Top 6 OSINT Tools for Security Professionals 2026
OSINT platforms compared: Maltego, Shodan, Censys, theHarvester, SpiderFoot and OWASP Amass, with the licensing and access changes that broke half of everyone's toolkit.
The short answer, by problem. For case-based investigation connecting people, domains and infrastructure, buy Maltego, and test the credit model on its free tier before you commit. For internet exposure research, buy Shodan at a $49 one-time membership, and add Censys if you need history or certificate depth. For enumeration inside a pipeline, run theHarvester, which is free and genuinely maintained. For a broad automated sweep with no budget, run the open source SpiderFoot. For deep subdomain and infrastructure discovery, run OWASP Amass.
Last verified: 18 September 2026. Every tool here was checked this session: commercial availability, published pricing, and for the open source projects, actual repository maintenance status rather than reputation.
Check maintenance status before you check features
OSINT tooling decays quietly. These tools are mostly thin layers over other people's data sources, so when a source changes its API, its terms or its price, an unmaintained tool does not fail loudly. It returns fewer results and reports a clean run. That is the most dangerous failure mode in the category, because an empty result reads as an answer.
| Project | Last tagged release | Last repository activity |
|---|---|---|
| theHarvester | 4.11.1, June 2026 | Commits in the week of checking |
| OWASP Amass | v5.1.1, April 2026 | July 2026 |
| SpiderFoot (open source) | v4.0, April 2022 | April 2026 |
| Recon-ng | None | November 2024 |
That table is why this revision made two changes. Recon-ng has been removed and replaced by OWASP Amass. It has no tagged release and no commit since November 2024, and in a category defined by source churn that is disqualifying for anything you depend on. SpiderFoot stays but with a caveat: the repository is alive and the last tagged release is four years old, so anyone wanting current module coverage is running unversioned code from the main branch.
The commercial product that no longer exists
Previous versions of this page ranked SpiderFoot HX as a commercial tier. It is not purchasable. Intel 471 acquired SpiderFoot in November 2022 and folded the hosted product into its TITAN platform, and spiderfoot.net now returns a permanent redirect to intel471.com. The open source tool was never affected and remains free under the MIT licence.
What was lost is the structure rather than the code. SpiderFoot used to offer the pattern this category needs: free to start, supported hosted edition to grow into. That escape hatch closed, and the upgrade path from the free tool is now a threat intelligence platform purchase.
What closed since 2025
Access restrictions are the defining OSINT story of the last two years, and a toolkit assembled before 2025 is partly broken.
- X and Nitter, August 2026. X Corp sent cease and desist letters to the open source Nitter project on 24 August 2026, demanding a permanent takedown of its instances and code repository. Nitter and XCancel went offline on 25 August and the GitHub project was archived. The project announced on 6 September that it would continue after legal advice and XCancel returned, but the episode is the clearest signal yet that platforms will enforce against scraping frontends regardless of whether the underlying content is public.
- Reddit. The Pushshift API was restricted in 2023, which ended the public archive services investigators relied on for historical subreddit and comment data. Reddit publishes no self-serve rate card for commercial Data API access today; commercial use is contract-gated.
- Metered commercial data. Both Maltego and Censys meter data access in credits on top of the licence fee. That is not a restriction so much as a pricing model, but it has the same practical effect: the number of queries you can run is a budget line rather than a technical limit.
The operational consequence is that OSINT collection capability now needs to be treated as perishable. Audit which of your configured sources are actually returning results on a schedule, rather than discovering the gap mid-investigation.
Two scan datasets, not one
Shodan and Censys scan the same internet and do not see the same thing. Scan cadence, port coverage, banner parsing and enrichment all differ, so a host present in one can be absent or differently characterised in the other. Their heritage differs too: Shodan is banner-first and strongest on devices and industrial control systems, Censys is certificate-first and strongest on web properties and infrastructure relationships.
For ad-hoc research, one is enough, and Shodan's $49 one-time membership is the best value entry point in OSINT. For a programme that reports on external exposure, where a missed asset is the failure mode, running both is a coverage decision rather than redundancy. If that programme is the actual requirement, compare against the external attack surface management tools, which are these datasets with workflow attached.
Where OSINT stops
OSINT is a collection discipline. It is not threat intelligence, which is the analytical product built from collection plus commercial feeds, sharing communities and internal telemetry. It is not attack surface management, which is the operational programme that applies collection to your own estate continuously and routes findings to remediation.
Holding that line matters commercially, because vendors in the adjacent categories sell OSINT collection with workflow attached and price it accordingly. For the analytical layer, see the top 5 threat intelligence platforms. For credential and breach exposure, see dark web monitoring tools. For the wider free tooling picture, see open source security tools.
One legal line worth drawing explicitly
Passive collection from third-party sources and active probing of a target are different legal categories, and several tools here do both. Amass can operate purely from certificate transparency and passive DNS, or it can probe the target directly. The first is open source collection. The second is reconnaissance against a system, and whether you are authorised to run it is a question to settle in writing beforehand.
Three further boundaries apply to any OSINT programme. Publicly available is not the same as lawfully collectable at scale, and collecting personal data about EU or UK residents carries GDPR obligations regardless of source. Automated collection routinely breaches platform terms even when the data is visible to anyone. And the same capability that supports a legitimate investigation supports harassment, so the policy that prevents misuse has to be written down rather than assumed.
Quick Comparison
| Tool | Best For | Approach | Maintenance Status (checked 18 Sep 2026) | Published Pricing |
|---|---|---|---|---|
| Maltego | Visual link analysis and case-based investigation | Graph, Transforms, credit-metered data access | Active; Graph (Browser) 2.19.0 shipped June 2026 | Yes, in EUR: Basic free; Entry Standard 3,000/yr; Professional 7,500/yr |
| Shodan | Internet-exposed device and service search | Continuous internet scan database | Active | Yes: $49 one-time membership; Freelancer $69/mo; Small Business $359/mo; Corporate $1,099/mo |
| Censys Platform | Certificate, host and web property research with a usable free tier | Continuous internet scan database | Active | Partial: free account with monthly credits; credit packages from $100; tier pricing not published |
| theHarvester | Email, subdomain and name enumeration | CLI enumeration across many sources | Active; 4.11.1 released June 2026, commits this week | Free and open source |
| SpiderFoot | Automated broad-sweep reconnaissance | Automated scan across 200+ modules | Open source repo active; last tagged release v4.0, April 2022 | Free open source. SpiderFoot HX is gone: spiderfoot.net redirects to Intel 471 |
| OWASP Amass | Attack surface mapping and subdomain discovery at depth | Graph-backed asset discovery engine | Active; v5.1.1 released April 2026 | Free and open source |
Maltego
- Best For
- Visual link analysis and case-based investigation
- Approach
- Graph, Transforms, credit-metered data access
- Maintenance Status (checked 18 Sep 2026)
- Active; Graph (Browser) 2.19.0 shipped June 2026
- Published Pricing
- Yes, in EUR: Basic free; Entry Standard 3,000/yr; Professional 7,500/yr
Shodan
- Best For
- Internet-exposed device and service search
- Approach
- Continuous internet scan database
- Maintenance Status (checked 18 Sep 2026)
- Active
- Published Pricing
- Yes: $49 one-time membership; Freelancer $69/mo; Small Business $359/mo; Corporate $1,099/mo
Censys Platform
- Best For
- Certificate, host and web property research with a usable free tier
- Approach
- Continuous internet scan database
- Maintenance Status (checked 18 Sep 2026)
- Active
- Published Pricing
- Partial: free account with monthly credits; credit packages from $100; tier pricing not published
theHarvester
- Best For
- Email, subdomain and name enumeration
- Approach
- CLI enumeration across many sources
- Maintenance Status (checked 18 Sep 2026)
- Active; 4.11.1 released June 2026, commits this week
- Published Pricing
- Free and open source
SpiderFoot
- Best For
- Automated broad-sweep reconnaissance
- Approach
- Automated scan across 200+ modules
- Maintenance Status (checked 18 Sep 2026)
- Open source repo active; last tagged release v4.0, April 2022
- Published Pricing
- Free open source. SpiderFoot HX is gone: spiderfoot.net redirects to Intel 471
OWASP Amass
- Best For
- Attack surface mapping and subdomain discovery at depth
- Approach
- Graph-backed asset discovery engine
- Maintenance Status (checked 18 Sep 2026)
- Active; v5.1.1 released April 2026
- Published Pricing
- Free and open source
Maltego
Best OverallBest for: Visual link analysis and case-based investigation
“Maltego is still the category-defining investigation platform and it is now considerably more than a graph tool. Maltego Search, Graph, Monitor and Hunchly sit under one platform, and Maltego One extends into structured person-of-interest investigation. It is also one of only two tools here that publishes real prices. Basic is free with 200 credits a month. Entry Standard is 3,000 euros a year with 10,000 credits a month, and Professional is 7,500 euros a year with 20,000 credits a month for up to five seats. The credit model is the thing to understand before you buy, because it is how data access is metered.”
Pros
- Publishes tiered pricing in euros, including a genuinely usable free tier at 200 credits a month
- Transform ecosystem reaches hundreds of public, commercial and proprietary data sources from one interface
- Hunchly, acquired in May 2025, adds in-browser evidence preservation, so collection and analysis live in one workflow
- Government and organizational email addresses qualify for Basic at 1,000 credits a month rather than 200
Cons
- The credit model, not the licence fee, is the real cost driver and it is hard to forecast before you start working cases
- Many valuable Transforms require a separate paid subscription with the underlying data provider
- Steep learning curve: the platform rewards investigative skill and punishes casual use
Credits are the pricing model
Every Transform run consumes credits, and commercial data sources consume more than free ones. That makes the annual licence a poor proxy for total cost, and it makes usage forecasting a real procurement exercise rather than a formality. The practical advice is to instrument your own usage on the free tier first, because vendor guidance on typical consumption is based on typical cases, and investigations are not typical.
The platform got wider
Maltego has been assembling an end-to-end investigation workflow through acquisition. PublicSonar and Social Network Harvester were acquired in April 2024, adding real-time public safety monitoring and court-ready social media evidence collection. Hunchly followed in May 2025, adding in-browser evidence preservation. Graph (Browser) 2.19.0, shipped June 2026, added an AI assistant with credit usage tracking. The company has been owned by Charlesbank Capital Partners since April 2023.
Published on maltego.com in euros: Basic free, 200 credits a month, or 1,000 credits for government and organizational email addresses. Entry Standard 3,000 euros a year, 10,000 credits a month. Professional Standard 7,500 euros a year, 20,000 credits a month, up to five seats billed per seat. Professional Advanced 7,500 euros a year base, 40,000 credits a month. Enterprise is custom, for five or more users.
Shodan
Best ValueBest for: Internet-exposed device and service search
“Shodan continuously scans the IPv4 and IPv6 internet and makes the result searchable, and it is the most transparently priced tool in this comparison. A one-time $49 membership unlocks the account permanently. API subscriptions run at $69 a month for Freelancer, with 10,000 query credits and 5,120 scan credits. Small Business is $359 a month for 200,000 query credits and 65,536 scan credits. Corporate is $1,099 a month for unlimited query credits and 327,680 scan credits. Every plan is rate limited to one request per second, which is the constraint that catches people out.”
Pros
- Publishes every price and every credit allowance, which is almost unique in the security tooling market
- The $49 one-time membership is a permanent account upgrade rather than a subscription, and it is the best value entry point in OSINT
- Coverage spans web servers, databases, industrial control systems and IoT devices across both IPv4 and IPv6
- Commercial use rights and basic Streaming API access are included on all paid plans
Cons
- One request per second on every plan, including Corporate, which shapes how you design automation
- Visibility is limited to what is exposed to the public internet; internal assets need a different approach
- Effective use depends on search syntax that takes real time to learn
Query credits versus scan credits
Searching consumes query credits, one per search request. Scanning an IP consumes scan credits, one per IP. These are separate budgets and conflating them is the most common cause of an unexpectedly exhausted plan. Corporate is the only tier with unlimited query credits, which is why organizations doing continuous monitoring rather than ad-hoc research end up there.
Where the data comes from
Shodan operates its own distributed scanning infrastructure and stores the banners returned by services it reaches. That is a fundamentally different data source from certificate transparency or DNS enumeration, which is why serious attack surface work uses more than one. Pairing Shodan with Censys is standard practice rather than redundancy, because their scan coverage and parsing differ.
Published on account.shodan.io: Membership $49 one-time. Freelancer $69 per month, up to 10,000 query credits and 5,120 scan credits. Small Business $359 per month, 200,000 query credits and 65,536 scan credits. Corporate $1,099 per month, unlimited query credits and 327,680 scan credits. All plans are rate limited to 1 request per second and include commercial use rights.
Censys Platform
Runner UpBest for: Certificate, host and web property research with a genuinely usable free tier
“Censys is the addition this page most needed. It is the other major internet-scan dataset, with a research heritage in certificate transparency, and it offers a free account with monthly credits that requires no credit card. There are three commercial tiers. Core covers analysts needing IP, service, domain and certificate visibility. Adversary Investigation adds searchable threat data and longer history for threat hunting. Security Operations is the enterprise tier, with unlimited users and twelve or more months of history. Tier prices are not published, though the site states that credit packages start as low as $100.”
Pros
- Free account with a monthly credit allowance, no credit card required, which makes it the easiest paid-grade dataset to start using
- Certificate and web property data is a genuine differentiator against a purely banner-oriented dataset
- API access is included at every tier including free, rather than being gated to enterprise
- Tier structure is transparent about what differs: users, data history and whether threat data is searchable or view-only
Cons
- Tier prices are not published; only the statement that credit packages start as low as $100
- Free and Starter users have credit-consuming functionality restricted once the monthly allowance is exhausted
- Historical data depth is the main paywall, at one month, three months and twelve or more months by tier
Why you want two scan datasets
Shodan and Censys scan the same internet and do not see the same thing. Scan cadence, port coverage, parsing and enrichment all differ, so a host that appears in one may be absent or differently characterised in the other. For attack surface work where a missed asset is the failure mode, running both is a coverage decision rather than a redundancy.
History is the paid product
Current-state visibility is close to commodity. What you pay for is the ability to look backwards: how this infrastructure changed, when a certificate appeared, what else shared it. The tier structure makes that explicit, with data history stepping from one month to three to twelve or more. Scope your subscription to the longest lookback your casework genuinely needs, because it is the single largest price lever.
Partially published on censys.com: a free account with monthly credits and no credit card required, and a statement that credit packages start as low as $100. The Core, Adversary Investigation and Security Operations tiers route to sales with no figures published.
theHarvester
Best Open SourceBest for: Email, subdomain and name enumeration
“theHarvester is the healthiest maintained project in this comparison. Version 4.11.1 shipped in June 2026 and the repository had commits the same week this page was checked. It does one job, gathering emails, subdomains, hosts and names from a long list of public sources, and it does it reliably. That reliability is exactly why active maintenance matters here: this tool is a thin layer over other people's data sources, and when those sources change their terms or their APIs, an unmaintained version silently returns less.”
Pros
- Genuinely actively maintained: release 4.11.1 in June 2026 and commits in the week this page was checked
- Free, open source, and trivial to run in a container or a CI job
- Wide source coverage that keeps pace with sources appearing and disappearing, which is the whole value
- Composes well: it is a component in a reconnaissance pipeline rather than a platform that wants to own one
Cons
- Narrow by design: enumeration only, with no analysis, correlation or case management
- Many sources require your own API keys, and several of those keys now cost money
- Output quality depends entirely on which sources are reachable on the day you run it
Maintenance status is the review
For a tool of this type, the only durable question is whether someone is keeping up with source churn. At the time of checking, the repository had 4.11.1 tagged in June 2026 and commits within the week. Compare that to Recon-ng, which this page previously ranked and which has had no commit since November 2024 and no tagged release at all.
Free and open source.
SpiderFoot
Best Free OptionBest for: Automated broad-sweep reconnaissance in one run
“The open source SpiderFoot is still free, still widely used at over twenty-two thousand GitHub stars, and still the fastest way to get broad automated reconnaissance across more than two hundred modules in a single scan. The commercial product is a different story. SpiderFoot HX no longer exists as an independent purchase: Intel 471 acquired SpiderFoot in November 2022 and spiderfoot.net now returns a permanent redirect to intel471.com, with the capabilities folded into the Intel 471 TITAN platform. Any comparison still listing SpiderFoot HX as a buyable commercial tier is describing a product you cannot order.”
Pros
- Over two hundred modules in one automated scan, which is the broadest single-command sweep available for free
- Repository is still receiving commits, with the most recent activity in April 2026
- Structured output suits pipelines and periodic monitoring rather than one-off manual use
- Zero licence cost, which makes it the realistic starting point for a team with no OSINT budget
Cons
- SpiderFoot HX is no longer purchasable; spiderfoot.net redirects to Intel 471
- Last tagged release is v4.0 from April 2022, so users are running from the main branch rather than a versioned build
- Automated breadth produces a volume of results that requires real triage effort
What happened to HX
Intel 471 acquired SpiderFoot in November 2022 and folded the hosted commercial product into its TITAN platform. The domain now issues a permanent redirect. The open source tool was never affected and remains available under the MIT licence, but the two-tier structure that made SpiderFoot attractive, free to start and a supported hosted edition to grow into, no longer exists.
Automation and triage
A SpiderFoot scan returns a great deal at once, and most of it is not interesting. That trade is right for periodic monitoring and for establishing a baseline, and wrong for a focused investigation where a graph tool produces a more directed result. Running it alongside Maltego rather than instead of it is the usual pattern.
Free and open source under the MIT licence. SpiderFoot HX is no longer sold; spiderfoot.net redirects to Intel 471, which acquired the project in November 2022.
OWASP Amass
Best Open SourceBest for: Attack surface mapping and subdomain discovery at depth
“Amass replaces Recon-ng on this list, and the reason is maintenance rather than preference. Recon-ng has had no commit since November 2024 and carries no tagged release. Amass shipped v5.1.1 in April 2026 with repository activity in July 2026, is an OWASP project, and does the enumeration job far more thoroughly. It combines DNS enumeration, certificate transparency, passive data sources and active reconnaissance into a graph-backed asset discovery engine, which is the closest thing in open source to what commercial attack surface management products sell.”
Pros
- Actively maintained under OWASP governance, with v5.1.1 released April 2026
- Goes deeper on subdomain and infrastructure discovery than any other free tool here
- Graph-backed data model that retains relationships between discovered assets rather than emitting a flat list
- Free, with no credit metering and no API cost on its default sources
Cons
- Active reconnaissance modes generate traffic to the target, which has authorisation implications
- Configuration is genuinely involved, and default runs undersell what the tool can do
- Discovery only: no analysis layer, no case management, no reporting
Passive and active are different legal questions
Amass can operate purely from third-party sources such as certificate transparency logs and passive DNS, or it can probe the target directly. The first is open source collection. The second is reconnaissance against a system, and whether you are authorised to do it is a question to answer before you run it, not after. Configure the mode deliberately rather than accepting a default.
Why Recon-ng came off this list
Recon-ng was a good modular framework and its GitHub repository shows no commit since November 2024 and no tagged release. In a category where the entire job is keeping up with data sources that change monthly, two years without maintenance is disqualifying for anything you depend on. The code still runs. The sources behind it have moved.
Free and open source.
Which One Should You Pick?
| Use Case | Our Recommendation |
|---|---|
| Case-based investigation connecting people, domains, infrastructure and accounts | Maltego is still the strongest graph investigation platform, and its free Basic tier at 200 credits a month lets you test the credit model before committing. |
| Finding what your organization has exposed to the public internet | Shodan for the banner data at a $49 one-time membership, and Censys alongside it, because the two scan datasets do not see the same hosts. |
| Tracking how attacker infrastructure changed over the past year | Censys prices data history by tier, from one month to twelve or more, so scope the subscription to the lookback your casework actually needs. |
| Quick email, subdomain and name enumeration inside a pipeline | theHarvester is free, actively maintained with a June 2026 release, and composes cleanly into automation. |
| Broad automated sweep with no budget at all | The open source SpiderFoot runs over two hundred modules in one scan. Note that SpiderFoot HX is no longer purchasable. |
| Deep subdomain and infrastructure discovery for attack surface work | OWASP Amass goes further than any other free tool, and replaces Recon-ng, which has had no commit since November 2024. |
How we evaluated
Last verified: 18 September 2026.
This is a research-based comparison, not a hands-on bake-off. It publishes no coverage benchmark, no comparative result count and no head-to-head accuracy claim, because those cannot be produced honestly without running every tool against the same targets under the same authorisation. What it does claim is that the following were checked, tool by tool, on 18 September 2026.
- Commercial availability. Whether each product can still be purchased and from whom. SpiderFoot HX cannot: Intel 471 acquired the project in November 2022 and spiderfoot.net returns a permanent redirect to intel471.com. Maltego has been owned by Charlesbank Capital Partners since April 2023 and has acquired PublicSonar and Social Network Harvester in April 2024 and Hunchly in May 2025.
- Repository maintenance status, measured rather than assumed. For each open source project, the GitHub API was queried directly for the latest tagged release and the most recent push. That is how Recon-ng came off this list, with no tagged release and no commit since November 2024, and how SpiderFoot earned its caveat, with commits in April 2026 but no tagged release since v4.0 in April 2022.
- Published pricing, and its absence. Every price here comes from the vendor's own pricing page. Maltego and Shodan publish full tier pricing and it is reproduced with its units. Censys publishes a free tier and a minimum credit package figure but not tier prices. No number on this page came from a comparison site or an aggregator.
- Metering models. Whether data access is charged separately from the licence, because in this category it usually is. Both Maltego and Censys meter in credits, which makes the published licence fee a floor rather than a cost.
- Data source availability. The access restrictions that shape what these tools can actually reach were checked against primary reporting, including the August 2026 X Corp action against Nitter and the state of Reddit commercial API access.
What we did not do
No vendor paid for placement and there are no affiliate links on this page. Nothing here reports hands-on testing, comparative coverage or result quality measured by us. No collection was performed against any third party in the course of writing this page.
How to read the ranking
Ranking reflects fit for the stated use case, weighted toward three things.
The first is whether the tool is actually maintained, which in this category outranks features. A tool that silently loses sources is worse than a narrower tool that works, because the failure looks like an answer. The second is pricing legibility, including the metering model rather than just the licence fee. The third is whether the tool does its job at depth, since OSINT rewards specialist tools composed into a workflow more than it rewards platforms that claim to cover everything.
One caution applies across the whole list. Every tool here returns evidence that something was true at some point, not ground truth about now. Scan banners go stale, can be spoofed, and can be served by something other than what they claim. Enumeration produces false positives from wildcard DNS and stale records. Treat any single-source finding as a lead to corroborate, and be especially careful in 2026, when AI-generated profiles, imagery and text have contaminated the public sources these tools collect from.
Editorial independence: this is a vendor-neutral comparison with no paid placements, sponsorships, or affiliate links. Rankings reflect fit for the stated use cases, not commercial relationships.
Frequently Asked Questions
What changed in OSINT tool licensing and data access since 2025?
Which OSINT tools publish a price?
Why was Recon-ng removed from this comparison?
What is the legal and ethical boundary for OSINT?
Do I need two internet scan datasets, or is one enough?
How does OSINT relate to threat intelligence and attack surface management?
How do AI tools change OSINT work?
Related Comparisons
Security Control Validation
Top 5 Breach and Attack Simulation Tools for 2026: Cymulate vs SafeBreach vs Picus vs AttackIQ vs Pentera
5 tools compared
Secure Design and Threat Modeling
Top 5 Threat Modeling Tools for 2026: IriusRisk vs SD Elements vs ThreatModeler vs Threat Dragon vs Microsoft TMT
5 tools compared
Secure Data Exchange
Top 6 Managed File Transfer and Secure File Sharing Tools for 2026: Compared on Patch Record
6 tools compared
Application Security Testing
Top 5 Intercepting Proxy Tools for 2026: Burp Suite vs mitmproxy vs ZAP vs Proxyman vs Charles
5 tools compared