Bow Tie Kreative Intel System

File 05

Technical and Passive OSINT Tool Library

Research snapshot: 2026-09-01. Verify licenses, free-tier limits, API schemas, and source terms again before deployment. An open-source collector does not grant rights to collect from an upstream source.

1. Mode legend

05.1-mode-legend.t1
ModeMeaning
CM0query third-party/open datasets or analyze already obtained artifacts; passive core
CM1low-impact direct retrieval such as an ordinary public page/DNS lookup or permitted rendered-page capture; policy and rate review required
CM2active resolution/probing, port/service interaction, or third-party scan submission; excluded and routed to a separately scoped security engagement
CM3authentication, credential validation, exploitation, disruption, or alteration; prohibited in this system

Many tools support several modes. The connector profile—not the product name—determines whether use is passive.

2. Deployable open-source components

05.2-deployable-open-source-components.t1
ToolLicense/statusPurpose and I/OIntegration fitPassive profile and limitationsOfficial source
OWASP Amass v5Apache-2.0; components may varydomain/org seeds → asset graph, names, IPs, ASNs, relationships, provenanceGo CLI/library, Docker, PostgreSQLsource allow-list; disable active enumeration, brute force, probing and alteration; discovery does not prove ownershipRepository · Docs
SpiderFootMITmulti-source OSINT aggregation and relationship exploration from approved targetsPython CLI/web UI; many independent modules and upstream APIscreate a module-level CM profile; allow only reviewed passive providers, disable active scan/breach/credential modules, and review every upstream key/term/quota separately; aggregator output is a lead, not proofRepository and license
ProjectDiscovery SubfinderMITdomains → candidate subdomains from passive providersGo CLI/library, JSON, streamsproviders and quotas vary; optional DNS resolution is CM1; keep upstream provenanceRepository
FindomainGPL-3.0domains → CT/archive/provider candidates, SQLite/monitor outputsRust binary, Dockerdisable DNS/HTTP/screenshot/port-scan features; review each provider's termsRepository
assetfinderMITdomain → related domains/subdomainssmall Go streaming CLIaging provider integrations; lead generator onlyRepository
Cert SpotterMPL-2.0watched domains → new certificate-transparency eventsGo CLI/hookscertificate issuance is historical evidence, not current deployment or ownershipRepository
openrdap/rdapMITdomain/IP/ASN/entity → authoritative current registration recordsGo CLI/libraryredaction and registry rate limits; current, not historical WHOISRepository · IANA bootstrap
gauMITdomains → URLs known to Wayback, Common Crawl, OTX and urlscanGo CLI, JSON, filtersURLs may be stale; do not automatically fetch/test themRepository
WappalyzerGoMITpreviously fetched headers/body → possible technology/version mapembedded Go libraryheuristic; record matched rule/evidence; never jump to vulnerability claimRepository
webappanalyzer fingerprintsGPL-3.0headers/HTML/scripts/cookies/DNS → technology matchesversioned fingerprint JSONlicense review before embedding; heuristic and version-sensitiveRepository
WhatWebGPL-2.0public URL → technology fingerprint; JSON/XML/SQLRuby CLI, large plugin setmakes direct requests; CM1 with explicit rate/terms profile; aggression level 1 onlyRepository
ExifToolArtistic License or GPL, same terms as Perllocal document/media → metadata, JSON/CSVmature CLI/Perl APIisolate untrusted files; metadata can be false; redact author/GPS/PIIRepository · Site
Apache TikaApache-2.0local files → MIME, text and metadataJava library/CLI/RESTcontainerize without network; file/page/time/memory limits; stay patchedProject
oletoolsBSD-style package; bundled parts varyOffice/OLE/RTF/OOXML → macros, objects, DDE/XLM indicatorsPython library/CLIsnever execute documents/macros; indicators are not proof of maliciousnessRepository
FOCAGPL-3.0public documents → metadata, paths, names and relationshipsWindows GUI/.NET/SQL Serverweaker unattended Linux fit; prefer local analysis and avoid search-engine scrapingRepository
Metagoofil maintained forkGPL-3.0-or-laterdomain/query → public document discovery/downloadPython/DockerGoogle scraping is brittle; no proxies/CAPTCHA/rate evasion; prefer official/archive discoveryRepository
GitleaksMITauthorized/public repository history → possible secrets, SARIF/JSON/CSVGo CLI/CInever validate/use secrets; retain redacted type/path/commit/fingerprint onlyRepository
detect-secretsApache-2.0local files/repos → heuristic secret baselinePython CLI/library/pluginsuse --no-verify; detector output is “possible secret,” not proofRepository
TruffleHogAGPL-3.0repos/files/cloud connectors → secret candidates/provenanceCLI/containercredential verification is CM3 and excluded; use only after validating a no-verification configuration and license fitRepository
OSV-ScannerApache-2.0authorized manifests/lockfiles/SBOMs/images → package advisory matchesCLI/Go, offline DB, JSON/SARIF/SBOMpublic artifact must be confidently attributed; package match does not prove deployed/reachable codeRepository

Conditional aggregator

theHarvester distinguishes passive, DNS, and active HTTP/TLS/scan sources and can emit JSONL/SQLite with provenance. Only passive and ordinary DNS profiles map to CM0/CM1 here; its active modes map to excluded CM2. The repository's licensing should be rechecked before vendoring, and every upstream provider must pass its own commercial-use review.

3. Hosted free/open-data sources

05.3-hosted-free-open-data-sources.t1
ServiceStatus/accessI/O and fitCurrent limitations and safe interpretationOfficial source
crt.shno-key hosted CT searchdomain/pattern → certificate/name records; commonly JSONno formal API SLA/quota; throttle/cache; issuance ≠ current assetcrt.sh
Censys Freehosted account/PAThost/web/certificate search and lookups; official SDKs/CLIabout 100 credits/month; standard query 5, lookup 1; limited pages/concurrency; no Free vuln/history timelineEntitlements · API
BuiltWith Free APIkey, hosted free endpointroot domain → technology group/category counts and first/last indexed dates1 request/second; not the paid detailed technology inventory; root domains onlyFree API
GreyNoise Communitykeyless limited or free keyIP → noise/RIOT/classification/last-seen contextlimited; free-key allowance documented around 50 searches/week; does not find target assets or prove compromiseDocs
urlscan.io SearchAPI keyexisting scan index → page/network/screenshot metadatasearch-only is CM0; submitting scans is CM2 and can leak URLs/tokens; dynamic quotas and visibility classesSearch API · MIT client
AlienVault OTXcommunity APIdomain/IP/URL/hash → community IOC/pulse contextcommunity data needs corroboration; IOC association ≠ compromise/ownershipAPI · Apache-2.0 SDK
Common Crawlfree CDXJ/JSON index and WARCURL/domain → captures/status/MIME/WARC; strong offline historyincomplete/stale; source copyright/privacy persists; prefer bulk data to hammering indexIndex · Terms
Wayback Machinepublic archiveURL → captures and snapshotsincomplete/excluded/throttled; capture date ≠ publication; Save Page Now is an external writeWayback · Help
Arquivo.ptfree archive APIs, GPL-3.0 stackfull-text/images/history/Memento → capturescoverage weighted toward Portuguese/selected international web; historical evidence onlyRepository
GitHub REST Code Searchauthenticated public-code searchorg/repo/query → repo/path/SHA/fragmentsmax 1,000 results, default branch and query/file limits, search rate limits; never validate secretsDocs
Have I Been Pwned (HIBP) Pwned Passwordsno-key k-anonymity API/downloadshash prefix → suffix/countfor authorized password hygiene, not prospect discovery; never send/store plaintextAPI
NVDfree feeds/APICVE/CPE/CVSS/references → vulnerability knowledgeno-key 5 requests/30s; key 50/30s; banner CPE ≠ target vulnerabilityAPI
CISA KEVfree JSON/CSVCVE → known-exploited status/datesexploitation observed somewhere, not evidence target is affected/exploitedCatalog
FIRST EPSSfree daily CSV/APICVE → estimated 30-day exploitation probabilityprobability ≠ exposure/impact; do not multiply blindly by CVSS; treat KEV separatelyFAQ/API
OSV APIfreepackage/version/commit → advisoriesneeds reliable package/version; no deployment/reachability proofAPI
GitHub Advisory DatabaseCC-BY-4.0 datacloneable OSV JSON advisoriessame applicability limits; attribution requiredRepository
ProjectDiscovery Chaosaccount/APIdomain → known subdomains; MIT clientcommercial/free entitlement is not guaranteed; fail closed until recordedSite · Client
LeakIX APIfree key advertised for researchersdomain/IP → indexed services/leak recordsresearcher access may not authorize commercial prospecting; obtain terms clarity; cached records need corroborationDocs

4. Not a commercial free core

05.4-not-a-commercial-free-core.t1
Tool/sourceWhy excluded from the default
Shodan InternetDBfree access is non-commercial; commercial audits need licensing; cached vulns are heuristic
Netlas Communityfree Community plan is explicitly personal-use
VirusTotal Public APIpublic API is noncommercial/academic and restricted for business/product use
SecurityTrails APIAPI/historical passive DNS/WHOIS access is paid; do not call it free
Google Custom Search JSON APIclosed to new customers; legacy users must transition before 2027-01-01
HIBP email/domain searchaccount lookups require subscription; domain enumeration requires proof of control; not a free “dark web scan”
Nmap, Masscan, Naabu, Nuclei, sqlmap, testssl.sh, scan submissionsdirect active interaction; separate written-authorization workflow
credential-verification featuresprohibited in prospect research; do not authenticate, redeem, or call detected secrets
private dark-web database claimsno legitimate comprehensive free/OSS source; licensed specialist plus explicit client authority required

5. Gaps a free passive stack cannot solve

  1. Comprehensive historical WHOIS and passive DNS are largely commercial.
  2. Current TLS protocols/ciphers require a recent cached observation or an authorized direct assessment; CT cannot show them.
  3. Public breach sources cannot prove a password still works, MFA is absent, or the target itself was breached.
  4. A passive technology fingerprint cannot establish reachable exploitability.
  5. Shared cloud/CDN IPs cannot establish asset ownership.
05.6-recommended-passive-core.t1
NeedFirst choiceSecondary/conditional
entity/domain registrationRDAP + official company/registry recordscurrent DNS under CM1 profile
subdomain/certificate historycrt.sh/Cert Spotter + Subfinder passive sourcesAmass passive graph
historical URLs/pagesCommon Crawl + Wayback + Arquivo.ptgau as adapter
technology hintsWappalyzerGo on permitted/cached HTMLBuiltWith free group signal
public documentsordinary permitted discovery + Tika/ExifTool in isolated local workerFOCA/manual review
public code/dependenciesGitHub official search + OSV-ScannerGitleaks/detect-secrets with redaction/no verification
advisory enrichmentOSV + NVD + CISA KEV + EPSSGitHub Advisory DB offline mirror
cached service contextCensys Free/urlscan search under quota and termsOTX/GreyNoise context

7. LAKA implementation ladder

05.7-laka-implementation-ladder.t1
Change stateTechnical intelligence capability
Baselinemanual official-domain/registry/CT/archive snapshot with source ledger
Minorscheduled passive adapters, normalization, provenance and change alerts
Majorasset graph, attribution confidence, SBOM/advisory enrichment and human triage
Structuralevent-sourced evidence, terms registry, redaction/quarantine, responsible-disclosure route
Paradigmclient-authorized continuous exposure-management product where evidence is tied to business dependencies and interventions—not sales scare tactics

8. Claim gates and freshness

05.8-claim-gates-and-freshness.t1
ClaimMinimum gate
owned assetcurrent RDAP/DNS/client inventory or strong target-controlled linkage; shared IP never enough
current exposed servicerecent provider last-seen plus current linkage or authorized validation
vulnerable systemexact product/version/config applicability + authoritative advisory + confirmed reachable authorized asset
breach exposure“identifier appeared in named corpus”; never current password/MFA/company breach claim
secret exposure“possible exposed secret”; redacted fingerprint and provenance; no validation
negative result“not observed in sources checked as of [UTC],” never “secure/none”

Refresh DNS/RDAP used in outreach within 24–72 hours, technology hints within 30 days, and NVD/KEV/EPSS/OSV daily. Always show the last-seen date of cached service evidence.

9. Mandatory connector fields

connector_id: ""
mode: CM0|CM1|CM2|CM3
commercial_ok: true|false|unknown
automation_ok: true|false|unknown
redistribution_ok: true|false|unknown
authentication: none|key|oauth|verified-domain|contract
quota: ""
cache_rule: ""
deletion_rule: ""
attribution_rule: ""
license: ""
terms_url: ""
terms_reviewed_at: ""
fail_closed: true

Unknown rights fail closed.


05-technical-osint-tool-library.md · 146 lines · 16474 bytes · SHA-256 5114d06a6c94c047