OpenOSINT

by openosint

Not rated
GitHub

About

MCP-native OSINT framework for AI agents. Exposes 9 intelligence tools (email enumeration, username search, breach check, WHOIS, IP intel, subdomain enum, dorks, paste search, phone intel) via Model Context Protocol. Also works as a standalone Python CLI.

Details

Author
openosint
Categories
Other, Security

Setup

Install OpenOSINT in your MCP client (Claude Desktop, Cursor, Windsurf, and others).

Repository: https://github.com/openosint/OpenOSINT

Follow the installation instructions in the repository README, then restart your MCP client.

OSINT agent for security researchers and analysts: 19 investigation tools behind a natural-language interface.

Use it as a REPL, CLI, MCP server, or browser Web UI.

The AI issues hard-stop tool calls; your code executes the real binary — hallucinated findings are structurally impossible.

IP2Location.io— powerssearch_ip2location·Integration guide

Enhanced IP geolocation, ISP, VPN/Proxy/Tor, and datacenter detection

Reliable Residential Proxies for Data Collection & Automation — 90M+ IPs across 200+ countries. 10% off: RAPID10.

TestMu AI (formerly LambdaTest) is an AI-native testing cloud platform built for modern engineering teams. It covers everything from autonomous test creation and fast execution to testing AI agents, chatbots and voice assistants.

Open: Breach / Compromised-Credential Data · Email / Identity Lookup — seeSPONSORSHIP.md.

Paid:Complete Kit — $55(prompts + playbook, bundled) ·Setup Sprint — $350(done-for-you install) ·Commercial License — from €300/yr(vendor contract, SLA, indemnification)

# Interactive AI REPL (default) openosint # Web interface openosint web # Direct tool (no AI) openosint email target@example.com

New to OSINT methodology? Grab thefree 5-prompt starter setor thefree Playbook editionbefore your first run.

No Python, noholehe/sherlock/sublist3r/phoneinfogabinaries inPATH, no API keys — run OpenOSINT Email Recon from your browser, or as an MCP tool in Claude, Cursor, and Windsurf via theApify MCP Server. Try for free.

Start the REPL and investigate any target — the agent decides which tools to run and chains them on findings:

openosint > investigate target@example.com -> generate_dorks('target@example.com') -> search_email('target@example.com') Found: Spotify, WordPress, Gravatar, Office365 -> search_breach('target@example.com') Found in 2 breaches: LinkedIn (2016), Adobe (2013) -> search_username('johndoe99') <- pivoted from email findings Found: GitHub, Reddit, Twitter Report saved -> reports/2026-05-11_14-32-11_report.md

Legal Disclaimer: OpenOSINT is intended forlegal and authorized use only. Users are solely responsible for ensuring their use complies with all applicable laws and regulations. The authors accept no liability for misuse. SeeDISCLAIMER.md.

Need OpenOSINT wired into your SOC, fraud, threat-intel, or AI-agent stack? I build bespoke OSINT integrations for teams — you bring the data sources and compliance requirements, I deliver a working integration.

Full per-tool documentation, CLI flags, and output formats:openosint.tech.

Enumerates online services linked to an email address usingholehe.

[+] Spotify https://open.spotify.com/user/target [+] WordPress https://wordpress.com/target [+] Gravatar https://gravatar.com/target [+] Office365 email used

Searches for a username across 300+ platforms usingsherlock.

[+] GitHub https://github.com/johndoe99 [+] Twitter https://twitter.com/johndoe99 [+] Reddit https://reddit.com/user/johndoe99

Checks data breach exposure viaHaveIBeenPwned v3 API. RequiresHIBP_API_KEY.

[+] LinkedIn (2016-05-05) — leaked: Email addresses, Passwords [+] Adobe (2013-10-04) — leaked: Email addresses, Password hints

Retrieves WHOIS data usingpython-whois.

[+] Registrar: ICANN [+] Created: 1995-08-14 [+] Expires: 2024-08-13 [+] Name Servers: A.IANA-SERVERS.NET

Retrieves geolocation and ASN data viaipinfo.io. Free tier: 50k/month.

[+] Hostname: dns.google [+] Org: AS15169 Google LLC [+] City: Mountain View, CA, US
[+] mail.example.com [+] dev.example.com [+] api.example.com

Generates 12 targeted Google dork URLs for any target. No network calls.

[+] "johndoe" site:linkedin.com https://www.google.com/search?q=%22johndoe%22+site%3Alinkedin.com [+] "johndoe" leaked OR breach OR dump https://www.google.com/search?q=%22johndoe%22+leaked+OR+breach+OR+dump
[+] https://pastebin.com/aB1cD2eF (2023-04-12) [+] https://pastebin.com/xY3zA4bC (2022-11-08)

Gathers phone intelligence usingphoneinfoga. Use E.164 format.

[+] Country: United States [+] Carrier: AT&T [+] Line type: Mobile

IPv4 input → host lookup (open ports, org, CVEs). Any other query → banner/keyword search. RequiresSHODAN_API_KEY.

openosint shodan 8.8.8.8 openosint shodan "apache port:80 country:DE"
[+] Org: Google LLC | Open ports: 53, 443

Checks an IP, domain, URL, or file hash againstVirusTotal's 70+ engines. Auto-detects input type. RequiresVIRUSTOTAL_API_KEY.

openosint virustotal 8.8.8.8 openosint virustotal example.com openosint virustotal 44d88612fea8a8f36de82e1278abb02f
[VirusTotal] Malicious: 0 / Harmless: 72

QueriesIP2Location.iofor enhanced IP intelligence: geolocation, ISP, ASN, and — on the Security Plan — VPN/Proxy/Tor/datacenter detection. Sponsored integration. RequiresIP2LOCATION_API_KEY.

[IP2Location] City: Mountain View, CA, US | ISP: Google LLC [IP2Location] VPN: No | Proxy: No | TOR: No | Datacenter: Yes

IPv4 → host view (open ports, services, ASN). Domain → certificate search (SANs, issuer). RequiresCENSYS_API_IDandCENSYS_SECRET.

openosint censys 8.8.8.8 openosint censys example.com
[Censys] Open Ports: 53, 443, 853 | ASN: AS15169 Google LLC

Checks an IP againstAbuseIPDBv2. Returns abuse confidence score, total reports, country, ISP, and last reported timestamp. RequiresABUSEIPDB_API_KEY.

[AbuseIPDB] Abuse Confidence Score: 87% | Total Reports: 143 ⚠️ HIGH ABUSE CONFIDENCE — flagged by AbuseIPDB

Warning appears whenabuseConfidenceScoreexceeds 50%.

QueriesGitHub REST API. Username → profile, repos, commit-discovered emails. Keyword → user/repo search. OptionalGITHUB_TOKENraises rate limit from 60 to 5000 req/h.

[GitHub] Repos: 42 | Followers: 128 [GitHub] Commit email: johndoe@example.com

Queries A/AAAA/MX/NS/TXT/CNAME/SOA records and analyzes SPF, DMARC, and DKIM configuration usingdnspython(no external API).

[DNS] A: 93.184.216.34 [DNS] MX: mail.example.com (priority 10) [DNS] SPF: v=spf1 include:_spf.google.com ~all

Executes live Google dork queries through theBright Data SERP API¹, returning structured results (title, URL, snippet). Defaults to 5 dorks per run; each is a separate billable API call. RequiresBRIGHTDATA_API_KEYandBRIGHTDATA_SERP_ZONE.

openosint search-dorks-live "john doe" --max-dorks 3
[+] Dork: "john doe" site:linkedin.com Title: John Doe | LinkedIn URL: https://www.linkedin.com/in/john-doe-12345

Fetches any public URL throughBright Data Web Unlocker¹, bypassing Cloudflare/CAPTCHA. Returns clean Markdown. RequiresBRIGHTDATA_API_KEYandBRIGHTDATA_UNLOCKER_ZONE.

[Web Unlocker] Remote status: 200 # Example Domain This domain is for use in illustrative examples in documents.

Collects a target's public search-engine footprint viaBright Data SERP API¹. Detects entity type (email, username, domain, phone, or full name) and runs entity-type-aware Google queries, returning structured results plus Entity Correlation Graph nodes/edges for discovered domains and profiles. RequiresBRIGHTDATA_API_KEYandBRIGHTDATA_SERP_ZONE.

pip install "openosint[web]" openosint web # Opens http://localhost:8080 automatically

Browser-based AI chat with streaming tool output, inline result cards, light/dark theme toggle. Supports local inference via Ollama or any OpenAI-compatible endpoint — no Anthropic API key required.

Try the live demo →— bring your own Anthropic / OpenRouter / Ollama key, no signup.

# Fully local (no API key) — requires Ollama runtime: https://ollama.com ollama pull llama3.2 openosint web # Settings -> Ollama (local) -> model: llama3.2 # OpenAI-compatible endpoint (LiteLLM, vLLM, LM Studio, ...) export OPENAI_BASE_URL="http://localhost:4000/v1" openosint web # Settings -> OpenAI API

Runopenosintwith no arguments to start the AI-powered REPL:

All sessions are auto-saved to~/.openosint/history/. Browse withopenosint history.

For the REPL/CLI with an OpenAI-compatible backend:

pip install "openosint[openai]" openosint --provider openai \ --openai-base-url http://localhost:4000/v1 \ --openai-model gpt-4o-mini

Full per-tool reference, CLI flags, and configuration options atopenosint.tech.

Expose all 19 OpenOSINT tools to any MCP-compatible AI client. Once connected, Claude can natively invoke all 19 tools during conversations.

claude mcp add openosint python /absolute/path/to/OpenOSINT/openosint/mcp_server.py claude mcp list

Claude Desktop— add to~/Library/Application Support/Claude/claude_desktop_config.json:

{ "mcpServers": { "openosint": { "command": "python", "args": ["/absolute/path/to/OpenOSINT/openosint/mcp_server.py"] } } }

Prefer zero setup? TheOpenOSINT Email Recon Actoris also available as a hosted MCP tool via theApify MCP Server— no server to run, no config file to edit. Try for free.

$ claude > Investigate target@example.com. Trace any username found across other platforms and compile a full report.
# From PyPI (recommended) pip install openosint # From source git clone https://github.com/OpenOSINT/OpenOSINT.git cd OpenOSINT pip install -e .

If a binary is absent, the corresponding tool returns a descriptive error. All other tools remain operational.

Don't want to install these locally? TheOpenOSINT Email Recon Actorruns email recon in Apify's cloud — zero dependencies, zero local setup.

Store keys in a.envfile at the project root (copy.env.example).python-dotenvloads it automatically at startup.

# Build and run docker compose up --build # One-off command docker compose run --rm openosint email target@example.com --json

SetANTHROPIC_API_KEY(and optionallyHIBP_API_KEY,IPINFO_TOKEN) in a.envfile or export them before runningdocker compose. Reports are persisted to./reports/via a volume mount.

DigitalOcean App Platform:see.do/app.yamlfor App Platform configuration.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.