Open Source Intelligence is having its AI moment. Username search tools are crossing 88K stars, AI-assisted profiling is built into mainstream tools, and curated OSINT directories like Legendary_OSINT (1,536⭐, +109/day) are trending daily. This is the definitive, zero-hype comparison of the 10 most popular OSINT projects on GitHub — ranked by stars, analyzed by use case.
Star counts verified live via the GitHub API on 2026-08-08. This category has almost no dedicated comparison content — most OSINT guides are tool lists, not head-to-head analyses.
| # | Tool | ⭐ Stars | Growth / Status | Category | Best For |
|---|---|---|---|---|---|
| 1 | sherlock-project/sherlock | 88,432 | Active · Daily updates | Username Search | Fast username enumeration across 400+ social networks |
| 2 | soxoj/maigret AI PROFILE | 36,243 | Active · Daily updates | Username Search + AI | Deep person dossiers from 3,000+ sites with AI-assisted profiling |
| 3 | Lissy93/web-check HOT | 34,427 | Active · Daily updates | Website OSINT | All-in-one website infrastructure & security analysis dashboard |
| 4 | smicallef/spiderfoot | 20,112 | Active · Daily updates | OSINT Automation | Automated attack-surface mapping & threat intelligence correlation |
| 5 | laramies/theHarvester | 16,981 | Active · Daily updates | Recon Gathering | Pentest recon: harvesting emails, subdomains, names & IPs |
| 6 | twintproject/twint ARCHIVED | 16,405 | Archived · Unmaintained | Twitter OSINT | Historical: no-API Twitter scraping (killed by X API changes) |
| 7 | s0md3v/Photon | 13,092 | Active | Web Crawling | Blazing-fast crawling, endpoint & secret-key extraction |
| 8 | lanmaster53/recon-ng | 5,832 | Active | Recon Framework | Modular, Metasploit-style web reconnaissance workflows |
| 9 | K2SOsint/Legendary_OSINT TRENDING +109/DAY | 1,536 | 🔥 +109/day · Viral growth | Curated Directory | Finding the right specialized tool fast (fraud, CTI, KYC, AML) |
| 10 | m4ll0k/Infoga REMOVED | ~1,000 (historical) | Repo removed from GitHub (Aug 2026) | Email OSINT | Historical: email harvesting & verification (do not build on it) |
📊 Total ecosystem tracked: ~233,000+ GitHub stars across these 10 projects. Note: Maigret's canonical repository is soxoj/maigret (the maaaaz mirror is stale). Infoga's repo was removed from GitHub — the m4ll0k account remains active with other projects.
Description: The undisputed king of OSINT. Sherlock hunts down social media accounts by username across 400+ social networks — and it is the single most-starred OSINT project on GitHub by a wide margin.
Best for: Investigators, recruiters, and security analysts who need to instantly map where a username exists across the open web.
Description: "Collect a dossier on a person by username" — Maigret checks 3,000+ sites and gathers available information from each page, building a rich person profile. It includes an AI profiling demo that uses LLMs to synthesize findings — the clearest example of AI integration in the category.
Best for: Deep-dive people investigations, due diligence, fraud investigations, and journalists verifying identity footprints.
Description: "All-in-one OSINT tool for analysing any website." Paste a URL and get 20+ intelligence checks in one dashboard: IP info, SSL chain, DNS records, cookies, headers, domain info, robots.txt, open ports, traceroute, trackers, tech stack, and even carbon footprint.
Best for: Website due-diligence, threat researchers analyzing malicious domains, blue teams checking their own exposure, and curious users who want a point-and-click OSINT dashboard.
Description: SpiderFoot automates OSINT for threat intelligence and attack-surface mapping. Its 200+ modules pull from public data sources, then a built-in correlation engine connects the dots — e.g., finding an email that links to a leaked password that links to a domain.
Best for: CTI analysts, SOC teams, and pentesters who need continuous, automated reconnaissance and entity correlation at scale.
Description: A penetration-testing staple since 2010. theHarvester gathers emails, subdomains, names, IPs, and URLs using 20+ public sources — search engines (Google, Bing, Brave, Baidu), certificate transparency logs, and APIs like Censys, CertSpotter, and BeVigil.
Best for: Red teams and pentesters running the recon phase of an assessment; bug bounty hunters mapping an organization's external footprint.
Description: Twint was the legendary no-API Twitter scraper — no authentication, no API limits — scraping tweets, followers, and followings straight from search operators. It remains one of the most-starred OSINT tools ever built, but the project is archived.
Best for: Learning about Twitter OSINT history and understanding platform-API risk. Do not build new workflows on it — X/Twitter's API lockdowns broke the underlying technique.
Description: "Incredibly fast crawler designed for OSINT." Photon crawls a target domain and extracts URLs (in-scope and out-of-scope), emails, social media accounts, S3 buckets, files, secret keys / API keys / hashes, and JavaScript endpoints — with multi-threaded speed.
Best for: Bug bounty hunters, pentesters, and researchers who need maximum crawl coverage of a web property and its hidden assets.
Description: A full-featured, modular web reconnaissance framework with a Metasploit-style interactive console. 90+ modules handle everything from whois and DNS to social-media enumeration, with workspaces and API-key management built in.
Best for: Analysts who love structured, repeatable workflows — Recon-ng turns ad-hoc recon into a documented, module-driven process.
Description: The trend story of 2026. Legendary_OSINT is a curated list of OSINT tools & resources built for fraud investigators, CTI analysts, KYC and AML teams. It organizes the exploding OSINT ecosystem into 20+ specialist categories — people search, aviation, maritime, railways, dark web, geospatial, image/video OSINT, business intelligence, and more.
Best for: Anyone drowning in tool choices. Instead of GitHub-searching 200 repos, investigators get a vetted, categorized launchpad — with sources from newsletters, Telegram groups, and curated startpages.
Description: Infoga was a popular email OSINT tool — harvesting emails from search engines, verifying them, and checking associated social accounts. As of August 2026, the repository has been removed from GitHub (the m4ll0k account remains active with other projects like SecretFinder and BBTz).
Best for: Understanding the category's history — and a reminder that email-harvesting tools face moderation and lifecycle risk.
Zero-competition category, high-intent technical audience (investigators, pentesters, CTI teams), and every tool above has a natural paid complement. Strong monetization paths:
Disclosure: This page may contain affiliate links. If you purchase through links on this page, we may earn a commission at no extra cost to you. All tools listed are free, open-source projects — affiliate revenue supports our research. Always verify tools against your own requirements and legal/ethical boundaries.
💡 Postman recommendation: Collaborative api platform for design, testing, and docs. Try Postman →
Affiliate disclosure: we may earn a commission if you sign up via this link, at no extra cost to you.
💡 Cloudflare recommendation: Cdn, dns, ddos protection, and edge compute for any site. Try Cloudflare →
Affiliate disclosure: we may earn a commission if you sign up via this link, at no extra cost to you.