OSINT Tool Deep-Dives
In-depth guides to specific OSINT and recon tools: what they do well and where they fall short.
-
nitefood/asn: BGP and IP Recon for Analysts
2026-09-13
How to use nitefood/asn for ASN lookups, RPKI validation, BGP path analysis, and IP reputation checks in offensive and defensive workflows.
-
subzeroid/instagrapi: A Security Analyst's Field Guide
2026-08-30
A practical breakdown of instagrapi for OSINT analysts: what it does, where it fits, how it compares to alternatives, and a reproducible 10-minute recipe.
-
theHarvester: Passive Recon Asset Discovery
2026-08-09
How laramies theHarvester fits into a real OSINT workflow — source selection, API configuration, output parsing, and a reproducible ten-minute recon recipe.
-
OWASP Amass for Attack Surface Mapping
2026-07-26
How OWASP Amass works, where it fits your recon pipeline, how it stacks up against Subfinder and SpiderFoot, and a reproducible 10-minute hands-on recipe.
-
reconFTW: Recon Orchestration from Domain to Findings
2026-06-28
How six2dez/reconFTW orchestrates subdomain enum, port scanning, and Nuclei against a target — setup, config, triage, and when to skip it.
-
Passive Subdomain Enumeration with subfinder
2026-06-22
How projectdiscovery subfinder works, where it fits against Amass and assetfinder, and a reproducible pipeline from install to live-host list.
-
projectdiscovery httpx: HTTP Enumeration at Scale
2026-06-15
How projectdiscovery httpx works, where it fits between subfinder and nuclei, how it compares to httprobe and EyeWitness, and a reproducible recon recipe.
-
BBOT: Recursive Recon for External Attack Surface Mapping
2026-06-01
How blacklanternsecurity/bbot's event-graph model works, where it beats Amass and Subfinder pipelines, and a passive scan recipe you can run in 10 minutes.
-
ivre: Self-Hosted Network Recon Framework
2026-05-17
ivre gives you Shodan-style querying over scan data you own. Here's how it fits an analyst's workflow and how to stand it up in under ten minutes.