SpiderFoot
SpiderFoot is an open-source OSINT automation platform, replacing hours of manual reconnaissance with automated intelligence gathering across more than 200 data collection modules. The platform accepts ten distinct target types including IP addresses, domains, hostnames, network subnets, ASNs, email addresses, phone numbers, usernames, person names, and Bitcoin addresses, then feeds them through a publisher-subscriber event bus where each module's findings trigger downstream analysis automatically. SpiderFoot queries Shodan, VirusTotal, HaveIBeenPwned, AlienVault OTX, Censys, crt.sh, WHOIS databases, social media platforms, breach databases, and dozens more sources, with most modules requiring no API keys and many offering free tiers for those that do. The YAML-configurable correlation engine applies 37 pre-defined rules to identify relationships between discovered data points, flagging patterns like shared infrastructure, credential exposure, and domain reputation anomalies. Results export in CSV, JSON, and GEXF graph formats for integration with external analysis tools. TOR integration enables dark web searching, and SpiderFoot can invoke external tools including DNSTwist, Whatweb, Nmap, and CMSeeK for deeper technical assessment. The embedded web server delivers an intuitive dashboard for scan management, data visualization, and result exploration alongside a full command-line interface for scripted automation. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Web-Check
Enter a URL and get a dashboard of everything publicly discoverable about its security posture, server architecture, and technology stack: Web-Check is an all-in-one OSINT tool for analyzing any website. One scan surfaces IP info and server location, the full SSL certificate chain with issuing authority and validity, DNS records (A, MX, NS, CNAME, TXT) with DNSSEC status, HTTP response headers interpreted for security directives like HSTS, CSP, and X-Frame-Options, cookies and their flags, WHOIS domain info, robots.txt crawl rules, a sitemap-derived page map, the redirect ledger, open ports, traceroute, detected technologies, third-party trackers, associated hostnames, site performance, and even carbon footprint. Each card explains what the data means and why it matters, which makes the tool double as a security education resource - junior engineers learn headers and attack surfaces by scanning real sites. Practical uses span pre-deployment security audits (catch missing headers and misconfigurations before they ship), privacy compliance checks (identify trackers and cookie behavior for GDPR work), competitive tech-stack research, and network debugging via DNS and redirect inspection. Built by Lissy93 in TypeScript, it deploys as a single Docker container, and self-hosting keeps your reconnaissance targets and audit activity off third-party services.
IRONSIGHT
IRONSIGHT fuses over 50 publicly available intelligence sources into a single real-time dashboard that requires zero API keys and zero configuration. The Live Intel Feed aggregates 20+ RSS news sources with keyword relevance filtering from outlets including Reuters, Al Jazeera, and Kyiv Post. The Telegram OSINT module scrapes 27 channels every 60 seconds with automatic translation from Hebrew, Arabic, and Farsi. The interactive Leaflet Theater Map plots military aircraft positions via ADS-B transponder data, naval vessel locations in the Persian Gulf and Eastern Mediterranean, strike markers extracted from news and Telegram, missile trajectory arcs with range rings, and country-border overlays with a distance measurement tool. A header toggle switches the entire dashboard between Iran/Israel and Russia/Ukraine theaters, re-pointing every panel, map layer, and data feed to the selected conflict. The Israel Alert module streams live Pikud HaOref missile alerts with audio notifications, while the Conflict Monitor categorizes events into strikes, defense, diplomatic, and nuclear. Financial panels track defense contractor stocks, S&P 500, VIX, gold, Bitcoin, Ethereum, energy commodities via Yahoo Finance, and Polymarket prediction odds on conflict outcomes. NASA FIRMS satellite thermal detection flags fire and explosion signatures. The Next.js 16 App Router handles server-side data fetching for RSS and API endpoints while client-side React state management drives real-time polling updates. On RepoCloud, deploy IRONSIGHT on a dedicated VPS with persistent storage, root SSH access, and full control over your intelligence monitoring environment, all under the MIT license.
World Monitor
World Monitor replaces twenty or more browser tabs by fusing geopolitical, military, financial, and infrastructure signals onto a single interactive canvas built with TypeScript, Vite, globe.gl with Three.js for the 3D globe, and deck.gl with MapLibre GL for the flat map. World Monitor ingests live data from 530 upstream sources including ACLED and UCDP for conflict events, OpenSky Network for military and civilian aircraft, AISStream for vessel positions, NASA FIRMS for satellite fire detection, USGS for earthquakes, and FRED, IMF, BIS, and Finnhub for macroeconomic and market data. The Country Instability Index v8 computes real-time stress scores across 31 Tier-1 nations, while the finance radar tracks 29 stock exchanges, commodities, and cryptocurrency with a 7-signal market composite. Six specialized dashboard variants — World, Tech, Finance, Commodity, Energy, and Happy — deploy from a single codebase. AI summarization runs locally through Ollama and LM Studio integration or optionally via Groq and OpenRouter cloud providers, with Transformers.js powering browser-side inference. The platform supports 26 languages with native-language feeds and RTL layout, and provides MCP server integration for AI agent connectivity. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Gods Eye View
God's Eye View turns your browser into a real-time spatial intelligence command center, rendering thousands of live aircraft, ships, satellites, earthquakes, traffic flows, and public cameras on a photorealistic 3D Earth powered by CesiumJS and Google Photorealistic 3D Tiles. Click any aircraft to see its transponder telemetry from OpenSky and adsb.lol, including route history, altitude, speed, and callsign; track live vessel positions worldwide through AIS beacon data from AISStream; or follow roughly 840 satellites color-coded by class using orbital elements from CelesTrak. A hands-free voice agent powered by the OpenAI Realtime API lets you ask the planet questions in natural language, and the globe annotates your answer directly in 3D space. Toggle FLIR mode for a thermal camera aesthetic, layer in NASA FIRMS wildfire data, switch between Google 3D, Bing aerial, and OpenStreetMap base layers, or tune into a geolocated world radio dial. Public CCTV cameras are projected into 3D city geometry with viewshed cones and direct-manipulation calibration. The cockpit mode provides a pilot-style briefing surface with mission-specific overlays. Entity inspection panels show detailed metadata for every tracked object, and shareable links let you send any scene configuration to a colleague. Ten of the thirteen live data layers work with zero API keys, while the required Google Maps key offers 1,000 free 3D tile sessions per month. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
PRISM
PRISM consolidates passive reconnaissance, credential leak detection, and network asset mapping into a unified operational dashboard to replace fragmented command-line security tools. Analysts can launch simultaneous multi-source investigations against domains, internet protocol addresses, email mailboxes, phone numbers, and online handles to uncover domain registrations, open network ports, cryptographic certificates, and historical web archives. The platform interrogates threat feeds and leak repositories to expose credential leaks, dark web mirrors, and email routing anomalies with automated SMTP mailbox verification. Cross-platform identity engines crawl thousands of social networks and public registries to correlate aliases, discover leaked commit identities, and trace digital footprints across the web. Discovered assets render into interactive entity relationship graphs alongside geographic internet protocol maps to help investigators visualize infrastructure clusters and ownership links. An automated operational security calculator evaluates exposure vulnerabilities across identity, web, and infrastructure vectors, producing an aggregated risk score with granular hardening recommendations. Scheduled watchlists continually monitor target infrastructure, dispatching webhook notifications to chat channels whenever new subdomains, ports, or credential leaks appear. Investigators can export comprehensive audit dossiers as self-contained HTML files, styled PDF documents, or structured spreadsheets. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Social Analyzer
Social Analyzer scans over 1,000 social media platforms in parallel to discover and correlate user profiles from a single username query, making it the most comprehensive OSINT reconnaissance tool of its kind. Three detection modes cover different accuracy and speed tradeoffs: fast HTTP library checks for rapid sweeps, Selenium WebDriver validation for JavaScript-heavy sites, and a special mode for stubborn edge cases. String analysis generates username permutations and combinations to catch related accounts with slight naming variations. Three interfaces serve different workflows: a Node.js web application on port 9005 with a browser-based GUI, a CLI for scripted batch operations, and Python plus Node.js APIs for embedding into automated investigation pipelines. The QeeqBox OSINT library extracts profile metadata, screenshots, titles, descriptions, and activity patterns, all visualized through Ixora-based force-directed graphs that map relationships between discovered accounts. Tesseract OCR analyzes profile images for additional detection vectors. Search results narrow by country codes, website categories, Alexa ranking thresholds, and confidence levels. Optional Google API and DuckDuckGo API integration adds search engine correlation alongside direct platform queries. Docker deployment bundles Node.js, Firefox ESR, Tesseract, and all dependencies into one container. Trusted by law enforcement and security researchers for digital forensics and identity verification. 23,000+ GitHub stars. AGPL-3.0 licensed.