddit.com
u/Agitated-Angle1793 — 2 days ago

Trying to find information

is there any free ways i can find various informations abt someone based on their usernames, maybe a picture, some keywords, and the country or city, someone i knew personally and i wanna know more stuff abt them

reddit.com
u/iFeelLonely123 — 2 days ago
▲ 178 r/osinttools+31 crossposts

The Seal, Harwich

I was jumped by a group of three men who shouted homophobic slurs at me near their pickup truck outside of The Seal pub in Harwich. Message me if you witnessed the incident or if you have any information.

reddit.com
u/ChadThunderconch — 3 days ago

I built a Hudson Rock / intelx alternative for infostealer & breach OSINT.

I built OathNet because most infostealer intelligence platforms are priced more toward enterprise teams than individual researchers.

The main focus is giving you actual context around an infection instead of only showing credentials.

You can inspect things like:

>infection path
exposed cookie count
domains / subdomains
emails / usernames / IPs
Discord / Steam / Instagram / Twitter IDs
HWID
source metadata

One of the features I wanted most was the original file tree.

You can open a victim and see how the collected artifacts were structured instead of only looking at normalized records.

It also includes normal breach search, so you can pivot between breach data and infostealer data in the same workflow.

I mainly built it for defensive exposure monitoring, OSINT research and security teams trying to understand where their own accounts or infrastructure have been exposed.

Would genuinely like feedback from people who use Hudson Rock, IntelX, or similar stealer-intelligence tools.

What would you add or change?

Criticism, feature ideas, and encouragement are all welcome.

u/Economy-Photograph29 — 2 days ago

# Need help identifying the public footprint of a persistent harasser's phone number

Hi everyone,

I'm looking for advice from people experienced with OSINT, phone-number research, and online harassment investigations.

I've been receiving unwanted contact for several months from the same Mexican phone number through WhatsApp, regular calls, and SMS. The contact is persistent and unwanted, and I'd like to document what is happening and determine whether there is any publicly available information that could help identify the source.

The number is:

+52 5633 003313

So far, I haven't found any reliable public information connecting it to a person, business, or known spam/fraud reports.

I'm not looking to dox anyone or obtain private information. I'm specifically interested in legitimate OSINT methods that could help me:

  • Check public phone-number databases and spam-report sites.
  • Search different international/national formats of the number.
  • Determine whether the number has publicly documented associations.
  • Identify publicly available aliases, businesses, or accounts associated with it, if any.
  • Preserve evidence and establish a timeline of the harassment.
  • Understand what information can legitimately be reported to Mexican authorities or the relevant platforms.

If you have experience investigating phone-number abuse, what OSINT sources or techniques would you recommend?

I'm happy to provide additional context about the messages/calls privately if necessary, but I don't want to publish screenshots containing personal information.

Thanks in advance. I'm mainly looking for ethical, legal OSINT techniques, not private-data hunting

reddit.com
u/Daddycoco666 — 3 days ago
▲ 27 r/osinttools+2 crossposts

OathNet is probably the most underrated IntelX / DeHashed alternative right now

I've known about OathNet since pretty much the start, and I still think a lot of people are sleeping on it.

IntelX has massive numbers, but a lot of the results I've seen are duplicate combo lists and repeated credentials. I don't need the same email showing up 20 times.

OathNet feels much more investigation-focused.

The infostealer side gives you the victim context, machine info, domains, services, identities, metadata and even the original file tree.

You can also pivot through fields like:

>email / username / phone / IP
domain / subdomain
Discord ID / Steam ID / Instagram ID / Twitter ID
HWID
service / OS
social + gaming identifiers

I mainly use it to monitor my own emails and accounts I manage through my agency, so I can catch exposed credentials early and rotate them before they become a security issue.

I'm on Pro and honestly it's more than enough for my use case. Paying around $30/mo instead of €2.5K/year for IntelX Researcher is a huge relief.

Their cheapest plan costs only $9.99/mo.

They're also running an anniversary promo right now with 30% off, so the plans are even cheaper at the moment, which is kind of insane for what you get. psst the coupon name is : ANIV30

I'll attach a few screenshots of the stealer view + file tree because that's the part that sold me.

I forgot to mention that it shows the amount of exposed cookies and the infection path, from where the infostealer was ran from.

This is the filetree view which is absolutely insane

https://preview.redd.it/nd20ayu3stjh1.jpg?width=2515&format=pjpg&auto=webp&s=b10517c3d5bbcd5b8537fac541ded46b569e7099

screenshots from : oathnet.org

reddit.com
u/SubstantialArtist948 — 3 days ago
▲ 1 r/osinttools+1 crossposts

I built a networks scanner with ssh.

https://apps.apple.com/us/app/network-scan-wi-fi-ssh/id6790997366

It scans your local network and shows:
Connected devices and IP addresses
Open ports and likely device types
Ping, DNS and port-scanning tools
Continuous device monitoring
When you find the machine you need, you can open a real interactive SSH terminal directly from its device page. It supports tools such as htop, vim, docker stats, Claude Code and Codex, along with multiple simultaneous terminal sessions.

u/Maximum_Selection696 — 3 days ago
▲ 5 r/osinttools+4 crossposts

Looking for an OSINT community?

Breadcrumbs is a community for open-source research and OSINT enthusiasts — from total beginners to seasoned researchers. Learn techniques, share tools, and follow the trail together. Strict zero-tolerance policy on targeting private individuals.

discord.gg
u/StudyNo2866 — 3 days ago

Twitter help

Hey all,

I'm looking for some advice as I've gone down an Osint loophole and wanted to know if it was possible finding out someone's identity through a "burner" account on Twitter. They're saying some really nasty things and I've had enough if I'm being honest. I have a feeling it's a former friend as they have a habit of only messaging me?

Does anyone know how I'd be able to find out their information their name or the area they live in at least? I don't even need their full address but at least with that I can breakdown the list of potential suspects and report them. I've even tried the 'forgot your password' route and it's a burner email. All ideas welcome, thanks a bunch.

reddit.com
u/MarionberryUsual8799 — 3 days ago
▲ 31 r/osinttools+1 crossposts

I built an OSINT tool for monitoring X accounts in real time

Hey,

I'm of Iranian descent and got tired of constantly refreshing X to keep up with the Middle East while working. So ~6 months ago I built a little desktop app that sits on top of my screen and streams posts from the accounts I pick, in real time with no X account needed. It just sits in a corner so I can keep half an eye on things while doing other stuff.

I put it online (sentinelxapp.com) in case it's useful to anyone else. It's a paid app but there's a free trial. Clip of it running is attached, happy to answer anything!

u/unknownsb12 — 4 days ago

Openarchive OSINT

OpenArchiveX — A unified search platform for OSINT research

Hey r/OSINT,

We’ve been working on OpenArchiveX, a platform designed to make OSINT investigations faster by bringing multiple data sources and research tools together in one place.

Currently, OpenArchiveX offers:

  • 🔎 Search across 60+ OSINT sources
  • 🧩 Pivoting between different identifiers
  • 🌐 Search using IPs, domains, usernames, emails, and other identifiers
  • 🗃️ 950B+ records available for searching
  • 🛠️ A growing collection of OSINT research tools
  • 🔌 API access for automation and integrations

The goal is to reduce the need to jump between dozens of different services during an investigation and make the research workflow more efficient.

Check it out here:
https://openarchivex.com/

We’d especially appreciate feedback from active OSINT researchers. What sources, features, or integrations would you like to see added?

Feedback and criticism are both welcome.

u/ImpressiveMaize1532 — 4 days ago
▲ 5 r/osinttools+3 crossposts

I built augur, the tool for finding hidden symbols across your documents

https://reddit.com/link/1vq8cyg/video/btfopmmbvsjh1/player

I built Augur, an open-source tool for seeing what is actually hidden inside a file.

It finds things like zero-width characters and hidden instructions, Trojan Source / bidi controls, mixed-script homoglyphs, EXIF and GPS metadata, C2PA manifests, and data appended after an image.

It can also write a cleaned copy without modifying the original or recompressing the image, then scans the result again to verify the selected stuff is actually gone.

Video shows the real thing - the demo files are generated by a script in the repo, including everything Augur then detects.

https://github.com/dejo1307/augur

reddit.com
u/fairwaycoder — 4 days ago

I mapped every public camera and sensor feed I could find. Free, no login, AGPL. Would like it torn apart.

I'm a CS student and I've spent the last few months building this.

It's a live map of public sensor feeds, the stuff governments already publish and almost nobody reads, because it comes out as XML on a page from 2011.

It's free, there's no account, no API key and nothing to install. The source is AGPL-3.0 and public:

https://provenance-online.vercel.app/ https://github.com/011-sam-110/Provenance

What's actually on it right now (measured today, these numbers move quickly as I continue to work on it):

- 19,748 road cameras: across 12 networks: Castle Rock 511 (13,136), Oregon TripCheck (1,141), DriveBC (1,060), TfL London (882), Caltrans (863), Finland Digitraffic (809), South Carolina DOT (768), Traffic Scotland (415), NZTA (319), Estonia (179), Iceland (165), CET São Paulo (11). Every one sits at its real coordinates, links back to its own source, and shows when it was last sampled.

- 37 signal layers: USGS and EMSC earthquakes, NASA FIRMS active fires, GDACS disaster alerts, NOAA cyclones and space weather, IODA internet outages, 702 TeleGeography submarine cables, UNHCR displacement, GDELT conflict and protest coding, abuse.ch C2 infrastructure, and others. All off by default. You turn on what you want.

The part I actually want feedback on.

I took an earlier build into an OSINT Discord last week and got taken apart, fairly. The short version was: "we've seen hundreds of these, they're all the same project, and we can't rely on the data anyway, because verification is the work". Kind of heart shattering but I'll move on and improve what needs improving.

I don't think a dashboard answers this issue, and I've stopped believing it will. But one thing did come out of it that I've been building around since:

- Observations: a camera frame, an ADS-B ping, a seismometer reading. A machine can be trusted to carry these.

Interpretations: "this protest is left-wing", "this aircraft is military", "this country is unstable". A machine is bad at these and shouldn't render them at the same visual weight as a fact.

Nearly every complaint I can find about tools in this category is really about the second class being dressed up as the first. So I'm labelling every layer by which one it is, and demoting the ones that are somebody's static claim about a place rather than a live reading. That's the actual project now; the map is just how you look at it.

What's broken right now, so you don't have to find it:

- The aircraft layer is capped, not empty. It's showing 3,000 aircraft against 5,108 available, because I cap the response. It comes from community ADS-B receivers and it's thin outside North America and Europe, so treat the count as a lower bound rather than a world total.

- 4 of the 37 layers need API keys I don't have and sit dormant (ACLED, AIS, ENTSO-E grid load, ReliefWeb). The other 33 are returning data. They're marked, but marked isn't fixed.

It's an upcoming tool rather than a finished one, and I'd rather have criticism than traffic, especially on: whether the observation/interpretation split is the right line to draw, and which feeds I'm obviously missing.

Thanks for any input!

https://provenance-online.vercel.app/ https://github.com/011-sam-110/Provenance

u/Impossible-Dare-4638 — 7 days ago