License & Deployment Mix: 15 tools – 5 OSS, 10 commercial, 8 SaaS, 9 self-host. (OSS and SaaS counts overlap when an open-source tool also offers a hosted edition; here they do not – the OSS tools are self-host only and the SaaS tools are all proprietary.)
Color: Blue/analyst – investigations, not attack.
What Is Investigative OSINT?
Open-Source Intelligence (OSINT) in this category is the analyst-driven investigation of people, companies, and entities using publicly available information (PAI): social media (SOCMINT), the dark web and breach data, blockchain, public records, archived web, and the links between them. The output is an entity picture – who a subject is, what accounts and addresses they control, who they connect to – assembled on a link-analysis graph and packaged as a defensible report.
The buyers are investigators, not sysadmins: law enforcement, government/defense intelligence, corporate security and due diligence, fraud / insurance SIU teams, and investigative journalists.
Distinct from neighbouring categories
This is deliberately not the same as the security-recon category. The line matters because both use the word “OSINT”:
- Reconnaissance & Asset Discovery (Reconnaissance & Asset Discovery) maps an organization’s external attack surface – subdomains, IPs, ports, exposed services – the adversary’s-eye view of infrastructure. OSINT here investigates people and entities. SpiderFoot straddles both and is filed under recon.
- Threat Intelligence Platforms (Threat Intelligence Platforms) curate IOCs and adversary infrastructure for a SOC. OSINT investigates subjects, not indicators.
- Background Check & Screening (Background Check / Screening) run regulated, consent-based employment screening against court/credit data (FCRA). OSINT is investigative and open-source, not a regulated consumer-reporting product.
- DFIR (Digital Forensics & IR (DFIR)) works owned evidence (disks, memory, logs) after an incident. OSINT works public data about a subject.
Capabilities typically present
- Link analysis / entity graph – pivot from a selector (email, username, phone, wallet, domain) to connected entities
- SOCMINT – social-media account discovery, content, and network mapping
- Dark web & breach data – leaked-credential and darknet mention search
- Crypto tracing – wallet / transaction attribution
- Face & image – reverse image and facial recognition (higher-end platforms)
- Selector enumeration – username / email -> registered accounts across hundreds of sites
- Evidence & reporting – timestamped, hashed capture and court-defensible export
- Automation / API – transforms, batch runs, headless integration
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
Cross-tool comparison for the OSINT & Investigative Intelligence category: analyst-driven investigative OSINT / SOCMINT / link-analysis platforms.
All facts below are point-in-time and derived from each tool’s per-tool evaluation file. Commercial platforms rarely publish SSO, API, or deployment specifics, so several cells are marked unconfirmed rather than asserted.
Licensing & Cost Model
| Tool | SPDX | Model | Free tier |
|---|---|---|---|
| Social Links | Proprietary | Quote / seat (LE, gov, enterprise) | No |
| Maltego | Proprietary | CE free; Pro / Enterprise paid | CE (limited) |
| Intelligence X | Proprietary | Freemium + paid API / subscription | Yes (limited) |
| OSINT Industries | Proprietary | Subscription + API | Trial |
| Skopenow | Proprietary | Subscription + API | No |
| ShadowDragon | Proprietary | Quote / metered transforms | No |
| Babel Street | Proprietary | Enterprise / gov contract | No |
| Fivecast | Proprietary | Enterprise / gov contract | No |
| Hunchly | Proprietary | ~US$130/yr single seat | 30-day trial |
| Lampyre | Proprietary | Freemium; per-request credits | Yes (credits) |
| Aleph | MIT | Open source (self-host) | Full |
| Datashare | AGPL-3.0-only | Open source (self-host) | Full |
| Sherlock | MIT | Open source | Full |
| Maigret | MIT | Open source | Full |
| Holehe | GPL-3.0-only | Open source | Full |
Only five tools here are OSI-licensed open source (Aleph, Datashare, Sherlock, Maigret, Holehe). This is a commercial-heavy category: the investigative-platform tier (Social Links, Maltego, Babel Street, Fivecast, ShadowDragon, Skopenow) sells curated data access, transforms, and case-management – value that OSS username/email enumerators and the two document-investigation platforms do not replicate.
SSO / Identity
Modes: native (built-in), paid (enterprise tier only), none (no SSO surface), n/a (single-user desktop / CLI).
| Tool | OIDC | SAML | LDAP | SCIM |
|---|---|---|---|---|
| Social Links | none | none | none | none |
| Maltego | paid | paid | none | none |
| Intelligence X | none | none | none | none |
| OSINT Industries | paid | paid | none | none |
| Skopenow | none | none | none | none |
| ShadowDragon | none | none | none | none |
| Babel Street | none | none | none | none |
| Fivecast | none | none | none | none |
| Hunchly | n/a | n/a | n/a | n/a |
| Lampyre | n/a | n/a | n/a | n/a |
| Aleph | native | none | none | none |
| Datashare | native | none | none | none |
| Sherlock | n/a | n/a | n/a | n/a |
| Maigret | n/a | n/a | n/a | n/a |
| Holehe | n/a | n/a | n/a | n/a |
Only the two OSS web platforms expose real SSO: Aleph ships built-in OIDC (Azure, Google, Keycloak, Cognito, generic discovery) and Datashare authenticates server mode via OAuth2/OIDC (documented against Keycloak). The commercial platforms almost certainly federate via a customer IdP on managed deployments, but none publish the modes, so they are recorded as none rather than assumed. Maltego and OSINT Industries document SSO only on their enterprise tiers (paid).
Deployment
| Tool | Docker | K8s | Native | SaaS | Package | Shape |
|---|---|---|---|---|---|---|
| Social Links | – | – | ✓ | ✓ | – | Hosted + private platform |
| Maltego | – | – | ✓ | ✓ | – | Desktop client + hosted back end |
| Intelligence X | – | – | – | ✓ | – | Hosted SaaS |
| OSINT Industries | – | – | – | ✓ | – | Hosted SaaS |
| Skopenow | – | – | – | ✓ | – | Hosted SaaS |
| ShadowDragon | – | – | – | ✓ | – | Hosted SaaS |
| Babel Street | – | – | – | ✓ | – | Hosted (gov enclaves) |
| Fivecast | – | – | – | ✓ | – | Hosted (mission variants) |
| Hunchly | – | – | ✓ | – | ✓ | Browser extension + local app |
| Lampyre | – | – | ✓ | – | ✓ | Windows desktop + cloud back end |
| Aleph | ✓ | ✓ | – | – | – | Self-hosted web (Compose / Helm) |
| Datashare | ✓ | – | ✓ | – | ✓ | Local desktop or self-hosted server |
| Sherlock | ✓ | – | ✓ | – | ✓ | CLI (pip / pipx / Docker) |
| Maigret | ✓ | – | ✓ | – | ✓ | CLI (pip / pipx / Docker) |
| Holehe | – | – | ✓ | – | ✓ | CLI (pip) |
Capability Matrix
Capabilities present (✓), partial / add-on (~), absent or not documented (blank). Tailored to what each tool actually does – not every tool attempts every axis.
Investigation & analysis
| Tool | Link analysis | Entity graph | Automation / transforms | Reporting / export |
|---|---|---|---|---|
| Social Links | ✓ | ✓ | ✓ | ✓ |
| Maltego | ✓ | ✓ | ✓ | ✓ |
| Intelligence X | ~ | ✓ (API) | ✓ | |
| OSINT Industries | ~ | ✓ (API) | ✓ | |
| Skopenow | ~ | ~ | ✓ | ✓ |
| ShadowDragon | ✓ | ✓ | ✓ | ✓ |
| Babel Street | ✓ | ✓ | ✓ | ✓ |
| Fivecast | ✓ | ✓ | ✓ | ✓ |
| Hunchly | ✓ (evidence) | |||
| Lampyre | ✓ | ~ | ✓ | ✓ |
| Aleph | ✓ | ✓ | ✓ (xref) | ✓ |
| Datashare | ~ | ✓ (NER) | ✓ (batch) | ✓ |
| Sherlock | ✓ (CLI) | ✓ (CSV/JSON) | ||
| Maigret | ~ | ✓ (CLI) | ✓ (HTML/PDF) | |
| Holehe | ✓ (CLI) | ✓ (CSV) |
Data domains
| Tool | Social (SOCMINT) | Dark web / breach | Crypto / blockchain | Face / image | Docs / records |
|---|---|---|---|---|---|
| Social Links | ✓ | ✓ | ✓ | ✓ | ~ |
| Maltego | ✓ | ~ | ✓ | ~ | |
| Intelligence X | ✓ | ~ | ✓ | ||
| OSINT Industries | ✓ | ~ | |||
| Skopenow | ✓ | ~ | ~ | ✓ | |
| ShadowDragon | ✓ | ✓ | ~ | ||
| Babel Street | ✓ | ✓ | ~ | ✓ | |
| Fivecast | ✓ | ✓ | ~ | ✓ | ✓ |
| Hunchly | ✓ | ✓ (capture) | ✓ (capture) | ||
| Lampyre | ✓ | ~ | ~ | ~ | |
| Aleph | ~ | ✓ | |||
| Datashare | ✓ | ||||
| Sherlock | ✓ (usernames) | ||||
| Maigret | ✓ (usernames) | ||||
| Holehe | ~ (accounts) |
API & Interop
| Tool | Public API | Maltego interop | Notable export |
|---|---|---|---|
| Social Links | ✓ (SL API) | ✓ (SL Professional add-on) | Maltego graph, reports |
| Maltego | ✓ (Transforms) | native | mtgx, CSV, GraphML |
| Intelligence X | ✓ | ✓ (transform) | JSON, API pull |
| OSINT Industries | ✓ | ~ | JSON, PDF report |
| Skopenow | ✓ (Selector) | PDF report, JSON | |
| ShadowDragon | ✓ (SocialNet) | ✓ (transforms) | via Maltego |
| Babel Street | ✓ | ~ | JSON, feeds |
| Fivecast | ~ | reports | |
| Hunchly | ✓ (export) | MHTML, GPG-signed case | |
| Lampyre | ✓ (Lighthouse) | ~ | tables, graph |
| Aleph | ✓ (REST) | ~ (FtM) | FtM JSON, API |
| Datashare | ✓ (REST) | JSON, batch | |
| Sherlock | – (CLI) | CSV, JSON | |
| Maigret | – (CLI) | HTML, PDF, JSON, XMind | |
| Holehe | – (CLI) | ✓ (transform) | CSV |
Legal & Ethical Use
Several tools in this category (SocialNet/Horizon, Babel Street Locate X, Fivecast) have drawn documented civil-liberties scrutiny for surveillance use. Any engagement touching investigative OSINT must stay inside platform terms of service, applicable privacy law, and a legitimate, authorized purpose. See each tool’s evaluation for specifics.
Tools
16 tools.
Aleph
OCCRP’s open-source investigative data platform: ingest documents and structured data, extract entities, and cross-reference against followthemoney watchlists for journalism-grade search.
License: MIT (OSS) · Kind: web · Deploy: docker, k8s · SSO: OIDC · Tags: osint, investigative-journalism, entity-resolution, followthemoney, occrp
Babel Street
Commercial multilingual PAI/OSINT and identity-intelligence platform (Babel X, Insights) for defense, intelligence and law enforcement; strong 200+ language text analytics after the Rosette acquisition.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none · Tags: osint, pai, socmint, multilingual, geolocation, entity-resolution
Datashare
ICIJ’s open-source, self-hosted document-analysis tool: local indexing, OCR, named-entity recognition, and full-text search, with a multi-user server mode for collaborative investigations.
License: AGPL-3.0-only (OSS) · Kind: web · Deploy: docker, native, package · SSO: OIDC · Tags: osint, investigative-journalism, document-analysis, ner, icij
Fivecast
Australian commercial OSINT platform (Fivecast ONYX) with broad and targeted surface/deep/dark-web collection and AI risk analytics for defense, intelligence, national security and corporate security.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none · Tags: osint, socmint, dark-web, ai-analytics, defense, link-analysis
Holehe
Command-line tool that checks whether an email address is registered on 120+ sites via their registration and password-reset flows, without alerting the target address.
License: GPL-3.0-only (OSS) · Kind: cli · Deploy: package, native · SSO: none · Tags: osint, email-osint, account-discovery, cli, python
Hunchly
Paid web-capture tool for OSINT investigators: a browser extension plus desktop app that silently captures, SHA-256 hashes, and timestamps every page visited to build a court-defensible evidence trail.
License: Proprietary (proprietary) · Kind: desktop · Deploy: package, native · SSO: none · Tags: osint, evidence-capture, chain-of-custody, forensics, investigations
Intelligence X
European search engine and data archive over darknet, leaks, breach data, paste sites, WHOIS/DNS history and the public web, searched by strong selectors. Freemium with paid API and subscriptions.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none · Tags: osint, breach-data, darknet, data-archive, whois-history, search-engine
Lampyre
Data-analysis and OSINT desktop application (plus the Lighthouse API) doing entity extraction, link analysis, and lookups across 100+ data sources, with table / map / graph visualization; freemium via Photon credits.
License: Proprietary (proprietary) · Kind: desktop · Deploy: package, native · SSO: none · Tags: osint, link-analysis, data-analysis, socmint, maltego-alternative
Maigret
Sherlock-derived username-investigation tool that compiles a dossier on a person from 3000+ sites, extracting profile data and running recursive search with HTML/PDF/graph reporting.
License: MIT (OSS) · Kind: cli · Deploy: package, docker, native · SSO: none · Tags: osint, socmint, username-enumeration, dossier, cli, python
Maltego
Canonical link-analysis and graph OSINT platform: a Java desktop client driven by transforms from the Transform Hub, with a free Community Edition and paid Professional/Enterprise tiers.
License: Proprietary (proprietary) · Kind: desktop · Deploy: native, saas · SSO: OIDC, SAML · Tags: osint, link-analysis, graph, transforms, socmint, threat-intel
OSINT Industries
Hosted SaaS that enriches an email, phone, username, name or wallet across 1,000+ platforms to discover linked accounts and build investigation reports with maps and timelines. Freemium plus API.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML · Tags: osint, account-discovery, email-enrichment, phone-lookup, digital-footprint
ShadowDragon
Investigator-focused OSINT suite – SocialNet link-analysis transforms and API (also sold as Maltego transforms), the Horizon monitoring platform, and OIMonitor – used heavily by law enforcement and enterprise security.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none · Tags: osint, socmint, link-analysis, maltego, monitoring, law-enforcement
Sherlock
Command-line username enumeration tool that hunts social-media and web accounts for a given username across 400+ sites, emitting text/CSV/JSON/XLSX.
License: MIT (OSS) · Kind: cli · Deploy: package, docker, native · SSO: none · Tags: osint, socmint, username-enumeration, cli, python
Skopenow
Automated OSINT investigation platform that builds analytical reports on people and businesses from social media, the open web, and public records, with risk scoring, link analysis, real-time monitoring, and an API.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none · Tags: osint, socmint, investigation, fraud, due-diligence, saas
Social Links
Commercial OSINT investigation platform: SL Crimewall (standalone) and SL Professional (Maltego add-on), with 1500+ search methods across social media, dark web, blockchain, and biometric image analysis.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: none · Tags: osint, socmint, dark-web, crypto, link-analysis, facial-recognition
SpiderFoot
Best-in-class open-source OSINT automation platform; 200+ modules covering domains, IPs, emails, names, Bitcoin addresses, phone numbers, leaked credentials, and dark-web mentions; web UI plus CLI.
License: MIT (OSS) · Kind: web · Deploy: docker, native, saas · SSO: none
Evaluated under Reconnaissance & Asset Discovery.