TL;DR: Open Source Intelligence (OSINT) tools let anyone investigate almost anything using publicly available information. Maltego maps relationships between people, domains, and organizations. Shodan finds every internet-connected device, including unsecured webcams and industrial systems. SpiderFoot automates reconnaissance across 200+ data sources. These tools are used legitimately by journalists, security researchers, and law enforcement, and illegitimately by stalkers, hackers, and bad actors. Understanding them shows what is discoverable about you.
What Is OSINT?
Open Source Intelligence is information collected from publicly available sources:[1]
- Social media: Posts, profiles, connections, metadata
- Public records: Property, court, voter records
- Domain/IP data: Website registrations, DNS records, hosting info
- Corporate filings: Business registrations, SEC filings, executive information
- Images and video: Metadata, reverse image search, geolocation
- News and media: Mentions, interviews, public statements
- Internet-connected devices: Servers, cameras, industrial systems
OSINT is legal; it uses only public information. But it can reveal far more about you than most people realize exists.
Major OSINT Tools
Maltego
Visual link analysis platform. Maps relationships between people, domains, companies, social media. Used by law enforcement worldwide.
Shodan
Search engine for internet-connected devices. Finds servers, webcams, industrial systems, IoT devices, including misconfigured or exposed ones.
SpiderFoot
Automated OSINT collection. 200+ modules gather data on domains, IPs, emails, names. Open source with commercial version.
TheHarvester
Email, subdomain, and host discovery. Pulls from search engines and public databases.
Censys
Internet-wide scanning. Discovers certificates, domains, and hosts. More structured than Shodan.
OSINT Framework
Collection of links to hundreds of OSINT resources organized by category. Starting point for investigations.
Deep Dive: Maltego
Maltego is the industry standard for relationship mapping:[2]
- Entities: Start with a person, domain, company, email, or phone number
- Transforms: Automated queries against dozens of data sources
- Graphs: Visual representation of connections between entities
- Integration: Pulls from social media APIs, public records, threat intelligence
What it can reveal:
- Social media profiles connected to an email address
- Domains registered by an organization
- Relationships between companies and individuals
- Infrastructure connections (hosting, DNS, IPs)
- Geographic clustering of related entities
Maltego One (2025) made this browser-based, lowering the barrier to sophisticated investigation.
Deep Dive: Shodan
Called "the search engine for hackers," Shodan scans the entire internet:[3]
- Device discovery: Finds every device responding on scanned ports
- Service identification: Determines what software is running
- Vulnerability detection: Identifies known vulnerable configurations
- Historical data: Tracks changes over time
What it finds:
- Unsecured webcams with live feeds
- Industrial control systems (SCADA)
- Databases without authentication
- Default-password routers
- Exposed network-attached storage
- Building management systems
Shodan Monitor alerts organizations when their systems appear on internet scans, often revealing exposures they did not know existed.
Deep Dive: SpiderFoot
SpiderFoot automates OSINT collection at scale:[4]
- 200+ modules: Integrations with data sources and APIs
- Target types: Domains, IPs, email addresses, phone numbers, names
- Open source: Free version with full functionality
- SpiderFoot HX: Cloud version with collaboration and reporting
Capabilities:
- Subdomain enumeration
- Email address discovery
- Data breach checking
- Threat intelligence correlation
- DNS reconnaissance
- Social media profile discovery
Run a scan against your own domain to see what's publicly discoverable about your organization.
Legitimate Uses
OSINT tools serve important purposes:
Journalism
Bellingcat investigations use OSINT to verify war crimes, track weapons, identify perpetrators.
Security Research
Finding exposed systems, tracking threat actors, understanding attack infrastructure.
Due Diligence
Background checks, M&A research, fraud investigation, asset discovery.
Law Enforcement
Missing persons, criminal investigation, network mapping, evidence gathering.
Penetration Testing
Authorized security assessments begin with OSINT reconnaissance.
Personal Security
Understanding your own exposure, finding what's public, reducing attack surface.
Malicious Uses
The same capabilities enable harm:
- Stalking: Tracking individuals across platforms, finding home addresses
- Doxxing: Compiling and publishing personal information
- Social engineering: Gathering details for convincing phishing attacks
- Attack reconnaissance: Mapping infrastructure before hacking
- Harassment campaigns: Identifying targets' workplaces, families, routines
There's no technical distinction between legitimate research and malicious surveillance. The same query that helps a journalist verify accountability can help an abuser locate a victim.
What They Find About You
A typical OSINT investigation on an individual might discover:
- All social media profiles (including old/forgotten ones)
- Email addresses (current and historical)
- Phone numbers
- Home addresses (current and previous)
- Property records, home value
- Vehicle registrations
- Political donations
- Professional history
- Data breach exposure (passwords, SSN)
- Family members and associates
- Images across the web
- Dating profiles
- Forum posts under pseudonyms (if linked)
The more connected your digital presence, the more discoverable.
How to Reduce Your OSINT Exposure
Audit Yourself
Search your name, email, phone in multiple browsers. Use people search sites. See what's public.
Remove from Data Brokers
Submit opt-out requests to Spokeo, Whitepages, BeenVerified, PeopleFinder. Repeat regularly.
Separate Identities
Use different emails for different contexts. Don't connect personal and professional.
Privacy Settings
Lock down social media. Friends-only. Disable search engine indexing where possible.
Limit Metadata
Strip EXIF data from photos. Disable location tagging. Be conscious of what you share.
Use Pseudonyms
For non-professional contexts, consider usernames that don't identify you.
Ethics and Legal Considerations
Using OSINT tools requires judgment:
- Legal boundaries: OSINT uses only public data, but violating Terms of Service or accessing restricted systems crosses lines
- GDPR/Privacy laws: Collecting data on individuals may be regulated depending on jurisdiction and purpose
- Purpose matters: Same action is ethical (journalism, security) or unethical (stalking, harassment) based on intent
- Proportionality: Collection should match legitimate need, not exceed it
- Documentation: Professional investigators document methodology for legal admissibility
The Bottom Line
OSINT tools have democratized investigation. Journalists uncover war crimes. Security researchers find exposed databases. Private investigators solve cases. But the same tools enable stalkers, harassers, and attackers.
Everything you've ever posted publicly is discoverable. Your connections can be mapped. Your address history is public record. Your data breach exposure is searchable. The digital footprint you've created over decades is aggregatable with a few queries.
Understanding these tools serves two purposes: knowing what you can investigate if needed, and understanding what can be discovered about you. Both matter in 2026.