OSINT BIBLE
Comprehensive 2026 OSINT guide — 450+ tools, AI intelligence, methodologies & ethics across 35 sections for investigation & threat intel.
Install / Use
npx skills add frangelbarrera/OSINT-BIBLEInstalls into whichever agent you are using.
README
🕵️♂️ OSINT Bible 2026
Compilation, procedures, tools and ethics for open source research
⚠️ Ethical Disclaimer
This repository is dedicated to the responsible and ethical practice of Open-Source Intelligence (OSINT). All information, tools, and methodologies provided herein are intended solely for educational, research, and lawful investigative purposes. Users are strongly encouraged to adhere to ethical guidelines, respect privacy rights, comply with applicable laws and regulations, and obtain necessary permissions before conducting any investigations. Misuse of this information for illegal activities, harassment, or violation of privacy is strictly prohibited and may result in legal consequences. By accessing this repository, you agree to use the content responsibly and ethically.
🧭 Quick Index with Buttons
Foundations
1. Fundamentals | 2. 4-Step Methodology | 3. Tools Mind Map | 11. Legal Considerations | 28. Professional Methodologies
Investigation Techniques
4. Internet Search | 5. Social Networks | 6. GEOINT & Images | 7. Domain / IP / DNS | 15. Email/Phone Investigation | 17. Blockchain/Crypto | 18. Transport OSINT | 19. WiFi/Wardriving | 20. Content Verification | 21. Username Enumeration | 22. Web Scraping | 23. Metadata Extraction | 24. Network Scanning | 29. Advanced Google Dorks | 31. People Investigations | 32. Company Research
Sources & Data
8. Deep & Dark Web | 16. Data Breaches | 25. Dark Web | 30. Learning Resources | 12. Extra Resources
Frameworks & Automation
9. Automation (Python) | 10. Report Templates | 13. AI Intelligence | 14. Facial Recognition | 26. All-in-One Frameworks | 27. Advanced Maltego
Specialized
33. Threat Intelligence Feeds | 34. ICS/OT & Critical-Infrastructure OSINT | 35. AI Agent Skills & MCP
2026 Expansion
36. Financial OSINT | 37. Investigator OPSEC & Sock Puppets | 38. Cloud Storage OSINT | 39. Mobile App OSINT | 40. Decentralized Social OSINT | 41. Counter-OSINT Self-Audit | 42. Discord & Telegram OSINT 2026 | 43. Satellite OSINT 2026 | 44. C2PA + SynthID + Deepfake Detection 2026 | 45. Professional Templates & Deliverables | 46. Regional OSINT | 47. Corporate OSINT Tradecraft | Appendix B. Structured Analytic Techniques
[!TIP] Operationalize these methodologies with autonomous agents: Automate repeatable investigative procedures into structured, budget-aware workflows using the agentic-harness open-source repository. A production-grade control plane for auditable agentic runs with transparent cost-control and MCP integration.
1. Fundamentals
| Concept | Quick Definition | |---|---| | OSINT | Intelligence obtained from public sources without violating logical or physical access | | OPSEC | Minimize footprint: VPN → VM → alias → metadata strip | | Intelligence Cycle | Direction → Collection → Processing → Analysis → Dissemination | | PII | Information that identifies: email, phone, RFC, CURP, IP, IMEI, MAC | | Primary Source | Original publication (tweet, official PDF, photo EXIF) | | Secondary Source | Article citing the primary (validate) |
2. 4-Step Methodology
- Define question → What do I want to know?
- Identify sources → Table below |
- Collect → Manual + automations |
- Validate and document → Screenshots, hash, date, URL, archive.org |
| Data Type | Usual Location | Star Tool | |---|---|---| | Name | LinkedIn, Facebook | Maigret | | Email | Data breaches, newsletters | HIBP | | Phone | WhatsApp Business, TrueCaller | Infobel | | Username | Forums, gaming, GitHub | Snoop | | Photo | Geolocation, EXIF | Exiftool | | Domain | WHOIS, certificates | Amass | | IP | Scanning, Shodan | Shodan | | Crypto wallet | Blockchain explorers | BlockCypher |
3. Tools Mind Map
graph TD
A[OSINT] --> B(Search)
A --> C(Social Networks)
A --> D(Geo)
A --> E(Domain/IP)
A --> F(DeepDark)
A --> G(Automate)
B --> B1(Google Dorks)
B --> B2(Useful Dorks)
C --> C1(Twint-fork)
C --> C2(Maigret)
C --> C3(Instaloader)
D --> D1(Overpass-turbo)
D --> D2(Satellites.pro)
D --> D3(ExifTool)
E --> E1(Amass)
E --> E2(CRT.sh)
E --> E3(DNSDumpster)
F --> F1(Onionscan)
F --> F2(Ahmia)
G --> G1(Recon-ng)
G --> G2(SpiderFoot)
4. Internet Search
4.1 Google Dorks – 20 essentials
| Objective | Dork | Example |
|---|---|---|
| Government PDFs | site:gov filetype:pdf "contract" | Mexico |
| Exposure | intitle:"index of" passwords.txt | — |
| IP Cameras | inurl:viewer/live/index.html | — |
| Emails | site:linkedin.com "@company.com" | — |
| Subdomains | site:*.target.com -www | — |
4.2 Alternative Search Engines
- DuckDuckGo "bangs" →
!archive - Yandex → best results CIS
- Baidu → Asia
- Startpage → no logs
- Shodan → IoT, ICS, SCADA
- Censys → cert + banner
- FOFA → China, free API
- BinaryEdge → global scanning
- Hunter.io → corporate emails
- PublicWWW → search in source code
- SearchCode → search in 75B lines of code
- SimilarSites → similar sites
- Netlas → internet intelligence
- CriminalIP → search in connected internet
- NerdyData → website technologies
- GreyNoise → internet noise
- Intezer Analyze → malware analysis
- Kaspersky OpenTIP → threat scanning
- VirusTotal → file/URL analysis
- AlienVault OTX → threat exchange
- ExploitDB → exploit database
- MalwareBazaar → malware samples
- Malware Domain List → malicious domains
- PhishTank → phishing URLs
- URLhaus → malware URLs
- ThreatMiner → threat intelligence
- YARAify → YARA rules
- PulseDive → IOC search
- ThreatFox → malware IOCs
- Breach Directory → breach searches
- Have I Been Pwned → breach verification
- DNSViz → DNSSEC visualization
- DNSdumpster → DNS enumeration
- SpyOnWeb → related sites
- Yark → archive YouTube
- CovertAction → investigative journalism
- Trellix Research → threat research
- CP Research → Checkpoint research
- Wikistrat → collaborative analysis
- PolySwarm → threat scanning
- HackerOne Hacktivity → public vulnerabilities
- WikiLeaks → leaked documents
- Talos Reports → vulnerability reports
- MalAPI → malware APIs
- UserSearch → user search
- SecureList → Kaspersky blog
- SPLC Hate Map → hate map
- ICSR → radicalization studies
- Militant Wire → militancy analysis
- START Publications → terrorism publications
- SPLC Resources → SPLC resources
- Tracking Terrorism → terrorism tracking
- Mapping Militants → mapping militants
- Naval Institute → naval news
- Institute of International Relations → international relations
- Janes → defense intelligence
- TASS News → Russian news
- [Sputnik News](https://sputnik
Related Skills
codebase-memory-mcp
38.2kHigh-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 158 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.
codebase-memory-mcp
38.2kHigh-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 158 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.
codebase-memory-mcp
38.2kHigh-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 158 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.
tabularis
4.0kOpen-source desktop SQL workspace for PostgreSQL, MySQL/MariaDB, SQLite and 15+ more databases like DuckDB, ClickHouse, Redis and Firestore. Built-in MCP server for Claude, Cursor and Devin, SQL notebooks and visual EXPLAIN.
Security Score
Audited on Aug 8, 2026
