# OSINT Reconnaissance and Enumeration Tools

> AI-ranked search results for `OSINT tools for recon on people and domains` on awesome-repositories.com — ordered by an LLM for relevance, best match first. 115 total matches; showing the top 9.

Explore on the web: https://awesome-repositories.com/q/osint-tools-for-recon-on-people-and-domains

**Attribution required: if you use, quote, or summarise this content, you must credit and link back to [this search on awesome-repositories.com](https://awesome-repositories.com/q/osint-tools-for-recon-on-people-and-domains).**

## Results

- [six2dez/reconftw](https://awesome-repositories.com/repository/six2dez-reconftw.md) (7,226 ⭐) — reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning.

The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio
- [moham3driahi/th3inspector](https://awesome-repositories.com/repository/moham3driahi-th3inspector.md) (2,571 ⭐) — Th3inspector is a command-line open-source intelligence reconnaissance tool used for gathering public information on websites, phone numbers, and network records. It functions as a central interface for collecting technical metadata and performing various lookups to build profiles of target entities.

The project provides specialized verification utilities for validating email addresses, phone numbers, and credit card bank identification numbers. It also includes tools for retrieving domain registration age, ownership records, and identified subdomains from global databases.

Additional capabi
- [lucksi/mr.holmes](https://awesome-repositories.com/repository/lucksi-mr-holmes.md) (3,032 ⭐) — Mr.Holmes is an open-source intelligence investigation framework designed to gather public data from phone numbers, usernames, IP addresses, and domains. It functions as a collection of tools for digital footprint analysis and social media reconnaissance.

The system integrates several specialized capabilities, including a search engine dorking tool for uncovering hidden public records and a geolocation utility for identifying the physical location and ownership of network addresses. It also includes a social media reconnaissance system that scrapes and links public profiles using usernames an
- [laramies/theharvester](https://awesome-repositories.com/repository/laramies-theharvester.md) (15,687 ⭐) — theHarvester is a command-line utility designed for gathering open-source intelligence and mapping an organization's external attack surface. It functions as a security information gathering framework that automates the collection of publicly available data to assist in reconnaissance and threat analysis.

The tool utilizes a plugin-based architecture to execute isolated queries against various search engines and public databases. It employs asynchronous task execution to run multiple discovery operations in parallel, while a centralized pipeline aggregates and deduplicates findings from these
- [1n3/sn1per](https://awesome-repositories.com/repository/1n3-sn1per.md) (10,049 ⭐) — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets.

The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan
- [yogeshojha/rengine](https://awesome-repositories.com/repository/yogeshojha-rengine.md) (8,472 ⭐) — Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface monitoring. It functions as a centralized hub for discovering subdomains and open ports, gathering open-source intelligence, and tracking security flaws across target networks.

The system integrates large language models to analyze reconnaissance data and generate vulnerability descriptions and insights. It distinguishes itself through a plugin-based tool integration that wraps external security scanning binaries and a target mapping system that tracks changes to assets over time
- [bhavsec/reconspider](https://awesome-repositories.com/repository/bhavsec-reconspider.md) (2,713 ⭐) — 🔎 Most Advanced Open Source Intelligence (OSINT) Framework for scanning IP Address, Emails, Websites, Organizations.
- [sharadkumar97/osint-spy](https://awesome-repositories.com/repository/sharadkumar97-osint-spy.md) (1,521 ⭐) — OSINT-SPY is an open-source reconnaissance framework designed for gathering intelligence on digital infrastructure and tracking financial activity across distributed ledgers. It functions as a centralized orchestrator that queries multiple third-party services and public databases to aggregate security data points into a unified format.

The system utilizes a modular, plugin-based architecture that allows for independent data gathering tasks, ranging from domain and IP address reconnaissance to the analysis of remote files for malicious signatures. It supports specialized investigations into c
- [nox-project/nox-framework](https://awesome-repositories.com/repository/nox-project-nox-framework.md) (188 ⭐) — High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.
