
Free OSINT investigation tool for Windows

Free OSINT investigation tool for Windows
This project is scheduled for launch
Launch date: Wednesday, July 8, 2026 at 08:00 AM UTC

Tom's OSINT Workbench is a free, open-source intelligence investigation tool for Windows. It enables structured, offline case management for tracking people, companies, domains, social profiles, emails, phones, addresses, usernames, and IP addresses as connected entities.
Key features include entity-centric case management with typed relationships and confidence levels, visual link analysis with force-directed or hierarchical graphs, and paste & extract functionality that pulls structured data from URLs using public APIs like RDAP, DNS, Shodan, and crt.sh.
The app supports snapshots & diffing to track changes over time, advanced search across all entities and notes, and self-contained HTML reports with embedded graphs and timelines. It also includes a built-in OSINT directory of 94 curated tools and resources.
No accounts, no cloud, no subscriptions. All data lives in a portable SQLite file on your machine.
Designed for analysts, journalists, and security researchers, the tool is entirely offline and private by design, with no telemetry or analytics.
Tom's OSINT Workbench is a free, open-source intelligence investigation tool for Windows. It enables structured, offline case management for tracking people, companies, domains, social profiles, emails, phones, addresses, usernames, and IP addresses as connected entities. All data lives in a portable SQLite file on your machine β no accounts, no cloud, no subscriptions.
Track nine entity types β people, companies, domains, social profiles, emails, phones, addresses, usernames, and IPs β with typed relationships and three confidence levels: confirmed, probable, and unverified.
Force-directed or hierarchical graph layouts rendered with GDI+ let you drag, zoom, pan, and click to inspect. Nodes are coloured by entity type, edges styled by confidence, and you can pop the graph out to a floating window for side-by-side analysis.
Drop a URL β or up to ten β and the app pulls structured data automatically. Domains return RDAP, DNS, IP geolocation, Shodan open ports, crt.sh subdomains, tech stack, and meta tags. Social URLs are recognised across X, LinkedIn, GitHub, Reddit, and more.
Take a point-in-time snapshot of any entity or the whole case. Compare any two snapshots to see additions, removals, and changes β colour-coded green, amber, and red β making it easy to track changes over time.
No accounts, no cloud, no subscriptions. All data lives in a portable SQLite file on your machine.
This is the core philosophy behind OSINT Workbench. It's a single portable EXE with zero dependencies, no telemetry, and no analytics. The only network traffic is the public API calls you explicitly trigger. For analysts who need absolute data sovereignty, this offline-first design is a fundamental differentiator from SaaS-based investigation tools.
You need a free, private OSINT investigation tool for Windows that keeps all case data on your machine. It's especially valuable if you regularly track multiple entity types, need visual link analysis with confidence-based styling, or want to snapshot and diff investigations over time without relying on cloud services.
Other tools you might consider
Comments will be available once the project is launched.
Maker
Aussie Picker βAs I See Itβ No BS
Visit Website
tomdahne.com/osint-workbench