License & Deployment Mix: 15 tools – 5 OSS, 10 commercial, 8 SaaS, 9 self-host. (OSS and SaaS counts overlap when an open-source tool also offers a hosted edition; here they do not – the OSS tools are self-host only and the SaaS tools are all proprietary.)

Color: Blue/analyst – investigations, not attack.

What Is Investigative OSINT?

Open-Source Intelligence (OSINT) in this category is the analyst-driven investigation of people, companies, and entities using publicly available information (PAI): social media (SOCMINT), the dark web and breach data, blockchain, public records, archived web, and the links between them. The output is an entity picture – who a subject is, what accounts and addresses they control, who they connect to – assembled on a link-analysis graph and packaged as a defensible report.

The buyers are investigators, not sysadmins: law enforcement, government/defense intelligence, corporate security and due diligence, fraud / insurance SIU teams, and investigative journalists.

Distinct from neighbouring categories

This is deliberately not the same as the security-recon category. The line matters because both use the word “OSINT”:

  • Reconnaissance & Asset Discovery (Reconnaissance & Asset Discovery) maps an organization’s external attack surface – subdomains, IPs, ports, exposed services – the adversary’s-eye view of infrastructure. OSINT here investigates people and entities. SpiderFoot straddles both and is filed under recon.
  • Threat Intelligence Platforms (Threat Intelligence Platforms) curate IOCs and adversary infrastructure for a SOC. OSINT investigates subjects, not indicators.
  • Background Check & Screening (Background Check / Screening) run regulated, consent-based employment screening against court/credit data (FCRA). OSINT is investigative and open-source, not a regulated consumer-reporting product.
  • DFIR (Digital Forensics & IR (DFIR)) works owned evidence (disks, memory, logs) after an incident. OSINT works public data about a subject.

Capabilities typically present

  • Link analysis / entity graph – pivot from a selector (email, username, phone, wallet, domain) to connected entities
  • SOCMINT – social-media account discovery, content, and network mapping
  • Dark web & breach data – leaked-credential and darknet mention search
  • Crypto tracing – wallet / transaction attribution
  • Face & image – reverse image and facial recognition (higher-end platforms)
  • Selector enumeration – username / email -> registered accounts across hundreds of sites
  • Evidence & reporting – timestamped, hashed capture and court-defensible export
  • Automation / API – transforms, batch runs, headless integration

The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.

Comparison

Cross-tool comparison for the OSINT & Investigative Intelligence category: analyst-driven investigative OSINT / SOCMINT / link-analysis platforms.

All facts below are point-in-time and derived from each tool’s per-tool evaluation file. Commercial platforms rarely publish SSO, API, or deployment specifics, so several cells are marked unconfirmed rather than asserted.

Licensing & Cost Model

ToolSPDXModelFree tier
Social LinksProprietaryQuote / seat (LE, gov, enterprise)No
MaltegoProprietaryCE free; Pro / Enterprise paidCE (limited)
Intelligence XProprietaryFreemium + paid API / subscriptionYes (limited)
OSINT IndustriesProprietarySubscription + APITrial
SkopenowProprietarySubscription + APINo
ShadowDragonProprietaryQuote / metered transformsNo
Babel StreetProprietaryEnterprise / gov contractNo
FivecastProprietaryEnterprise / gov contractNo
HunchlyProprietary~US$130/yr single seat30-day trial
LampyreProprietaryFreemium; per-request creditsYes (credits)
AlephMITOpen source (self-host)Full
DatashareAGPL-3.0-onlyOpen source (self-host)Full
SherlockMITOpen sourceFull
MaigretMITOpen sourceFull
HoleheGPL-3.0-onlyOpen sourceFull

Only five tools here are OSI-licensed open source (Aleph, Datashare, Sherlock, Maigret, Holehe). This is a commercial-heavy category: the investigative-platform tier (Social Links, Maltego, Babel Street, Fivecast, ShadowDragon, Skopenow) sells curated data access, transforms, and case-management – value that OSS username/email enumerators and the two document-investigation platforms do not replicate.

SSO / Identity

Modes: native (built-in), paid (enterprise tier only), none (no SSO surface), n/a (single-user desktop / CLI).

ToolOIDCSAMLLDAPSCIM
Social Linksnonenonenonenone
Maltegopaidpaidnonenone
Intelligence Xnonenonenonenone
OSINT Industriespaidpaidnonenone
Skopenownonenonenonenone
ShadowDragonnonenonenonenone
Babel Streetnonenonenonenone
Fivecastnonenonenonenone
Hunchlyn/an/an/an/a
Lampyren/an/an/an/a
Alephnativenonenonenone
Datasharenativenonenonenone
Sherlockn/an/an/an/a
Maigretn/an/an/an/a
Holehen/an/an/an/a

Only the two OSS web platforms expose real SSO: Aleph ships built-in OIDC (Azure, Google, Keycloak, Cognito, generic discovery) and Datashare authenticates server mode via OAuth2/OIDC (documented against Keycloak). The commercial platforms almost certainly federate via a customer IdP on managed deployments, but none publish the modes, so they are recorded as none rather than assumed. Maltego and OSINT Industries document SSO only on their enterprise tiers (paid).

Deployment

ToolDockerK8sNativeSaaSPackageShape
Social LinksHosted + private platform
MaltegoDesktop client + hosted back end
Intelligence XHosted SaaS
OSINT IndustriesHosted SaaS
SkopenowHosted SaaS
ShadowDragonHosted SaaS
Babel StreetHosted (gov enclaves)
FivecastHosted (mission variants)
HunchlyBrowser extension + local app
LampyreWindows desktop + cloud back end
AlephSelf-hosted web (Compose / Helm)
DatashareLocal desktop or self-hosted server
SherlockCLI (pip / pipx / Docker)
MaigretCLI (pip / pipx / Docker)
HoleheCLI (pip)

Capability Matrix

Capabilities present (✓), partial / add-on (~), absent or not documented (blank). Tailored to what each tool actually does – not every tool attempts every axis.

Investigation & analysis

ToolLink analysisEntity graphAutomation / transformsReporting / export
Social Links
Maltego
Intelligence X~✓ (API)
OSINT Industries~✓ (API)
Skopenow~~
ShadowDragon
Babel Street
Fivecast
Hunchly✓ (evidence)
Lampyre~
Aleph✓ (xref)
Datashare~✓ (NER)✓ (batch)
Sherlock✓ (CLI)✓ (CSV/JSON)
Maigret~✓ (CLI)✓ (HTML/PDF)
Holehe✓ (CLI)✓ (CSV)

Data domains

ToolSocial (SOCMINT)Dark web / breachCrypto / blockchainFace / imageDocs / records
Social Links~
Maltego~~
Intelligence X~
OSINT Industries~
Skopenow~~
ShadowDragon~
Babel Street~
Fivecast~
Hunchly✓ (capture)✓ (capture)
Lampyre~~~
Aleph~
Datashare
Sherlock✓ (usernames)
Maigret✓ (usernames)
Holehe~ (accounts)

API & Interop

ToolPublic APIMaltego interopNotable export
Social Links✓ (SL API)✓ (SL Professional add-on)Maltego graph, reports
Maltego✓ (Transforms)nativemtgx, CSV, GraphML
Intelligence X✓ (transform)JSON, API pull
OSINT Industries~JSON, PDF report
Skopenow✓ (Selector)PDF report, JSON
ShadowDragon✓ (SocialNet)✓ (transforms)via Maltego
Babel Street~JSON, feeds
Fivecast~reports
Hunchly✓ (export)MHTML, GPG-signed case
Lampyre✓ (Lighthouse)~tables, graph
Aleph✓ (REST)~ (FtM)FtM JSON, API
Datashare✓ (REST)JSON, batch
Sherlock– (CLI)CSV, JSON
Maigret– (CLI)HTML, PDF, JSON, XMind
Holehe– (CLI)✓ (transform)CSV

Several tools in this category (SocialNet/Horizon, Babel Street Locate X, Fivecast) have drawn documented civil-liberties scrutiny for surveillance use. Any engagement touching investigative OSINT must stay inside platform terms of service, applicable privacy law, and a legitimate, authorized purpose. See each tool’s evaluation for specifics.

Tools

16 tools.

Aleph

OCCRP’s open-source investigative data platform: ingest documents and structured data, extract entities, and cross-reference against followthemoney watchlists for journalism-grade search.

License: MIT (OSS) · Kind: web · Deploy: docker, k8s · SSO: OIDC · Tags: osint, investigative-journalism, entity-resolution, followthemoney, occrp

Website · Source

Babel Street

Commercial multilingual PAI/OSINT and identity-intelligence platform (Babel X, Insights) for defense, intelligence and law enforcement; strong 200+ language text analytics after the Rosette acquisition.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none · Tags: osint, pai, socmint, multilingual, geolocation, entity-resolution

Website

Datashare

ICIJ’s open-source, self-hosted document-analysis tool: local indexing, OCR, named-entity recognition, and full-text search, with a multi-user server mode for collaborative investigations.

License: AGPL-3.0-only (OSS) · Kind: web · Deploy: docker, native, package · SSO: OIDC · Tags: osint, investigative-journalism, document-analysis, ner, icij

Website · Source

Fivecast

Australian commercial OSINT platform (Fivecast ONYX) with broad and targeted surface/deep/dark-web collection and AI risk analytics for defense, intelligence, national security and corporate security.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none · Tags: osint, socmint, dark-web, ai-analytics, defense, link-analysis

Website

Holehe

Command-line tool that checks whether an email address is registered on 120+ sites via their registration and password-reset flows, without alerting the target address.

License: GPL-3.0-only (OSS) · Kind: cli · Deploy: package, native · SSO: none · Tags: osint, email-osint, account-discovery, cli, python

Website · Source

Hunchly

Paid web-capture tool for OSINT investigators: a browser extension plus desktop app that silently captures, SHA-256 hashes, and timestamps every page visited to build a court-defensible evidence trail.

License: Proprietary (proprietary) · Kind: desktop · Deploy: package, native · SSO: none · Tags: osint, evidence-capture, chain-of-custody, forensics, investigations

Website

Intelligence X

European search engine and data archive over darknet, leaks, breach data, paste sites, WHOIS/DNS history and the public web, searched by strong selectors. Freemium with paid API and subscriptions.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none · Tags: osint, breach-data, darknet, data-archive, whois-history, search-engine

Website

Lampyre

Data-analysis and OSINT desktop application (plus the Lighthouse API) doing entity extraction, link analysis, and lookups across 100+ data sources, with table / map / graph visualization; freemium via Photon credits.

License: Proprietary (proprietary) · Kind: desktop · Deploy: package, native · SSO: none · Tags: osint, link-analysis, data-analysis, socmint, maltego-alternative

Website

Maigret

Sherlock-derived username-investigation tool that compiles a dossier on a person from 3000+ sites, extracting profile data and running recursive search with HTML/PDF/graph reporting.

License: MIT (OSS) · Kind: cli · Deploy: package, docker, native · SSO: none · Tags: osint, socmint, username-enumeration, dossier, cli, python

Website · Source

Maltego

Canonical link-analysis and graph OSINT platform: a Java desktop client driven by transforms from the Transform Hub, with a free Community Edition and paid Professional/Enterprise tiers.

License: Proprietary (proprietary) · Kind: desktop · Deploy: native, saas · SSO: OIDC, SAML · Tags: osint, link-analysis, graph, transforms, socmint, threat-intel

Website

OSINT Industries

Hosted SaaS that enriches an email, phone, username, name or wallet across 1,000+ platforms to discover linked accounts and build investigation reports with maps and timelines. Freemium plus API.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML · Tags: osint, account-discovery, email-enrichment, phone-lookup, digital-footprint

Website

ShadowDragon

Investigator-focused OSINT suite – SocialNet link-analysis transforms and API (also sold as Maltego transforms), the Horizon monitoring platform, and OIMonitor – used heavily by law enforcement and enterprise security.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none · Tags: osint, socmint, link-analysis, maltego, monitoring, law-enforcement

Website

Sherlock

Command-line username enumeration tool that hunts social-media and web accounts for a given username across 400+ sites, emitting text/CSV/JSON/XLSX.

License: MIT (OSS) · Kind: cli · Deploy: package, docker, native · SSO: none · Tags: osint, socmint, username-enumeration, cli, python

Website · Source

Skopenow

Automated OSINT investigation platform that builds analytical reports on people and businesses from social media, the open web, and public records, with risk scoring, link analysis, real-time monitoring, and an API.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none · Tags: osint, socmint, investigation, fraud, due-diligence, saas

Website

Commercial OSINT investigation platform: SL Crimewall (standalone) and SL Professional (Maltego add-on), with 1500+ search methods across social media, dark web, blockchain, and biometric image analysis.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: none · Tags: osint, socmint, dark-web, crypto, link-analysis, facial-recognition

Website

SpiderFoot

Best-in-class open-source OSINT automation platform; 200+ modules covering domains, IPs, emails, names, Bitcoin addresses, phone numbers, leaked credentials, and dark-web mentions; web UI plus CLI.

License: MIT (OSS) · Kind: web · Deploy: docker, native, saas · SSO: none

Website · Source

Evaluated under Reconnaissance & Asset Discovery.

ResorsIT Tools Catalog Search