Logo
Deploy Now

SaaS Alternative

Shodan

Stars

21,324

Forks

3,432

Watchers

474

Developer links

SpiderFoot

SpiderFoot is an open-source OSINT automation platform, replacing hours of manual reconnaissance with automated intelligence gathering across more than 200 data collection modules. The platform accepts ten distinct target types including IP addresses, domains, hostnames, network subnets, ASNs, email addresses, phone numbers, usernames, person names, and Bitcoin addresses, then feeds them through a publisher-subscriber event bus where each module's findings trigger downstream analysis automatically. SpiderFoot queries Shodan, VirusTotal, HaveIBeenPwned, AlienVault OTX, Censys, crt.sh, WHOIS databases, social media platforms, breach databases, and dozens more sources, with most modules requiring no API keys and many offering free tiers for those that do. The YAML-configurable correlation engine applies 37 pre-defined rules to identify relationships between discovered data points, flagging patterns like shared infrastructure, credential exposure, and domain reputation anomalies. Results export in CSV, JSON, and GEXF graph formats for integration with external analysis tools. TOR integration enables dark web searching, and SpiderFoot can invoke external tools including DNSTwist, Whatweb, Nmap, and CMSeeK for deeper technical assessment. The embedded web server delivers an intuitive dashboard for scan management, data visualization, and result exploration alongside a full command-line interface for scripted automation. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.

SpiderFoot
SpiderFoot
SpiderFoot
SpiderFoot
SpiderFoot

Benefits

  • 200+ OSINT Data Modules
  • Queries Shodan, VirusTotal, HaveIBeenPwned, AlienVault OTX, Censys, WHOIS databases, social media, and breach databases with most modules requiring zero API keys.
  • Cascading Intelligence Pipeline
  • Publisher-subscriber event bus chains module findings automatically so a discovered subdomain triggers IP lookups, reputation checks, and malicious host flagging sequentially.
  • YAML Correlation Engine
  • Thirty-seven pre-defined correlation rules detect patterns like shared infrastructure, credential exposure, and domain anomalies across all collected intelligence data points.
  • Ten Target Type Coverage
  • Scans IP addresses, domains, hostnames, subnets, ASNs, email addresses, phone numbers, usernames, person names, and Bitcoin addresses through a single unified interface.

Features

  • Embedded Web Dashboard
  • Built-in web server provides scan management, data visualization, module configuration, and interactive result exploration alongside full command-line automation.
  • TOR Dark Web Integration
  • Routes queries through the TOR network to search dark web sources, onion services, and hidden forums for target-related intelligence data.
  • External Tool Integration
  • Invokes DNSTwist for domain permutation scanning, Whatweb for technology fingerprinting, Nmap for port discovery, and CMSeeK for CMS identification.
  • Multi-Format Data Export
  • Exports scan results in CSV, JSON, and GEXF graph formats for import into network analysis tools, SIEM platforms, and custom reporting workflows.
  • API Key Management
  • Centralized import and export of third-party API credentials with per-module configuration and free-tier availability tracking across data sources.