Skip to content

Latest commit

 

History

History
425 lines (333 loc) · 15.9 KB

APIs.md

File metadata and controls

425 lines (333 loc) · 15.9 KB

OSINT Free and Open-Source APIs

General OSINT APIs

  • Description: Shodan is a search engine for internet-connected devices. It allows you to query IoT devices, servers, webcams, and more.
  • Free Tier: Yes (limited)
  • Authentication: API Key
  • Usage Limit: 1,000 queries per month (free tier)
  • Description: Allows you to check if an email or domain has been exposed in a data breach.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 1,000 requests per month (free tier)
  • Description: Amass is a tool used for network mapping, subdomain enumeration, and DNS discovery.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited (depends on setup)
  • Description: Provides data on devices and servers exposed to the internet. You can search and query the data via the API.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 50 requests per day (free tier)
  • Description: Provides geolocation and IP data, including the organization, country, region, and city information.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 50,000 requests per month (free tier)

Geolocation & IP APIs

  • Description: Provides geolocation data based on the IP address, offering insights like location, currency, and languages spoken.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 1,000 requests per month (free tier)
  • Description: Provides IP address geolocation services, including city, country, and organization information.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 1,000 requests per day
  • Description: Provides geolocation information for an IP address, including city, region, country, and more.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 1,000 requests per month (free tier)
  • Description: Offers geolocation data for IP addresses, including location details such as country, city, and postal code.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 1,000 requests per day
  • Description: Allows you to find the public IP address of a user, as well as geolocation information.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited

Domain & DNS APIs

  • Description: A free online resource that can be used to gather DNS information for domains, including subdomains and IP addresses.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited
  • Description: Provides access to WHOIS information for domain names, including registration details.
  • Free Tier: Yes (limited access)
  • Authentication: API Key
  • Usage Limit: 500 queries per month

13. IPVoid

  • Description: An IP reputation tool for checking if an IP address is flagged for malicious activities.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: 50 requests per day
  • Description: Allows you to scan URLs, domains, and IP addresses to check for malware, phishing, and other malicious activities.
  • Free Tier: Yes (limited queries)
  • Authentication: API Key
  • Usage Limit: 4 requests per minute (free tier)

15. Robtex

  • Description: Offers information about IP addresses, DNS records, and WHOIS data.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited

Email & Social Media Intelligence

  • Description: A tool for finding email addresses related to a specific domain name.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 50 requests per month (free tier)
  • Description: Email validation and verification service to detect if an email is real and valid.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: 25 requests per day
  • Description: Provides company and social data based on email addresses or domain names.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 50 requests per month
  • Description: Search for social media profiles associated with a specific email address or username.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited

Security & Vulnerability APIs

  • Description: A database of exploits and vulnerabilities that provides access via API.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited
  • Description: An OSINT framework with links to multiple publicly available intelligence tools and APIs.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited
  • Description: Provides threat intelligence from the community, including indicators of compromise (IoCs).
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 500 queries per day
  • Description: Provides data about internet-connected devices, including vulnerabilities and security risks.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 1,000 queries per month
  • Description: A security tool that scans the internet for vulnerabilities, particularly related to websites.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited

Social Media & Web Scraping APIs

  • Description: Allows interaction with Twitter data, including tweets, followers, and trends.
  • Free Tier: Yes
  • Authentication: OAuth
  • Usage Limit: 500,000 requests per month (free tier)
  • Description: Provides programmatic access to Reddit posts, comments, and subreddits.
  • Free Tier: Yes
  • Authentication: OAuth
  • Usage Limit: 60 requests per minute
  • Description: Provides programmatic access to Instagram business accounts, media, and user profiles.
  • Free Tier: Yes
  • Authentication: OAuth
  • Usage Limit: Varies
  • Description: A platform for running web scraping jobs at scale.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: Limited on

free tier


Other Useful OSINT APIs

  • Description: Provides real-time protection against phishing and malware by querying Google’s Safe Browsing lists.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 10,000 requests per day
  • Description: Provides access to real-time cyber threat intelligence data.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: Limited on free tier

Miscellaneous OSINT APIs

  • Description: Access to archived web pages from the Wayback Machine.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited
  • Description: Allows you to query WHOIS data about domains, including registration information.
  • Free Tier: Yes (limited access)
  • Authentication: API Key
  • Usage Limit: 500 requests per month

33. ip-api

  • Description: A fast and accurate IP geolocation API for location and organization data based on IP address.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: 45 requests per minute (free tier)
  • Description: Provides geolocation services with accuracy on city, country, and organization data for IP addresses.
  • Free Tier: Yes (GeoLite2 version)
  • Authentication: None
  • Usage Limit: Unlimited (depends on setup)
  • Description: Provides fraud prevention and IP geolocation data including proxy detection.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 1,000 requests per month (free tier)
  • Description: Provides geolocation services, including city, region, country, and proxy detection based on IP addresses.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 1,000 requests per day (free tier)

Email & Domain Intelligence

  • Description: Provides DNS, SMTP, and blacklist checking tools for domain and email server analysis.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: 1,000 requests per month
  • Description: Email validation and delivery services that also allow for domain and email security analysis.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 100 emails per day (for free tier)
  • Description: A tool to validate the existence of email addresses in real-time to help identify spam traps.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Limited daily requests
  • Description: Finds email addresses linked to domains or specific names for outreach and investigation.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 50 requests per month (free tier)

Social Media & Web Scraping

  • Description: A search engine for discovering social media profiles associated with a given username or email address.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited
  • Description: Web scraping tool that aggregates data from blogs, news sites, and forums across the web.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 1,000 requests per month (free tier)
  • Description: A popular Python framework for web scraping, allowing you to crawl websites and gather data programmatically.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Depends on usage
  • Description: Allows you to access Twitter data, including tweets, user profiles, and trends.
  • Free Tier: Yes
  • Authentication: OAuth
  • Usage Limit: 500,000 requests per month
  • Description: Allows interaction with Facebook data, such as user information, pages, groups, and posts.
  • Free Tier: Yes
  • Authentication: OAuth
  • Usage Limit: Varies by app and endpoint
  • Description: Provides programmatic access to LinkedIn user profiles, job postings, and company data.
  • Free Tier: Yes
  • Authentication: OAuth
  • Usage Limit: Varies based on usage

Cybersecurity & Threat Intelligence APIs

  • Description: A public repository of reports on IP addresses that have been involved in malicious activity.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 1,000 queries per day
  • Description: Provides access to a community-driven threat intelligence platform for threat indicators (IoCs).
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 500 queries per day
  • Description: A vulnerability database that provides access to CVE data, software vulnerabilities, and other security risks.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: 100 queries per day (free tier)
  • Description: Provides various security tools for vulnerability scanning, including DNS lookup, reverse DNS, and domain analysis.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: 50 requests per day

Publicly Available Datasets & Miscellaneous APIs

  • Description: Provides access to data on non-profit organizations, government data, and more.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited
  • Description: Provides access to U.S. Census data, which can be useful for demographic analysis.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited
  • Description: Allows you to access web search data from Bing, including images, news, and web results.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 1,000 requests per month
  • Description: Provides access to Google's search index, enabling you to query specific websites or web pages.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 100 queries per day (free tier)

DNS & Network Analysis

  • Description: Allows you to perform DNS queries and retrieve records like A, MX, NS, and TXT.
  • Free Tier: Yes
  • Authentication: API Key
  • Usage Limit: 100 queries per day (free tier)
  • Description: A service that provides screenshots and metadata of websites, helping to analyze their contents.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: 50 requests per month

57. Spyse

  • Description: An internet-wide data search engine that allows you to query information related to IPs, domains, and certificates.
  • Free Tier: Yes (limited access)
  • Authentication: API Key
  • Usage Limit: Varies by access

Miscellaneous Open Data APIs

  • Description: A collection of free, public APIs across multiple domains, including OSINT, government, and social media.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited
  • Description: A platform for accessing open datasets from a variety of domains, such as transportation, government, and environment.
  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Varies by dataset

  • Description: A tool that queries databases of known compromised sites,

also known as "dorking," used for penetration testing.

  • Free Tier: Yes
  • Authentication: None
  • Usage Limit: Unlimited