I’ve been working on a project called OSINTCompass.
The idea is to bring a bunch of useful OSINT workflows into one interface instead of constantly jumping between separate websites, scripts, terminals, APIs, and browser tabs.
The first version is being built around things like:
– Username investigation
– Email investigation
– Phone number lookup
– Domain / WHOIS / DNS analysis
– Breach exposure checks
– Subdomain discovery
– IP investigation
– Social account discovery
– VirusTotal / threat intelligence integrations
– Investigation history and evidence management
Under the hood, I’m looking at a mix of open-source tools and APIs rather than reinventing everything. Things like Sherlock, PhoneInfoga, HIBP, VirusTotal, Shodan, WHOIS/DNS tools, etc., with OSINTCompass acting as the workflow and analysis layer.
One thing I don’t want to build is another site that just takes a query, calls an API, and dumps raw JSON on the screen.
The longer-term idea is more like an investigation workspace:
Target → Sources → Findings → Correlation → Evidence → Report
I also want results to explain where information came from, distinguish confirmed information from possible matches, and preserve source/evidence information instead of letting AI magically declare that two records belong to the same person.
I'm considering separate modes for:
Free / public OSINT
Basic searches and open-source tools.
Professional investigations
More integrations, saved cases, correlation tools, exports, evidence collection, and API access.
Legal / investigative work
Audit trails, timestamps, source documentation, evidence preservation, and reproducible searches.
There would also be aggressive caching and free/open-source data sources wherever possible so the platform doesn't become an expensive API wrapper.
I’m building this myself and I’m still early enough in development that changing direction is relatively easy.
So I’d really like input from people who actually do OSINT:
What tools do you currently jump between constantly?
What part of an investigation wastes the most time?
What would make an “OSINT dashboard” genuinely useful rather than just another collection of lookup boxes?
And maybe most importantly:
What would immediately make you NOT trust a platform like this?
I’m especially interested in criticism. I'd rather discover bad assumptions now than after building them into the architecture.
Project: OSINTCompass.com
Happy to share more of the architecture / roadmap too if anyone is interested
Source: r/osinttools · by /u/acourtjester