SpiderFoot
SpiderFoot automates OSINT for threat intelligence and mapping
...It collects and correlates data from more than 200 modules and numerous public or API-based sources. Users can investigate domains, IP addresses, subnets, ASNs, email addresses, usernames, phone numbers, people, and cryptocurrency addresses. It runs through a web interface or command line and stores results in SQLite for custom querying. Scans can uncover infrastructure, breaches, exposed services, social accounts, metadata, and dark-web references. Results can be visualized, correlated with configurable rules, and exported in formats such as CSV, JSON, and GEXF.