This document summarizes all OSINT tools used across the investigation workflow. It covers every major part of modern open-source intelligence: blockchain tracing, infrastructure lookups, metadata extraction, credential reconnaissance, dark-web analysis and automation.

The list is structured to match the real investigative workflow.


1. Blockchain Analysis Tools

Tools used for tracing transactions, visualizing flows and identifying exchanges or mixers.

Multi-chain explorers

Chain-specific explorers

Graph analysis / attribution

Risk scoring / off-ramp identification


2. Infrastructure OSINT

Tools for mapping servers, domains, IPs, DNS history and backend infrastructure.

DNS / IP Intelligence

Certificates

Routing & Netblocks


3. Metadata & File Intelligence

Tools for extracting EXIF data, document metadata, file hashes and digital footprints.

Metadata extraction

File and hash lookup


4. Social & Human OSINT

Tools used for researching online profiles, usernames, email addresses and identities.

Person search

Username & handle investigation

Email intelligence


5. Dark Web & Deep Web Tools


6. Recon Automation & Intelligence Platforms

Automation & scanning

Containers & scripting


7. Visualisation & Reporting


8. Workflow Summary

A typical OSINT investigation follows this structure:

  1. Initial scoping
  1. Infrastructure OSINT
  1. Blockchain tracing (if crypto is involved)
  1. Human OSINT
  1. Threat attribution
  1. Report generation

Conclusion

This toolkit provides a unified set of tools suitable for:

It forms the backbone of the SystemLog OSINT workflow, supporting both field work and analytical investigations.