A modular OSINT reconnaissance tool built entirely on public data and official APIs. No scraping of platforms whose Terms of Service prohibit it (e.g. LinkedIn) — that kind of tool is not included here, by design, for legal reasons.
Only run this against:
- Domains/infrastructure you own
- Targets covered by a signed penetration testing engagement / authorization letter
- Your own accounts/emails, for personal security hygiene checks
Running recon against third parties without authorization can violate computer misuse laws (e.g. CFAA in the US, similar laws elsewhere) even when the tool itself only touches "public" data.
| Module | Data Source | API Key Needed? |
|---|---|---|
| domain | WHOIS, DNS, crt.sh (cert transparency) | No |
| breach | Have I Been Pwned | Yes (paid) |
| username | Public profile URL existence checks | No |
| ip | Shodan | Yes (free tier) |
pip install requests dnspython python-whois --break-system-packages
chmod +x osint_toolkit.py
- HIBP: https://haveibeenpwned.com/API/Key
- Shodan: https://account.shodan.io/register (free tier available)
# Domain recon: WHOIS + DNS + subdomains + tech fingerprint
python3 osint_toolkit.py domain example.com
# Check if an email appears in known breaches
python3 osint_toolkit.py breach test@example.com --api-key YOUR_HIBP_KEY
# Check which platforms a username exists on (public existence only)
python3 osint_toolkit.py username johndoe123
# Shodan lookup on an IP
python3 osint_toolkit.py ip 8.8.8.8 --api-key YOUR_SHODAN_KEY
- VirusTotal API — domain/file/IP reputation
- SecurityTrails API — historical DNS data
- theHarvester (already in Kali) — combine for email pattern discovery from search engines
- Google Dorking helper — generate dork queries for manual review
- Scrape LinkedIn, Facebook, or any platform whose ToS prohibits automated data collection
- Attempt to bypass authentication, rate limits, or CAPTCHAs
- Aggregate private/non-public personal data