mytools-osint

by Bluetm.uz

Free Download 1 Visit Website

Versions:

  • 4.2.1
  • 4.2.0
  • 4.1.1

mytools-osint is a personal-use open-source intelligence (OSINT) command-line toolkit published by Bluetm.uz, currently at version 4.2.1, with three versions released to date. Falling within the security research and threat-intelligence category, the software is designed to support authorised security testing and reconnaissance workflows. It provides 45 modules spanning both passive and active reconnaissance. Passive sources include Shodan InternetDB, crt.sh, CertSpotter, RIPEstat, HackerTarget, the Wayback Machine CDX API, and threat-intelligence feeds, all of which rely exclusively on free APIs, meaning no paid keys are required. Active reconnaissance capabilities cover route discovery, port scanning, WAF, CMS and GraphQL fingerprinting, favicon hash analysis, and subdomain takeover detection. The feature set has evolved across its release history: version 4.0 introduced an entity graph with auto-pivot functionality for correlating discovered data points and automatically expanding investigations along related entities; version 4.1 added the active recon modules; and version 4.2 delivered a smart single-fire shell with seven themes. The current release, version 4.2.1, focuses on security, user experience, and quality-assurance polish. Its improvements include stronger OPSEC discipline, SSRF guards, URL-injection fixes, corrections to the command palette and theme picker, and profile inclusion for the six new modules. Typical use cases include mapping an organisation's external footprint, enumerating subdomains and certificates, reviewing historical web content, assessing exposed services and ports, identifying web technologies in use, and checking for subdomain takeover risks. Because the toolkit combines passive data gathering with active probing techniques, it is explicitly intended for authorised security testing only, and operators are expected to hold proper permission for any target they assess. Its reliance on free data sources makes it accessible to individual researchers and security practitioners conducting sanctioned assessments without incurring API costs.

Tags: