Skip to content
Citizens Transparency Institute
Research desk

Resource library + OSINT field manual

Official starting points, specialist research services, and 224 documented OSINT tools with worked procedures.

Verified entry points
75 institutional + civic resources

Start with the record system closest to the fact.

Government and official sources are labeled. Independent tools are useful for discovery and analysis, but consequential findings should be traced to the originating filing, dataset, case, post, transaction, image, or record whenever possible.

75 matching resourcesProcedures and links change; verify at time of use

FOIA.gov

Public records· Federal· Official

Find the correct federal agency, learn the federal process, search existing releases, and begin a request.

FOIA request wizard

Public records· Federal· Official

A guided federal tool for identifying the agency likely to hold the records you need.

DOJ Office of Information Policy

Public records· Federal· Official

Federal FOIA policy, guidance, reports, training materials, and agency compliance resources.

National Archives

Public records· Federal· Official

Research permanently valuable federal records, military service files, historical records, and archival catalogs.

California Public Records Act guide

Public records· California· Official

California DOJ guidance on access to state and local agency records under the CPRA.

California open-government resources

Public records· California· Official

State resources covering the Public Records Act, Brown Act, and Bagley-Keene open-meeting law.

MuckRock

Public records· General· Independent

Independent request filing, tracking, document hosting, and public examples from other requesters.

Access note: Some services require payment.

Reporters Committee Open Government Guide

Public records· General· Independent

State-by-state access-law and open-meetings reference prepared for journalists and the public.

City of Oakland public records

Bay Area· Local· Official

Search prior releases, find departmental liaisons, submit Oakland requests, and check request status.

Oakland public-records mediation

Bay Area· Local· Official

Ask the Oakland Public Ethics Commission to mediate a disputed or delayed city records request.

Oakland OPD records

Bay Area· Local· Official

Request Oakland Police Department reports and other records through the listed portal and records unit.

Oakland legislation and meetings

Bay Area· Local· Official

Search agendas, minutes, staff reports, legislation, votes, and meeting video for City Council and committees.

Oakland campaign finance

Money & influence· Local· Official

Search Oakland campaign statements, committees, donors, expenditures, and elected-official filings.

Oakland open data

Bay Area· Local· Official

City datasets covering service requests, public safety, infrastructure, budgets, permits, and other operations.

Alameda County services and records

Bay Area· Regional· Official

Directory for county public records, property taxes, purchasing events, permits, and service systems.

Alameda County Clerk-Recorder

Companies & property· Regional· Official

Locate and order recorded deeds, liens, fictitious business names, and other official county records.

Alameda County Superior Court records

Courts & law· Regional· Official

Search available civil, criminal, family, probate, and traffic case information for Alameda County.

San Francisco public records

Bay Area· Local· Official

Find departmental portals and procedures for requesting San Francisco city and county records.

San Francisco legislation

Bay Area· Local· Official

Search Board of Supervisors agendas, files, votes, minutes, and supporting documents.

BART public records

Bay Area· Regional· Official

Request records from the Bay Area Rapid Transit District and review access instructions.

Metropolitan Transportation Commission open data

Bay Area· Regional· Official

Regional transportation, land-use, housing, equity, and planning datasets for the Bay Area.

Bay Area Air Quality data

Bay Area· Regional· Official

Official regional air-monitoring measurements and station information.

California State Controller public pay

Money & influence· California· Official

Search compensation reported by California cities, counties, special districts, and public employers.

California State Auditor

Government data· California· Official

Search state and local audit reports, high-risk findings, recommendations, and follow-up status.

California open data

Government data· California· Official

Statewide datasets published by California departments and agencies.

California Secretary of State business search

Companies & property· California· Official

Search corporations, LLCs, limited partnerships, statements of information, and filing status.

California campaign finance search

Money & influence· California· Official

Search state campaign committees, contributions, expenditures, lobbying, and financial disclosures.

California courts case information

Courts & law· California· Official

Official guidance and links for finding California state court case information by county.

California legislation

Courts & law· California· Official

Search bills, votes, analyses, committee materials, statutes, and the California Constitution.

Data.gov

Government data· Federal· Official

Search the federal government's catalog of datasets, APIs, and agency data resources.

USAspending

Money & influence· Federal· Official

Trace federal awards, contracts, grants, loans, recipients, agencies, places, and spending accounts.

SAM.gov contract opportunities

Money & influence· Federal· Official

Search federal solicitations, contract opportunities, notices, exclusions, and entity registrations.

Federal Audit Clearinghouse

Money & influence· Federal· Official

Search Single Audit submissions for governments and nonprofit recipients of federal awards.

Federal Election Commission

Money & influence· Federal· Official

Search federal candidates, committees, donors, receipts, spending, filings, and enforcement matters.

SEC EDGAR

Companies & property· Federal· Official

Search public-company filings, ownership reports, exhibits, financial statements, and enforcement disclosures.

Federal Register

Government data· Federal· Official

Search proposed and final rules, notices, executive documents, and public-comment deadlines.

Regulations.gov

Government data· Federal· Official

Search federal rulemaking dockets, supporting documents, agency comments, and public submissions.

Congress.gov

Government data· Federal· Official

Search federal bills, votes, committee reports, hearings, nominations, and the Congressional Record.

GovInfo

Government data· Federal· Official

Authenticated publications from all three branches of the federal government.

U.S. Census data

Government data· Federal· Official

Population, housing, economic, demographic, and geographic tables from Census programs.

Government Accountability Office

Government data· Federal· Official

Federal audits, evaluations, legal decisions, recommendations, and agency implementation status.

Council of the Inspectors General

Government data· Federal· Official

Directory of federal inspectors general for audits, investigations, hotlines, and oversight reports.

PACER

Courts & law· Federal· Official

Nationwide federal appellate, district, and bankruptcy case locator and docket system.

Access note: Registration required; fees may apply, subject to exemptions and quarterly waiver rules.

CourtListener and RECAP

Courts & law· Federal· Independent

Free independent search for opinions, oral arguments, judges, and many federal docket documents collected through RECAP.

Supreme Court opinions

Courts & law· Federal· Official

Official opinions, orders, calendars, transcripts, audio, docket information, and rules.

Internet Archive Wayback Machine

OSINT tools· General· Independent

Retrieve archived versions of public web pages and preserve a dated public webpage snapshot.

Google advanced search

OSINT tools· General· Independent

Constrain public-web searches by exact phrase, domain, file type, excluded words, language, and date.

Google Lens

OSINT tools· General· Independent

Reverse-search public images and examine visually similar or previously published material.

TinEye

OSINT tools· General· Independent

Reverse image search focused on prior appearances, modified copies, and publication history.

InVID verification plugin

OSINT tools· General· Independent

Browser tools for extracting video keyframes and supporting image and video verification work.

ICANN Registration Data Lookup

OSINT tools· General· Independent

Search public domain-registration data, registrar details, nameservers, and registration dates.

OpenStreetMap

OSINT tools· General· Independent

Open geographic data for streets, buildings, land uses, infrastructure, and map-based verification.

Mapillary

OSINT tools· General· Independent

Crowdsourced street-level imagery that can help establish place conditions and visual chronology.

SunCalc

OSINT tools· General· Independent

Check historical sun position and shadows when verifying the likely time or orientation of imagery.

ExifTool

OSINT tools· General· Independent

Inspect metadata embedded in files you lawfully possess; preserve originals because platforms often strip metadata.

AnnualCreditReport.com

Credit & identity· Federal· Official

The federally authorized source for free reports from Equifax, Experian, and TransUnion.

CFPB credit-report dispute guide

Credit & identity· Federal· Official

Steps for disputing inaccurate information with both the reporting company and the data furnisher.

CFPB dispute sample letters

Credit & identity· Federal· Official

Downloadable letters for disputes to consumer reporting companies and information furnishers.

CFPB consumer-reporting company list

Background reports· Federal· Official

Request and dispute specialty reports covering tenants, employment, insurance, banking, utilities, and more.

FTC credit freezes and fraud alerts

Credit & identity· Federal· Official

Official instructions for freezing credit files and placing fraud alerts after identity-theft risk.

IdentityTheft.gov

Credit & identity· Federal· Official

Create a recovery plan, report identity theft, and generate letters and documentation for creditors.

California consumer privacy rights

Credit & identity· California· Official

Learn how covered businesses must handle California requests to know, delete, correct, limit, or opt out of certain uses of personal information.

HHS right of access to health records

Credit & identity· Federal· Official

Federal guidance for inspecting, obtaining, and requesting corrections to health information covered by HIPAA.

California DMV driver record

Background reports· California· Official

Request your California driver record and review the official history maintained by DMV.

ChexSystems consumer disclosure

Background reports· General· Independent

Request the checking-account consumer report used by many banks and credit unions.

LexisNexis consumer disclosure

Background reports· General· Independent

Request a personal disclosure containing public-record and consumer-reporting information held by LexisNexis Risk Solutions.

The Work Number employment data report

Background reports· General· Independent

Request employment and income information maintained by Equifax Workforce Solutions about you.

NCTUE consumer report

Background reports· General· Independent

Request or freeze telecommunications, pay-TV, and utility exchange information associated with you.

MIB consumer file

Background reports· General· Independent

Request the medical-information report used in some life, health, disability, and long-term-care underwriting.

FBI Identity History Summary

Background reports· Federal· Official

Request your own FBI identity-history summary and learn how to challenge inaccurate federal criminal-history information.

Access note: Fingerprint submission and fee generally required; waiver instructions are available.

California DOJ record review

Background reports· California· Official

Request a copy of your California criminal-history record and challenge errors or omissions.

FTC employment background checks

Background reports· Federal· Official

Understand notice, authorization, disclosure, and adverse-action rights when employers use background reports.

California Civil Rights Department fair chance guidance

Background reports· California· Official

California rights and complaint options concerning criminal-history questions and employment decisions.

Social Security earnings record

Credit & identity· Federal· Official

Review the earnings history used to calculate Social Security benefits and report errors.

IRS tax transcripts

Credit & identity· Federal· Official

Retrieve official tax-return, account, wage-and-income, and verification-of-nonfiling transcripts.

CTI / OSINT field manual
224 indexed tools · instructions included

The tool is never the finding.

Every entry begins with the proper starting identifier, gives a worked example, and then lays out a reproducible sequence for collection, corroboration, evidence preservation, and safe use. Availability, pricing, APIs, and platform access can change; CTI treats status as something to verify at the time of use.

224 resultsPublic sources only · verify current status before use
001

OSINT Framework

WebPassive

Hierarchical directory that organizes OSINT resources by the kind of identifier or question you have.

Meta-resources & frameworksFree
Open procedure +
Start with

A target type such as username, email, domain, image, IP, company, or location

Worked example

Start with a domain name, choose the Domain Name branch, then move through WHOIS, certificate, archive, and technology lookups while logging each source separately.

Open official/project site
Step-by-step use
  1. 01

    Write the research question before opening OSINT Framework. Start with: A target type such as username, email, domain, image, IP, company, or location.

  2. 02

    Choose the branch or category that matches the identifier you actually possess; do not browse randomly for a person.

  3. 03

    Shortlist two or three relevant tools and note whether each is an original data source, an index, or another directory.

  4. 04

    Open the underlying source directly and test the same fact with an independent source before treating it as corroborated.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. OSINT Framework is a lead source unless the underlying record itself is authoritative.

002

Awesome OSINT

WebPassive

Large community-maintained GitHub index of open-source intelligence resources.

Meta-resources & frameworksFree / open source
Open procedure +
Start with

A research category or missing capability

Worked example

If a case needs vessel tracking, search the repository for maritime or transportation resources, compare the listed tools, then open the primary source rather than treating the directory itself as evidence.

Open official/project site
Step-by-step use
  1. 01

    Write the research question before opening Awesome OSINT. Start with: A research category or missing capability.

  2. 02

    Choose the branch or category that matches the identifier you actually possess; do not browse randomly for a person.

  3. 03

    Shortlist two or three relevant tools and note whether each is an original data source, an index, or another directory.

  4. 04

    Open the underlying source directly and test the same fact with an independent source before treating it as corroborated.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Awesome OSINT is a lead source unless the underlying record itself is authoritative.

003

Awesome OSINT Arsenal

MixedPassive

Broad tool inventory oriented toward Linux-based investigative and security workflows.

Meta-resources & frameworksFree / open source
Open procedure +
Start with

A Linux workstation and an investigation category

Worked example

Use the category index to identify username tools, review each project's repository before installation, then test only against identifiers you are authorized to research.

Open official/project site
Step-by-step use
  1. 01

    Write the research question before opening Awesome OSINT Arsenal. Start with: A Linux workstation and an investigation category.

  2. 02

    Choose the branch or category that matches the identifier you actually possess; do not browse randomly for a person.

  3. 03

    Shortlist two or three relevant tools and note whether each is an original data source, an index, or another directory.

  4. 04

    Open the underlying source directly and test the same fact with an independent source before treating it as corroborated.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Awesome OSINT Arsenal is a lead source unless the underlying record itself is authoritative.

004

Bellingcat Online Investigation Toolkit

WebPassive

Journalism-focused collection of verification, geolocation, social, transport, archival, and data tools.

Meta-resources & frameworksFree / mixed
Open procedure +
Start with

An investigation question involving images, maps, people, companies, transport, archives, or conflict

Worked example

For a geolocation problem, open the Maps & Satellites section, select street-view and satellite sources, then document which visual landmarks support or contradict the proposed location.

Open official/project site
Step-by-step use
  1. 01

    Write the research question before opening Bellingcat Online Investigation Toolkit. Start with: An investigation question involving images, maps, people, companies, transport, archives, or conflict.

  2. 02

    Choose the branch or category that matches the identifier you actually possess; do not browse randomly for a person.

  3. 03

    Shortlist two or three relevant tools and note whether each is an original data source, an index, or another directory.

  4. 04

    Open the underlying source directly and test the same fact with an independent source before treating it as corroborated.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Bellingcat Online Investigation Toolkit is a lead source unless the underlying record itself is authoritative.

005

SpiderFoot

MixedPassive

Automated OSINT collection and correlation framework with a large module ecosystem.

Meta-resources & frameworksOpen source / commercial
Open procedure +
Start with

A domain, IP, email, username, organization, or other authorized seed

Worked example

Create a passive scan for an organization domain, disable modules that would make active requests if the target is not yours, then review the relationship graph and validate every high-value finding at the original source.

Open official/project site
Step-by-step use
  1. 01

    Create a case/workspace for one defined question and seed it with A domain, IP, email, username, organization, or other authorized seed.

  2. 02

    Configure passive/public-source modules first. Disable intrusive, authenticated, or active modules unless the target is explicitly authorized.

  3. 03

    Run the smallest useful collection in SpiderFoot; review which source produced each returned entity or relationship.

  4. 04

    Manually open high-value results and remove false positives, stale data, shared-name collisions, and unsupported automated correlations.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. SpiderFoot is a lead source unless the underlying record itself is authoritative.

006

Maltego

DesktopPassive

Graph-based link analysis platform for organizing entities, relationships, and transform results.

Meta-resources & frameworksFree community / commercial
Open procedure +
Start with

A seed entity such as a domain, organization, person, email, or crypto address

Worked example

Place a company domain on a graph, run passive transforms for DNS and public company data, separate generated leads from verified nodes, and attach source URLs to the facts you keep.

Open official/project site
Step-by-step use
  1. 01

    Create a case/workspace for one defined question and seed it with A seed entity such as a domain, organization, person, email, or crypto address.

  2. 02

    Configure passive/public-source modules first. Disable intrusive, authenticated, or active modules unless the target is explicitly authorized.

  3. 03

    Run the smallest useful collection in Maltego; review which source produced each returned entity or relationship.

  4. 04

    Manually open high-value results and remove false positives, stale data, shared-name collisions, and unsupported automated correlations.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Maltego is a lead source unless the underlying record itself is authoritative.

007

Recon-ng

CLIPassive

Modular reconnaissance framework with workspaces, modules, and reporting.

Meta-resources & frameworksFree / open source
Open procedure +
Start with

Authorized domains, organizations, contacts, or locations

Worked example

Create a workspace for your own organization, add the corporate domain, choose passive discovery modules, store results in the workspace database, and export only findings you manually validate.

Open official/project site
Step-by-step use
  1. 01

    Create a case/workspace for one defined question and seed it with Authorized domains, organizations, contacts, or locations.

  2. 02

    Configure passive/public-source modules first. Disable intrusive, authenticated, or active modules unless the target is explicitly authorized.

  3. 03

    Run the smallest useful collection in Recon-ng; review which source produced each returned entity or relationship.

  4. 04

    Manually open high-value results and remove false positives, stale data, shared-name collisions, and unsupported automated correlations.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Recon-ng is a lead source unless the underlying record itself is authoritative.

008

theHarvester

CLIPassive

Classic passive discovery tool for emails, names, hosts, subdomains, and related public data.

Meta-resources & frameworksFree / open source
Open procedure +
Start with

A domain you are authorized to research

Worked example

Run a passive search against your organization's domain using supported public data sources, review discovered emails and subdomains, then verify them directly before treating them as current.

Open official/project site
Step-by-step use
  1. 01

    Create a case/workspace for one defined question and seed it with A domain you are authorized to research.

  2. 02

    Configure passive/public-source modules first. Disable intrusive, authenticated, or active modules unless the target is explicitly authorized.

  3. 03

    Run the smallest useful collection in theHarvester; review which source produced each returned entity or relationship.

  4. 04

    Manually open high-value results and remove false positives, stale data, shared-name collisions, and unsupported automated correlations.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. theHarvester is a lead source unless the underlying record itself is authoritative.

009

IntelTechniques

WebPassive

Investigation resources, search utilities, and training materials centered on practical OSINT.

Meta-resources & frameworksFree / paid training
Open procedure +
Start with

A defined identifier or investigative problem

Worked example

Use the search-tools pages to pivot from a known username into search engines and public profiles, then preserve direct source links rather than citing the aggregator.

Open official/project site
Step-by-step use
  1. 01

    Write the research question before opening IntelTechniques. Start with: A defined identifier or investigative problem.

  2. 02

    Choose the branch or category that matches the identifier you actually possess; do not browse randomly for a person.

  3. 03

    Shortlist two or three relevant tools and note whether each is an original data source, an index, or another directory.

  4. 04

    Open the underlying source directly and test the same fact with an independent source before treating it as corroborated.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. IntelTechniques is a lead source unless the underlying record itself is authoritative.

010

Cylect.io

WebPassive

AI-assisted OSINT search and correlation environment; verify current product scope before use.

Meta-resources & frameworksService terms vary
Open procedure +
Start with

A research question and public identifiers

Worked example

Create a case with a public identifier, let the service suggest pivots, and manually inspect source provenance before incorporating any correlation into a report.

Status note: Availability and feature set may change.

Open official/project site
Step-by-step use
  1. 01

    Create a case/workspace for one defined question and seed it with A research question and public identifiers.

  2. 02

    Configure passive/public-source modules first. Disable intrusive, authenticated, or active modules unless the target is explicitly authorized.

  3. 03

    Run the smallest useful collection in Cylect.io; review which source produced each returned entity or relationship.

  4. 04

    Manually open high-value results and remove false positives, stale data, shared-name collisions, and unsupported automated correlations.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Cylect.io is a lead source unless the underlying record itself is authoritative.

011

OpenOSINT

MixedPassive

Label used by multiple open-source OSINT projects; confirm the specific implementation before installation.

Meta-resources & frameworksProject-dependent
Open procedure +
Start with

A self-hosted OSINT workflow or agentic research need

Worked example

Confirm which OpenOSINT project or implementation you intend to use, inspect its repository and data handling, then test on non-sensitive public identifiers before production use.

Status note: No single canonical project is assumed by CTI.

Step-by-step use
  1. 01

    Create a case/workspace for one defined question and seed it with A self-hosted OSINT workflow or agentic research need.

  2. 02

    Configure passive/public-source modules first. Disable intrusive, authenticated, or active modules unless the target is explicitly authorized.

  3. 03

    Run the smallest useful collection in OpenOSINT; review which source produced each returned entity or relationship.

  4. 04

    Manually open high-value results and remove false positives, stale data, shared-name collisions, and unsupported automated correlations.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. OpenOSINT is a lead source unless the underlying record itself is authoritative.

012

LinkScope

DesktopPassive

Link-analysis and investigation environment for organizing entities, evidence, and automated collection.

Meta-resources & frameworksFree / open source
Open procedure +
Start with

A collection of entities and public-source relationships

Worked example

Import a CSV of organizations and domains, add publicly documented relationships, run supported collectors, and keep analyst-added facts visually separate from automated suggestions.

Open official/project site
Step-by-step use
  1. 01

    Create a case/workspace for one defined question and seed it with A collection of entities and public-source relationships.

  2. 02

    Configure passive/public-source modules first. Disable intrusive, authenticated, or active modules unless the target is explicitly authorized.

  3. 03

    Run the smallest useful collection in LinkScope; review which source produced each returned entity or relationship.

  4. 04

    Manually open high-value results and remove false positives, stale data, shared-name collisions, and unsupported automated correlations.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. LinkScope is a lead source unless the underlying record itself is authoritative.

013

Sintelix

WebSensitive

Commercial text analytics and intelligence platform for entity extraction and link analysis.

Meta-resources & frameworksCommercial
Open procedure +
Start with

A licensed corpus, investigation, or intelligence project

Worked example

Define the case scope, ingest only authorized datasets, use entity extraction to surface connections, and require analysts to open the underlying documents before reaching conclusions.

Open official/project site
Step-by-step use
  1. 01

    Create a governed case with a defined purpose, authorized users, retention period, and permitted datasets. Starting input: A licensed corpus, investigation, or intelligence project.

  2. 02

    Ingest or query only sources allowed by the organization's license, law, policy, and investigation mandate.

  3. 03

    Use Sintelix's correlation, graph, search, or model features to generate leads, while preserving lineage back to the original record.

  4. 04

    Require human review for consequential identity, risk, or relationship findings and document why an analyst accepted or rejected automated suggestions.

  5. 05

    Export an audit-ready result containing source references, analytical limits, access controls, and correction/retention decisions.

014

Social Links

MixedSensitive

Commercial OSINT platform integrating social, identity, domain, crypto, and other data sources.

Meta-resources & frameworksCommercial
Open procedure +
Start with

A licensed investigation with lawful public-data targets

Worked example

Create a case, begin with a verified public identifier, run only permitted data-source connectors, and document each source and retention decision before exporting findings.

Open official/project site
Step-by-step use
  1. 01

    Create a governed case with a defined purpose, authorized users, retention period, and permitted datasets. Starting input: A licensed investigation with lawful public-data targets.

  2. 02

    Ingest or query only sources allowed by the organization's license, law, policy, and investigation mandate.

  3. 03

    Use Social Links's correlation, graph, search, or model features to generate leads, while preserving lineage back to the original record.

  4. 04

    Require human review for consequential identity, risk, or relationship findings and document why an analyst accepted or rejected automated suggestions.

  5. 05

    Export an audit-ready result containing source references, analytical limits, access controls, and correction/retention decisions.

015

Babel Street

WebSensitive

Commercial public-data discovery and analytics platform.

Meta-resources & frameworksCommercial
Open procedure +
Start with

A licensed public-source monitoring or investigative use case

Worked example

Define approved keywords and geographies, collect public-source results, review false positives manually, and preserve the original publication context for consequential claims.

Open official/project site
Step-by-step use
  1. 01

    Create a governed case with a defined purpose, authorized users, retention period, and permitted datasets. Starting input: A licensed public-source monitoring or investigative use case.

  2. 02

    Ingest or query only sources allowed by the organization's license, law, policy, and investigation mandate.

  3. 03

    Use Babel Street's correlation, graph, search, or model features to generate leads, while preserving lineage back to the original record.

  4. 04

    Require human review for consequential identity, risk, or relationship findings and document why an analyst accepted or rejected automated suggestions.

  5. 05

    Export an audit-ready result containing source references, analytical limits, access controls, and correction/retention decisions.

016

Fivecast

WebSensitive

Commercial OSINT analytics and risk platform.

Meta-resources & frameworksCommercial
Open procedure +
Start with

A licensed risk, security, or public-source intelligence case

Worked example

Set a narrowly defined research objective, configure approved open-source collections, review model-generated indicators as leads, and escalate only after human verification.

Open official/project site
Step-by-step use
  1. 01

    Create a governed case with a defined purpose, authorized users, retention period, and permitted datasets. Starting input: A licensed risk, security, or public-source intelligence case.

  2. 02

    Ingest or query only sources allowed by the organization's license, law, policy, and investigation mandate.

  3. 03

    Use Fivecast's correlation, graph, search, or model features to generate leads, while preserving lineage back to the original record.

  4. 04

    Require human review for consequential identity, risk, or relationship findings and document why an analyst accepted or rejected automated suggestions.

  5. 05

    Export an audit-ready result containing source references, analytical limits, access controls, and correction/retention decisions.

017

Palantir

MixedSensitive

Enterprise data integration and analysis platform; not an OSINT source by itself.

Meta-resources & frameworksCommercial
Open procedure +
Start with

Authorized institutional datasets and a governed investigative question

Worked example

Model the permitted data sources and entities, restrict access by role, trace any analytical claim back to the originating record, and record analyst decisions for auditability.

Open official/project site
Step-by-step use
  1. 01

    Create a governed case with a defined purpose, authorized users, retention period, and permitted datasets. Starting input: Authorized institutional datasets and a governed investigative question.

  2. 02

    Ingest or query only sources allowed by the organization's license, law, policy, and investigation mandate.

  3. 03

    Use Palantir's correlation, graph, search, or model features to generate leads, while preserving lineage back to the original record.

  4. 04

    Require human review for consequential identity, risk, or relationship findings and document why an analyst accepted or rejected automated suggestions.

  5. 05

    Export an audit-ready result containing source references, analytical limits, access controls, and correction/retention decisions.

018

IBM i2

DesktopSensitive

Enterprise intelligence analysis suite for charts, timelines, and relationship analysis.

Meta-resources & frameworksCommercial
Open procedure +
Start with

Authorized case data and public-source entities

Worked example

Create a chart from documented entities, encode relationships with source references, use analysis features to identify patterns, and verify every material relationship against primary evidence.

Open official/project site
Step-by-step use
  1. 01

    Create a governed case with a defined purpose, authorized users, retention period, and permitted datasets. Starting input: Authorized case data and public-source entities.

  2. 02

    Ingest or query only sources allowed by the organization's license, law, policy, and investigation mandate.

  3. 03

    Use IBM i2's correlation, graph, search, or model features to generate leads, while preserving lineage back to the original record.

  4. 04

    Require human review for consequential identity, risk, or relationship findings and document why an analyst accepted or rejected automated suggestions.

  5. 05

    Export an audit-ready result containing source references, analytical limits, access controls, and correction/retention decisions.

019

Sherlock

CLIPassive

Checks a username across many public websites.

Username & account discoveryFree / open source
Open procedure +
Start with

A username or handle

Worked example

Search a public handle such as `oaklandresearcher`, review returned profile URLs, then compare avatar, bio, location, and posting history before deciding two accounts belong to the same person.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username or handle.

  2. 02

    Submit the handle to Sherlock and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Sherlock is a lead source unless the underlying record itself is authoritative.

020

Maigret

CLIPassive

Large-scale username search with metadata and report generation.

Username & account discoveryFree / open source
Open procedure +
Start with

A username, alias, or handle

Worked example

Run a handle across supported sites, export a report, then manually verify high-value matches because shared usernames frequently produce false attribution.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username, alias, or handle.

  2. 02

    Submit the handle to Maigret and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Maigret is a lead source unless the underlying record itself is authoritative.

021

WhatsMyName

WebPassive

Web interface for checking username presence across many services.

Username & account discoveryFree
Open procedure +
Start with

A username

Worked example

Enter a username, open candidate account links, compare dates and profile markers, and record only matches supported by more than the handle itself.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username.

  2. 02

    Submit the handle to WhatsMyName and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. WhatsMyName is a lead source unless the underlying record itself is authoritative.

022

Namechk

WebPassive

Username and domain availability checker that can also surface account leads.

Username & account discoveryFree / freemium
Open procedure +
Start with

A username or brand name

Worked example

Enter a proposed handle, inspect which major services show availability or use, then open the service directly before concluding an account exists.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username or brand name.

  2. 02

    Submit the handle to Namechk and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Namechk is a lead source unless the underlying record itself is authoritative.

023

Namecheckup

WebPassive

Cross-platform username availability and discovery checker.

Username & account discoveryFree
Open procedure +
Start with

A username or brand term

Worked example

Search the handle, use results as a lead list, then verify candidate profiles at the originating platform.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username or brand term.

  2. 02

    Submit the handle to Namecheckup and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Namecheckup is a lead source unless the underlying record itself is authoritative.

024

KnowEm

WebPassive

Username and brand-presence checker across social platforms.

Username & account discoveryFree / commercial
Open procedure +
Start with

A username, brand, or trademark term

Worked example

Search a brand handle, note platforms indicating use, then visit each platform and distinguish active accounts from stale or unrelated registrations.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username, brand, or trademark term.

  2. 02

    Submit the handle to KnowEm and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. KnowEm is a lead source unless the underlying record itself is authoritative.

025

Instant Username Search

WebPassive

Fast multi-site username presence checker.

Username & account discoveryFree
Open procedure +
Start with

A username

Worked example

Enter a handle, scan candidate services, and manually validate any result you intend to cite.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username.

  2. 02

    Submit the handle to Instant Username Search and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Instant Username Search is a lead source unless the underlying record itself is authoritative.

026

CheckUserNames

WebPassive

Username checker across multiple websites.

Username & account discoveryFree
Open procedure +
Start with

A username

Worked example

Check a handle across listed services, then open positive results and compare corroborating profile details.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username.

  2. 02

    Submit the handle to CheckUserNames and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. CheckUserNames is a lead source unless the underlying record itself is authoritative.

027

Blackbird

CLIPassive

OSINT account-discovery tool for usernames and related identifiers.

Username & account discoveryFree / open source
Open procedure +
Start with

A username or email where supported

Worked example

Run a username search, save the result list, and manually review matches for identity consistency before pivoting further.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username or email where supported.

  2. 02

    Submit the handle to Blackbird and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Blackbird is a lead source unless the underlying record itself is authoritative.

028

NExfil

CLIPassive

CLI username enumeration utility.

Username & account discoveryFree / open source
Open procedure +
Start with

A username

Worked example

Run the handle against supported sites, inspect positive URLs, and reject matches lacking independent identity signals.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username.

  2. 02

    Submit the handle to NExfil and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. NExfil is a lead source unless the underlying record itself is authoritative.

029

Social Analyzer

MixedPassive

Cross-platform profile analysis and discovery project.

Username & account discoveryFree / open source
Open procedure +
Start with

A username, name, or profile indicator

Worked example

Search a public handle, inspect candidate profiles and metadata, then verify each profile on-platform before adding it to an entity map.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username, name, or profile indicator.

  2. 02

    Submit the handle to Social Analyzer and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Social Analyzer is a lead source unless the underlying record itself is authoritative.

030

Snoop

CLIPassive

Username search utility covering many web services.

Username & account discoveryFree / open source
Open procedure +
Start with

A username

Worked example

Query a handle, review site hits, and keep a confidence column distinguishing exact handle matches from verified identity matches.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username.

  2. 02

    Submit the handle to Snoop and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Snoop is a lead source unless the underlying record itself is authoritative.

031

UserRecon

CLIPassive

Username reconnaissance script; project maintenance can vary.

Username & account discoveryFree / open source
Open procedure +
Start with

A username

Worked example

Run a handle, inspect returned public URLs, and verify the current project status before relying on coverage.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username.

  2. 02

    Submit the handle to UserRecon and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. UserRecon is a lead source unless the underlying record itself is authoritative.

032

Investigo

MixedPassive

Name used by multiple investigation projects; verify the specific tool and maintainer.

Username & account discoveryProject-dependent
Open procedure +
Start with

A username or public identity seed

Worked example

Identify the exact Investigo implementation, inspect its documentation, test with a known public account, then use results only as leads until verified.

Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username or public identity seed.

  2. 02

    Submit the handle to Investigo and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Investigo is a lead source unless the underlying record itself is authoritative.

033

OSRFramework

CLIPassive

Modular open-source research framework for multiple identifier types.

Username & account discoveryFree / open source
Open procedure +
Start with

Usernames, domains, emails, or names

Worked example

Select the module matching your identifier, run it against a public or authorized seed, then validate returned entities and URLs independently.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: Usernames, domains, emails, or names.

  2. 02

    Submit the handle to OSRFramework and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. OSRFramework is a lead source unless the underlying record itself is authoritative.

034

socialscan

CLIPassive

Checks username and email registration signals across selected platforms.

Username & account discoveryFree / open source
Open procedure +
Start with

A username or email address you are authorized to check

Worked example

Check a username across supported services, note where registration appears present, and treat registration status as a lead rather than proof of account ownership.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username or email address you are authorized to check.

  2. 02

    Submit the handle to socialscan and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. socialscan is a lead source unless the underlying record itself is authoritative.

035

Holehe

CLISensitive

Checks whether an email appears registered on supported services without accessing the account.

Username & account discoveryFree / open source
Open procedure +
Start with

An email address you own, have consent to audit, or have a legitimate public-interest reason to examine

Worked example

Test your own email to see which services disclose registration status, record only service-presence signals, and do not attempt password recovery or account access.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with An email address you own, have consent to audit, or have a legitimate public-interest reason to examine.

  2. 02

    Use Holehe only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Holehe is a lead source unless the underlying record itself is authoritative.

036

FootprintIQ

WebSensitive

Digital-footprint discovery and correlation service.

Username & account discoveryFreemium
Open procedure +
Start with

A username or public profile seed

Worked example

Search a known public handle, review candidate accounts and risk flags, then confirm identity using direct platform evidence before citing results.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username or public profile seed.

  2. 02

    Submit the handle to FootprintIQ and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. FootprintIQ is a lead source unless the underlying record itself is authoritative.

037

Trace

MixedSensitive

Multiple OSINT products use the name Trace; CTI does not assume one canonical implementation.

Username & account discoveryProject-dependent
Open procedure +
Start with

A specific public identifier

Worked example

Confirm which Trace OSINT product you are using, review its data sources and privacy terms, then validate every identity match outside the tool.

Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A specific public identifier.

  2. 02

    Submit the handle to Trace and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Trace is a lead source unless the underlying record itself is authoritative.

038

Lullar

WebSensitive

People and profile search utility with variable coverage.

Username & account discoveryFree
Open procedure +
Start with

A name, username, or email fragment

Worked example

Search a public identity term, use results as leads to public profiles, and verify identity manually before retaining any personal information.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A name, username, or email fragment.

  2. 02

    Submit the handle to Lullar and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Lullar is a lead source unless the underlying record itself is authoritative.

039

Usersearch.org

WebSensitive

Cross-platform identity and account search service.

Username & account discoveryFreemium
Open procedure +
Start with

A username, email, or phone number you may lawfully research

Worked example

Search the identifier, review public-profile leads, and corroborate matches with direct platform records before attribution.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A username, email, or phone number you may lawfully research.

  2. 02

    Submit the handle to Usersearch.org and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Usersearch.org is a lead source unless the underlying record itself is authoritative.

040

IDCrawl

WebSensitive

Aggregator for public profiles and people-search leads.

Username & account discoveryFree / ad-supported
Open procedure +
Start with

A name or username

Worked example

Search a public-facing professional or public-interest subject, open candidate profiles, and avoid publishing private contact or home-address data unless necessary and justified.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A name or username.

  2. 02

    Search IDCrawl and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. IDCrawl is a lead source unless the underlying record itself is authoritative.

041

Digital Footprint Check

WebSensitive

Generic label used by several footprint-audit services; confirm the provider before use.

Username & account discoveryService-dependent
Open procedure +
Start with

A self-audit identifier such as your own email or username

Worked example

Use the service for your own footprint audit, note where information appears exposed, then remove or correct information through the original site rather than relying on the aggregator alone.

Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A self-audit identifier such as your own email or username.

  2. 02

    Search Digital Footprint Check and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Digital Footprint Check is a lead source unless the underlying record itself is authoritative.

042

GHunt

CLISensitive

Google-account OSINT framework using publicly exposed account signals.

Username & account discoveryFree / open source
Open procedure +
Start with

A Google-linked identifier you are authorized to research

Worked example

Use only on your own account, a consenting subject, or a justified public-interest target; run supported passive queries, then verify any profile association through public primary sources.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with A Google-linked identifier you are authorized to research.

  2. 02

    Use GHunt only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. GHunt is a lead source unless the underlying record itself is authoritative.

043

Gitrecon

CLIPassive

GitHub-focused public-profile reconnaissance utility.

Username & account discoveryFree / open source
Open procedure +
Start with

A GitHub username

Worked example

Run the public username, review repositories and public metadata identified by the tool, then inspect the original GitHub pages before recording a finding.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: A GitHub username.

  2. 02

    Submit the handle to Gitrecon and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Gitrecon is a lead source unless the underlying record itself is authoritative.

044

linkedin2username

CLISensitive

Generates likely username patterns from public LinkedIn-derived names; platform restrictions and authorization matter.

Username & account discoveryFree / open source
Open procedure +
Start with

An authorized organization and lawfully obtained public LinkedIn employee data

Worked example

Use only where collection complies with law and platform rules; generate possible corporate username formats, then validate against authorized internal or public evidence rather than probing accounts.

Open official/project site
Step-by-step use
  1. 01

    Normalize the handle exactly as observed, including punctuation and capitalization where relevant. Starting input: An authorized organization and lawfully obtained public LinkedIn employee data.

  2. 02

    Submit the handle to linkedin2username and save the candidate account URLs rather than assuming every positive result belongs to one person.

  3. 03

    Open each candidate profile and compare independent identity markers such as avatar history, biography, location, links, posting topics, and account dates.

  4. 04

    Assign a confidence level: handle-only match, probable match, or corroborated match. A shared username by itself is not identity proof.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. linkedin2username is a lead source unless the underlying record itself is authoritative.

045

Have I Been Pwned

WebSensitive

Breach-notification service for emails, domains, and exposed data classes.

Email, breach & reputationFree / API tiers
Open procedure +
Start with

Your own email address or a domain you control

Worked example

Search your email, note which named breaches include it, change exposed passwords through the real services, and preserve only breach metadata rather than leaked credential contents.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with Your own email address or a domain you control.

  2. 02

    Use Have I Been Pwned only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Have I Been Pwned is a lead source unless the underlying record itself is authoritative.

046

h8mail

CLISensitive

Email breach-hunting and correlation tool.

Email, breach & reputationFree / open source
Open procedure +
Start with

Emails you own or are authorized to audit

Worked example

Run authorized email addresses against configured lawful sources, record exposure indicators, and never use results to attempt account access.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with Emails you own or are authorized to audit.

  2. 02

    Use h8mail only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. h8mail is a lead source unless the underlying record itself is authoritative.

047

DeHashed

WebSensitive

Commercial breach-data search service.

Email, breach & reputationCommercial
Open procedure +
Start with

An identifier you are legally authorized to examine

Worked example

Search your own email or company domain, record which incidents and data types appear, avoid downloading or reusing passwords, and remediate through legitimate account-security channels.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with An identifier you are legally authorized to examine.

  2. 02

    Use DeHashed only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. DeHashed is a lead source unless the underlying record itself is authoritative.

048

LeakCheck

WebSensitive

Breach-exposure search service.

Email, breach & reputationFreemium / commercial
Open procedure +
Start with

Your own email, username, or organization domain

Worked example

Check an owned identifier, record exposure dates and source labels, and use the result to prioritize password resets and monitoring rather than accessing compromised accounts.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with Your own email, username, or organization domain.

  2. 02

    Use LeakCheck only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. LeakCheck is a lead source unless the underlying record itself is authoritative.

049

Snusbase

WebSensitive

Commercial breach-data search platform.

Email, breach & reputationCommercial
Open procedure +
Start with

An authorized identifier

Worked example

Use for self-audit or authorized incident response, capture only the minimum exposure metadata needed, and do not repurpose leaked credentials or private content.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with An authorized identifier.

  2. 02

    Use Snusbase only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Snusbase is a lead source unless the underlying record itself is authoritative.

050

Intelligence X

WebSensitive

Search engine and archive for public web, documents, historical material, and some leak-related sources.

Email, breach & reputationFreemium / commercial
Open procedure +
Start with

A public identifier, domain, URL, document, or authorized breach-research term

Worked example

Search an owned domain or public document hash, review indexed sources, and avoid retrieving sensitive leaked material that is unnecessary to the public-interest question.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with A public identifier, domain, URL, document, or authorized breach-research term.

  2. 02

    Use Intelligence X only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Intelligence X is a lead source unless the underlying record itself is authoritative.

051

Hudson Rock

WebSensitive

Infostealer intelligence and exposure-monitoring service.

Email, breach & reputationFree tools / commercial
Open procedure +
Start with

A company domain or email you are authorized to assess

Worked example

Use the public exposure tools on an owned domain, note infostealer exposure indicators, then move remediation into formal security and credential-reset processes.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with A company domain or email you are authorized to assess.

  2. 02

    Use Hudson Rock only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Hudson Rock is a lead source unless the underlying record itself is authoritative.

052

Hunter.io

WebPassive

Professional email discovery and verification service.

Email, breach & reputationFreemium
Open procedure +
Start with

A company domain or known professional name

Worked example

Search an organization's domain, review publicly sourced email patterns, then verify a contact through the organization's own website before outreach or publication.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with A company domain or known professional name.

  2. 02

    Use Hunter.io only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Hunter.io is a lead source unless the underlying record itself is authoritative.

053

Epieos

WebSensitive

Email and phone OSINT service using public account and identity signals.

Email, breach & reputationFreemium
Open procedure +
Start with

An email or phone number you have a lawful reason to research

Worked example

Search a consenting or public-interest identifier, review public account signals, and corroborate any identity connection using independent public records.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with An email or phone number you have a lawful reason to research.

  2. 02

    Use Epieos only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Epieos is a lead source unless the underlying record itself is authoritative.

054

EmailRep

APISensitive

Email reputation service and API.

Email, breach & reputationFree / API tiers
Open procedure +
Start with

An email address used in an authorized trust or fraud review

Worked example

Query the address, interpret reputation flags as indicators rather than proof, and compare the result with transaction or account evidence you are authorized to hold.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with An email address used in an authorized trust or fraud review.

  2. 02

    Use EmailRep only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. EmailRep is a lead source unless the underlying record itself is authoritative.

055

Phonebook.cz

WebPassive

Cybersecurity-focused search engine for domains, URLs, emails, and related infrastructure.

Email, breach & reputationFree with account
Open procedure +
Start with

A domain, email fragment, or organization

Worked example

Search a company domain for publicly indexed addresses and subdomains, then verify contacts on official sites before using them.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with A domain, email fragment, or organization.

  2. 02

    Use Phonebook.cz only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Phonebook.cz is a lead source unless the underlying record itself is authoritative.

056

Snov.io

WebPassive

Professional contact discovery and verification platform.

Email, breach & reputationFreemium / commercial
Open procedure +
Start with

A company or professional identity

Worked example

Use domain or prospect search for legitimate contact research, verify results against official professional pages, and do not infer private affiliation from an unverified match.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with A company or professional identity.

  2. 02

    Use Snov.io only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Snov.io is a lead source unless the underlying record itself is authoritative.

057

Voila Norbert

WebPassive

Business email discovery and verification service.

Email, breach & reputationCommercial
Open procedure +
Start with

A professional name plus company/domain

Worked example

Enter a known professional name and employer, review the suggested business email, and verify through independent professional sources before relying on it.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with A professional name plus company/domain.

  2. 02

    Use Voila Norbert only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Voila Norbert is a lead source unless the underlying record itself is authoritative.

058

Clearbit

APISensitive

Business-data enrichment platform; product packaging can change.

Email, breach & reputationCommercial
Open procedure +
Start with

A business email or company domain in an authorized enrichment workflow

Worked example

Enrich a business-domain record, inspect returned company fields, and validate important claims against the company or regulatory record.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with A business email or company domain in an authorized enrichment workflow.

  2. 02

    Use Clearbit only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Clearbit is a lead source unless the underlying record itself is authoritative.

059

RocketReach

WebSensitive

Professional contact and company information service.

Email, breach & reputationFreemium / commercial
Open procedure +
Start with

A professional name, company, or business domain

Worked example

Search a public-facing professional, use returned contact details only for legitimate outreach, and verify role and employer on current primary sources.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with A professional name, company, or business domain.

  2. 02

    Use RocketReach only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. RocketReach is a lead source unless the underlying record itself is authoritative.

060

Apollo.io

WebSensitive

Sales-intelligence database that can support company and professional research.

Email, breach & reputationFreemium / commercial
Open procedure +
Start with

A company or professional prospect in a legitimate research or outreach context

Worked example

Search an organization, filter employees by role, confirm current employment from public professional sources, and minimize unnecessary personal data retention.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with A company or professional prospect in a legitimate research or outreach context.

  2. 02

    Use Apollo.io only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Apollo.io is a lead source unless the underlying record itself is authoritative.

061

MXToolbox

WebPassive

Mail, DNS, blacklist, and header-analysis utilities.

Email, breach & reputationFree / paid
Open procedure +
Start with

A mail domain, IP, or email header

Worked example

Paste the mail domain or analyze an email header you lawfully possess, inspect DNS/MX/SPF/DKIM signals, and document the exact fields supporting your conclusion.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A mail domain, IP, or email header.

  2. 02

    Use MXToolbox for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. MXToolbox is a lead source unless the underlying record itself is authoritative.

062

Infoga

CLIPassive

Email OSINT and domain-related reconnaissance project; verify maintenance status.

Email, breach & reputationFree / open source
Open procedure +
Start with

A domain or organization you are authorized to research

Worked example

Use the domain as a seed, collect publicly indexed email patterns, and validate current addresses through primary organizational sources.

Open official/project site
Step-by-step use
  1. 01

    Confirm you have a legitimate basis to examine the address. Start with A domain or organization you are authorized to research.

  2. 02

    Use Infoga only for the service's intended public signal—registration, breach exposure, reputation, professional contact, or domain metadata.

  3. 03

    Collect only the minimum metadata needed for the investigation. Do not retrieve, test, reuse, or publish passwords, recovery codes, or private account content.

  4. 04

    Corroborate identity or exposure with a second lawful source and distinguish a historical breach from current account compromise.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Infoga is a lead source unless the underlying record itself is authoritative.

063

PhoneInfoga

MixedSensitive

Phone-number OSINT framework using public and passive sources.

Phone number OSINTFree / open source
Open procedure +
Start with

A phone number you own, have consent to investigate, or have a strong public-interest basis to research

Worked example

Normalize the number, review country/carrier and public-web search pivots, and never use results to harass, locate, or impersonate a private person.

Open official/project site
Step-by-step use
  1. 01

    Normalize the number to international format where possible and document why the lookup is justified. Starting input: A phone number you own, have consent to investigate, or have a strong public-interest basis to research.

  2. 02

    Use PhoneInfoga to obtain only the available public metadata, directory association, carrier, or registration signal.

  3. 03

    Treat crowd-sourced names, tags, and approximate locations as unverified leads; numbers are recycled and databases become stale.

  4. 04

    Corroborate any identity match with independent public records or direct evidence and minimize collection of home-address or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. PhoneInfoga is a lead source unless the underlying record itself is authoritative.

064

Ignorant

CLISensitive

Checks phone registration signals on selected services.

Phone number OSINTFree / open source
Open procedure +
Start with

A phone number you are authorized to audit

Worked example

Check whether your own number appears associated with supported services, record only registration indicators, and do not initiate account recovery or access attempts.

Open official/project site
Step-by-step use
  1. 01

    Normalize the number to international format where possible and document why the lookup is justified. Starting input: A phone number you are authorized to audit.

  2. 02

    Use Ignorant to obtain only the available public metadata, directory association, carrier, or registration signal.

  3. 03

    Treat crowd-sourced names, tags, and approximate locations as unverified leads; numbers are recycled and databases become stale.

  4. 04

    Corroborate any identity match with independent public records or direct evidence and minimize collection of home-address or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Ignorant is a lead source unless the underlying record itself is authoritative.

065

Truecaller

WebSensitive

Caller-identification and community-labeled phone directory.

Phone number OSINTFreemium
Open procedure +
Start with

A phone number involved in a legitimate contact, fraud, or self-audit question

Worked example

Search the number, treat the displayed name as user-contributed and potentially wrong, and corroborate identity independently before attribution.

Open official/project site
Step-by-step use
  1. 01

    Normalize the number to international format where possible and document why the lookup is justified. Starting input: A phone number involved in a legitimate contact, fraud, or self-audit question.

  2. 02

    Use Truecaller to obtain only the available public metadata, directory association, carrier, or registration signal.

  3. 03

    Treat crowd-sourced names, tags, and approximate locations as unverified leads; numbers are recycled and databases become stale.

  4. 04

    Corroborate any identity match with independent public records or direct evidence and minimize collection of home-address or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Truecaller is a lead source unless the underlying record itself is authoritative.

066

Getcontact

WebSensitive

Caller identification and community tagging service.

Phone number OSINTFreemium
Open procedure +
Start with

A number you are lawfully permitted to review

Worked example

Check public/community labels, record them only as unverified leads, and avoid using crowd-sourced tags as proof of identity or misconduct.

Open official/project site
Step-by-step use
  1. 01

    Normalize the number to international format where possible and document why the lookup is justified. Starting input: A number you are lawfully permitted to review.

  2. 02

    Use Getcontact to obtain only the available public metadata, directory association, carrier, or registration signal.

  3. 03

    Treat crowd-sourced names, tags, and approximate locations as unverified leads; numbers are recycled and databases become stale.

  4. 04

    Corroborate any identity match with independent public records or direct evidence and minimize collection of home-address or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Getcontact is a lead source unless the underlying record itself is authoritative.

067

NumVerify

APIPassive

Phone-number validation and metadata API.

Phone number OSINTFreemium / commercial
Open procedure +
Start with

A phone number

Worked example

Submit the number, retrieve country, line-type, and carrier metadata where available, and document the lookup date because carrier assignments can change.

Open official/project site
Step-by-step use
  1. 01

    Normalize the number to international format where possible and document why the lookup is justified. Starting input: A phone number.

  2. 02

    Use NumVerify to obtain only the available public metadata, directory association, carrier, or registration signal.

  3. 03

    Treat crowd-sourced names, tags, and approximate locations as unverified leads; numbers are recycled and databases become stale.

  4. 04

    Corroborate any identity match with independent public records or direct evidence and minimize collection of home-address or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. NumVerify is a lead source unless the underlying record itself is authoritative.

068

SpyDialer

WebSensitive

Reverse-phone lookup service with privacy-sensitive outputs.

Phone number OSINTFree / ad-supported
Open procedure +
Start with

A U.S. number you have a lawful reason to research

Worked example

Use only for legitimate self-audit or public-interest work, record the minimum directory information needed, and independently verify identity before publication.

Open official/project site
Step-by-step use
  1. 01

    Normalize the number to international format where possible and document why the lookup is justified. Starting input: A U.S. number you have a lawful reason to research.

  2. 02

    Use SpyDialer to obtain only the available public metadata, directory association, carrier, or registration signal.

  3. 03

    Treat crowd-sourced names, tags, and approximate locations as unverified leads; numbers are recycled and databases become stale.

  4. 04

    Corroborate any identity match with independent public records or direct evidence and minimize collection of home-address or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. SpyDialer is a lead source unless the underlying record itself is authoritative.

069

NumLookup

WebSensitive

Reverse-phone and carrier-information service.

Phone number OSINTFree / commercial
Open procedure +
Start with

A phone number

Worked example

Search the number, treat names and carrier details as leads, and cross-check against direct or official sources.

Open official/project site
Step-by-step use
  1. 01

    Normalize the number to international format where possible and document why the lookup is justified. Starting input: A phone number.

  2. 02

    Use NumLookup to obtain only the available public metadata, directory association, carrier, or registration signal.

  3. 03

    Treat crowd-sourced names, tags, and approximate locations as unverified leads; numbers are recycled and databases become stale.

  4. 04

    Corroborate any identity match with independent public records or direct evidence and minimize collection of home-address or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. NumLookup is a lead source unless the underlying record itself is authoritative.

070

Sync.me

WebSensitive

Caller ID and contact-profile service.

Phone number OSINTFreemium
Open procedure +
Start with

A phone number involved in a legitimate identity-verification question

Worked example

Review caller/profile information, assume crowd-sourced data may be stale, and require independent corroboration before attribution.

Open official/project site
Step-by-step use
  1. 01

    Normalize the number to international format where possible and document why the lookup is justified. Starting input: A phone number involved in a legitimate identity-verification question.

  2. 02

    Use Sync.me to obtain only the available public metadata, directory association, carrier, or registration signal.

  3. 03

    Treat crowd-sourced names, tags, and approximate locations as unverified leads; numbers are recycled and databases become stale.

  4. 04

    Corroborate any identity match with independent public records or direct evidence and minimize collection of home-address or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Sync.me is a lead source unless the underlying record itself is authoritative.

071

CallerIDTest

WebSensitive

Phone lookup utility; coverage and availability can vary.

Phone number OSINTService terms vary
Open procedure +
Start with

A phone number

Worked example

Run a lawful lookup, note carrier or caller-ID signals, and confirm identity elsewhere before using the result in a case file.

Open official/project site
Step-by-step use
  1. 01

    Normalize the number to international format where possible and document why the lookup is justified. Starting input: A phone number.

  2. 02

    Use CallerIDTest to obtain only the available public metadata, directory association, carrier, or registration signal.

  3. 03

    Treat crowd-sourced names, tags, and approximate locations as unverified leads; numbers are recycled and databases become stale.

  4. 04

    Corroborate any identity match with independent public records or direct evidence and minimize collection of home-address or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. CallerIDTest is a lead source unless the underlying record itself is authoritative.

072

ThatsThem

WebSensitive

People-search aggregator connecting public contact and address information.

Phone number OSINTFree / commercial
Open procedure +
Start with

A self-audit or legitimate public-interest identifier

Worked example

Search your own name, address, email, or phone to learn what an aggregator exposes; for third parties, minimize collection and never publish precise home-location data without strong justification.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A self-audit or legitimate public-interest identifier.

  2. 02

    Search ThatsThem and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. ThatsThem is a lead source unless the underlying record itself is authoritative.

073

Spokeo

WebSensitive

Commercial people-search aggregator.

People search & public recordsCommercial
Open procedure +
Start with

A self-audit or legitimate public-interest name, email, phone, or username

Worked example

Search a known public-facing person, separate directory hints from verified records, and confirm identity through primary public documents before publication.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A self-audit or legitimate public-interest name, email, phone, or username.

  2. 02

    Search Spokeo and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Spokeo is a lead source unless the underlying record itself is authoritative.

074

BeenVerified

WebSensitive

Commercial people-search and public-record aggregation service.

People search & public recordsCommercial
Open procedure +
Start with

A self-audit or legitimate public-interest identity

Worked example

Search a person, inspect possible age/location associations, and corroborate each material fact with official records rather than citing the aggregator alone.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A self-audit or legitimate public-interest identity.

  2. 02

    Search BeenVerified and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. BeenVerified is a lead source unless the underlying record itself is authoritative.

075

Intelius

WebSensitive

Commercial people-search and background-data aggregator.

People search & public recordsCommercial
Open procedure +
Start with

A self-audit or public-interest identity question

Worked example

Use the report to generate possible jurisdictions and aliases, then verify those details against court, property, corporate, or government records.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A self-audit or public-interest identity question.

  2. 02

    Search Intelius and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Intelius is a lead source unless the underlying record itself is authoritative.

076

TruthFinder

WebSensitive

Commercial public-record and people-search service.

People search & public recordsCommercial
Open procedure +
Start with

A lawful self-audit or public-interest identity

Worked example

Treat results as a lead set, verify criminal/court claims directly with courts, and do not use the service for regulated eligibility decisions unless legally permitted.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A lawful self-audit or public-interest identity.

  2. 02

    Search TruthFinder and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. TruthFinder is a lead source unless the underlying record itself is authoritative.

077

Instant Checkmate

WebSensitive

Commercial people-search aggregator.

People search & public recordsCommercial
Open procedure +
Start with

A lawful public-record research question

Worked example

Search a person, record possible jurisdictions and aliases, then open official court or government sources before relying on any consequential information.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A lawful public-record research question.

  2. 02

    Search Instant Checkmate and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Instant Checkmate is a lead source unless the underlying record itself is authoritative.

078

ZabaSearch

WebSensitive

Public people-search directory.

People search & public recordsFree / commercial links
Open procedure +
Start with

A name and approximate location

Worked example

Use the result to identify possible age or city matches, then corroborate with official records and avoid publishing home addresses unnecessarily.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A name and approximate location.

  2. 02

    Search ZabaSearch and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. ZabaSearch is a lead source unless the underlying record itself is authoritative.

079

Whitepages

WebSensitive

Directory and people-search service.

People search & public recordsFreemium / commercial
Open procedure +
Start with

A name, phone number, or address

Worked example

Run a self-audit or legitimate lookup, distinguish household associations from identity proof, and verify important facts elsewhere.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A name, phone number, or address.

  2. 02

    Search Whitepages and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Whitepages is a lead source unless the underlying record itself is authoritative.

080

Pipl

WebSensitive

Commercial identity-resolution platform.

People search & public recordsCommercial
Open procedure +
Start with

A licensed identity-resolution case

Worked example

Search a known identifier, review possible entity resolution, and require independent evidence before treating matched records as one person.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A licensed identity-resolution case.

  2. 02

    Search Pipl and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Pipl is a lead source unless the underlying record itself is authoritative.

081

PeekYou

WebSensitive

People and public-profile search aggregator.

People search & public recordsFree / ad-supported
Open procedure +
Start with

A name or username

Worked example

Use results to find candidate public profiles, then confirm identity directly on the originating sites.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A name or username.

  2. 02

    Search PeekYou and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. PeekYou is a lead source unless the underlying record itself is authoritative.

082

FamilyTreeNow

WebSensitive

Genealogy-oriented public-record aggregator with privacy-sensitive data.

People search & public recordsFree
Open procedure +
Start with

Your own public-data footprint or legitimate genealogy research

Worked example

Search yourself to understand exposed family/address associations, verify records at original sources, and use opt-out procedures if appropriate.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with Your own public-data footprint or legitimate genealogy research.

  2. 02

    Search FamilyTreeNow and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. FamilyTreeNow is a lead source unless the underlying record itself is authoritative.

083

VoterRecords

WebSensitive

Aggregator of publicly available voter-registration records in participating jurisdictions.

People search & public recordsFree
Open procedure +
Start with

A public-interest voter-registration question where disclosure is lawful

Worked example

Search by name and jurisdiction, treat registration data as jurisdiction-specific and potentially stale, and avoid republishing residential addresses without necessity.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A public-interest voter-registration question where disclosure is lawful.

  2. 02

    Search VoterRecords and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. VoterRecords is a lead source unless the underlying record itself is authoritative.

084

Judyrecords

WebSensitive

Large search index of U.S. court records and dockets.

People search & public recordsFree
Open procedure +
Start with

A name, business, case term, or jurisdiction

Worked example

Search a party name, inspect docket snippets, then verify the case and current disposition with the originating court before citation.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A name, business, case term, or jurisdiction.

  2. 02

    Search Judyrecords and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Judyrecords is a lead source unless the underlying record itself is authoritative.

085

UniCourt

WebSensitive

Court-record aggregation and legal analytics platform.

People search & public recordsFreemium / commercial
Open procedure +
Start with

A party, attorney, company, or case number

Worked example

Search the name, narrow by jurisdiction and date, then confirm filings and disposition through the official court system where possible.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A party, attorney, company, or case number.

  2. 02

    Search UniCourt and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. UniCourt is a lead source unless the underlying record itself is authoritative.

086

Federal Bureau of Prisons inmate locator

WebSensitive

Official federal inmate locator.

People search & public recordsOfficial / free
Open procedure +
Start with

A full name or federal inmate number

Worked example

Search the exact name or register number, record custody/release information with the lookup date, and distinguish federal BOP custody from state or local systems.

Open official/project site
Step-by-step use
  1. 01

    Define the person precisely before searching: full name, approximate age, jurisdiction, profession, or another non-sensitive discriminator. Start with A full name or federal inmate number.

  2. 02

    Search Federal Bureau of Prisons inmate locator and separate possible matches from the specific individual in your case file.

  3. 03

    Use aggregator data to identify jurisdictions, aliases, cases, companies, or other leads—not as the final authority for consequential facts.

  4. 04

    Verify court, corporate, property, custody, or regulatory information at the originating official source and redact unnecessary residential or family data.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Federal Bureau of Prisons inmate locator is a lead source unless the underlying record itself is authoritative.

087

OpenCorporates

WebPassive

Global company registry aggregator.

People search & public recordsFree / commercial API
Open procedure +
Start with

A company name, officer, or jurisdiction

Worked example

Search an entity name, identify the legal jurisdiction and company number, then confirm current filings with the official corporate registry.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A company name, officer, or jurisdiction.

  2. 02

    Search OpenCorporates for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. OpenCorporates is a lead source unless the underlying record itself is authoritative.

088

OpenSanctions

WebSensitive

Open sanctions, PEP, and entity-risk dataset.

People search & public recordsOpen data / commercial services
Open procedure +
Start with

A person or entity in a sanctions or politically exposed-person research context

Worked example

Search the exact legal name, compare identifiers and dates of birth, and confirm any match against the originating sanctions authority before publication.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A person or entity in a sanctions or politically exposed-person research context.

  2. 02

    Search OpenSanctions for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. OpenSanctions is a lead source unless the underlying record itself is authoritative.

089

Companies House

WebPassive

Official UK company registry.

People search & public recordsOfficial / free
Open procedure +
Start with

A UK company name, number, or officer

Worked example

Search the company, open filing history and officer records, download the relevant filing, and record the company number so similarly named entities are not confused.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A UK company name, number, or officer.

  2. 02

    Search Companies House for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Companies House is a lead source unless the underlying record itself is authoritative.

090

SEC EDGAR

WebPassive

Official U.S. securities filing system.

People search & public recordsOfficial / free
Open procedure +
Start with

A public company, ticker, CIK, executive, or filing type

Worked example

Search the company, open its latest 10-K or 8-K, use exhibits for contracts, and cite the filing accession number and date.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A public company, ticker, CIK, executive, or filing type.

  2. 02

    Search SEC EDGAR for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. SEC EDGAR is a lead source unless the underlying record itself is authoritative.

091

North Data

WebPassive

Company and executive research platform with strong European coverage.

People search & public recordsFreemium / commercial
Open procedure +
Start with

A European company or executive

Worked example

Search an entity, inspect corporate relationships and filing-derived history, then verify important records with the relevant national registry.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A European company or executive.

  2. 02

    Search North Data for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. North Data is a lead source unless the underlying record itself is authoritative.

092

Crunchbase

WebPassive

Company, funding, founder, and investor database.

People search & public recordsFreemium / commercial
Open procedure +
Start with

A company, founder, investor, or funding question

Worked example

Search the company, note funding rounds and key people, then corroborate major figures with filings, investor announcements, or the company itself.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A company, founder, investor, or funding question.

  2. 02

    Search Crunchbase for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Crunchbase is a lead source unless the underlying record itself is authoritative.

093

OpenOwnership

WebPassive

Beneficial-ownership data and standards initiative.

People search & public recordsOpen data
Open procedure +
Start with

A company or beneficial-ownership research question

Worked example

Search available ownership data, capture entity identifiers and source jurisdiction, then confirm the latest ownership position with the authoritative registry where possible.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A company or beneficial-ownership research question.

  2. 02

    Search OpenOwnership for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. OpenOwnership is a lead source unless the underlying record itself is authoritative.

094

FaceCheck.ID

WebSensitive

Face-search service that returns visually similar public images and pages.

People search & public recordsFreemium / commercial
Open procedure +
Start with

A face image you may lawfully use for identification research

Worked example

Upload a public or consented image, review candidate matches, and never treat visual similarity alone as identity proof; corroborate with independent biographical evidence.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original file or original public URL first. Work from a copy. Starting input: A face image you may lawfully use for identification research.

  2. 02

    Use FaceCheck.ID on the full image and, where useful, on crops containing distinctive faces, signs, buildings, objects, or textures.

  3. 03

    Compare publication dates, source pages, metadata, and visual details. Missing metadata is not evidence of manipulation because platforms often strip it.

  4. 04

    Treat forensic filters and face-similarity results as indicators, not verdicts; seek independent confirmation from chronology, geography, or primary-source context.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. FaceCheck.ID is a lead source unless the underlying record itself is authoritative.

095

PimEyes

WebSensitive

Reverse face-search engine.

People search & public recordsFreemium / commercial
Open procedure +
Start with

Your own face or an image used for a justified public-interest verification

Worked example

Upload the image, inspect returned pages, and verify identity from page context and independent records rather than relying on similarity score alone.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original file or original public URL first. Work from a copy. Starting input: Your own face or an image used for a justified public-interest verification.

  2. 02

    Use PimEyes on the full image and, where useful, on crops containing distinctive faces, signs, buildings, objects, or textures.

  3. 03

    Compare publication dates, source pages, metadata, and visual details. Missing metadata is not evidence of manipulation because platforms often strip it.

  4. 04

    Treat forensic filters and face-similarity results as indicators, not verdicts; seek independent confirmation from chronology, geography, or primary-source context.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. PimEyes is a lead source unless the underlying record itself is authoritative.

096

Search4Faces

WebSensitive

Face-search service focused on selected social and public-image sources.

People search & public recordsFreemium
Open procedure +
Start with

A lawful face-search question

Worked example

Upload an authorized image, review possible profile matches, and require independent corroboration before naming a person.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original file or original public URL first. Work from a copy. Starting input: A lawful face-search question.

  2. 02

    Use Search4Faces on the full image and, where useful, on crops containing distinctive faces, signs, buildings, objects, or textures.

  3. 03

    Compare publication dates, source pages, metadata, and visual details. Missing metadata is not evidence of manipulation because platforms often strip it.

  4. 04

    Treat forensic filters and face-similarity results as indicators, not verdicts; seek independent confirmation from chronology, geography, or primary-source context.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Search4Faces is a lead source unless the underlying record itself is authoritative.

097

X advanced search

WebSensitive

Native advanced search for public posts on X where available.

Social media intelligenceFree / account restrictions may apply
Open procedure +
Start with

Keywords, accounts, dates, language, or engagement terms

Worked example

Search an exact phrase from a public statement, constrain it to the account and date window, open the original post, and archive the URL and timestamp before analysis.

Open official/project site
Step-by-step use
  1. 01

    Turn the research question into a bounded query using Keywords, accounts, dates, language, or engagement terms.

  2. 02

    Use X advanced search to locate the smallest relevant set of public posts, channels, accounts, or mentions; narrow by date and exact phrase whenever possible.

  3. 03

    Open the original post or channel rather than relying only on an analytics dashboard, search snippet, or repost.

  4. 04

    Capture chronology, author/account identity, edits or deletions where observable, and whether multiple sources are independent or merely copying one another.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. X advanced search is a lead source unless the underlying record itself is authoritative.

098

Foller.me

WebSensitive

Twitter/X profile analytics utility; API changes can affect functionality.

Social media intelligenceFree / status varies
Open procedure +
Start with

A public X/Twitter username

Worked example

Enter a public account, review profile and activity summaries as leads, then confirm any material pattern by opening the original posts.

Open official/project site
Step-by-step use
  1. 01

    Turn the research question into a bounded query using A public X/Twitter username.

  2. 02

    Use Foller.me to locate the smallest relevant set of public posts, channels, accounts, or mentions; narrow by date and exact phrase whenever possible.

  3. 03

    Open the original post or channel rather than relying only on an analytics dashboard, search snippet, or repost.

  4. 04

    Capture chronology, author/account identity, edits or deletions where observable, and whether multiple sources are independent or merely copying one another.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Foller.me is a lead source unless the underlying record itself is authoritative.

099

RedditMetis

WebSensitive

Reddit profile analytics and visualization tool.

Social media intelligenceFree
Open procedure +
Start with

A public Reddit username

Worked example

Analyze a public account, treat inferred interests as probabilistic, and cite specific public posts rather than the profile summary when making a claim.

Open official/project site
Step-by-step use
  1. 01

    Turn the research question into a bounded query using A public Reddit username.

  2. 02

    Use RedditMetis to locate the smallest relevant set of public posts, channels, accounts, or mentions; narrow by date and exact phrase whenever possible.

  3. 03

    Open the original post or channel rather than relying only on an analytics dashboard, search snippet, or repost.

  4. 04

    Capture chronology, author/account identity, edits or deletions where observable, and whether multiple sources are independent or merely copying one another.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. RedditMetis is a lead source unless the underlying record itself is authoritative.

100

Arctic Shift

APISensitive

Community Reddit data archive and API.

Social media intelligenceFree / community service
Open procedure +
Start with

A Reddit post, comment, user, subreddit, or time range

Worked example

Query a public post or account time range, retrieve historical Reddit material, and compare it with live Reddit and archived copies before treating deleted content as authentic context.

Open official/project site
Step-by-step use
  1. 01

    Turn the research question into a bounded query using A Reddit post, comment, user, subreddit, or time range.

  2. 02

    Use Arctic Shift to locate the smallest relevant set of public posts, channels, accounts, or mentions; narrow by date and exact phrase whenever possible.

  3. 03

    Open the original post or channel rather than relying only on an analytics dashboard, search snippet, or repost.

  4. 04

    Capture chronology, author/account identity, edits or deletions where observable, and whether multiple sources are independent or merely copying one another.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Arctic Shift is a lead source unless the underlying record itself is authoritative.

101

TGStat

WebSensitive

Telegram channel analytics and search platform.

Social media intelligenceFreemium / commercial
Open procedure +
Start with

A public Telegram channel, keyword, or topic

Worked example

Search a public channel, review post history and forward relationships, then open the original Telegram content and record publication dates and channel identity.

Open official/project site
Step-by-step use
  1. 01

    Turn the research question into a bounded query using A public Telegram channel, keyword, or topic.

  2. 02

    Use TGStat to locate the smallest relevant set of public posts, channels, accounts, or mentions; narrow by date and exact phrase whenever possible.

  3. 03

    Open the original post or channel rather than relying only on an analytics dashboard, search snippet, or repost.

  4. 04

    Capture chronology, author/account identity, edits or deletions where observable, and whether multiple sources are independent or merely copying one another.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. TGStat is a lead source unless the underlying record itself is authoritative.

102

Telegago

WebSensitive

Telegram-focused search engine.

Social media intelligenceFree / status varies
Open procedure +
Start with

A public Telegram keyword, channel, or message topic

Worked example

Search a distinctive phrase, open candidate channel results, and confirm message context and date in the original public channel.

Open official/project site
Step-by-step use
  1. 01

    Turn the research question into a bounded query using A public Telegram keyword, channel, or message topic.

  2. 02

    Use Telegago to locate the smallest relevant set of public posts, channels, accounts, or mentions; narrow by date and exact phrase whenever possible.

  3. 03

    Open the original post or channel rather than relying only on an analytics dashboard, search snippet, or repost.

  4. 04

    Capture chronology, author/account identity, edits or deletions where observable, and whether multiple sources are independent or merely copying one another.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Telegago is a lead source unless the underlying record itself is authoritative.

103

Telemetr

WebSensitive

Telegram analytics and channel discovery service.

Social media intelligenceFreemium / commercial
Open procedure +
Start with

A public Telegram channel or topic

Worked example

Search the channel, inspect analytics and mentions, and verify significant posts directly in Telegram before citation.

Open official/project site
Step-by-step use
  1. 01

    Turn the research question into a bounded query using A public Telegram channel or topic.

  2. 02

    Use Telemetr to locate the smallest relevant set of public posts, channels, accounts, or mentions; narrow by date and exact phrase whenever possible.

  3. 03

    Open the original post or channel rather than relying only on an analytics dashboard, search snippet, or repost.

  4. 04

    Capture chronology, author/account identity, edits or deletions where observable, and whether multiple sources are independent or merely copying one another.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Telemetr is a lead source unless the underlying record itself is authoritative.

104

Telerecon

MixedSensitive

Name used for Telegram reconnaissance projects; verify the implementation before use.

Social media intelligenceProject-dependent
Open procedure +
Start with

A public Telegram research question

Worked example

Confirm the exact Telerecon project, review collection methods and current maintenance, then use it only on lawfully accessible public channels and validate outputs at source.

Step-by-step use
  1. 01

    Turn the research question into a bounded query using A public Telegram research question.

  2. 02

    Use Telerecon to locate the smallest relevant set of public posts, channels, accounts, or mentions; narrow by date and exact phrase whenever possible.

  3. 03

    Open the original post or channel rather than relying only on an analytics dashboard, search snippet, or repost.

  4. 04

    Capture chronology, author/account identity, edits or deletions where observable, and whether multiple sources are independent or merely copying one another.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Telerecon is a lead source unless the underlying record itself is authoritative.

105

Bluesky / AT Protocol tools

MixedSensitive

Public Bluesky and AT Protocol data can be investigated through native search and documented protocol endpoints.

Social media intelligenceFree / open protocol
Open procedure +
Start with

A public Bluesky handle, DID, post URI, or feed

Worked example

Resolve a handle to its public profile, capture the post URI or DID, use public AT Protocol endpoints where appropriate, and preserve the original post context before drawing conclusions.

Open official/project site
Step-by-step use
  1. 01

    Turn the research question into a bounded query using A public Bluesky handle, DID, post URI, or feed.

  2. 02

    Use Bluesky / AT Protocol tools to locate the smallest relevant set of public posts, channels, accounts, or mentions; narrow by date and exact phrase whenever possible.

  3. 03

    Open the original post or channel rather than relying only on an analytics dashboard, search snippet, or repost.

  4. 04

    Capture chronology, author/account identity, edits or deletions where observable, and whether multiple sources are independent or merely copying one another.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Bluesky / AT Protocol tools is a lead source unless the underlying record itself is authoritative.

106

Social Searcher

WebSensitive

Cross-platform social and web mention search service.

Social media intelligenceFreemium
Open procedure +
Start with

A keyword, brand, phrase, or public account

Worked example

Search a distinctive phrase, filter by source and time where available, open original posts, and separate duplicate syndication from independent mentions.

Open official/project site
Step-by-step use
  1. 01

    Turn the research question into a bounded query using A keyword, brand, phrase, or public account.

  2. 02

    Use Social Searcher to locate the smallest relevant set of public posts, channels, accounts, or mentions; narrow by date and exact phrase whenever possible.

  3. 03

    Open the original post or channel rather than relying only on an analytics dashboard, search snippet, or repost.

  4. 04

    Capture chronology, author/account identity, edits or deletions where observable, and whether multiple sources are independent or merely copying one another.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Social Searcher is a lead source unless the underlying record itself is authoritative.

107

Hootsuite

WebSensitive

Commercial social media management and listening platform.

Social media intelligenceCommercial
Open procedure +
Start with

Authorized social accounts, keywords, or listening queries

Worked example

Create a listening stream for a campaign term, review spikes and representative posts, and preserve original links rather than treating dashboard counts as self-explanatory.

Open official/project site
Step-by-step use
  1. 01

    Turn the research question into a bounded query using Authorized social accounts, keywords, or listening queries.

  2. 02

    Use Hootsuite to locate the smallest relevant set of public posts, channels, accounts, or mentions; narrow by date and exact phrase whenever possible.

  3. 03

    Open the original post or channel rather than relying only on an analytics dashboard, search snippet, or repost.

  4. 04

    Capture chronology, author/account identity, edits or deletions where observable, and whether multiple sources are independent or merely copying one another.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Hootsuite is a lead source unless the underlying record itself is authoritative.

108

GeoCreepy

DesktopSensitive

Older geolocation tool for public social-media metadata; maintenance and platform support vary.

Social media intelligenceFree / open source
Open procedure +
Start with

Lawfully available geotagged public posts

Worked example

Use only for ethical, public-interest geolocation work, restrict collection to necessary public posts, and never use it to track a private person in real time.

Open official/project site
Step-by-step use
  1. 01

    Turn the research question into a bounded query using Lawfully available geotagged public posts.

  2. 02

    Use GeoCreepy to locate the smallest relevant set of public posts, channels, accounts, or mentions; narrow by date and exact phrase whenever possible.

  3. 03

    Open the original post or channel rather than relying only on an analytics dashboard, search snippet, or repost.

  4. 04

    Capture chronology, author/account identity, edits or deletions where observable, and whether multiple sources are independent or merely copying one another.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. GeoCreepy is a lead source unless the underlying record itself is authoritative.

109

OWASP Amass

CLIPassive

Attack-surface and subdomain enumeration framework with strong passive data support.

Domain, DNS & infrastructureFree / open source
Open procedure +
Start with

A domain you own or are authorized to assess

Worked example

Run passive enumeration first, collect discovered subdomains and certificate relationships, and validate hosts before any active probing.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A domain you own or are authorized to assess.

  2. 02

    Use OWASP Amass for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. OWASP Amass is a lead source unless the underlying record itself is authoritative.

110

Subfinder

CLIPassive

Fast passive subdomain discovery tool.

Domain, DNS & infrastructureFree / open source
Open procedure +
Start with

An authorized domain

Worked example

Enumerate passive subdomain sources for your domain, deduplicate results, resolve them, and retain source provenance for assets you investigate further.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: An authorized domain.

  2. 02

    Use Subfinder for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Subfinder is a lead source unless the underlying record itself is authoritative.

111

Sublist3r

CLIPassive

Classic subdomain enumeration tool; maintenance can vary.

Domain, DNS & infrastructureFree / open source
Open procedure +
Start with

An authorized domain

Worked example

Run passive subdomain enumeration, compare results with certificate-transparency data, and verify which hosts still resolve.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: An authorized domain.

  2. 02

    Use Sublist3r for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Sublist3r is a lead source unless the underlying record itself is authoritative.

112

Findomain

CLIPassive

Subdomain discovery and monitoring tool.

Domain, DNS & infrastructureFree / open source
Open procedure +
Start with

An authorized domain

Worked example

Enumerate passive subdomains, save the output, resolve candidates, and compare with your known asset inventory.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: An authorized domain.

  2. 02

    Use Findomain for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Findomain is a lead source unless the underlying record itself is authoritative.

113

assetfinder

CLIPassive

Lightweight passive domain and subdomain discovery utility.

Domain, DNS & infrastructureFree / open source
Open procedure +
Start with

An authorized domain

Worked example

Run the domain through passive sources, sort and deduplicate the output, and validate current DNS resolution before classification.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: An authorized domain.

  2. 02

    Use assetfinder for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. assetfinder is a lead source unless the underlying record itself is authoritative.

114

Knockpy

CLIAuthorized-active

DNS and subdomain enumeration tool that may perform active lookups.

Domain, DNS & infrastructureFree / open source
Open procedure +
Start with

A domain you own or have explicit permission to enumerate

Worked example

Begin with passive discovery where possible, use DNS enumeration only within scope, record the authorization and time window, and stop if the target falls outside the agreed domain space.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A domain you own or have explicit permission to enumerate.

  2. 02

    Use Knockpy for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Knockpy is a lead source unless the underlying record itself is authoritative.

115

crt.sh

WebPassive

Certificate Transparency search interface.

Domain, DNS & infrastructureFree
Open procedure +
Start with

A domain or organization name

Worked example

Search `%25.example.com`, review certificate names and issue dates, and confirm whether discovered subdomains still resolve before treating them as current assets.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A domain or organization name.

  2. 02

    Use crt.sh for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. crt.sh is a lead source unless the underlying record itself is authoritative.

116

DNSDumpster

WebPassive

Passive DNS and domain reconnaissance service.

Domain, DNS & infrastructureFree
Open procedure +
Start with

A domain

Worked example

Enter the domain, review discovered DNS records and host map, then confirm important records with direct DNS lookups and current certificate data.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A domain.

  2. 02

    Use DNSDumpster for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. DNSDumpster is a lead source unless the underlying record itself is authoritative.

117

ViewDNS.info

WebPassive

Collection of DNS, IP, WHOIS, and domain-analysis utilities.

Domain, DNS & infrastructureFree / commercial API
Open procedure +
Start with

A domain, IP, ASN, or related infrastructure identifier

Worked example

Use reverse-IP, DNS history, or WHOIS tools as appropriate, record the lookup date, and corroborate historical ownership with archived or registry records.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A domain, IP, ASN, or related infrastructure identifier.

  2. 02

    Use ViewDNS.info for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. ViewDNS.info is a lead source unless the underlying record itself is authoritative.

118

SecurityTrails

WebPassive

DNS, domain, IP, and historical infrastructure data platform.

Domain, DNS & infrastructureFreemium / commercial
Open procedure +
Start with

A domain, IP, DNS record, or organization

Worked example

Search an authorized domain, review current and historical DNS, pivot to related hosts, and separate historical association from current control.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A domain, IP, DNS record, or organization.

  2. 02

    Use SecurityTrails for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. SecurityTrails is a lead source unless the underlying record itself is authoritative.

119

Whoisology

WebPassive

Historical WHOIS research service.

Domain, DNS & infrastructureFreemium / commercial
Open procedure +
Start with

A domain or registrant string

Worked example

Search a domain, inspect historical WHOIS relationships, and corroborate any registrant association because privacy proxies and stale records can mislead.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A domain or registrant string.

  2. 02

    Use Whoisology for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Whoisology is a lead source unless the underlying record itself is authoritative.

120

Whoxy

WebPassive

WHOIS and domain-data search service.

Domain, DNS & infrastructureFreemium / commercial
Open procedure +
Start with

A domain, registrant, or company

Worked example

Search the domain, review current/historical WHOIS where available, and verify corporate identity independently before attribution.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A domain, registrant, or company.

  2. 02

    Use Whoxy for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Whoxy is a lead source unless the underlying record itself is authoritative.

121

Robtex

WebPassive

DNS, IP, ASN, route, and shared-infrastructure research service.

Domain, DNS & infrastructureFree / commercial
Open procedure +
Start with

A domain, IP, ASN, or hostname

Worked example

Enter the identifier, inspect DNS/BGP relationships and neighboring infrastructure, and validate any ownership inference with authoritative records.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A domain, IP, ASN, or hostname.

  2. 02

    Use Robtex for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Robtex is a lead source unless the underlying record itself is authoritative.

122

Hurricane Electric BGP Toolkit

WebPassive

Public BGP, ASN, prefix, and peering research interface.

Domain, DNS & infrastructureFree
Open procedure +
Start with

An ASN, IP prefix, organization, or domain-related network question

Worked example

Search an ASN, inspect announced prefixes and peers, then confirm organization ownership and routing context using RIR or operator information.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: An ASN, IP prefix, organization, or domain-related network question.

  2. 02

    Use Hurricane Electric BGP Toolkit for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Hurricane Electric BGP Toolkit is a lead source unless the underlying record itself is authoritative.

123

reconFTW

CLIAuthorized-active

Automated reconnaissance framework that can combine passive and active modules.

Domain, DNS & infrastructureFree / open source
Open procedure +
Start with

An explicitly authorized domain or asset scope

Worked example

Define the scope file, disable intrusive modules you do not need, run passive stages first, and execute active modules only under written authorization while logging commands and targets.

Open official/project site
Step-by-step use
  1. 01

    Create a case/workspace for one defined question and seed it with An explicitly authorized domain or asset scope.

  2. 02

    Configure passive/public-source modules first. Disable intrusive, authenticated, or active modules unless the target is explicitly authorized.

  3. 03

    Run the smallest useful collection in reconFTW; review which source produced each returned entity or relationship.

  4. 04

    Manually open high-value results and remove false positives, stale data, shared-name collisions, and unsupported automated correlations.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. reconFTW is a lead source unless the underlying record itself is authoritative.

124

Axiom

CLIAuthorized-active

Parallel distributed reconnaissance orchestration for authorized environments.

Domain, DNS & infrastructureFree / open source plus cloud cost
Open procedure +
Start with

A controlled fleet and explicit authorized target list

Worked example

Provision workers only in an approved account, load the exact scope, run authorized parallel enumeration or scanning, and destroy workers after exporting logs and results.

Open official/project site
Step-by-step use
  1. 01

    Create a case/workspace for one defined question and seed it with A controlled fleet and explicit authorized target list.

  2. 02

    Configure passive/public-source modules first. Disable intrusive, authenticated, or active modules unless the target is explicitly authorized.

  3. 03

    Run the smallest useful collection in Axiom; review which source produced each returned entity or relationship.

  4. 04

    Manually open high-value results and remove false positives, stale data, shared-name collisions, and unsupported automated correlations.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Axiom is a lead source unless the underlying record itself is authoritative.

125

urlscan.io

WebSensitive

Public URL scanning and historical web-request intelligence service.

Domain, DNS & infrastructureFree / commercial
Open procedure +
Start with

A URL or domain

Worked example

Search existing scans before submitting anything sensitive, inspect requests, hosts, certificates, and screenshots, and avoid submitting private or credential-bearing URLs to a public scan.

Open official/project site
Step-by-step use
  1. 01

    Begin with a known IP, domain, ASN, certificate, or organization that you are permitted to investigate. Starting input: A URL or domain.

  2. 02

    Search urlscan.io's existing internet-wide index instead of sending traffic to unrelated systems.

  3. 03

    Review service banners, scan timestamps, certificates, ports, and network ownership; treat the data as a dated observation rather than a live guarantee.

  4. 04

    If validation requires direct probing, stop unless the system is yours or you have explicit authorization for active testing.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. urlscan.io is a lead source unless the underlying record itself is authoritative.

126

Web-Check

WebPassive

Web OSINT dashboard that consolidates many public checks.

Domain, DNS & infrastructureFree / open source
Open procedure +
Start with

A public website or domain

Worked example

Enter a public domain, review DNS, headers, technologies, certificates, and other exposed metadata, and verify important findings with the originating source.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A public website or domain.

  2. 02

    Use Web-Check for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Web-Check is a lead source unless the underlying record itself is authoritative.

127

BuiltWith

WebPassive

Website technology profiling and market-intelligence service.

Domain, DNS & infrastructureFreemium / commercial
Open procedure +
Start with

A website domain

Worked example

Search the domain, review detected technologies and historical changes, and confirm current technology from live headers or source where consequential.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A website domain.

  2. 02

    Use BuiltWith for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. BuiltWith is a lead source unless the underlying record itself is authoritative.

128

DomainTools

WebPassive

Commercial domain, DNS, WHOIS, and threat-intelligence platform.

Domain, DNS & infrastructureCommercial
Open procedure +
Start with

A domain, IP, registrant, or infrastructure question

Worked example

Search the domain, inspect registration and DNS history, pivot to related infrastructure, and distinguish historical correlation from present ownership.

Open official/project site
Step-by-step use
  1. 01

    Canonicalize the domain and confirm it is the entity you intend to research. Starting input: A domain, IP, registrant, or infrastructure question.

  2. 02

    Use DomainTools for passive DNS, certificates, WHOIS, subdomains, technologies, routing, or historical infrastructure as appropriate.

  3. 03

    Record timestamps because DNS, certificates, hosting, and ownership change; a historical association is not necessarily current control.

  4. 04

    Cross-check important relationships with a second infrastructure source and, for ownership claims, an authoritative registry or organization record.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. DomainTools is a lead source unless the underlying record itself is authoritative.

129

Shodan

WebPassive

Internet-wide search engine for publicly reachable services and device banners.

IP, network & attack surfaceFreemium / commercial
Open procedure +
Start with

An IP, ASN, hostname, organization, product banner, or authorized exposure question

Worked example

Search your own public IP or organization filter, review previously indexed service banners, and use results to identify exposure without sending exploit traffic to third-party systems.

Open official/project site
Step-by-step use
  1. 01

    Begin with a known IP, domain, ASN, certificate, or organization that you are permitted to investigate. Starting input: An IP, ASN, hostname, organization, product banner, or authorized exposure question.

  2. 02

    Search Shodan's existing internet-wide index instead of sending traffic to unrelated systems.

  3. 03

    Review service banners, scan timestamps, certificates, ports, and network ownership; treat the data as a dated observation rather than a live guarantee.

  4. 04

    If validation requires direct probing, stop unless the system is yours or you have explicit authorization for active testing.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Shodan is a lead source unless the underlying record itself is authoritative.

130

Censys

WebPassive

Internet-wide host, certificate, and service search platform.

IP, network & attack surfaceFreemium / commercial
Open procedure +
Start with

An IP, domain, certificate, service, or organization

Worked example

Search an owned domain or certificate fingerprint, review observed hosts and services, and compare timestamps because internet-wide scan data is a snapshot, not real-time truth.

Open official/project site
Step-by-step use
  1. 01

    Begin with a known IP, domain, ASN, certificate, or organization that you are permitted to investigate. Starting input: An IP, domain, certificate, service, or organization.

  2. 02

    Search Censys's existing internet-wide index instead of sending traffic to unrelated systems.

  3. 03

    Review service banners, scan timestamps, certificates, ports, and network ownership; treat the data as a dated observation rather than a live guarantee.

  4. 04

    If validation requires direct probing, stop unless the system is yours or you have explicit authorization for active testing.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Censys is a lead source unless the underlying record itself is authoritative.

131

ZoomEye

WebPassive

Internet device and service search engine.

IP, network & attack surfaceFreemium / commercial
Open procedure +
Start with

An IP, service, device fingerprint, or authorized organization

Worked example

Search an owned service fingerprint, review indexed hosts, and validate findings through your authorized asset inventory rather than probing unrelated systems.

Open official/project site
Step-by-step use
  1. 01

    Begin with a known IP, domain, ASN, certificate, or organization that you are permitted to investigate. Starting input: An IP, service, device fingerprint, or authorized organization.

  2. 02

    Search ZoomEye's existing internet-wide index instead of sending traffic to unrelated systems.

  3. 03

    Review service banners, scan timestamps, certificates, ports, and network ownership; treat the data as a dated observation rather than a live guarantee.

  4. 04

    If validation requires direct probing, stop unless the system is yours or you have explicit authorization for active testing.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. ZoomEye is a lead source unless the underlying record itself is authoritative.

132

FOFA

WebPassive

Internet asset search engine.

IP, network & attack surfaceFreemium / commercial
Open procedure +
Start with

An IP, domain, certificate, service, or technology fingerprint

Worked example

Search only to identify publicly indexed exposure, narrow results to your assets, and do not use discoveries as authorization to access third-party systems.

Open official/project site
Step-by-step use
  1. 01

    Begin with a known IP, domain, ASN, certificate, or organization that you are permitted to investigate. Starting input: An IP, domain, certificate, service, or technology fingerprint.

  2. 02

    Search FOFA's existing internet-wide index instead of sending traffic to unrelated systems.

  3. 03

    Review service banners, scan timestamps, certificates, ports, and network ownership; treat the data as a dated observation rather than a live guarantee.

  4. 04

    If validation requires direct probing, stop unless the system is yours or you have explicit authorization for active testing.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. FOFA is a lead source unless the underlying record itself is authoritative.

133

Criminal IP

WebPassive

Attack-surface and threat-intelligence search service.

IP, network & attack surfaceFreemium / commercial
Open procedure +
Start with

An IP, domain, asset, or exposure question

Worked example

Check an owned domain or IP, review risk and service observations, and independently verify high-severity labels before remediation or reporting.

Open official/project site
Step-by-step use
  1. 01

    Begin with a known IP, domain, ASN, certificate, or organization that you are permitted to investigate. Starting input: An IP, domain, asset, or exposure question.

  2. 02

    Search Criminal IP's existing internet-wide index instead of sending traffic to unrelated systems.

  3. 03

    Review service banners, scan timestamps, certificates, ports, and network ownership; treat the data as a dated observation rather than a live guarantee.

  4. 04

    If validation requires direct probing, stop unless the system is yours or you have explicit authorization for active testing.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Criminal IP is a lead source unless the underlying record itself is authoritative.

134

AbuseIPDB

WebPassive

Community IP-abuse reputation database.

IP, network & attack surfaceFree / API tiers
Open procedure +
Start with

An IP address observed in logs or public infrastructure

Worked example

Search the IP, review report dates and categories, compare with your own log evidence, and avoid treating community reports as definitive attribution.

Open official/project site
Step-by-step use
  1. 01

    Begin with a known IP, domain, ASN, certificate, or organization that you are permitted to investigate. Starting input: An IP address observed in logs or public infrastructure.

  2. 02

    Search AbuseIPDB's existing internet-wide index instead of sending traffic to unrelated systems.

  3. 03

    Review service banners, scan timestamps, certificates, ports, and network ownership; treat the data as a dated observation rather than a live guarantee.

  4. 04

    If validation requires direct probing, stop unless the system is yours or you have explicit authorization for active testing.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. AbuseIPDB is a lead source unless the underlying record itself is authoritative.

135

IPinfo

WebPassive

IP metadata, ASN, carrier, and approximate geolocation service.

IP, network & attack surfaceFreemium / commercial
Open procedure +
Start with

An IP address

Worked example

Look up the IP, capture ASN, organization, and approximate region, and do not infer a person's exact physical location from IP geolocation.

Open official/project site
Step-by-step use
  1. 01

    Begin with a known IP, domain, ASN, certificate, or organization that you are permitted to investigate. Starting input: An IP address.

  2. 02

    Search IPinfo's existing internet-wide index instead of sending traffic to unrelated systems.

  3. 03

    Review service banners, scan timestamps, certificates, ports, and network ownership; treat the data as a dated observation rather than a live guarantee.

  4. 04

    If validation requires direct probing, stop unless the system is yours or you have explicit authorization for active testing.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. IPinfo is a lead source unless the underlying record itself is authoritative.

136

DB-IP

WebPassive

IP geolocation and network metadata database.

IP, network & attack surfaceFree / commercial data
Open procedure +
Start with

An IP address

Worked example

Query the IP, record the database date and approximate location, and use it only as coarse network context, not proof of a user's address.

Open official/project site
Step-by-step use
  1. 01

    Begin with a known IP, domain, ASN, certificate, or organization that you are permitted to investigate. Starting input: An IP address.

  2. 02

    Search DB-IP's existing internet-wide index instead of sending traffic to unrelated systems.

  3. 03

    Review service banners, scan timestamps, certificates, ports, and network ownership; treat the data as a dated observation rather than a live guarantee.

  4. 04

    If validation requires direct probing, stop unless the system is yours or you have explicit authorization for active testing.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. DB-IP is a lead source unless the underlying record itself is authoritative.

137

VirusTotal

WebSensitive

Multi-engine malware, URL, domain, IP, and file intelligence platform.

IP, network & attack surfaceFree / commercial
Open procedure +
Start with

A public hash, domain, URL, or IP; files only when you are permitted to upload them

Worked example

Search a known hash first, inspect vendor detections and relationships, and never upload confidential files to a public analysis service.

Open official/project site
Step-by-step use
  1. 01

    Start with a defensible indicator such as a hash, domain, URL, IP, family name, or event from your own logs. Starting input: A public hash, domain, URL, or IP; files only when you are permitted to upload them.

  2. 02

    Search VirusTotal without executing a file or directly visiting a suspicious URL from a normal workstation.

  3. 03

    Compare first/last-seen dates, detection names, confidence, and source provenance across at least one additional threat-intelligence source.

  4. 04

    Separate indicator reputation from attribution; a malicious IP, shared host, or detection label does not by itself identify the responsible actor.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. VirusTotal is a lead source unless the underlying record itself is authoritative.

138

Nmap

CLIAuthorized-active

Network discovery and service-enumeration scanner.

IP, network & attack surfaceFree / open source
Open procedure +
Start with

An IP or subnet you own or have explicit permission to scan

Worked example

Record written scope, run a limited service/version scan against your own lab or authorized host, save the output, and compare discovered services with the approved asset inventory.

Open official/project site
Step-by-step use
  1. 01

    Obtain explicit authorization and write down the exact hosts, ports, dates, rate limits, and prohibited actions before using Nmap.

  2. 02

    Load only the approved target set. Starting input: An IP or subnet you own or have explicit permission to scan.

  3. 03

    Begin with the least intrusive scan that answers the question; use conservative rates and do not expand scope because a new host or service appears interesting.

  4. 04

    Save the command, version, timestamps, and raw output; confirm positives using another authorized method rather than escalating automatically.

  5. 05

    Stop immediately on scope ambiguity, instability, or evidence that the target is owned by a third party not covered by the authorization.

139

Masscan

CLIAuthorized-active

Very high-speed network port scanner; use only in explicitly authorized environments.

IP, network & attack surfaceFree / open source
Open procedure +
Start with

A specifically authorized IP range

Worked example

Use a conservative rate against a lab or approved range, target only approved ports, log the command and scope, and validate positives with a less aggressive authorized tool.

Open official/project site
Step-by-step use
  1. 01

    Obtain explicit authorization and write down the exact hosts, ports, dates, rate limits, and prohibited actions before using Masscan.

  2. 02

    Load only the approved target set. Starting input: A specifically authorized IP range.

  3. 03

    Begin with the least intrusive scan that answers the question; use conservative rates and do not expand scope because a new host or service appears interesting.

  4. 04

    Save the command, version, timestamps, and raw output; confirm positives using another authorized method rather than escalating automatically.

  5. 05

    Stop immediately on scope ambiguity, instability, or evidence that the target is owned by a third party not covered by the authorization.

140

Naabu

CLIAuthorized-active

Fast port-scanning utility for security assessments.

IP, network & attack surfaceFree / open source
Open procedure +
Start with

Authorized hosts or IP ranges

Worked example

Provide the approved host list, scan only the ports required by the assessment, save results, and hand confirmed services to your authorized validation workflow.

Open official/project site
Step-by-step use
  1. 01

    Obtain explicit authorization and write down the exact hosts, ports, dates, rate limits, and prohibited actions before using Naabu.

  2. 02

    Load only the approved target set. Starting input: Authorized hosts or IP ranges.

  3. 03

    Begin with the least intrusive scan that answers the question; use conservative rates and do not expand scope because a new host or service appears interesting.

  4. 04

    Save the command, version, timestamps, and raw output; confirm positives using another authorized method rather than escalating automatically.

  5. 05

    Stop immediately on scope ambiguity, instability, or evidence that the target is owned by a third party not covered by the authorization.

141

RustScan

CLIAuthorized-active

Fast port discovery scanner that can feed Nmap.

IP, network & attack surfaceFree / open source
Open procedure +
Start with

An authorized host

Worked example

Run it only against your own system or written assessment scope, limit concurrency as appropriate, and use discovered ports as inputs to an approved service-review process.

Open official/project site
Step-by-step use
  1. 01

    Obtain explicit authorization and write down the exact hosts, ports, dates, rate limits, and prohibited actions before using RustScan.

  2. 02

    Load only the approved target set. Starting input: An authorized host.

  3. 03

    Begin with the least intrusive scan that answers the question; use conservative rates and do not expand scope because a new host or service appears interesting.

  4. 04

    Save the command, version, timestamps, and raw output; confirm positives using another authorized method rather than escalating automatically.

  5. 05

    Stop immediately on scope ambiguity, instability, or evidence that the target is owned by a third party not covered by the authorization.

142

httpx

CLIAuthorized-active

HTTP probing and metadata collection utility for authorized web assets.

IP, network & attack surfaceFree / open source
Open procedure +
Start with

A list of authorized web hosts or URLs

Worked example

Feed an approved asset list, collect HTTP status, title, technologies, and TLS metadata, then compare live results with your known inventory without sending exploit payloads.

Open official/project site
Step-by-step use
  1. 01

    Obtain explicit authorization and write down the exact hosts, ports, dates, rate limits, and prohibited actions before using httpx.

  2. 02

    Load only the approved target set. Starting input: A list of authorized web hosts or URLs.

  3. 03

    Begin with the least intrusive scan that answers the question; use conservative rates and do not expand scope because a new host or service appears interesting.

  4. 04

    Save the command, version, timestamps, and raw output; confirm positives using another authorized method rather than escalating automatically.

  5. 05

    Stop immediately on scope ambiguity, instability, or evidence that the target is owned by a third party not covered by the authorization.

143

BinaryEdge

WebPassive

Internet exposure and attack-surface data provider.

IP, network & attack surfaceCommercial / status varies
Open procedure +
Start with

An IP, service, or authorized organization

Worked example

Search an owned IP or domain, review historical exposure, and confirm the service's current product availability and data freshness before relying on it.

Open official/project site
Step-by-step use
  1. 01

    Begin with a known IP, domain, ASN, certificate, or organization that you are permitted to investigate. Starting input: An IP, service, or authorized organization.

  2. 02

    Search BinaryEdge's existing internet-wide index instead of sending traffic to unrelated systems.

  3. 03

    Review service banners, scan timestamps, certificates, ports, and network ownership; treat the data as a dated observation rather than a live guarantee.

  4. 04

    If validation requires direct probing, stop unless the system is yours or you have explicit authorization for active testing.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. BinaryEdge is a lead source unless the underlying record itself is authoritative.

144

Google Lens

WebPassive

Reverse-image and visual-search service.

Image, video & verificationFree
Open procedure +
Start with

An image or crop

Worked example

Upload the full image, then crop distinctive objects or signage, compare earlier appearances and context, and save the URLs of the strongest original-source matches.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original file or original public URL first. Work from a copy. Starting input: An image or crop.

  2. 02

    Use Google Lens on the full image and, where useful, on crops containing distinctive faces, signs, buildings, objects, or textures.

  3. 03

    Compare publication dates, source pages, metadata, and visual details. Missing metadata is not evidence of manipulation because platforms often strip it.

  4. 04

    Treat forensic filters and face-similarity results as indicators, not verdicts; seek independent confirmation from chronology, geography, or primary-source context.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Google Lens is a lead source unless the underlying record itself is authoritative.

145

Yandex Images

WebPassive

Reverse-image and visual-similarity search engine.

Image, video & verificationFree
Open procedure +
Start with

An image or crop

Worked example

Upload an image, review visually similar results, then compare landmarks, faces, clothing, and publication dates across candidate sources.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original file or original public URL first. Work from a copy. Starting input: An image or crop.

  2. 02

    Use Yandex Images on the full image and, where useful, on crops containing distinctive faces, signs, buildings, objects, or textures.

  3. 03

    Compare publication dates, source pages, metadata, and visual details. Missing metadata is not evidence of manipulation because platforms often strip it.

  4. 04

    Treat forensic filters and face-similarity results as indicators, not verdicts; seek independent confirmation from chronology, geography, or primary-source context.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Yandex Images is a lead source unless the underlying record itself is authoritative.

146

TinEye

WebPassive

Reverse-image search specializing in prior appearances and modified copies.

Image, video & verificationFree / commercial API
Open procedure +
Start with

An image

Worked example

Upload the image, sort matches by oldest or most changed, inspect source dates, and use the publication history to test whether a claimed 'new' image predates the event.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original file or original public URL first. Work from a copy. Starting input: An image.

  2. 02

    Use TinEye on the full image and, where useful, on crops containing distinctive faces, signs, buildings, objects, or textures.

  3. 03

    Compare publication dates, source pages, metadata, and visual details. Missing metadata is not evidence of manipulation because platforms often strip it.

  4. 04

    Treat forensic filters and face-similarity results as indicators, not verdicts; seek independent confirmation from chronology, geography, or primary-source context.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. TinEye is a lead source unless the underlying record itself is authoritative.

147

Bing Visual Search

WebPassive

Microsoft visual-search and reverse-image service.

Image, video & verificationFree
Open procedure +
Start with

An image or crop

Worked example

Upload a photo, focus the crop on a distinctive object or place, review similar images, and verify any proposed source independently.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original file or original public URL first. Work from a copy. Starting input: An image or crop.

  2. 02

    Use Bing Visual Search on the full image and, where useful, on crops containing distinctive faces, signs, buildings, objects, or textures.

  3. 03

    Compare publication dates, source pages, metadata, and visual details. Missing metadata is not evidence of manipulation because platforms often strip it.

  4. 04

    Treat forensic filters and face-similarity results as indicators, not verdicts; seek independent confirmation from chronology, geography, or primary-source context.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Bing Visual Search is a lead source unless the underlying record itself is authoritative.

148

ExifTool

CLISensitive

Comprehensive metadata reader and writer for media and document files.

Image, video & verificationFree / open source
Open procedure +
Start with

An original media file you lawfully possess

Worked example

Work on a copy, inspect EXIF/XMP/IPTC metadata, record the exact tags that matter, and remember that missing metadata does not prove manipulation because platforms commonly strip it.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original file or original public URL first. Work from a copy. Starting input: An original media file you lawfully possess.

  2. 02

    Use ExifTool on the full image and, where useful, on crops containing distinctive faces, signs, buildings, objects, or textures.

  3. 03

    Compare publication dates, source pages, metadata, and visual details. Missing metadata is not evidence of manipulation because platforms often strip it.

  4. 04

    Treat forensic filters and face-similarity results as indicators, not verdicts; seek independent confirmation from chronology, geography, or primary-source context.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. ExifTool is a lead source unless the underlying record itself is authoritative.

149

Forensically

WebSensitive

Browser-based image-forensics toolkit.

Image, video & verificationFree
Open procedure +
Start with

An image you may lawfully upload to the service

Worked example

Load the image, compare clone detection, noise, and level-analysis views, and use anomalies only as prompts for further verification rather than declaring an edit from one filter.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original file or original public URL first. Work from a copy. Starting input: An image you may lawfully upload to the service.

  2. 02

    Use Forensically on the full image and, where useful, on crops containing distinctive faces, signs, buildings, objects, or textures.

  3. 03

    Compare publication dates, source pages, metadata, and visual details. Missing metadata is not evidence of manipulation because platforms often strip it.

  4. 04

    Treat forensic filters and face-similarity results as indicators, not verdicts; seek independent confirmation from chronology, geography, or primary-source context.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Forensically is a lead source unless the underlying record itself is authoritative.

150

FotoForensics

WebSensitive

Image-forensics service with error-level analysis and metadata tools.

Image, video & verificationFree / donations
Open procedure +
Start with

A non-confidential image

Worked example

Upload the image, inspect error-level analysis and metadata, read the site's methodology, and avoid treating ELA patterns as conclusive evidence of manipulation.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original file or original public URL first. Work from a copy. Starting input: A non-confidential image.

  2. 02

    Use FotoForensics on the full image and, where useful, on crops containing distinctive faces, signs, buildings, objects, or textures.

  3. 03

    Compare publication dates, source pages, metadata, and visual details. Missing metadata is not evidence of manipulation because platforms often strip it.

  4. 04

    Treat forensic filters and face-similarity results as indicators, not verdicts; seek independent confirmation from chronology, geography, or primary-source context.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. FotoForensics is a lead source unless the underlying record itself is authoritative.

151

Ghiro

MixedSensitive

Automated image-forensics project; verify current maintenance.

Image, video & verificationFree / open source
Open procedure +
Start with

Image files in a controlled forensic workspace

Worked example

Import copies of the images, run automated metadata and consistency checks, review flagged features manually, and preserve originals outside the analysis workspace.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original file or original public URL first. Work from a copy. Starting input: Image files in a controlled forensic workspace.

  2. 02

    Use Ghiro on the full image and, where useful, on crops containing distinctive faces, signs, buildings, objects, or textures.

  3. 03

    Compare publication dates, source pages, metadata, and visual details. Missing metadata is not evidence of manipulation because platforms often strip it.

  4. 04

    Treat forensic filters and face-similarity results as indicators, not verdicts; seek independent confirmation from chronology, geography, or primary-source context.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Ghiro is a lead source unless the underlying record itself is authoritative.

152

Sherloq

DesktopSensitive

Desktop image-forensics environment.

Image, video & verificationFree / open source
Open procedure +
Start with

An image file

Worked example

Open a copy of the image, inspect metadata and multiple forensic transforms, compare findings across methods, and document uncertainty rather than relying on one visual artifact.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original file or original public URL first. Work from a copy. Starting input: An image file.

  2. 02

    Use Sherloq on the full image and, where useful, on crops containing distinctive faces, signs, buildings, objects, or textures.

  3. 03

    Compare publication dates, source pages, metadata, and visual details. Missing metadata is not evidence of manipulation because platforms often strip it.

  4. 04

    Treat forensic filters and face-similarity results as indicators, not verdicts; seek independent confirmation from chronology, geography, or primary-source context.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Sherloq is a lead source unless the underlying record itself is authoritative.

153

InVID Verification Plugin

Browser extensionPassive

Verification browser extension for video keyframes, images, and social content.

Image, video & verificationFree
Open procedure +
Start with

A public video URL, image, or social-media post

Worked example

Extract keyframes from the video, reverse-search several distinct frames, inspect metadata/context tools, and compare upload chronology across platforms.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original public URL or authorized file and note the upload time, account, title, and stated location. Starting input: A public video URL, image, or social-media post.

  2. 02

    Use InVID Verification Plugin to extract keyframes, transcript, scenes, or detector outputs relevant to the question.

  3. 03

    Reverse-search several distinct keyframes and compare the earliest known appearances rather than relying on one frame.

  4. 04

    Test chronology, audio/visual continuity, geolocation clues, and any synthetic-media score against independent evidence; model scores are probabilistic.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. InVID Verification Plugin is a lead source unless the underlying record itself is authoritative.

154

Azure AI Video Indexer

WebSensitive

Cloud video indexing, transcription, and content-analysis service.

Image, video & verificationCloud service / paid tiers
Open procedure +
Start with

A video you are permitted to upload

Worked example

Upload only non-confidential or authorized footage, review transcript/scene/entity outputs as machine-generated aids, and verify important identifications manually.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original public URL or authorized file and note the upload time, account, title, and stated location. Starting input: A video you are permitted to upload.

  2. 02

    Use Azure AI Video Indexer to extract keyframes, transcript, scenes, or detector outputs relevant to the question.

  3. 03

    Reverse-search several distinct keyframes and compare the earliest known appearances rather than relying on one frame.

  4. 04

    Test chronology, audio/visual continuity, geolocation clues, and any synthetic-media score against independent evidence; model scores are probabilistic.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Azure AI Video Indexer is a lead source unless the underlying record itself is authoritative.

155

DeepFake-O-Meter

WebSensitive

Research interface for running multiple synthetic-media detectors.

Image, video & verificationResearch service
Open procedure +
Start with

A media file you are permitted to upload

Worked example

Submit the file, compare outputs from multiple detectors, preserve the detector/version and date, and treat scores as probabilistic evidence requiring contextual verification.

Open official/project site
Step-by-step use
  1. 01

    Preserve the original public URL or authorized file and note the upload time, account, title, and stated location. Starting input: A media file you are permitted to upload.

  2. 02

    Use DeepFake-O-Meter to extract keyframes, transcript, scenes, or detector outputs relevant to the question.

  3. 03

    Reverse-search several distinct keyframes and compare the earliest known appearances rather than relying on one frame.

  4. 04

    Test chronology, audio/visual continuity, geolocation clues, and any synthetic-media score against independent evidence; model scores are probabilistic.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. DeepFake-O-Meter is a lead source unless the underlying record itself is authoritative.

156

GeoSpy

WebSensitive

AI-assisted image geolocation service.

Image, video & verificationFreemium / commercial
Open procedure +
Start with

A location image you may lawfully analyze

Worked example

Upload the scene, record suggested countries/cities and confidence, then independently test visual clues with maps, signage, terrain, and street imagery before geolocating.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A location image you may lawfully analyze.

  2. 02

    Use GeoSpy to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. GeoSpy is a lead source unless the underlying record itself is authoritative.

157

Picarta

WebSensitive

AI image geolocation service.

Image, video & verificationFreemium / commercial
Open procedure +
Start with

A geolocation image

Worked example

Upload the image, note proposed coordinates/regions, and corroborate with road geometry, architecture, vegetation, sun, and map sources before acceptance.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A geolocation image.

  2. 02

    Use Picarta to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Picarta is a lead source unless the underlying record itself is authoritative.

158

GeoInfer

MixedSensitive

Name used by multiple geolocation projects; verify the implementation.

Image, video & verificationProject-dependent
Open procedure +
Start with

A geolocation image

Worked example

Confirm the specific GeoInfer project or service, submit only permitted media, and treat location predictions as hypotheses to be tested with independent map evidence.

Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A geolocation image.

  2. 02

    Use GeoInfer to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. GeoInfer is a lead source unless the underlying record itself is authoritative.

159

ReverseImageLocation

WebSensitive

Generic image-location service label; verify provider and current availability.

Image, video & verificationService-dependent
Open procedure +
Start with

A public or authorized image

Worked example

Use the service to obtain candidate locations, then verify street layout, skyline, terrain, and other fixed features against independent map and imagery sources.

Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A public or authorized image.

  2. 02

    Use ReverseImageLocation to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. ReverseImageLocation is a lead source unless the underlying record itself is authoritative.

160

ShadowFinder

WebPassive

Shadow-analysis project label; verify the current implementation.

Image, video & verificationProject-dependent
Open procedure +
Start with

An image with clear shadows plus a candidate location/date

Worked example

Measure shadow direction/length, compare it with candidate sun geometry, and treat the result as a consistency test rather than a standalone timestamp.

Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: An image with clear shadows plus a candidate location/date.

  2. 02

    Use ShadowFinder to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. ShadowFinder is a lead source unless the underlying record itself is authoritative.

161

SunCalc

WebPassive

Sun position and shadow geometry calculator.

Image, video & verificationFree
Open procedure +
Start with

Candidate coordinates, date, and local time

Worked example

Enter the proposed location and date, compare sun azimuth/elevation with visible shadows, and test multiple plausible times rather than forcing one match.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: Candidate coordinates, date, and local time.

  2. 02

    Use SunCalc to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. SunCalc is a lead source unless the underlying record itself is authoritative.

162

ShadeMap

WebPassive

Interactive terrain/building shadow visualization service.

Image, video & verificationFreemium
Open procedure +
Start with

A location, date, and time

Worked example

Set the candidate place and date, adjust time until modeled shadows resemble the image, and use the result only alongside other geolocation evidence.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A location, date, and time.

  2. 02

    Use ShadeMap to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. ShadeMap is a lead source unless the underlying record itself is authoritative.

163

Google Earth Pro

DesktopPassive

Desktop globe with historical imagery, measurement, and KML support.

Geolocation, maps & GEOINTFree
Open procedure +
Start with

A place name, coordinates, KML/KMZ, or visual landmark

Worked example

Search the candidate location, use historical imagery where available, measure distances and sight lines, and capture imagery dates when comparing change over time.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A place name, coordinates, KML/KMZ, or visual landmark.

  2. 02

    Use Google Earth Pro to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Google Earth Pro is a lead source unless the underlying record itself is authoritative.

164

Google Earth Engine

WebPassive

Cloud geospatial analysis platform with large earth-observation datasets.

Geolocation, maps & GEOINTResearch / cloud access
Open procedure +
Start with

An area of interest, date range, and remote-sensing question

Worked example

Define the area and period, select an appropriate satellite dataset, visualize a change indicator, and document dataset provenance and cloud/coverage limitations.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: An area of interest, date range, and remote-sensing question.

  2. 02

    Use Google Earth Engine to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Google Earth Engine is a lead source unless the underlying record itself is authoritative.

165

Google Maps

WebPassive

General mapping, routing, place, and street-imagery service.

Geolocation, maps & GEOINTFree
Open procedure +
Start with

A place, address, coordinates, business, or route

Worked example

Search the location, compare map geometry and street imagery, check business/address labels cautiously, and corroborate time-sensitive details with other sources.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A place, address, coordinates, business, or route.

  2. 02

    Use Google Maps to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Google Maps is a lead source unless the underlying record itself is authoritative.

166

Bing Maps

WebPassive

Microsoft mapping and aerial imagery service.

Geolocation, maps & GEOINTFree
Open procedure +
Start with

A place or coordinates

Worked example

Search the candidate location, compare aerial imagery and road geometry with the source image, and note imagery recency where available.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A place or coordinates.

  2. 02

    Use Bing Maps to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Bing Maps is a lead source unless the underlying record itself is authoritative.

167

Apple Maps

WebPassive

Apple mapping and place-information service.

Geolocation, maps & GEOINTFree
Open procedure +
Start with

A place, address, or coordinates

Worked example

Search the location, compare business/place records and imagery, and use it as an independent mapping source when labels differ across platforms.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A place, address, or coordinates.

  2. 02

    Use Apple Maps to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Apple Maps is a lead source unless the underlying record itself is authoritative.

168

OpenStreetMap

WebPassive

Open collaborative geographic database.

Geolocation, maps & GEOINTOpen data
Open procedure +
Start with

A place, coordinates, road, feature, or map object

Worked example

Search the location, inspect mapped buildings/roads/land use, open object history when relevant, and remember community mapping completeness varies by area.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A place, coordinates, road, feature, or map object.

  2. 02

    Use OpenStreetMap to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. OpenStreetMap is a lead source unless the underlying record itself is authoritative.

169

Overpass Turbo

WebPassive

Interactive interface to the OpenStreetMap Overpass API.

Geolocation, maps & GEOINTFree
Open procedure +
Start with

An OpenStreetMap feature query and geographic area

Worked example

Use the query wizard for a feature such as `amenity=school in Oakland`, run it, inspect mapped results, and export GeoJSON while recording the query and retrieval date.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: An OpenStreetMap feature query and geographic area.

  2. 02

    Use Overpass Turbo to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Overpass Turbo is a lead source unless the underlying record itself is authoritative.

170

Mapillary

WebPassive

Crowdsourced street-level imagery platform.

Geolocation, maps & GEOINTFree / account features
Open procedure +
Start with

A location or roadway

Worked example

Navigate to the area, inspect street-level image sequences and capture dates, and compare fixed landmarks with the image you are verifying.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A location or roadway.

  2. 02

    Use Mapillary to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Mapillary is a lead source unless the underlying record itself is authoritative.

171

KartaView

WebPassive

Open street-level imagery platform.

Geolocation, maps & GEOINTFree / open
Open procedure +
Start with

A location or roadway

Worked example

Search the area, review available drive imagery and capture dates, and compare road signs, building fronts, and lane geometry.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A location or roadway.

  2. 02

    Use KartaView to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. KartaView is a lead source unless the underlying record itself is authoritative.

172

Sentinel Hub

WebPassive

Satellite imagery access and processing platform.

Geolocation, maps & GEOINTFree trials / commercial
Open procedure +
Start with

An area of interest, date range, and satellite imagery need

Worked example

Select the area and dates, choose Sentinel imagery and visualization bands, compare scenes for change, and record acquisition dates and cloud cover.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: An area of interest, date range, and satellite imagery need.

  2. 02

    Use Sentinel Hub to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Sentinel Hub is a lead source unless the underlying record itself is authoritative.

173

NASA Worldview

WebPassive

Near-real-time and historical NASA earth-observation viewer.

Geolocation, maps & GEOINTFree
Open procedure +
Start with

A date, region, and environmental event

Worked example

Set the date, choose relevant imagery layers, animate adjacent days, and capture the layer name and timestamp supporting the observation.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A date, region, and environmental event.

  2. 02

    Use NASA Worldview to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. NASA Worldview is a lead source unless the underlying record itself is authoritative.

174

USGS EarthExplorer

WebPassive

USGS search and download portal for satellite and aerial datasets.

Geolocation, maps & GEOINTFree with account for downloads
Open procedure +
Start with

An area of interest, coordinates, date range, and imagery dataset

Worked example

Define the map area, set dates, select Landsat or another dataset, preview scenes, and record scene IDs for reproducibility.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: An area of interest, coordinates, date range, and imagery dataset.

  2. 02

    Use USGS EarthExplorer to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. USGS EarthExplorer is a lead source unless the underlying record itself is authoritative.

175

Planet Labs

WebPassive

Commercial high-frequency satellite-imagery platform.

Geolocation, maps & GEOINTCommercial / selected access programs
Open procedure +
Start with

An area of interest and date range

Worked example

Search the authorized imagery catalog, compare dated scenes, and preserve scene identifiers and licensing restrictions when using imagery in reporting.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: An area of interest and date range.

  2. 02

    Use Planet Labs to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Planet Labs is a lead source unless the underlying record itself is authoritative.

176

Satellites.pro

WebPassive

Map interface combining satellite and base-map views.

Geolocation, maps & GEOINTFree / ad-supported
Open procedure +
Start with

A place or coordinates

Worked example

Search the location, compare available satellite/base-map layers, and verify imagery dates or provenance with a primary provider when the date matters.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A place or coordinates.

  2. 02

    Use Satellites.pro to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Satellites.pro is a lead source unless the underlying record itself is authoritative.

177

Liveuamap

WebSensitive

Event-mapping platform for conflict and breaking-news reports.

Geolocation, maps & GEOINTFreemium
Open procedure +
Start with

A conflict/event region and date

Worked example

Navigate to the region, use the timeline to identify reported events, open linked sources, and independently verify the underlying reports before treating map markers as confirmed facts.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A conflict/event region and date.

  2. 02

    Use Liveuamap to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Liveuamap is a lead source unless the underlying record itself is authoritative.

178

Global Fishing Watch

WebPassive

Maritime activity visualization using AIS and related datasets.

Geolocation, maps & GEOINTFree / registration features
Open procedure +
Start with

A vessel, maritime area, or date range

Worked example

Search a vessel or draw an area, inspect AIS-derived activity over time, and record gaps or spoofing possibilities before reaching conclusions.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A vessel, maritime area, or date range.

  2. 02

    Use Global Fishing Watch to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Global Fishing Watch is a lead source unless the underlying record itself is authoritative.

179

Global Forest Watch

WebPassive

Forest monitoring and environmental change platform.

Geolocation, maps & GEOINTFree
Open procedure +
Start with

A forest area, administrative region, or date range

Worked example

Navigate to the area, enable tree-cover loss or alert layers, set dates, and export or cite the specific dataset behind the visualization.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A forest area, administrative region, or date range.

  2. 02

    Use Global Forest Watch to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Global Forest Watch is a lead source unless the underlying record itself is authoritative.

180

FlightAware

WebPassive

Flight tracking and aviation data service.

Geolocation, maps & GEOINTFreemium / commercial
Open procedure +
Start with

A flight number, registration, airport, or date

Worked example

Search the flight or aircraft, review route and timing history, and corroborate significant claims with airport records or another flight-data source.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A flight number, registration, airport, or date.

  2. 02

    Use FlightAware to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. FlightAware is a lead source unless the underlying record itself is authoritative.

181

Flightradar24

WebPassive

Global flight-tracking service using ADS-B and related feeds.

Geolocation, maps & GEOINTFreemium / commercial
Open procedure +
Start with

An aircraft registration, callsign, flight, airport, or location

Worked example

Search the aircraft, replay the relevant time window where available, and note coverage limitations and blocked aircraft before drawing conclusions.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: An aircraft registration, callsign, flight, airport, or location.

  2. 02

    Use Flightradar24 to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Flightradar24 is a lead source unless the underlying record itself is authoritative.

182

MarineTraffic

WebPassive

Commercial AIS vessel-tracking and maritime information platform.

Geolocation, maps & GEOINTFreemium / commercial
Open procedure +
Start with

A vessel name, IMO/MMSI, port, or area

Worked example

Search the vessel, inspect track and port calls, record IMO/MMSI to avoid name confusion, and corroborate sensitive findings with additional maritime data.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A vessel name, IMO/MMSI, port, or area.

  2. 02

    Use MarineTraffic to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. MarineTraffic is a lead source unless the underlying record itself is authoritative.

183

VesselFinder

WebPassive

AIS vessel-tracking and ship information service.

Geolocation, maps & GEOINTFreemium / commercial
Open procedure +
Start with

A vessel name, IMO/MMSI, or port

Worked example

Search the vessel, review recent positions and port calls, and compare identifiers with registries or a second AIS source.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A vessel name, IMO/MMSI, or port.

  2. 02

    Use VesselFinder to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. VesselFinder is a lead source unless the underlying record itself is authoritative.

184

AllTrails

WebPassive

Trail, route, elevation, and user-photo platform useful for terrain verification.

Geolocation, maps & GEOINTFreemium
Open procedure +
Start with

A trail, park, or terrain feature

Worked example

Search a trail or park, compare elevation and route geometry with imagery, and use trail photos only with attention to upload date and seasonal change.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A trail, park, or terrain feature.

  2. 02

    Use AllTrails to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. AllTrails is a lead source unless the underlying record itself is authoritative.

185

PeakVisor

WebPassive

Mountain identification and terrain visualization service.

Geolocation, maps & GEOINTFreemium
Open procedure +
Start with

A mountain skyline or candidate location

Worked example

Identify visible peaks from a candidate viewpoint, compare skyline geometry, and use the result to test rather than assume the proposed location.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A mountain skyline or candidate location.

  2. 02

    Use PeakVisor to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. PeakVisor is a lead source unless the underlying record itself is authoritative.

186

GeoHints

WebPassive

Reference guide for visual geolocation clues.

Geolocation, maps & GEOINTFree
Open procedure +
Start with

A road sign, bollard, utility pole, road marking, or other country clue

Worked example

Compare the visible road infrastructure with the site's country examples, shortlist plausible countries, and corroborate with language, driving side, vegetation, and mapping evidence.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A road sign, bollard, utility pole, road marking, or other country clue.

  2. 02

    Use GeoHints to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. GeoHints is a lead source unless the underlying record itself is authoritative.

187

OpenCellID

APISensitive

Open cell-tower location database.

Geolocation, maps & GEOINTOpen data / registration
Open procedure +
Start with

A cell-tower identifier or authorized radio-location dataset

Worked example

Query an authorized cell identifier, record the database timestamp and uncertainty, and do not treat tower location as a person's precise location.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A cell-tower identifier or authorized radio-location dataset.

  2. 02

    Use OpenCellID to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. OpenCellID is a lead source unless the underlying record itself is authoritative.

188

Mylnikov

APISensitive

Wi-Fi and cell geolocation API/service.

Geolocation, maps & GEOINTFree / service limits
Open procedure +
Start with

A Wi-Fi BSSID or cell identifier you may lawfully research

Worked example

Query an authorized network identifier, capture returned approximate coordinates and date, and corroborate with other evidence because wardriving-derived databases can be stale.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A Wi-Fi BSSID or cell identifier you may lawfully research.

  2. 02

    Use Mylnikov to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Mylnikov is a lead source unless the underlying record itself is authoritative.

189

GeoGuessr

WebPassive

Geolocation training game; useful for analyst practice rather than evidence collection.

Geolocation, maps & GEOINTFreemium
Open procedure +
Start with

A need to practice visual geolocation skills

Worked example

Use training maps to practice recognizing road markings, architecture, terrain, and signage, then document which clue types consistently produce reliable location hypotheses.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A need to practice visual geolocation skills.

  2. 02

    Use GeoGuessr to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. GeoGuessr is a lead source unless the underlying record itself is authoritative.

190

Ahmia

WebSensitive

Search engine indexing selected Tor onion services.

Dark web, leaks & undergroundFree
Open procedure +
Start with

A narrowly defined research term with a legitimate public-interest or security purpose

Worked example

Search from a hardened research environment, avoid illegal or exploitative content, open only material necessary to the research question, and preserve minimal metadata rather than downloading sensitive datasets.

Open official/project site
Step-by-step use
  1. 01

    Define a narrow lawful research purpose before searching. Starting input: A narrowly defined research term with a legitimate public-interest or security purpose.

  2. 02

    Use a separated, hardened research environment and current OPSEC procedures; do not authenticate into illicit services or interact with sellers, victims, or operators.

  3. 03

    Use Ahmia only to identify material necessary to the question. Avoid illegal, exploitative, or clearly private content and do not download credential dumps or victim datasets.

  4. 04

    Preserve only minimal metadata such as title, source identifier, date, and a lawful archive/reference where appropriate; escalate sensitive findings through legal/security counsel.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Ahmia is a lead source unless the underlying record itself is authoritative.

191

Torch

WebSensitive

Long-running name used for Tor search services; endpoints and clones change frequently.

Dark web, leaks & undergroundFree / status varies
Open procedure +
Start with

A narrowly scoped lawful research query

Worked example

Confirm the current legitimate Torch endpoint through a trusted directory, use Tor with strong research isolation, avoid illicit content, and do not download credentials or victim data.

Status note: CTI intentionally does not publish an onion address because authenticity changes and clones are common.

Step-by-step use
  1. 01

    Define a narrow lawful research purpose before searching. Starting input: A narrowly scoped lawful research query.

  2. 02

    Use a separated, hardened research environment and current OPSEC procedures; do not authenticate into illicit services or interact with sellers, victims, or operators.

  3. 03

    Use Torch only to identify material necessary to the question. Avoid illegal, exploitative, or clearly private content and do not download credential dumps or victim datasets.

  4. 04

    Preserve only minimal metadata such as title, source identifier, date, and a lawful archive/reference where appropriate; escalate sensitive findings through legal/security counsel.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Torch is a lead source unless the underlying record itself is authoritative.

192

Kompass

WebPassive

Global business directory and company information service.

Companies, sanctions & financialFreemium / commercial
Open procedure +
Start with

A company, industry, product, or country

Worked example

Search the company, review business classification and locations, and confirm ownership and legal status through official registries.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A company, industry, product, or country.

  2. 02

    Search Kompass for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Kompass is a lead source unless the underlying record itself is authoritative.

193

PitchBook

WebPassive

Commercial private-market, venture, private-equity, and M&A database.

Companies, sanctions & financialCommercial
Open procedure +
Start with

A private company, investor, fund, or deal

Worked example

Search the entity, review financing and ownership records, and corroborate material transaction figures with filings, press releases, or regulatory documents.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A private company, investor, fund, or deal.

  2. 02

    Search PitchBook for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. PitchBook is a lead source unless the underlying record itself is authoritative.

194

ZoomInfo

WebSensitive

Commercial business and professional intelligence database.

Companies, sanctions & financialCommercial
Open procedure +
Start with

A company or professional role

Worked example

Search the company, use organizational data as a lead, and verify executives, addresses, and subsidiaries with primary corporate sources.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A company or professional role.

  2. 02

    Search ZoomInfo for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. ZoomInfo is a lead source unless the underlying record itself is authoritative.

195

Dun & Bradstreet

WebPassive

Commercial business-identity, credit, and corporate information provider.

Companies, sanctions & financialCommercial
Open procedure +
Start with

A company name or D-U-N-S number

Worked example

Search the entity, record identifiers and corporate family information, and confirm legal status and ownership using official filings where available.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A company name or D-U-N-S number.

  2. 02

    Search Dun & Bradstreet for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Dun & Bradstreet is a lead source unless the underlying record itself is authoritative.

196

EU Sanctions Map

WebSensitive

European Union interface for sanctions regimes and legal measures.

Companies, sanctions & financialOfficial / free
Open procedure +
Start with

A person, entity, country, or sanctions regime

Worked example

Search the name or regime, compare identifiers and legal instruments, and cite the governing EU measure rather than relying on name similarity alone.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A person, entity, country, or sanctions regime.

  2. 02

    Search EU Sanctions Map for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. EU Sanctions Map is a lead source unless the underlying record itself is authoritative.

197

OCCRP Aleph

WebSensitive

Investigative data platform indexing company, property, court, leak, and document datasets.

Companies, sanctions & financialFree / account features
Open procedure +
Start with

A company, person, document, or cross-border corruption research question

Worked example

Search a legal entity name, inspect documents and dataset provenance, and verify consequential claims against the original filing or document source.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A company, person, document, or cross-border corruption research question.

  2. 02

    Search OCCRP Aleph for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. OCCRP Aleph is a lead source unless the underlying record itself is authoritative.

198

LittleSis

WebSensitive

Public database of relationships among powerful people and organizations.

Companies, sanctions & financialFree
Open procedure +
Start with

A public figure, company, nonprofit, donor, board, or influence network

Worked example

Search the entity, inspect relationships and cited sources, and open the underlying filings or reports before using a relationship in publication.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A public figure, company, nonprofit, donor, board, or influence network.

  2. 02

    Search LittleSis for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. LittleSis is a lead source unless the underlying record itself is authoritative.

199

ImportGenius

WebPassive

Commercial international trade and shipping-record database.

Companies, sanctions & financialCommercial
Open procedure +
Start with

A company, supplier, product, port, or trade route

Worked example

Search an importer/exporter, review shipment records and counterparties, and distinguish shipping-party names from legal ownership.

Open official/project site
Step-by-step use
  1. 01

    Resolve the entity's exact legal name, jurisdiction, and unique identifier before pivoting. Starting input: A company, supplier, product, port, or trade route.

  2. 02

    Search ImportGenius for filings, officers, ownership, sanctions, funding, trade, counterparties, or corporate relationships relevant to the question.

  3. 03

    Separate registry facts from vendor-enriched estimates and distinguish current officers/owners from historical ones.

  4. 04

    Confirm material facts in the authoritative company registry, securities filing, sanctions instrument, contract, or other primary record whenever available.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. ImportGenius is a lead source unless the underlying record itself is authoritative.

200

Etherscan

WebSensitive

Ethereum blockchain explorer and analytics interface.

Crypto & blockchain forensicsFree / API tiers
Open procedure +
Start with

An Ethereum address, transaction hash, token, or contract

Worked example

Paste the address or transaction hash, review transfers and contract interactions, label only what can be sourced, and never infer a real-world identity from an address without independent evidence.

Open official/project site
Step-by-step use
  1. 01

    Confirm the chain and copy the exact address, transaction hash, token, or contract identifier. Starting input: An Ethereum address, transaction hash, token, or contract.

  2. 02

    Use Etherscan to review transaction history, counterparties, labels, timing, and flows without attempting to access any wallet.

  3. 03

    Treat entity labels and clustering as analytical claims unless independently documented; an address is not a real-world identity by itself.

  4. 04

    Verify important transfers on the underlying chain explorer and preserve transaction hashes, block numbers, timestamps, and the label source.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Etherscan is a lead source unless the underlying record itself is authoritative.

201

Arkham

WebSensitive

Blockchain intelligence and entity-labeling platform.

Crypto & blockchain forensicsFreemium / commercial
Open procedure +
Start with

A blockchain address, entity, transaction, or flow question

Worked example

Search the address, inspect labeled entities and transfers, treat labels as claims requiring corroboration, and trace important transactions on the underlying chain explorer.

Open official/project site
Step-by-step use
  1. 01

    Confirm the chain and copy the exact address, transaction hash, token, or contract identifier. Starting input: A blockchain address, entity, transaction, or flow question.

  2. 02

    Use Arkham to review transaction history, counterparties, labels, timing, and flows without attempting to access any wallet.

  3. 03

    Treat entity labels and clustering as analytical claims unless independently documented; an address is not a real-world identity by itself.

  4. 04

    Verify important transfers on the underlying chain explorer and preserve transaction hashes, block numbers, timestamps, and the label source.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Arkham is a lead source unless the underlying record itself is authoritative.

202

TRM Labs

WebSensitive

Commercial blockchain intelligence and compliance platform.

Crypto & blockchain forensicsCommercial
Open procedure +
Start with

A licensed compliance or investigative crypto case

Worked example

Enter an authorized address or transaction, review risk indicators and transaction paths, and document the source and analyst basis for any attribution.

Open official/project site
Step-by-step use
  1. 01

    Confirm the chain and copy the exact address, transaction hash, token, or contract identifier. Starting input: A licensed compliance or investigative crypto case.

  2. 02

    Use TRM Labs to review transaction history, counterparties, labels, timing, and flows without attempting to access any wallet.

  3. 03

    Treat entity labels and clustering as analytical claims unless independently documented; an address is not a real-world identity by itself.

  4. 04

    Verify important transfers on the underlying chain explorer and preserve transaction hashes, block numbers, timestamps, and the label source.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. TRM Labs is a lead source unless the underlying record itself is authoritative.

203

Chainalysis

WebSensitive

Commercial blockchain analytics and investigation platform.

Crypto & blockchain forensicsCommercial
Open procedure +
Start with

A licensed blockchain investigation or compliance case

Worked example

Trace an authorized address, review clusters and service labels, validate important transactions on-chain, and avoid treating proprietary attribution as self-proving.

Open official/project site
Step-by-step use
  1. 01

    Confirm the chain and copy the exact address, transaction hash, token, or contract identifier. Starting input: A licensed blockchain investigation or compliance case.

  2. 02

    Use Chainalysis to review transaction history, counterparties, labels, timing, and flows without attempting to access any wallet.

  3. 03

    Treat entity labels and clustering as analytical claims unless independently documented; an address is not a real-world identity by itself.

  4. 04

    Verify important transfers on the underlying chain explorer and preserve transaction hashes, block numbers, timestamps, and the label source.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Chainalysis is a lead source unless the underlying record itself is authoritative.

204

Cielo

WebSensitive

Crypto wallet tracking and activity-monitoring service.

Crypto & blockchain forensicsFreemium / commercial
Open procedure +
Start with

A public wallet address or watchlist

Worked example

Add a wallet you may lawfully monitor, review transaction alerts and counterparties, and verify transfers on the chain explorer before drawing conclusions.

Open official/project site
Step-by-step use
  1. 01

    Confirm the chain and copy the exact address, transaction hash, token, or contract identifier. Starting input: A public wallet address or watchlist.

  2. 02

    Use Cielo to review transaction history, counterparties, labels, timing, and flows without attempting to access any wallet.

  3. 03

    Treat entity labels and clustering as analytical claims unless independently documented; an address is not a real-world identity by itself.

  4. 04

    Verify important transfers on the underlying chain explorer and preserve transaction hashes, block numbers, timestamps, and the label source.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Cielo is a lead source unless the underlying record itself is authoritative.

205

MetaSleuth

WebSensitive

Visual blockchain investigation and relationship-analysis platform.

Crypto & blockchain forensicsFreemium / commercial
Open procedure +
Start with

A blockchain address or transaction

Worked example

Start from an address, expand transaction relationships, label only entities supported by evidence, and preserve transaction hashes for reproducibility.

Open official/project site
Step-by-step use
  1. 01

    Confirm the chain and copy the exact address, transaction hash, token, or contract identifier. Starting input: A blockchain address or transaction.

  2. 02

    Use MetaSleuth to review transaction history, counterparties, labels, timing, and flows without attempting to access any wallet.

  3. 03

    Treat entity labels and clustering as analytical claims unless independently documented; an address is not a real-world identity by itself.

  4. 04

    Verify important transfers on the underlying chain explorer and preserve transaction hashes, block numbers, timestamps, and the label source.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. MetaSleuth is a lead source unless the underlying record itself is authoritative.

206

Internet Archive Wayback Machine

WebPassive

Historical web-page archive.

Archiving, web history & codeFree
Open procedure +
Start with

A public URL or domain

Worked example

Enter the URL, select captures around the relevant date, compare page changes, and record the exact archive timestamp in your evidence log.

Open official/project site
Step-by-step use
  1. 01

    Normalize the public URL or domain and define the date window you need. Starting input: A public URL or domain.

  2. 02

    Search Internet Archive Wayback Machine for existing captures before creating a new one.

  3. 03

    Compare multiple snapshots around the relevant date to distinguish a genuine change from a failed capture, redirect, or missing asset.

  4. 04

    Record the exact archive timestamp, original URL, capture URL, and any missing interactive content or images.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Internet Archive Wayback Machine is a lead source unless the underlying record itself is authoritative.

207

Archive.today

WebSensitive

On-demand and historical webpage archiving service.

Archiving, web history & codeFree
Open procedure +
Start with

A public webpage that can lawfully be archived

Worked example

Search existing captures first, create a snapshot only for public non-sensitive material, and save the resulting archive URL plus capture time.

Open official/project site
Step-by-step use
  1. 01

    Normalize the public URL or domain and define the date window you need. Starting input: A public webpage that can lawfully be archived.

  2. 02

    Search Archive.today for existing captures before creating a new one.

  3. 03

    Compare multiple snapshots around the relevant date to distinguish a genuine change from a failed capture, redirect, or missing asset.

  4. 04

    Record the exact archive timestamp, original URL, capture URL, and any missing interactive content or images.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Archive.today is a lead source unless the underlying record itself is authoritative.

208

Bellingcat Auto Archiver

MixedSensitive

Automation project for preserving online content across archive services.

Archiving, web history & codeFree / open source
Open procedure +
Start with

Public URLs or social-media links that should be preserved

Worked example

Configure approved archive destinations, feed public URLs, check each generated archive, and log failures because dynamic platforms may not preserve perfectly.

Open official/project site
Step-by-step use
  1. 01

    Normalize the public URL or domain and define the date window you need. Starting input: Public URLs or social-media links that should be preserved.

  2. 02

    Search Bellingcat Auto Archiver for existing captures before creating a new one.

  3. 03

    Compare multiple snapshots around the relevant date to distinguish a genuine change from a failed capture, redirect, or missing asset.

  4. 04

    Record the exact archive timestamp, original URL, capture URL, and any missing interactive content or images.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Bellingcat Auto Archiver is a lead source unless the underlying record itself is authoritative.

209

waybackurls

CLIPassive

CLI utility for retrieving URLs known to the Wayback Machine.

Archiving, web history & codeFree / open source
Open procedure +
Start with

A domain

Worked example

Query an authorized or public-interest domain, collect historical URLs, sort by path or extension, and open archive captures rather than assuming an old URL is still live.

Open official/project site
Step-by-step use
  1. 01

    Normalize the public URL or domain and define the date window you need. Starting input: A domain.

  2. 02

    Search waybackurls for existing captures before creating a new one.

  3. 03

    Compare multiple snapshots around the relevant date to distinguish a genuine change from a failed capture, redirect, or missing asset.

  4. 04

    Record the exact archive timestamp, original URL, capture URL, and any missing interactive content or images.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. waybackurls is a lead source unless the underlying record itself is authoritative.

210

Common Crawl

APIPassive

Open repository of large-scale historical web crawls.

Archiving, web history & codeOpen data
Open procedure +
Start with

A domain, URL pattern, or large-scale historical-web research question

Worked example

Query the index for a domain and date range, retrieve only needed WARC records, and record crawl identifiers so results can be reproduced.

Open official/project site
Step-by-step use
  1. 01

    Normalize the public URL or domain and define the date window you need. Starting input: A domain, URL pattern, or large-scale historical-web research question.

  2. 02

    Search Common Crawl for existing captures before creating a new one.

  3. 03

    Compare multiple snapshots around the relevant date to distinguish a genuine change from a failed capture, redirect, or missing asset.

  4. 04

    Record the exact archive timestamp, original URL, capture URL, and any missing interactive content or images.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Common Crawl is a lead source unless the underlying record itself is authoritative.

211

GitHub Search

WebSensitive

Native GitHub search across public code, repositories, issues, and commits.

Archiving, web history & codeFree / account features
Open procedure +
Start with

A public code term, organization, filename, commit, or repository

Worked example

Search an organization's public repositories for a distinctive configuration name, open the exact file and commit history, and avoid using discovered secrets to access any service.

Open official/project site
Step-by-step use
  1. 01

    Use a precise public-code term, repository, filename, hash, or organization. Starting input: A public code term, organization, filename, commit, or repository.

  2. 02

    Search GitHub Search, then open the originating repository, file, commit, or paste rather than relying on a result snippet.

  3. 03

    Inspect commit history and surrounding code to establish context, authorship, and whether the material was later removed or corrected.

  4. 04

    If you encounter credentials or secrets, do not test them. Preserve minimal evidence and use responsible disclosure or the owner's security process.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. GitHub Search is a lead source unless the underlying record itself is authoritative.

212

Grep.app

WebSensitive

Public code search engine across many GitHub repositories.

Archiving, web history & codeFree
Open procedure +
Start with

A code string, package name, error text, or public secret pattern

Worked example

Search the exact string, open the source repository, inspect commit context, and if a credential appears exposed, report it responsibly rather than testing it.

Open official/project site
Step-by-step use
  1. 01

    Use a precise public-code term, repository, filename, hash, or organization. Starting input: A code string, package name, error text, or public secret pattern.

  2. 02

    Search Grep.app, then open the originating repository, file, commit, or paste rather than relying on a result snippet.

  3. 03

    Inspect commit history and surrounding code to establish context, authorship, and whether the material was later removed or corrected.

  4. 04

    If you encounter credentials or secrets, do not test them. Preserve minimal evidence and use responsible disclosure or the owner's security process.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Grep.app is a lead source unless the underlying record itself is authoritative.

213

Pastebin

WebSensitive

Public text-paste service that can be a source of public leads.

Archiving, web history & codeFree / paid
Open procedure +
Start with

A public paste URL or public-interest keyword where permitted

Worked example

Search or review public material only, preserve minimal metadata, and avoid collecting credentials, personal data, or illegal content that is unnecessary to the investigation.

Open official/project site
Step-by-step use
  1. 01

    Use a precise public-code term, repository, filename, hash, or organization. Starting input: A public paste URL or public-interest keyword where permitted.

  2. 02

    Search Pastebin, then open the originating repository, file, commit, or paste rather than relying on a result snippet.

  3. 03

    Inspect commit history and surrounding code to establish context, authorship, and whether the material was later removed or corrected.

  4. 04

    If you encounter credentials or secrets, do not test them. Preserve minimal evidence and use responsible disclosure or the owner's security process.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. Pastebin is a lead source unless the underlying record itself is authoritative.

214

psbdmp

CLISensitive

Pastebin scraping/search project; maintenance and service restrictions can change.

Archiving, web history & codeFree / open source
Open procedure +
Start with

Public Pastebin-related research terms

Worked example

Confirm project status and legal scope, search only public material, and do not download or reuse leaked credentials or private datasets.

Open official/project site
Step-by-step use
  1. 01

    Use a precise public-code term, repository, filename, hash, or organization. Starting input: Public Pastebin-related research terms.

  2. 02

    Search psbdmp, then open the originating repository, file, commit, or paste rather than relying on a result snippet.

  3. 03

    Inspect commit history and surrounding code to establish context, authorship, and whether the material was later removed or corrected.

  4. 04

    If you encounter credentials or secrets, do not test them. Preserve minimal evidence and use responsible disclosure or the owner's security process.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. psbdmp is a lead source unless the underlying record itself is authoritative.

215

TruffleHog

CLIAuthorized-active

Secret-scanning tool for repositories and other authorized data sources.

Archiving, web history & codeFree / open source
Open procedure +
Start with

A repository or storage location you own or are authorized to audit

Worked example

Run it against your own repository history, review suspected secrets, revoke confirmed exposed credentials, and never test third-party credentials discovered in public code.

Open official/project site
Step-by-step use
  1. 01

    Use a precise public-code term, repository, filename, hash, or organization. Starting input: A repository or storage location you own or are authorized to audit.

  2. 02

    Search TruffleHog, then open the originating repository, file, commit, or paste rather than relying on a result snippet.

  3. 03

    Inspect commit history and surrounding code to establish context, authorship, and whether the material was later removed or corrected.

  4. 04

    If you encounter credentials or secrets, do not test them. Preserve minimal evidence and use responsible disclosure or the owner's security process.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. TruffleHog is a lead source unless the underlying record itself is authoritative.

216

gitleaks

CLIAuthorized-active

Secret-detection scanner for Git repositories and files.

Archiving, web history & codeFree / open source
Open procedure +
Start with

A repository you own or are authorized to assess

Worked example

Scan the working tree and history, triage findings, rotate confirmed secrets, and add prevention checks to CI without attempting to use exposed credentials.

Open official/project site
Step-by-step use
  1. 01

    Use a precise public-code term, repository, filename, hash, or organization. Starting input: A repository you own or are authorized to assess.

  2. 02

    Search gitleaks, then open the originating repository, file, commit, or paste rather than relying on a result snippet.

  3. 03

    Inspect commit history and surrounding code to establish context, authorship, and whether the material was later removed or corrected.

  4. 04

    If you encounter credentials or secrets, do not test them. Preserve minimal evidence and use responsible disclosure or the owner's security process.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. gitleaks is a lead source unless the underlying record itself is authoritative.

217

AlienVault OTX

WebSensitive

Community threat-intelligence exchange.

Threat intelligence & malwareFree / account
Open procedure +
Start with

An IP, domain, URL, file hash, CVE, or threat indicator

Worked example

Search the indicator, review pulses and dates, compare with other intelligence sources, and treat community attribution as a lead unless supported independently.

Open official/project site
Step-by-step use
  1. 01

    Start with a defensible indicator such as a hash, domain, URL, IP, family name, or event from your own logs. Starting input: An IP, domain, URL, file hash, CVE, or threat indicator.

  2. 02

    Search AlienVault OTX without executing a file or directly visiting a suspicious URL from a normal workstation.

  3. 03

    Compare first/last-seen dates, detection names, confidence, and source provenance across at least one additional threat-intelligence source.

  4. 04

    Separate indicator reputation from attribution; a malicious IP, shared host, or detection label does not by itself identify the responsible actor.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. AlienVault OTX is a lead source unless the underlying record itself is authoritative.

218

MalwareBazaar

WebSensitive

Malware sample and metadata exchange operated by abuse.ch.

Threat intelligence & malwareFree
Open procedure +
Start with

A malware hash, signature, family, or authorized research query

Worked example

Search by hash first, review metadata and family labels, and download samples only inside a properly isolated malware-analysis environment with a legitimate need.

Open official/project site
Step-by-step use
  1. 01

    Start with a defensible indicator such as a hash, domain, URL, IP, family name, or event from your own logs. Starting input: A malware hash, signature, family, or authorized research query.

  2. 02

    Search MalwareBazaar without executing a file or directly visiting a suspicious URL from a normal workstation.

  3. 03

    Compare first/last-seen dates, detection names, confidence, and source provenance across at least one additional threat-intelligence source.

  4. 04

    Separate indicator reputation from attribution; a malicious IP, shared host, or detection label does not by itself identify the responsible actor.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. MalwareBazaar is a lead source unless the underlying record itself is authoritative.

219

URLhaus

WebSensitive

Malware URL intelligence service operated by abuse.ch.

Threat intelligence & malwareFree
Open procedure +
Start with

A URL, domain, host, or malware-delivery indicator

Worked example

Search the indicator, review observation dates and payload associations, and never visit a suspected malicious URL directly from a normal workstation.

Open official/project site
Step-by-step use
  1. 01

    Start with a defensible indicator such as a hash, domain, URL, IP, family name, or event from your own logs. Starting input: A URL, domain, host, or malware-delivery indicator.

  2. 02

    Search URLhaus without executing a file or directly visiting a suspicious URL from a normal workstation.

  3. 03

    Compare first/last-seen dates, detection names, confidence, and source provenance across at least one additional threat-intelligence source.

  4. 04

    Separate indicator reputation from attribution; a malicious IP, shared host, or detection label does not by itself identify the responsible actor.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. URLhaus is a lead source unless the underlying record itself is authoritative.

220

ThreatFox

WebSensitive

Community IOC-sharing platform operated by abuse.ch.

Threat intelligence & malwareFree
Open procedure +
Start with

An IOC such as IP, domain, URL, hash, or malware family

Worked example

Search the IOC, compare confidence and timestamps, and corroborate with your logs and at least one independent intelligence source.

Open official/project site
Step-by-step use
  1. 01

    Start with a defensible indicator such as a hash, domain, URL, IP, family name, or event from your own logs. Starting input: An IOC such as IP, domain, URL, hash, or malware family.

  2. 02

    Search ThreatFox without executing a file or directly visiting a suspicious URL from a normal workstation.

  3. 03

    Compare first/last-seen dates, detection names, confidence, and source provenance across at least one additional threat-intelligence source.

  4. 04

    Separate indicator reputation from attribution; a malicious IP, shared host, or detection label does not by itself identify the responsible actor.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. ThreatFox is a lead source unless the underlying record itself is authoritative.

221

PhishTank

WebSensitive

Community phishing URL verification database.

Threat intelligence & malwareFree
Open procedure +
Start with

A suspected phishing URL

Worked example

Search the URL without visiting it, review community verification and submission time, and compare with URLhaus or VirusTotal before blocking or reporting.

Open official/project site
Step-by-step use
  1. 01

    Start with a defensible indicator such as a hash, domain, URL, IP, family name, or event from your own logs. Starting input: A suspected phishing URL.

  2. 02

    Search PhishTank without executing a file or directly visiting a suspicious URL from a normal workstation.

  3. 03

    Compare first/last-seen dates, detection names, confidence, and source provenance across at least one additional threat-intelligence source.

  4. 04

    Separate indicator reputation from attribution; a malicious IP, shared host, or detection label does not by itself identify the responsible actor.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. PhishTank is a lead source unless the underlying record itself is authoritative.

222

OpenPhish

WebSensitive

Phishing intelligence and feeds.

Threat intelligence & malwareFree feeds / commercial
Open procedure +
Start with

A phishing URL or feed-consumption use case

Worked example

Check the suspected URL or consume an authorized feed, compare observation time with your logs, and do not browse malicious URLs directly.

Open official/project site
Step-by-step use
  1. 01

    Start with a defensible indicator such as a hash, domain, URL, IP, family name, or event from your own logs. Starting input: A phishing URL or feed-consumption use case.

  2. 02

    Search OpenPhish without executing a file or directly visiting a suspicious URL from a normal workstation.

  3. 03

    Compare first/last-seen dates, detection names, confidence, and source provenance across at least one additional threat-intelligence source.

  4. 04

    Separate indicator reputation from attribution; a malicious IP, shared host, or detection label does not by itself identify the responsible actor.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. OpenPhish is a lead source unless the underlying record itself is authoritative.

223

ACLED

WebSensitive

Structured political violence and protest event dataset.

Specialized datasetsFree registration / commercial terms
Open procedure +
Start with

A conflict-event region, actor, event type, or date range

Worked example

Filter a country and date range, inspect source notes and methodology, export the event table, and distinguish reported-event coding from independently proven causation.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A conflict-event region, actor, event type, or date range.

  2. 02

    Use ACLED to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. ACLED is a lead source unless the underlying record itself is authoritative.

224

CAT-UXO

WebSensitive

Visual reference database for explosive ordnance identification.

Specialized datasetsFree
Open procedure +
Start with

A munition image or conflict-ordnance identification question

Worked example

Compare visible shape, fins, markings, and dimensions with catalog entries, record uncertainty, and never handle or approach suspected unexploded ordnance based on online identification.

Open official/project site
Step-by-step use
  1. 01

    Write a location or timing hypothesis and list the visible fixed clues. Starting input: A munition image or conflict-ordnance identification question.

  2. 02

    Use CAT-UXO to test road geometry, terrain, building footprints, satellite imagery, street imagery, transport tracks, or environmental layers.

  3. 03

    Compare at least three independent clue types—for example road shape, signage, terrain, and shadow geometry—before assigning high confidence.

  4. 04

    Record imagery dates, coverage gaps, map-edit dates, and sensor limitations; do not assume a current map label existed at the event time.

  5. 05

    Record the source URL or command, retrieval time, relevant identifiers, and your confidence level. CAT-UXO is a lead source unless the underlying record itself is authoritative.

Evidence rule. A tool output is normally a lead or analytical aid. Preserve the originating webpage, filing, post, transaction, map layer, file, or other primary material whenever the claim matters.

Safety rule. “Authorized-active” tools require explicit scope. Sensitive identity, breach, people-search, face-search, phone, and dark-web tools require heightened necessity, minimization, and publication judgment.

Link inclusion is an entry point, not endorsement of every claim made by a service. Sensitive data should be minimized and consequential findings independently corroborated.

OSINT method