GDE-055 |
OSINT Framework | |||||||
OSINT tooling and workflow | ||||||||
September 2026 | ||||||||
01
What it is
OSINT Framework is the practice of using osintframework.com, a free categorised directory of open-source intelligence tools organised as a clickable mind map by data type, to identify which tool fits a specific investigative question rather than searching for tools one at a time.
OSINT Framework is a static, community-maintained website that organises hundreds of OSINT tools and resources into a branching tree by category, such as username, email address, domain name, phone number or social network, rather than by vendor. Clicking a category reveals the specific tools that address it, each linking out to the tool's own site. It carries no login, no tracking of what you click, and no tools of its own; it is purely a navigation layer over the wider OSINT ecosystem.
Investigators use it as a starting map when a case opens with a data type rather than a known tool: given a phone number, a username or a domain, the framework surfaces the relevant category and a curated shortlist rather than requiring a general search.
| When to use this guide
|
02
How do you use OSINT Framework effectively?
Six steps from picking the right branch to verifying a listed tool still does what the framework says.
The following resources are used across the steps below.
OSINT Framework: Free, no login. The directory itself, organised as a clickable category tree.
OSINT Framework GitHub repository: Free, open-source. The underlying source that powers the site, useful for suggesting additions or spotting recent changes.
Signal & Shadow's own toolkit guide: Free. A curated, annotated alternative for a narrower, vetted starting set.
| Before you begin Stop at the login. OSINT Framework itself requires no login and tracks nothing about what you click. Individual tools it links out to each carry their own login rules, covered in this publication's tool-specific guides, not by the framework. Legal considerations. OSINT Framework is a directory, not a vetting service: a tool's presence on the site is not an endorsement of its accuracy, legality in your jurisdiction, or continued maintenance. Some listed tools require payment, registration or carry their own terms restricting use; check each tool's own page before relying on it, the same as you would for a tool found any other way. |
Identify which branch matches your starting point, such as email address, username, domain name or phone number, and open that category rather than searching the page for a specific tool.
Categories often nest further, such as email address splitting into breach-check tools, verification tools and enumeration tools. Expand the relevant sub-branch before committing to the first listed option.
The framework does not consistently flag cost or account requirements. Open a tool's own page first to confirm what it actually needs before building a workflow around it.
A static directory can lag behind a tool's real-world status. Confirm a lesser-known tool is still active and legitimate, the same verification this publication applies before featuring any tool in a Guide.
Pick two or three tools from the relevant category to actually run, rather than treating the framework as a checklist to exhaust.
As a case develops, from example a username investigation surfacing an email address, return to the relevant new branch rather than relying only on tools already in hand.
|
03
What are the pitfalls of using OSINT Framework?
A listing is not a recommendation, and the site itself changes more slowly than the tools it links to.
Listing mistaken for vetting: inclusion in the framework does not mean a tool is accurate, safe, current or free. Verifying check: confirm a tool's status directly on its own site before building a workflow around it.
Category breadth mistaken for tool quality: a category with many listed tools does not mean the top result is the best one for your case; ordering is not a ranking. Verifying check: scan several options in a category rather than assuming position reflects quality.
Static site mistaken for a live tool database: the framework itself does not run checks against listed tools, so a dead link or a rebranded tool can sit unflagged for some time. Verifying check: treat any listed tool that fails to load or behaves unexpectedly as needing independent verification before you trust the category around it.
Chain of custody: the framework itself produces no findings; every finding traces back to whichever tool you actually ran, so custody obligations sit with that tool, not with the directory.
Record which specific tool from the framework was used for each finding, not just that the framework was consulted.
Note the date the tool was accessed via the framework, since both can change independently.
Apply the chain-of-custody standard of the underlying tool itself, not a separate standard for the framework.
Flag any tool found through the framework that turned out to be inactive, so the finding is not later assumed reproducible.
04
Go deeper
A curated, annotated alternative and the wider free toolkit landscape.
GUIDE · GDE-008
Free OSINT tools and frameworks: 2026 toolkit guide
A curated, annotated shortlist for when a full directory tree is more than you need.
GUIDE · GDE-054
Osiris: deploying an open-source live intelligence dashboard
A different kind of meta-tool, aggregating live data feeds rather than tool listings.
Evidentiary standard
Signal & Shadow operates to the LST-001 evidentiary standard. All claims are graded against the LST-001 v1.0.3 confidence tiers (Confirmed, Corroborated, Reported, Alleged) per the canonical voice and structural specification.
About Signal & Shadow
Signal & Shadow is an independent forensic investigation and methodology practice publishing tutorials, reference cards, and forensic dossiers for working practitioners. Founded by Derek Bowler.




