Skip to content
Creative projects, practical resources, and technology with purpose
WrightsMind Creativity, technology, and purpose – built to help people move forward.
Featured guide The Morning Ritual

OSINT & Security Resource Library

Defensive OSINT Library

OSINT & Security Resource Library

A practical collection of free and freemium tools for checking IPs, domains, URLs, breaches, privacy exposure, website hygiene, and everyday online security questions.

Use responsibly.

These resources are provided only for lawful, ethical, defensive, educational, and personal security purposes. They do not give you permission to investigate, contact, probe, target, or collect information about systems, accounts, people, or organizations without proper authorization.

  • Do not use these tools for stalking, harassment, doxxing, credential theft, unlawful surveillance, unauthorized probing, bypassing security, or abuse.
  • Third-party data may be inaccurate, incomplete, outdated, unavailable, or interpreted incorrectly. Results are signals, not guarantees of security, attribution, location, identity, or threat determination.
  • Native tool and member breach lookup usage may be logged for abuse prevention, safety, compliance, and troubleshooting, including IP address, browser details, timestamps, submitted queries where appropriate, redacted or hashed query previews, and acknowledgement timing.
  • Breach Lookup is member-only and redacts returned data. It is for checking your own information or information you are authorized to review, not for people searching, profiling, scraping, or targeting others.
View acceptable use terms
Native tools

Quick checks you can run here

These lightweight tools validate inputs, rate-limit requests, and keep private API keys on the server.

Native Tool

IP Reputation Lookup

Check a public IP against AbuseIPDB when an API key is configured.

For safety and abuse prevention, WrightsMind logs security tool usage, including IP address, browser details, timestamps, and submitted queries where appropriate. VPNs, proxies, or privacy tools do not grant permission to misuse these resources. Use these tools only for lawful, ethical, defensive purposes.

View acceptable use terms
Native Tool

DNS Lookup

Review common DNS records for a domain without leaving the page.

For safety and abuse prevention, WrightsMind logs security tool usage, including IP address, browser details, timestamps, and submitted queries where appropriate. VPNs, proxies, or privacy tools do not grant permission to misuse these resources. Use these tools only for lawful, ethical, defensive purposes.

View acceptable use terms
Native Tool

WHOIS/RDAP Lookup

Get a plain-language RDAP summary for a domain or public IP.

For safety and abuse prevention, WrightsMind logs security tool usage, including IP address, browser details, timestamps, and submitted queries where appropriate. VPNs, proxies, or privacy tools do not grant permission to misuse these resources. Use these tools only for lawful, ethical, defensive purposes.

View acceptable use terms
Native Tool

Security Headers Check

Check whether a website sends common browser security headers.

For safety and abuse prevention, WrightsMind logs security tool usage, including IP address, browser details, timestamps, and submitted queries where appropriate. VPNs, proxies, or privacy tools do not grant permission to misuse these resources. Use these tools only for lawful, ethical, defensive purposes.

View acceptable use terms
Native Tool

SSL Certificate Check

Check basic certificate issuer, date, and expiration details.

For safety and abuse prevention, WrightsMind logs security tool usage, including IP address, browser details, timestamps, and submitted queries where appropriate. VPNs, proxies, or privacy tools do not grant permission to misuse these resources. Use these tools only for lawful, ethical, defensive purposes.

View acceptable use terms
Native Tool

URL Safety Checklist

Break down common phishing and fake-login warning signs.

For safety and abuse prevention, WrightsMind logs security tool usage, including IP address, browser details, timestamps, and submitted queries where appropriate. VPNs, proxies, or privacy tools do not grant permission to misuse these resources. Use these tools only for lawful, ethical, defensive purposes.

View acceptable use terms
Local Tool

Password Strength Check

Estimate password strength in your browser. The password is not sent to WrightsMind or any third party.

Tool directory

Search free OSINT and security resources

Filter by category or search for a tool, use case, tag, or keyword.

IP & Domain Lookup
Freemium API Available Native Tool

AbuseIPDB

Checks reported abusive activity for public IP addresses and supports defensive reputation review.

IP reputation abuse reports threat intel
URL & Phishing Analysis
Freemium API Available External Tool

urlscan.io

Safely scans and records public details about URLs, pages, redirects, and network requests.

URL scanning phishing web requests
DNS & WHOIS
Free External Tool

CentralOps

Classic browser-based network utilities for DNS, domain, email, and connectivity checks.

DNS WHOIS network tools
Learning Frameworks
Free External Tool

OSINT Framework

A curated map of OSINT categories and tools for ethical research and learning paths.

OSINT learning framework
Breach & Credential Exposure
Freemium API Available External Tool

Have I Been Pwned

Checks whether an email or password hash prefix appears in known public breach datasets.

breaches password exposure email exposure
Threat Intelligence
Freemium API Available External Tool

VirusTotal

Aggregates file, URL, domain, and IP analysis from many security engines and datasets.

malware URL reputation hash lookup
Certificate & Infrastructure
Freemium API Available External Tool

Shodan

Searches internet-exposed services and banners, useful for asset awareness and defensive checks.

exposed services internet scan asset discovery
Certificate & Infrastructure
Freemium API Available External Tool

Censys Search

Searches hosts, certificates, and internet-exposed infrastructure for defensive visibility.

certificates hosts infrastructure
DNS & WHOIS
Freemium API Available External Tool

SecurityTrails

DNS, domain, subdomain, and historical infrastructure intelligence for site owners.

DNS history subdomains domains
Threat Intelligence
Freemium API Available External Tool

GreyNoise

Adds context around internet scanner noise and suspicious IP activity.

scanner noise IP context threat intel
Threat Intelligence
Free API Available External Tool

AlienVault OTX

Community threat intelligence pulses and indicators for defensive research.

IOCs pulses threat intel
DNS & WHOIS
Freemium External Tool

MXToolbox

Checks DNS, MX, SPF, DKIM, DMARC, blacklists, and email delivery signals.

email security DNS blacklists
DNS & WHOIS
Free External Tool

DNSDumpster

Maps public DNS records and visible infrastructure for a domain.

DNS mapping domain recon defensive visibility
DNS & WHOIS
Free External Tool

ICANN Lookup

Public domain registration lookup with modern privacy redactions where applicable.

WHOIS domain registration RDAP
DNS & WHOIS
Free Native Tool External Tool

RDAP.org

Public RDAP lookup endpoint for domains and IP registration summaries.

RDAP WHOIS replacement registration data
Certificate & Infrastructure
Free External Tool

crt.sh

Certificate Transparency search for public certificates and related domain names.

certificates subdomains certificate transparency
Website Security Checks
Free API Available External Tool

Wayback Machine

Reviews archived web pages and historical content changes.

archives site history content review
Website Security Checks
Freemium API Available External Tool

BuiltWith

Identifies public website technologies, analytics, scripts, and platform signals.

technology lookup web stack site profile
Website Security Checks
Freemium API Available External Tool

Wappalyzer

Detects visible web technologies and software signals on public sites.

technology lookup web apps fingerprinting
Email & Username OSINT
Freemium API Available External Tool

Hunter.io

Finds and verifies professional email patterns from public web sources.

email OSINT email verification public sources
Email & Username OSINT
Freemium API Available External Tool

EmailRep

Email reputation context based on public and private signals.

email reputation fraud signals OSINT
Dark Web / Exposure Awareness
Freemium External Tool

DeHashed

Exposure search service that should be used carefully, legally, and only for authorized defensive review.

exposure awareness breach data authorized use only
Learning Frameworks
Free External Tool

Google Advanced Search

Uses search operators defensively to find your own exposed pages, files, and public mentions.

search operators defensive dorks public exposure
Social Media OSINT
Freemium External Tool

Social Searcher

Searches public social posts and mentions for awareness and brand monitoring.

social search mentions public posts
Image & Metadata
Free External Tool

TinEye

Reverse image search that helps find where an image appears online.

reverse image image OSINT verification
Image & Metadata
Free External Tool

ExifTool

Local metadata inspection utility for files and images. Best used locally to avoid uploading sensitive files.

metadata EXIF local tool
Image & Metadata
Free External Tool

Metadata2Go

Browser-based file metadata viewer. Avoid uploading sensitive files unless you understand the privacy tradeoff.

metadata file privacy EXIF
IP & Domain Lookup
Freemium API Available External Tool

IPinfo

IP geolocation, ASN, and network context for public IP addresses.

IP info ASN geolocation
IP & Domain Lookup
Freemium API Available External Tool

ip-api

Simple public IP geolocation and network lookup service.

IP lookup geolocation network
IP & Domain Lookup
Freemium API Available External Tool

ipwhois.io

IP geolocation and ASN context with a documented API.

IP lookup ASN geolocation
Website Security Checks
Free API Available External Tool

SSL Labs

Deep TLS/SSL configuration testing for public websites.

TLS SSL HTTPS
Website Security Checks
Free API Available External Tool

Mozilla Observatory

HTTP security header and site hygiene checks from Mozilla/MDN.

headers web hygiene browser security
Website Security Checks
Free External Tool Native Tool

SecurityHeaders.com

Quick public check for common browser security headers.

headers CSP HSTS
URL & Phishing Analysis
Free API Available External Tool

Google Safe Browsing Transparency Report

Checks Google Safe Browsing status for a URL or site.

URL safety phishing malware
URL & Phishing Analysis
Free API Available External Tool

PhishTank

Community phishing verification and reporting database.

phishing URL reputation reporting
URL & Phishing Analysis
Freemium External Tool

OpenPhish

Phishing intelligence feeds and lookup options for security teams.

phishing feeds URL intel
URL & Phishing Analysis
Free API Available External Tool

URLhaus

abuse.ch project for malware URL intelligence and defensive blocklist research.

malware URLs abuse.ch threat intel
Browser & Device Safety
Free External Tool

EFF Cover Your Tracks

Shows how trackable your browser may be through fingerprinting and tracking signals.

browser privacy fingerprinting tracking
Browser & Device Safety
Free External Tool

BrowserLeaks

Browser privacy and fingerprinting tests for IP, WebRTC, canvas, DNS, and more.

browser leaks fingerprinting privacy
Privacy & Data Broker Awareness
Free External Tool

Privacy Guides

Community-reviewed privacy recommendations for browsers, devices, accounts, and services.

privacy recommendations safer tools
Privacy & Data Broker Awareness
Free External Tool

FTC IdentityTheft.gov

U.S. government recovery plans for identity theft and personal data misuse.

identity theft recovery FTC
Browser & Device Safety
Free External Tool

CISA Secure Our World

Plain-language online safety guidance for passwords, MFA, updates, and phishing.

passwords MFA phishing updates

Need help understanding a result?

Contact Chris for practical online security guidance around accounts, passwords, breach cleanup, privacy settings, and small website hygiene.

Contact Chris
FAQ

Using OSINT tools responsibly

Can these OSINT tools tell me if something is completely safe?

No. OSINT and reputation tools provide context, not guarantees. Use results as signals alongside your own judgment, account activity, logs, and trusted security guidance.

Should I enter passwords into these tools?

Do not enter real passwords into third-party tools. The password strength checker on this page runs locally in your browser and does not send the password to WrightsMind or any external service.

Why do some native tools require API keys?

Some providers require keys to control abuse, rate limits, billing, or account terms. WrightsMind stores keys server-side in WordPress options and does not expose them in frontend code.

Can Chris help me understand a result?

Yes. Use the contact page if you need help interpreting a result or applying practical security steps to your accounts, devices, or small website.