Skip to content
Cybersecurity · Threat Intelligence

Top 6 OSINT Tools for Security Professionals 2026

OSINT platforms compared: Maltego, Shodan, Censys, theHarvester, SpiderFoot and OWASP Amass, with the licensing and access changes that broke half of everyone's toolkit.

By ·May 8, 2026·Updated Sep 18, 2026·15 min·6 tools compared
OSINTThreat IntelligenceReconnaissanceSecurity ResearchCybersecurity

The short answer, by problem. For case-based investigation connecting people, domains and infrastructure, buy Maltego, and test the credit model on its free tier before you commit. For internet exposure research, buy Shodan at a $49 one-time membership, and add Censys if you need history or certificate depth. For enumeration inside a pipeline, run theHarvester, which is free and genuinely maintained. For a broad automated sweep with no budget, run the open source SpiderFoot. For deep subdomain and infrastructure discovery, run OWASP Amass.

Last verified: 18 September 2026. Every tool here was checked this session: commercial availability, published pricing, and for the open source projects, actual repository maintenance status rather than reputation.

Check maintenance status before you check features

OSINT tooling decays quietly. These tools are mostly thin layers over other people's data sources, so when a source changes its API, its terms or its price, an unmaintained tool does not fail loudly. It returns fewer results and reports a clean run. That is the most dangerous failure mode in the category, because an empty result reads as an answer.

Project Last tagged release Last repository activity
theHarvester 4.11.1, June 2026 Commits in the week of checking
OWASP Amass v5.1.1, April 2026 July 2026
SpiderFoot (open source) v4.0, April 2022 April 2026
Recon-ng None November 2024

That table is why this revision made two changes. Recon-ng has been removed and replaced by OWASP Amass. It has no tagged release and no commit since November 2024, and in a category defined by source churn that is disqualifying for anything you depend on. SpiderFoot stays but with a caveat: the repository is alive and the last tagged release is four years old, so anyone wanting current module coverage is running unversioned code from the main branch.

The commercial product that no longer exists

Previous versions of this page ranked SpiderFoot HX as a commercial tier. It is not purchasable. Intel 471 acquired SpiderFoot in November 2022 and folded the hosted product into its TITAN platform, and spiderfoot.net now returns a permanent redirect to intel471.com. The open source tool was never affected and remains free under the MIT licence.

What was lost is the structure rather than the code. SpiderFoot used to offer the pattern this category needs: free to start, supported hosted edition to grow into. That escape hatch closed, and the upgrade path from the free tool is now a threat intelligence platform purchase.

What closed since 2025

Access restrictions are the defining OSINT story of the last two years, and a toolkit assembled before 2025 is partly broken.

  • X and Nitter, August 2026. X Corp sent cease and desist letters to the open source Nitter project on 24 August 2026, demanding a permanent takedown of its instances and code repository. Nitter and XCancel went offline on 25 August and the GitHub project was archived. The project announced on 6 September that it would continue after legal advice and XCancel returned, but the episode is the clearest signal yet that platforms will enforce against scraping frontends regardless of whether the underlying content is public.
  • Reddit. The Pushshift API was restricted in 2023, which ended the public archive services investigators relied on for historical subreddit and comment data. Reddit publishes no self-serve rate card for commercial Data API access today; commercial use is contract-gated.
  • Metered commercial data. Both Maltego and Censys meter data access in credits on top of the licence fee. That is not a restriction so much as a pricing model, but it has the same practical effect: the number of queries you can run is a budget line rather than a technical limit.

The operational consequence is that OSINT collection capability now needs to be treated as perishable. Audit which of your configured sources are actually returning results on a schedule, rather than discovering the gap mid-investigation.

Two scan datasets, not one

Shodan and Censys scan the same internet and do not see the same thing. Scan cadence, port coverage, banner parsing and enrichment all differ, so a host present in one can be absent or differently characterised in the other. Their heritage differs too: Shodan is banner-first and strongest on devices and industrial control systems, Censys is certificate-first and strongest on web properties and infrastructure relationships.

For ad-hoc research, one is enough, and Shodan's $49 one-time membership is the best value entry point in OSINT. For a programme that reports on external exposure, where a missed asset is the failure mode, running both is a coverage decision rather than redundancy. If that programme is the actual requirement, compare against the external attack surface management tools, which are these datasets with workflow attached.

Where OSINT stops

OSINT is a collection discipline. It is not threat intelligence, which is the analytical product built from collection plus commercial feeds, sharing communities and internal telemetry. It is not attack surface management, which is the operational programme that applies collection to your own estate continuously and routes findings to remediation.

Holding that line matters commercially, because vendors in the adjacent categories sell OSINT collection with workflow attached and price it accordingly. For the analytical layer, see the top 5 threat intelligence platforms. For credential and breach exposure, see dark web monitoring tools. For the wider free tooling picture, see open source security tools.

Passive collection from third-party sources and active probing of a target are different legal categories, and several tools here do both. Amass can operate purely from certificate transparency and passive DNS, or it can probe the target directly. The first is open source collection. The second is reconnaissance against a system, and whether you are authorised to run it is a question to settle in writing beforehand.

Three further boundaries apply to any OSINT programme. Publicly available is not the same as lawfully collectable at scale, and collecting personal data about EU or UK residents carries GDPR obligations regardless of source. Automated collection routinely breaches platform terms even when the data is visible to anyone. And the same capability that supports a legitimate investigation supports harassment, so the policy that prevents misuse has to be written down rather than assumed.

Quick Comparison

ToolBest ForApproachMaintenance Status (checked 18 Sep 2026)Published Pricing
MaltegoVisual link analysis and case-based investigationGraph, Transforms, credit-metered data accessActive; Graph (Browser) 2.19.0 shipped June 2026Yes, in EUR: Basic free; Entry Standard 3,000/yr; Professional 7,500/yr
ShodanInternet-exposed device and service searchContinuous internet scan databaseActiveYes: $49 one-time membership; Freelancer $69/mo; Small Business $359/mo; Corporate $1,099/mo
Censys PlatformCertificate, host and web property research with a usable free tierContinuous internet scan databaseActivePartial: free account with monthly credits; credit packages from $100; tier pricing not published
theHarvesterEmail, subdomain and name enumerationCLI enumeration across many sourcesActive; 4.11.1 released June 2026, commits this weekFree and open source
SpiderFootAutomated broad-sweep reconnaissanceAutomated scan across 200+ modulesOpen source repo active; last tagged release v4.0, April 2022Free open source. SpiderFoot HX is gone: spiderfoot.net redirects to Intel 471
OWASP AmassAttack surface mapping and subdomain discovery at depthGraph-backed asset discovery engineActive; v5.1.1 released April 2026Free and open source

Maltego

Best For
Visual link analysis and case-based investigation
Approach
Graph, Transforms, credit-metered data access
Maintenance Status (checked 18 Sep 2026)
Active; Graph (Browser) 2.19.0 shipped June 2026
Published Pricing
Yes, in EUR: Basic free; Entry Standard 3,000/yr; Professional 7,500/yr

Shodan

Best For
Internet-exposed device and service search
Approach
Continuous internet scan database
Maintenance Status (checked 18 Sep 2026)
Active
Published Pricing
Yes: $49 one-time membership; Freelancer $69/mo; Small Business $359/mo; Corporate $1,099/mo

Censys Platform

Best For
Certificate, host and web property research with a usable free tier
Approach
Continuous internet scan database
Maintenance Status (checked 18 Sep 2026)
Active
Published Pricing
Partial: free account with monthly credits; credit packages from $100; tier pricing not published

theHarvester

Best For
Email, subdomain and name enumeration
Approach
CLI enumeration across many sources
Maintenance Status (checked 18 Sep 2026)
Active; 4.11.1 released June 2026, commits this week
Published Pricing
Free and open source

SpiderFoot

Best For
Automated broad-sweep reconnaissance
Approach
Automated scan across 200+ modules
Maintenance Status (checked 18 Sep 2026)
Open source repo active; last tagged release v4.0, April 2022
Published Pricing
Free open source. SpiderFoot HX is gone: spiderfoot.net redirects to Intel 471

OWASP Amass

Best For
Attack surface mapping and subdomain discovery at depth
Approach
Graph-backed asset discovery engine
Maintenance Status (checked 18 Sep 2026)
Active; v5.1.1 released April 2026
Published Pricing
Free and open source
1

Maltego

Best Overall

Best for: Visual link analysis and case-based investigation

“Maltego is still the category-defining investigation platform and it is now considerably more than a graph tool. Maltego Search, Graph, Monitor and Hunchly sit under one platform, and Maltego One extends into structured person-of-interest investigation. It is also one of only two tools here that publishes real prices. Basic is free with 200 credits a month. Entry Standard is 3,000 euros a year with 10,000 credits a month, and Professional is 7,500 euros a year with 20,000 credits a month for up to five seats. The credit model is the thing to understand before you buy, because it is how data access is metered.”

Pros

  • Publishes tiered pricing in euros, including a genuinely usable free tier at 200 credits a month
  • Transform ecosystem reaches hundreds of public, commercial and proprietary data sources from one interface
  • Hunchly, acquired in May 2025, adds in-browser evidence preservation, so collection and analysis live in one workflow
  • Government and organizational email addresses qualify for Basic at 1,000 credits a month rather than 200

Cons

  • The credit model, not the licence fee, is the real cost driver and it is hard to forecast before you start working cases
  • Many valuable Transforms require a separate paid subscription with the underlying data provider
  • Steep learning curve: the platform rewards investigative skill and punishes casual use
Honest Weakness: Maltego's published licence price is the floor, not the cost. Data access is metered in credits, commercial Transforms frequently require a separate paid relationship with the data provider on top, and a single deep investigation can consume a meaningful share of a monthly allowance. The published tiers are genuinely useful for comparison and genuinely misleading as a budget. Before committing, run three representative cases on the free tier and count credits, then multiply by your real caseload. The second caution is unchanged from previous years: the platform's value scales with analyst skill, so a licence bought without training time produces an expensive graph nobody reads.

Credits are the pricing model

Every Transform run consumes credits, and commercial data sources consume more than free ones. That makes the annual licence a poor proxy for total cost, and it makes usage forecasting a real procurement exercise rather than a formality. The practical advice is to instrument your own usage on the free tier first, because vendor guidance on typical consumption is based on typical cases, and investigations are not typical.

The platform got wider

Maltego has been assembling an end-to-end investigation workflow through acquisition. PublicSonar and Social Network Harvester were acquired in April 2024, adding real-time public safety monitoring and court-ready social media evidence collection. Hunchly followed in May 2025, adding in-browser evidence preservation. Graph (Browser) 2.19.0, shipped June 2026, added an AI assistant with credit usage tracking. The company has been owned by Charlesbank Capital Partners since April 2023.

Published on maltego.com in euros: Basic free, 200 credits a month, or 1,000 credits for government and organizational email addresses. Entry Standard 3,000 euros a year, 10,000 credits a month. Professional Standard 7,500 euros a year, 20,000 credits a month, up to five seats billed per seat. Professional Advanced 7,500 euros a year base, 40,000 credits a month. Enterprise is custom, for five or more users.

Visit Maltego
2

Shodan

Best Value

Best for: Internet-exposed device and service search

“Shodan continuously scans the IPv4 and IPv6 internet and makes the result searchable, and it is the most transparently priced tool in this comparison. A one-time $49 membership unlocks the account permanently. API subscriptions run at $69 a month for Freelancer, with 10,000 query credits and 5,120 scan credits. Small Business is $359 a month for 200,000 query credits and 65,536 scan credits. Corporate is $1,099 a month for unlimited query credits and 327,680 scan credits. Every plan is rate limited to one request per second, which is the constraint that catches people out.”

Pros

  • Publishes every price and every credit allowance, which is almost unique in the security tooling market
  • The $49 one-time membership is a permanent account upgrade rather than a subscription, and it is the best value entry point in OSINT
  • Coverage spans web servers, databases, industrial control systems and IoT devices across both IPv4 and IPv6
  • Commercial use rights and basic Streaming API access are included on all paid plans

Cons

  • One request per second on every plan, including Corporate, which shapes how you design automation
  • Visibility is limited to what is exposed to the public internet; internal assets need a different approach
  • Effective use depends on search syntax that takes real time to learn
Honest Weakness: Shodan's data is a snapshot of scan results, not ground truth, and the gap matters more than most users assume. Banners can be stale, spoofed or served by something other than what they claim, and a result set is evidence that something answered a probe at some point, not that a specific vulnerable service is running now. Verify before acting on it. The one request per second rate limit is the other practical trap. It applies to every tier including the $1,099 Corporate plan, so paying more buys credits rather than throughput. Any enrichment pipeline has to be designed around a hard one-per-second ceiling.

Query credits versus scan credits

Searching consumes query credits, one per search request. Scanning an IP consumes scan credits, one per IP. These are separate budgets and conflating them is the most common cause of an unexpectedly exhausted plan. Corporate is the only tier with unlimited query credits, which is why organizations doing continuous monitoring rather than ad-hoc research end up there.

Where the data comes from

Shodan operates its own distributed scanning infrastructure and stores the banners returned by services it reaches. That is a fundamentally different data source from certificate transparency or DNS enumeration, which is why serious attack surface work uses more than one. Pairing Shodan with Censys is standard practice rather than redundancy, because their scan coverage and parsing differ.

Published on account.shodan.io: Membership $49 one-time. Freelancer $69 per month, up to 10,000 query credits and 5,120 scan credits. Small Business $359 per month, 200,000 query credits and 65,536 scan credits. Corporate $1,099 per month, unlimited query credits and 327,680 scan credits. All plans are rate limited to 1 request per second and include commercial use rights.

Visit Shodan
3

Censys Platform

Runner Up

Best for: Certificate, host and web property research with a genuinely usable free tier

“Censys is the addition this page most needed. It is the other major internet-scan dataset, with a research heritage in certificate transparency, and it offers a free account with monthly credits that requires no credit card. There are three commercial tiers. Core covers analysts needing IP, service, domain and certificate visibility. Adversary Investigation adds searchable threat data and longer history for threat hunting. Security Operations is the enterprise tier, with unlimited users and twelve or more months of history. Tier prices are not published, though the site states that credit packages start as low as $100.”

Pros

  • Free account with a monthly credit allowance, no credit card required, which makes it the easiest paid-grade dataset to start using
  • Certificate and web property data is a genuine differentiator against a purely banner-oriented dataset
  • API access is included at every tier including free, rather than being gated to enterprise
  • Tier structure is transparent about what differs: users, data history and whether threat data is searchable or view-only

Cons

  • Tier prices are not published; only the statement that credit packages start as low as $100
  • Free and Starter users have credit-consuming functionality restricted once the monthly allowance is exhausted
  • Historical data depth is the main paywall, at one month, three months and twelve or more months by tier
Honest Weakness: Censys prices its history rather than its data, and that is the thing to check against your actual work. The free tier will answer a current-state question competently. It will not answer what this certificate looked like eight months ago, which is precisely the question that matters in attribution and infrastructure tracking, and the twelve-month window sits in the most expensive tier. The second issue is the credit model. When a free or starter account exhausts its monthly allowance, credit-consuming functionality is restricted until the next allocation or until you buy more. That is workable for research and awkward in the middle of an incident.

Why you want two scan datasets

Shodan and Censys scan the same internet and do not see the same thing. Scan cadence, port coverage, parsing and enrichment all differ, so a host that appears in one may be absent or differently characterised in the other. For attack surface work where a missed asset is the failure mode, running both is a coverage decision rather than a redundancy.

History is the paid product

Current-state visibility is close to commodity. What you pay for is the ability to look backwards: how this infrastructure changed, when a certificate appeared, what else shared it. The tier structure makes that explicit, with data history stepping from one month to three to twelve or more. Scope your subscription to the longest lookback your casework genuinely needs, because it is the single largest price lever.

Partially published on censys.com: a free account with monthly credits and no credit card required, and a statement that credit packages start as low as $100. The Core, Adversary Investigation and Security Operations tiers route to sales with no figures published.

Visit Censys Platform
4

theHarvester

Best Open Source

Best for: Email, subdomain and name enumeration

“theHarvester is the healthiest maintained project in this comparison. Version 4.11.1 shipped in June 2026 and the repository had commits the same week this page was checked. It does one job, gathering emails, subdomains, hosts and names from a long list of public sources, and it does it reliably. That reliability is exactly why active maintenance matters here: this tool is a thin layer over other people's data sources, and when those sources change their terms or their APIs, an unmaintained version silently returns less.”

Pros

  • Genuinely actively maintained: release 4.11.1 in June 2026 and commits in the week this page was checked
  • Free, open source, and trivial to run in a container or a CI job
  • Wide source coverage that keeps pace with sources appearing and disappearing, which is the whole value
  • Composes well: it is a component in a reconnaissance pipeline rather than a platform that wants to own one

Cons

  • Narrow by design: enumeration only, with no analysis, correlation or case management
  • Many sources require your own API keys, and several of those keys now cost money
  • Output quality depends entirely on which sources are reachable on the day you run it
Honest Weakness: theHarvester is a wrapper, and wrappers inherit the health of what they wrap. The tool being maintained does not mean the data sources behind it are open, and a growing share now require an API key you have to pay for, or have tightened their terms since 2025. A clean run that returns twelve subdomains may mean twelve subdomains exist, or it may mean nine of your configured sources quietly returned nothing. Check which modules actually produced results rather than reading the aggregate, and assume coverage degrades over time unless you keep keys current.

Maintenance status is the review

For a tool of this type, the only durable question is whether someone is keeping up with source churn. At the time of checking, the repository had 4.11.1 tagged in June 2026 and commits within the week. Compare that to Recon-ng, which this page previously ranked and which has had no commit since November 2024 and no tagged release at all.

Free and open source.

Visit theHarvester
5

SpiderFoot

Best Free Option

Best for: Automated broad-sweep reconnaissance in one run

“The open source SpiderFoot is still free, still widely used at over twenty-two thousand GitHub stars, and still the fastest way to get broad automated reconnaissance across more than two hundred modules in a single scan. The commercial product is a different story. SpiderFoot HX no longer exists as an independent purchase: Intel 471 acquired SpiderFoot in November 2022 and spiderfoot.net now returns a permanent redirect to intel471.com, with the capabilities folded into the Intel 471 TITAN platform. Any comparison still listing SpiderFoot HX as a buyable commercial tier is describing a product you cannot order.”

Pros

  • Over two hundred modules in one automated scan, which is the broadest single-command sweep available for free
  • Repository is still receiving commits, with the most recent activity in April 2026
  • Structured output suits pipelines and periodic monitoring rather than one-off manual use
  • Zero licence cost, which makes it the realistic starting point for a team with no OSINT budget

Cons

  • SpiderFoot HX is no longer purchasable; spiderfoot.net redirects to Intel 471
  • Last tagged release is v4.0 from April 2022, so users are running from the main branch rather than a versioned build
  • Automated breadth produces a volume of results that requires real triage effort
Honest Weakness: There is a gap between the repository being alive and the project being maintained in the way a security team needs. Commits continued into 2026, but the most recent tagged release is v4.0 from April 2022, which means anyone wanting current module coverage is running unversioned code from the main branch. That is acceptable for a researcher and awkward for anyone who needs a reproducible, auditable tool version. The commercial escape hatch that used to exist is closed. HX was absorbed into Intel 471 TITAN, so the upgrade path from the free tool is now a threat intelligence platform purchase rather than a supported edition of the same product.

What happened to HX

Intel 471 acquired SpiderFoot in November 2022 and folded the hosted commercial product into its TITAN platform. The domain now issues a permanent redirect. The open source tool was never affected and remains available under the MIT licence, but the two-tier structure that made SpiderFoot attractive, free to start and a supported hosted edition to grow into, no longer exists.

Automation and triage

A SpiderFoot scan returns a great deal at once, and most of it is not interesting. That trade is right for periodic monitoring and for establishing a baseline, and wrong for a focused investigation where a graph tool produces a more directed result. Running it alongside Maltego rather than instead of it is the usual pattern.

Free and open source under the MIT licence. SpiderFoot HX is no longer sold; spiderfoot.net redirects to Intel 471, which acquired the project in November 2022.

Visit SpiderFoot
6

OWASP Amass

Best Open Source

Best for: Attack surface mapping and subdomain discovery at depth

“Amass replaces Recon-ng on this list, and the reason is maintenance rather than preference. Recon-ng has had no commit since November 2024 and carries no tagged release. Amass shipped v5.1.1 in April 2026 with repository activity in July 2026, is an OWASP project, and does the enumeration job far more thoroughly. It combines DNS enumeration, certificate transparency, passive data sources and active reconnaissance into a graph-backed asset discovery engine, which is the closest thing in open source to what commercial attack surface management products sell.”

Pros

  • Actively maintained under OWASP governance, with v5.1.1 released April 2026
  • Goes deeper on subdomain and infrastructure discovery than any other free tool here
  • Graph-backed data model that retains relationships between discovered assets rather than emitting a flat list
  • Free, with no credit metering and no API cost on its default sources

Cons

  • Active reconnaissance modes generate traffic to the target, which has authorisation implications
  • Configuration is genuinely involved, and default runs undersell what the tool can do
  • Discovery only: no analysis layer, no case management, no reporting
Honest Weakness: Amass is powerful enough to get you in trouble if you run it carelessly. Its active modes touch the target directly rather than only querying third-party data, and running those against infrastructure you have no written authorisation to test is a different legal question from passive collection. Keep the distinction explicit in your tooling and your runbooks. The second issue is that the results deserve verification: aggressive subdomain enumeration produces false positives from wildcard DNS and from stale records, and treating raw output as a confirmed asset inventory will put things in scope that are not yours.

Passive and active are different legal questions

Amass can operate purely from third-party sources such as certificate transparency logs and passive DNS, or it can probe the target directly. The first is open source collection. The second is reconnaissance against a system, and whether you are authorised to do it is a question to answer before you run it, not after. Configure the mode deliberately rather than accepting a default.

Why Recon-ng came off this list

Recon-ng was a good modular framework and its GitHub repository shows no commit since November 2024 and no tagged release. In a category where the entire job is keeping up with data sources that change monthly, two years without maintenance is disqualifying for anything you depend on. The code still runs. The sources behind it have moved.

Free and open source.

Visit OWASP Amass

Which One Should You Pick?

Use CaseOur Recommendation
Case-based investigation connecting people, domains, infrastructure and accountsMaltego is still the strongest graph investigation platform, and its free Basic tier at 200 credits a month lets you test the credit model before committing.
Finding what your organization has exposed to the public internetShodan for the banner data at a $49 one-time membership, and Censys alongside it, because the two scan datasets do not see the same hosts.
Tracking how attacker infrastructure changed over the past yearCensys prices data history by tier, from one month to twelve or more, so scope the subscription to the lookback your casework actually needs.
Quick email, subdomain and name enumeration inside a pipelinetheHarvester is free, actively maintained with a June 2026 release, and composes cleanly into automation.
Broad automated sweep with no budget at allThe open source SpiderFoot runs over two hundred modules in one scan. Note that SpiderFoot HX is no longer purchasable.
Deep subdomain and infrastructure discovery for attack surface workOWASP Amass goes further than any other free tool, and replaces Recon-ng, which has had no commit since November 2024.

How we evaluated

Last verified: 18 September 2026.

This is a research-based comparison, not a hands-on bake-off. It publishes no coverage benchmark, no comparative result count and no head-to-head accuracy claim, because those cannot be produced honestly without running every tool against the same targets under the same authorisation. What it does claim is that the following were checked, tool by tool, on 18 September 2026.

  • Commercial availability. Whether each product can still be purchased and from whom. SpiderFoot HX cannot: Intel 471 acquired the project in November 2022 and spiderfoot.net returns a permanent redirect to intel471.com. Maltego has been owned by Charlesbank Capital Partners since April 2023 and has acquired PublicSonar and Social Network Harvester in April 2024 and Hunchly in May 2025.
  • Repository maintenance status, measured rather than assumed. For each open source project, the GitHub API was queried directly for the latest tagged release and the most recent push. That is how Recon-ng came off this list, with no tagged release and no commit since November 2024, and how SpiderFoot earned its caveat, with commits in April 2026 but no tagged release since v4.0 in April 2022.
  • Published pricing, and its absence. Every price here comes from the vendor's own pricing page. Maltego and Shodan publish full tier pricing and it is reproduced with its units. Censys publishes a free tier and a minimum credit package figure but not tier prices. No number on this page came from a comparison site or an aggregator.
  • Metering models. Whether data access is charged separately from the licence, because in this category it usually is. Both Maltego and Censys meter in credits, which makes the published licence fee a floor rather than a cost.
  • Data source availability. The access restrictions that shape what these tools can actually reach were checked against primary reporting, including the August 2026 X Corp action against Nitter and the state of Reddit commercial API access.

What we did not do

No vendor paid for placement and there are no affiliate links on this page. Nothing here reports hands-on testing, comparative coverage or result quality measured by us. No collection was performed against any third party in the course of writing this page.

How to read the ranking

Ranking reflects fit for the stated use case, weighted toward three things.

The first is whether the tool is actually maintained, which in this category outranks features. A tool that silently loses sources is worse than a narrower tool that works, because the failure looks like an answer. The second is pricing legibility, including the metering model rather than just the licence fee. The third is whether the tool does its job at depth, since OSINT rewards specialist tools composed into a workflow more than it rewards platforms that claim to cover everything.

One caution applies across the whole list. Every tool here returns evidence that something was true at some point, not ground truth about now. Scan banners go stale, can be spoofed, and can be served by something other than what they claim. Enumeration produces false positives from wildcard DNS and stale records. Treat any single-source finding as a lead to corroborate, and be especially careful in 2026, when AI-generated profiles, imagery and text have contaminated the public sources these tools collect from.

Note

Editorial independence: this is a vendor-neutral comparison with no paid placements, sponsorships, or affiliate links. Rankings reflect fit for the stated use cases, not commercial relationships.

Frequently Asked Questions

What changed in OSINT tool licensing and data access since 2025?
Several things closed at once and a toolkit assembled before 2025 is now partly broken. On 24 August 2026 X Corp sent cease and desist letters to the open source Nitter project, demanding takedown of its instances and repository. Nitter and XCancel went offline on 25 August and the GitHub project was archived. The project announced on 6 September 2026 that it would continue after legal advice, and XCancel returned. Reddit restricted the Pushshift API in 2023, which ended the public archive services investigators had relied on, and publishes no self-serve rate card for commercial Data API access today. On the commercial side, SpiderFoot HX ceased to exist as an independent purchase after Intel 471 acquired the project, and spiderfoot.net now redirects to Intel 471. The practical lesson is to check maintenance status and data source availability before you depend on a tool, not after an investigation stalls.
Which OSINT tools publish a price?
Two publish full price lists and one publishes part of one, checked on each vendor's own site on 18 September 2026. Maltego publishes tiers in euros: Basic free with 200 credits a month, Entry Standard at 3,000 euros a year, Professional at 7,500 euros a year. Shodan publishes everything: a $49 one-time membership, then Freelancer at $69 a month, Small Business at $359 and Corporate at $1,099, with credit allowances stated for each. Censys publishes a free tier and the statement that credit packages start as low as $100, but routes its Core, Adversary Investigation and Security Operations tiers to sales. theHarvester, SpiderFoot and OWASP Amass are free and open source. Be aware that for Maltego and Censys the licence is only part of the cost, because data access is metered in credits on top.
Why was Recon-ng removed from this comparison?
Maintenance. Recon-ng's GitHub repository shows no commit since November 2024 and carries no tagged release at all. In a category whose entire function is querying third-party data sources that change their APIs and terms monthly, two years without maintenance means silent coverage loss: modules fail, return nothing, and the tool reports a clean run. The code still executes. It is the sources behind it that have moved. OWASP Amass takes its place, is actively maintained with v5.1.1 released in April 2026, and does the enumeration job more thoroughly. Anyone still running Recon-ng should at minimum verify which modules are actually returning results rather than trusting the aggregate output.
What is the legal and ethical boundary for OSINT?
Three lines matter and they are frequently blurred. First, publicly available is not the same as lawfully collectable at scale: collecting personal data about EU or UK residents triggers GDPR obligations regardless of whether the source was public, and several US state privacy laws now reach similar collection. Second, automated collection routinely breaches platform terms of service even when the data is visible to anyone, and 2026 demonstrated that platforms will enforce, as X Corp did against Nitter in August. Third, passive collection from third-party sources and active probing of a target are different legal categories, which matters directly for tools like Amass that can do both. Establish written authorisation scope before active reconnaissance and document the purpose of any collection involving individuals. Set a boundary that prevents the same capability being used for harassment, because these tools do not distinguish between an investigation and a stalking campaign.
Do I need two internet scan datasets, or is one enough?
Two, if the work is attack surface management where a missed asset is the failure. Shodan and Censys scan the same internet and do not return the same results, because scan cadence, port coverage, banner parsing and enrichment all differ, and a host present in one can be absent from the other. They also have different heritage: Shodan is banner-first and strongest on devices and industrial systems, Censys is certificate-first and strongest on web properties and infrastructure relationships. For ad-hoc research one is enough and Shodan's $49 one-time membership is the cheapest useful entry point in OSINT. For a programme that reports on external exposure, running both is a coverage decision.
How does OSINT relate to threat intelligence and attack surface management?
OSINT is a collection discipline. Threat intelligence is the analytical product built from it plus commercial feeds, sharing communities and internal telemetry. Attack surface management is the operational programme that continuously applies collection to your own estate and routes findings to remediation. The tools blur: Amass and Shodan are OSINT tools and also attack surface inputs, and every commercial attack surface product is OSINT collection with workflow attached. The distinction worth holding is purpose. If you are answering a question about a specific target, that is investigation and Maltego is the right shape. If you are continuously monitoring your own exposure, that is a programme, and a manual tool will not sustain it.
How do AI tools change OSINT work?
In two directions, and only one of them helps. Analytically, large language models genuinely accelerate summarisation, translation and correlation across large collected datasets, and Maltego shipped an AI assistant into Graph (Browser) 2.19.0 in June 2026. The obligation that comes with that is verification: a model that fabricates a plausible connection between two entities is worse than no tool at all, because the output looks like analysis. In the other direction, AI-generated content contaminates the sources OSINT collects from. Synthetic profiles, generated imagery and machine-written text now populate the public web and social platforms, which means provenance and corroboration matter more than they did three years ago. Treat any single-source finding as a lead rather than a fact.

About the author

is the founder and creator of LoginRadius, a customer identity platform he built and scaled to over a billion users. He is now the founder of GrackerAI, a GEO platform for B2B SaaS and cybersecurity teams, and has spent more than 15 years building identity and security products.

Related Comparisons