OSINT Cheatsheet

This site is a reference for Open Source Intelligence (OSINT)

Last updated on 14 June, 2021

Open Source Intelligence deals with information gathered from publicly available sources that can be used in an intelligence context. This can vary widely and be anything from hashes, emails, newspaper articles or geo-locations.

Tools used for OSINT investigations

Command Description

Powerfull tool to network topology mapping and much more


A tool that automates OSINT collection


An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations


Incredibly fast crawler designed for OSINT


Search email addresses that has been subject to a data breach and get information about the data breach


Google Hacking Databse

Dorks for querying sensitive information or vulnerable content


Terms used in relation to OSINT

Command Description

Using search parameters to narrow down results in a Google search for information which is otherwise difficult to locate (see tools for a database of dorks)

Archived Information

Search through cached and archived content

Command Description
The Wayback Machine

Archive of webpages throughout time as they change

Archive Today

Another timecapsule for webpages

Google and Bing

Both offer cached versions of webpages

Search Operators

Google and Bing

Also known as Google Dorking

Command Description
"Search Term"

Search for the exact phase

TermA OR TermB

Search for TermA or TermB


Return results only from www.example.com


Return results that are of filetype pdf


Search for sites with the given words in their title


Search for sites with the given words in their URL


Search for sites with the given words in the text of the page


Search for sites that have the given words in links pointing to them


Show most recent cache of a webpage

