theadminstack.com

OSINT Tools

Free browser-based open-source intelligence tools for security researchers, red teamers, threat hunters, and brand protection teams. No accounts, no API keys, no tracking.

SquatWatch
Generate thousands of domain typos & lookalikes, then check which are registered, live in DNS, running email infrastructure, or hosting Azure AD tenants. 17 fuzzing algorithms including homoglyphs, bit-squatting, and Punycode IDN.
17 fuzzers · WHOIS/RDAP · Client-side Open →
NetRecon
Unified IP, domain & ASN intelligence. Geolocate, resolve DNS records, check public threat feeds, inspect SSL certificates, trace passive DNS history, and launch enrichment lookups across AbuseIPDB, VirusTotal, Shodan & more.
IP · ASN · Threat feeds · Client-side Open →
Email Header Analyzer
SOC-grade header analysis. Composite authentication trust score (SPF/DKIM/DMARC), BEC indicator detection, hop-by-hop delivery timeline with delay anomalies, IP enrichment with RBL checks, and Microsoft Exchange X-header intelligence.
SPF/DKIM/DMARC · BEC · Client-side Open →
TenantRecon
Map the full externally-visible attack surface of any Microsoft 365 / Azure AD tenant: tenant ID, federation type, Intune MDM, Teams SIP, Exchange Online, SPF/DMARC, Google Workspace, and 25+ SaaS verification signals.
M365 · 25+ SaaS signals · Client-side Open →
Takeover
Subdomain takeover scanner. Enumerate subdomains via Certificate Transparency, HackerTarget, AlienVault OTX, and RapidDNS. Resolve CNAME chains, detect NS delegation takeovers, check wildcard DNS, and fingerprint dangling records against 65+ cloud services.
CT · CNAME · 65+ services · Client-side Open →
CertScout
Query Certificate Transparency logs to enumerate every SSL/TLS certificate ever issued for a domain and its subdomains. Deduplicated, wildcard-flagged, expiry-marked, and export-ready — a faster, cleaner alternative to raw crt.sh.
CT logs · Subdomain enum · Client-side Open →
TechDetect
Identify the technology stack behind any website — CMS, JavaScript frameworks, web servers, analytics, CDNs, ecommerce platforms and more. Server-side fingerprinting on a Wappalyzer-format ruleset, with version detection and implied-tech cascades. No browser extension required.
Headers · HTML · Scripts · Server-side Open →

Free OSINT tools for security research

This is a suite of free, browser-based open-source intelligence (OSINT) tools for security researchers, red teamers, SOC analysts, threat hunters, and brand protection teams. Every tool runs without an account, sign-up, or API key, and draws only on publicly available data — DNS, WHOIS/RDAP, Certificate Transparency logs, open threat feeds, and unauthenticated discovery endpoints.

Hunt typosquatting and phishing infrastructure with SquatWatch, profile IPs and ASNs with NetRecon, investigate suspicious mail with the Email Header Analyzer, map Microsoft 365 footprints with TenantRecon, surface dangling DNS with Takeover and CertScout, and fingerprint any site's stack with TechDetect.

Frequently asked questions

What are OSINT tools?

OSINT (open-source intelligence) tools collect and analyze information from publicly available sources — DNS, WHOIS, Certificate Transparency logs, threat feeds, and public cloud endpoints — without authenticated access to the target. This suite covers domain, IP, email, Microsoft 365, subdomain, and website-technology reconnaissance for defenders and researchers.

Are these OSINT tools really free?

Yes. Every tool here is free to use with no account, sign-up, or API key. They run in your browser (or proxy through public sources) and do not store your queries.

Which tool should I use?

Use SquatWatch for typosquat/brand-abuse monitoring, NetRecon for IP/ASN reputation, Email Header Analyzer for phishing and BEC investigation, TenantRecon for Microsoft 365 reconnaissance, Takeover and CertScout for subdomain discovery and dangling-record risk, and TechDetect to fingerprint a website's technology stack.

Can I use these tools for security assessments?

Yes — they are built for blue teams, red teamers, and researchers performing passive reconnaissance. Only assess assets you own or are authorized to test.