TL;DR: Open Source Intelligence (OSINT) tools let anyone investigate almost anything using publicly available information. Maltego maps relationships between people, domains, and organizations. Shodan finds every internet-connected device, including unsecured webcams and industrial systems. SpiderFoot automates reconnaissance across 200+ data sources. These tools are used legitimately by journalists, security researchers, and law enforcement, and illegitimately by stalkers, hackers, and bad actors. Understanding them shows what is discoverable about you.

What Is OSINT?

Open Source Intelligence is information collected from publicly available sources:[1]

  • Social media: Posts, profiles, connections, metadata
  • Public records: Property, court, voter records
  • Domain/IP data: Website registrations, DNS records, hosting info
  • Corporate filings: Business registrations, SEC filings, executive information
  • Images and video: Metadata, reverse image search, geolocation
  • News and media: Mentions, interviews, public statements
  • Internet-connected devices: Servers, cameras, industrial systems

OSINT is legal; it uses only public information. But it can reveal far more about you than most people realize exists.

Major OSINT Tools

Maltego

Visual link analysis platform. Maps relationships between people, domains, companies, social media. Used by law enforcement worldwide.

Shodan

Search engine for internet-connected devices. Finds servers, webcams, industrial systems, IoT devices, including misconfigured or exposed ones.

SpiderFoot

Automated OSINT collection. 200+ modules gather data on domains, IPs, emails, names. Open source with commercial version.

TheHarvester

Email, subdomain, and host discovery. Pulls from search engines and public databases.

Censys

Internet-wide scanning. Discovers certificates, domains, and hosts. More structured than Shodan.

OSINT Framework

Collection of links to hundreds of OSINT resources organized by category. Starting point for investigations.

Deep Dive: Maltego

Maltego is the industry standard for relationship mapping:[2]

  • Entities: Start with a person, domain, company, email, or phone number
  • Transforms: Automated queries against dozens of data sources
  • Graphs: Visual representation of connections between entities
  • Integration: Pulls from social media APIs, public records, threat intelligence

What it can reveal:

  • Social media profiles connected to an email address
  • Domains registered by an organization
  • Relationships between companies and individuals
  • Infrastructure connections (hosting, DNS, IPs)
  • Geographic clustering of related entities

Maltego One (2025) made this browser-based, lowering the barrier to sophisticated investigation.

Deep Dive: Shodan

Called "the search engine for hackers," Shodan scans the entire internet:[3]

  • Device discovery: Finds every device responding on scanned ports
  • Service identification: Determines what software is running
  • Vulnerability detection: Identifies known vulnerable configurations
  • Historical data: Tracks changes over time

What it finds:

  • Unsecured webcams with live feeds
  • Industrial control systems (SCADA)
  • Databases without authentication
  • Default-password routers
  • Exposed network-attached storage
  • Building management systems

Shodan Monitor alerts organizations when their systems appear on internet scans, often revealing exposures they did not know existed.

Deep Dive: SpiderFoot

SpiderFoot automates OSINT collection at scale:[4]

  • 200+ modules: Integrations with data sources and APIs
  • Target types: Domains, IPs, email addresses, phone numbers, names
  • Open source: Free version with full functionality
  • SpiderFoot HX: Cloud version with collaboration and reporting

Capabilities:

  • Subdomain enumeration
  • Email address discovery
  • Data breach checking
  • Threat intelligence correlation
  • DNS reconnaissance
  • Social media profile discovery

Run a scan against your own domain to see what's publicly discoverable about your organization.

Legitimate Uses

OSINT tools serve important purposes:

Journalism

Bellingcat investigations use OSINT to verify war crimes, track weapons, identify perpetrators.

Security Research

Finding exposed systems, tracking threat actors, understanding attack infrastructure.

Due Diligence

Background checks, M&A research, fraud investigation, asset discovery.

Law Enforcement

Missing persons, criminal investigation, network mapping, evidence gathering.

Penetration Testing

Authorized security assessments begin with OSINT reconnaissance.

Personal Security

Understanding your own exposure, finding what's public, reducing attack surface.

Malicious Uses

The same capabilities enable harm:

  • Stalking: Tracking individuals across platforms, finding home addresses
  • Doxxing: Compiling and publishing personal information
  • Social engineering: Gathering details for convincing phishing attacks
  • Attack reconnaissance: Mapping infrastructure before hacking
  • Harassment campaigns: Identifying targets' workplaces, families, routines

There's no technical distinction between legitimate research and malicious surveillance. The same query that helps a journalist verify accountability can help an abuser locate a victim.

What They Find About You

A typical OSINT investigation on an individual might discover:

  • All social media profiles (including old/forgotten ones)
  • Email addresses (current and historical)
  • Phone numbers
  • Home addresses (current and previous)
  • Property records, home value
  • Vehicle registrations
  • Political donations
  • Professional history
  • Data breach exposure (passwords, SSN)
  • Family members and associates
  • Images across the web
  • Dating profiles
  • Forum posts under pseudonyms (if linked)

The more connected your digital presence, the more discoverable.

How to Reduce Your OSINT Exposure

Audit Yourself

Search your name, email, phone in multiple browsers. Use people search sites. See what's public.

Remove from Data Brokers

Submit opt-out requests to Spokeo, Whitepages, BeenVerified, PeopleFinder. Repeat regularly.

Separate Identities

Use different emails for different contexts. Don't connect personal and professional.

Privacy Settings

Lock down social media. Friends-only. Disable search engine indexing where possible.

Limit Metadata

Strip EXIF data from photos. Disable location tagging. Be conscious of what you share.

Use Pseudonyms

For non-professional contexts, consider usernames that don't identify you.

The Bottom Line

OSINT tools have democratized investigation. Journalists uncover war crimes. Security researchers find exposed databases. Private investigators solve cases. But the same tools enable stalkers, harassers, and attackers.

Everything you've ever posted publicly is discoverable. Your connections can be mapped. Your address history is public record. Your data breach exposure is searchable. The digital footprint you've created over decades is aggregatable with a few queries.

Understanding these tools serves two purposes: knowing what you can investigate if needed, and understanding what can be discovered about you. Both matter in 2026.

References

  1. OSINT Framework - Collection of OSINT Resources
  2. Maltego - Link Analysis and Data Mining
  3. Shodan - Search Engine for Internet-Connected Devices
  4. SpiderFoot - OSINT Automation
  5. Bellingcat - OSINT Tools and Methods