{
  "id": 213735,
  "title": "15 OSINT Tools Every Investigator Should Actually Open — In Order",
  "url": "https://urgent.news/2026/08/06/15-osint-tools-every-investigator-should-actually-open-in-order",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-06T09:32:22.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/whereisthisplace/15-osint-tools-every-investigator-should-actually-open-in-order-436k"
  },
  "original_language": "en",
  "account": "In the process of investigative work, it is crucial to follow a specific order of operations rather than simply using a large number of tools. Each stage should either provide answers quickly or serve as a better input for the next stage. The stages are designed asymmetrically to match the nature of the investigation at hand.\n\nStage 0: Preserve the source and define the claim before starting any tool. Clearly outline the claim you are trying to support, as different claims require varying levels of evidence. Keep the original file and record its origin, hashing it if necessary for cases that require high scrutiny. Only present publicly reachable data to those who will review the conclusion, as not all data should be made public.\n\nStage 1: Begin by analyzing the file itself. Use ExifTool to examine images and media files, as it provides valuable information about camera model, capture time, editing software, and embedded metadata. Remember that some platforms strip metadata, and the absence of EXIF data does not necessarily indicate a fake or untraceable photo. Use offline parsers for batch triage when only specific file types need to be examined.\n\nStage 2: Next, check if the artifact has already been published. Use Google Lens, TinEye, and Yandex Images. These tools have different strengths, so search all three with variations in cropping and detail selection. Keep in mind that a zero-result screen does not mean the image is genuine or new; it only indicates that the search engine did not find a match in its index.\n\nStage 3: Examine the visible evidence within the file. Look for clues such as script and signage, road markings, traffic direction, plate shape, architecture, terrain, vegetation, utilities, weather, and shadows. This stage requires separating observations from inferences, as mixing them can lead to a confident but unverifiable story. Aim for three independent anchors, such as a transit logo, a language fragment, and road design, to support each other.\n\nStage 4: Pivot from the surrounding identity if usernames or emails are present. Utilize Sherlock for fast username sweeps, Maigret for broader searches, WhatsMyName for signal quality issues, Holehe to check email registration, and Have I Been Pwned to assess breach exposure context. Treat every username hit as a lead rather than a finding and verify the account details, profile information, dates, avatars, writing style, and linked identities.\n\nStage 5: Only proceed to infrastructure-related tools when infrastructure exists. Use theHarvester to collect public emails, subdomains, and hosts, Shodan to index exposed services, and Censys for certificates and asset pivots. Be cautious not to create an infrastructure stage unnecessarily, as large result sets do not always equate to progress.\n\nStage 6: Finally, hold the case together using Maltego CE and Hunchly. Maltego CE is valuable when relationships no longer fit within a few browser tabs, allowing you to represent entities and provenance. Use Hunchly to capture and track relevant information throughout the investigation, ensuring a cohesive and well-documented case.",
  "summary": "Installing more OSINT tools rarely fixes an investigation. Opening the right tool at the wrong stage can still waste an afternoon. The mistake I see most often is starting with the largest possible sweep. Someone has a username, so they run three username enumerators. Someone has a domain, so they open Shodan before checking the site itself. Someone has a photo, so they upload it to every…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}