Command Palette

Search for a command to run...

UnylyUnyly
Browse all

Awesome Osint Mcp Servers

FreeNot checked

πŸ”Œ A curated list of OSINT MCP servers. Pull requests are welcomed!

GitHubEmbed

About

πŸ”Œ A curated list of OSINT MCP servers. Pull requests are welcomed!

README

Awesome OSINT MCP Servers

Awesome

A curated list of MCP servers for OSINT (Open Source Intelligence).

An MCP server connects tools and services to LLM systems like Claude, Cursor, Windsurf, etc.
MCP servers simplify execution of OSINT tools by combining them with the ease of LLM querying
and the ability to create flexible reports.


Legend: πŸ“¦ Open Source  ·  πŸ†“ Free / Has Free Tier  ·  πŸ’° Paid / Requires Paid API

Contents

SOCMINT

  • πŸ’° Expose Team β€” AI-powered OSINT at lightspeed. Credit-based plans from $8/month.
  • πŸ“¦πŸ†“ Maigret β€” Collect user account information from various public sources by username.
  • πŸ“¦πŸ’° Xquik β€” X (Twitter) data extraction and automation with 40+ REST API endpoints, real-time account monitoring, and trending topics. MCP server with API key auth.
  • πŸ“¦πŸ†“ OSINT Tools MCP β€” Wraps seven classic OSINT CLIs behind one server: Sherlock and Blackbird (usernames), Maigret, Holehe (email), GHunt (Google accounts), theHarvester (domains) and SpiderFoot. Python, installs the underlying tools itself.
  • πŸ“¦πŸ†“ LinkedIn MCP β€” Search LinkedIn people, companies and jobs, and pull structured profile, company and post data. Uses your own session cookie; no API key.

Network Scanning

  • πŸ“¦πŸ†“πŸ’° Shodan β€” Query the Shodan API and CVEDB for IP reconnaissance, DNS operations, vulnerability tracking, and device discovery. Free tier available with limited queries, requires Shodan API key.
  • πŸ“¦πŸ†“πŸ’° ZoomEye β€” Obtain network asset information by querying ZoomEye using dorks and other search parameters. 7-day free trial available, requires ZoomEye API key.
  • πŸ“¦πŸ†“ DNSTwist β€” DNS fuzzing tool that helps detect typosquatting, phishing, and corporate espionage.
  • πŸ“¦πŸ†“ OSINT Toolkit β€” Unified interface for network reconnaissance with parallel execution of WHOIS, Nmap, DNS lookups, and typosquatting detection.
  • πŸ“¦πŸ†“πŸ’° ContrastAPI β€” Security intelligence server with 49 tools: domain recon (DNS, WHOIS, SSL, subdomains, WAF, Wayback) plus orchestrated audit_domain, IP reputation plus orchestrated threat_report (Shodan + AbuseIPDB + ASN), CVE/EPSS/KEV lookup plus calculate_risk_score (CVSS+EPSS+KEV+PoC fusion) and bulk_cve_lookup (50/call), cve_leading (MITRE/GHSA pre-NVD), IOC enrichment plus bulk_ioc_lookup (50/call), threat intel, MITRE ATLAS (167 AI/ML attack techniques + bulk drill) and D3FEND defenses (149 techniques + coverage report), web intelligence (robots.txt, redirect chain, email validation, brand assets, SEO audit), check_dependencies (requirements.txt / package.json audit), and code security scanning. Anonymous tier + Pro tier with API key.
  • πŸ†“πŸ’° DomScan β€” Domain intelligence with DNS, WHOIS/RDAP, SSL/TLS, subdomain enumeration, certificate search, typosquatting and brand monitoring, plus domain valuation and availability. One API and MCP server; free tools with paid API tiers.
  • πŸ†“πŸ’° CrawlGraph β€” Passive web footprinting via the Common Crawl webgraph - mapping which sites reference a target, without ever touching the target (passive, no active scanning). Two tools for OSINT research: inbound linking to target and link-gap between two or more targets. npx -y crawlgraph-mcp. Free sign up for 15 targets/mo ; paid lifetime API for higher limits and link-gap research.
  • πŸ†“πŸ’° DomainKits β€” Search newly registered, expired, and dropped domains across gTLDs for phishing, typosquatting, and brand-impersonation monitoring, with WHOIS, DNS, reverse-nameserver, IP geolocation, and Google Safe Browsing lookups. Requires paid API key.
  • πŸ“¦πŸ†“ IPInfo β€” IP geolocation, ASN and network details, Tor exit-node checks, and interactive maps for sets of IPs via ipinfo.io. Free API token required.
  • πŸ“¦πŸ’° StackScan β€” Technographic lookups over 360M+ sites: what a domain is built on, who is behind it (industry, city, country, LinkedIn), and how many sites run a given technology and where. Batch domain lookup for list enrichment. Local stdio server, MIT, npx -y @stackscan/mcp-server. Charged per resolving domain; misses are not charged and check_credits is free.

Web Scraping

  • πŸ†“πŸ’° AnySite β€” Structured data access to 115+ endpoints across 40+ platforms (LinkedIn, Instagram, X, Reddit, YouTube, GitHub, Amazon, etc.) via five meta-tools. 7-day free trial with 1,000 credits.
  • πŸ“¦πŸ†“πŸ’° Bright Data β€” Real-time web search, scraping, and structured data extraction from 60+ sources (Amazon, LinkedIn, TikTok, Google Maps, etc.) with CAPTCHA and anti-bot bypass. Free tier: 5,000 requests/month.
  • πŸ†“πŸ’° Parallel Search MCP β€” Web search and page-content extraction (web_search, web_fetch) for LLM agents. Default endpoint works without an API key; an account with credits is needed for production rate limits. MCP: https://search.parallel.ai/mcp
  • πŸ“¦πŸ†“ Wayback Machine MCP β€” Query and save Internet Archive snapshots: check archive status, fetch archived URLs, search the CDX index, and compare two snapshots of a page. No API key for reads. npx -y mcp-wayback-machine

Company Intelligence

  • πŸ“¦πŸ†“πŸ’° CompanyScope β€” Company intelligence aggregating data from 8 public sources (Wikipedia, SEC EDGAR, OpenCorporates, RDAP, GitHub, and more) for corporate reconnaissance. Free tier 25 calls/day, pay-per-use tier on Apify.
  • πŸ“¦πŸ†“ StockScope β€” SEC EDGAR financial intelligence for stock research. Revenue, net income, margins, filings, and company comparisons for any US public company. Free, no API key needed.
  • πŸ†“πŸ’° FilingFirehose β€” Hosted SEC EDGAR MCP for any US ticker: 8-K body-text parsing (catches buried items beyond what the filer reported), 10-K / 10-Q / S-3 / Schedule 13D reads, forensic risk scoring (LOW/MODERATE/ELEVATED/HIGH), and cyber-incident tracking. Free public endpoints + paid tiers from $9/mo. MCP: https://filingfirehose.com/mcp
  • πŸ“¦πŸ’° US Business Data β€” Search Secretary of State business registrations across 17 US states, building permits in 400+ cities, and Yellow Pages business leads. Returns entity details, filing status, and registered agents.
  • πŸ†“πŸ’° OpenRegistry β€” Real-time access to 27 national corporate registries worldwide (UK Companies House, France Sirene, Germany Handelsregister, South Korea OPENDART, Australia ABR, Canada Corporations, etc.) via a unified JSON schema. Returns company profiles, officers, shareholders, beneficial ownership, filings, and raw documents. Free tier: 20 rpm without signup, 30 rpm with email. Paid up to $29/mo. OAuth 2.1, no API keys.
  • πŸ“¦πŸ’° Checko MCP β€” Unofficial wrapper for the Russian Checko.ru API: verify counterparties (companies, sole proprietors, individuals) via EGRUL/EGRIP, arbitration cases, government contracts (44-FZ/223-FZ), Rosstat financials, inspections, Fedresurs and EFRSB bankruptcy records. 12 tools and 6 ready-made workflow prompts. Requires paid CHECKO_API_KEY.
  • πŸ†“ Fylings β€” African company intelligence across 18+ official national registries (Nigeria's CAC, Tanzania's BRELA, Mauritius's CBRD, Senegal's RCCM, and more) via a unified schema, with the official registry source and a last-verified date on every record. Company search & verification, beneficial ownership, government-contract awards, and sanctions screening. Free, no API key. Hosted MCP: https://www.fylings.com/api/mcp
  • πŸ“¦πŸ†“ Companies House MCP β€” 38 tools over the UK Companies House API: company and officer search, profiles, filing history and documents, charges, insolvency, PSC/beneficial ownership and disqualifications. Free API key required. AGPL-3.0.

Public Records & Compliance

  • πŸ†“πŸ’° DataNexus MCP β€” Public records intelligence across 7 domains: domain recon (RDAP, DNS, SSL, subdomains, email security), patent search & inventor portfolios (EPO/WIPO), US government contract awards & vendor history (SAM.gov), regulatory filings & dockets (Regulations.gov + Federal Register), US/UK nonprofit 990 data & health scores, CVE/SBOM/EPSS vulnerability intelligence, and professional licence verification (NPI, FINRA, SAM exclusions). 55 tools, no API key required for free tier, hosted remote MCP.
  • πŸ“¦πŸ’° Nummeropslag β€” Privacy-first Danish phone-number intelligence using official CVR and telecom-register data. Look up registered companies, operators, number types, and community spam/trust signals without exposing private individuals' names. Requires a paid API key.
  • πŸ“¦πŸ†“ Sanctions Screening MCP β€” Screen names against the consolidated OFAC, EU, UK and UN sanctions lists, resolve companies to GLEIF LEIs, and trace ownership chains. Mirrors the lists into a local SQLite/FTS5 index, so matching runs offline with no API key and no rate limit; hits carry a raw Jaro-Winkler score and source provenance rather than a verdict. npx -y @cyanheads/sanctions-screening-mcp-server
  • πŸ“¦πŸ†“ Sift β€” 80 tools for cross-referencing public financial and corporate records across 9 sources: OpenSanctions, the ICIJ Offshore Leaks database (via Aleph), UK Companies House, SEC EDGAR, CourtListener, GLEIF, Wikidata and land registries. Ships 24 structural detection patterns (shell companies, nominee shields, phoenix companies, circular ownership) and interactive network graphs. Free OpenSanctions API key required.

Threat Intelligence

  • πŸ“¦πŸ†“ VirusTotal β€” Analyze URLs, files (by hash), IPs, and domains with detailed relationship mapping. Free API tier available, requires VIRUSTOTAL_API_KEY.
  • πŸ“¦πŸ†“ Voidly β€” Global internet censorship intelligence: 116 tools across 119+ countries. Query OONI / IODA / CensoredPlanet evidence, look up 5,356 citable incidents, check if a domain or service is blocked in a country, fetch ISP-level risk scores, run ML-driven shutdown forecasts, and verify censorship claims. Free, no API key needed for read endpoints. npx @voidly/mcp-server.
  • πŸ“¦πŸ†“ OpenOSINT β€” AI-powered OSINT agent with interactive REPL, MCP server, and CLI.
  • πŸ“¦πŸ†“ osint-agent-skills β€” 23 MCP tools (DNS, Shodan InternetDB, crt.sh, Wayback CDX, GitHub code search, OTX, HIBP, Etherscan, Mastodon) with zero-dependency Node.js server for Claude Code, Cursor, and Ollama.
  • πŸ“¦πŸ†“ VulneraMCP β€” AI-powered bug bounty MCP server with recon (subfinder, httpx, gau, ffuf), vulnerability testing (XSS/SQLi/IDOR/CSRF), API/auth/cloud scanning, knowledge-graph analysis, and Markdown reporting. Integrates OWASP ZAP and CLI tools with PostgreSQL storage.
  • πŸ“¦πŸ†“ Clearfront β€” Self-OSINT footprint scanner exposing 30 tools over MCP: username enumeration (Sherlock, Maigret, WhatsMyName), email and breach checks (holehe, HIBP, Hudson Rock infostealer logs), domain and IP recon (crt.sh, Shodan, Censys, GreyNoise, Wayback Machine), and EXIF/GPS extraction. Correlates findings into an evidence graph and rates each by source, confidence and severity. Configurable sweep depth and a local web console. pip install clearfront, runs locally, most tools keyless.
  • πŸ“¦πŸ†“ ScanMalware β€” Submit a URL for sandboxed browser analysis, then pivot across the scan archive: search by domain, IP, ASN, JARM, favicon mmh3, TLSH/ssdeep fuzzy hash, screenshot hash, OCR text, or JavaScript fingerprint. Also exposes YARA matches, TLS/RDAP records, Certificate Transparency pivots, detected technologies, and pastejacking/clipboard events. 128 tools, no API key required. MCP: https://mcp.scanmalware.com/mcp
  • πŸ“¦πŸ†“ Darknet MCP β€” 66 tools for dark web and breach intelligence: ransomware group tracking and victim listings, stealer logs, HIBP breach lookups, IntelX search, Tor .onion fetching and exit-node checks, MalwareBazaar/ThreatFox/URLhaus feeds, and Bitcoin address intel. Many tools work with no API key; premium sources unlock with your own keys. npx darknet-mcp-server
  • πŸ“¦πŸ†“ OpenCTI MCP β€” Natural-language access to an OpenCTI instance: latest reports, campaigns by name, attack patterns, indicators, labels and marking definitions over the GraphQL API. Requires your own OpenCTI URL and token.

Geospatial & Geopolitical Intelligence

  • πŸ“¦πŸ†“ World Intel MCP β€” 120 tools for real-time global situational awareness across 30+ domains: GDELT and 119 RSS news feeds, ACLED conflict events, military aircraft tracking (ADS-B/OpenSky), NGA maritime warnings, submarine cables and datacenters, OFAC sanctions, USGS/NASA disaster feeds, plus geospatial datasets for bases, ports, pipelines and nuclear facilities. All sources are free public APIs; optional free keys (FRED, EIA, NASA FIRMS, ACLED, OpenSky) unlock a few of them. Python, installed from source.
  • πŸ“¦πŸ†“ Satellite MCP β€” 171 tools across 27 categories of geospatial intelligence: Sentinel-2 and Landsat scene search, NASA FIRMS wildfire detections, night-lights change detection, aircraft and vessel tracking, military and conflict data, sanctions, terrain and OpenStreetMap queries, plus spectral and change-detection math. Most tools need no key; premium imagery (Planet, NASA Earthdata, N2YO) uses your own. npx satellite-mcp
  • πŸ“¦πŸ†“ GDELT MCP β€” Search and analyse global news coverage through the GDELT Project: article search, coverage timelines and breakdowns, tone distribution, and US television transcripts with clip, context and trending queries. No API key. npx -y @cyanheads/gdelt-mcp-server

Research Intelligence

  • πŸ“¦πŸ†“πŸ’° BGPT MCP β€” Scientific paper search with structured full-text evidence: methods, sample sizes, results, limitations, quality scores, and falsification prompts. Useful for claim verification and literature OSINT. Remote MCP + REST. Free tier: 50 results. docs Β· MCP: https://bgpt.pro/mcp/sse

Meta / Discovery

  • πŸ†“ Not Human Search β€” Agent-first discovery engine for MCP servers. Search, score, and live-probe (verify_mcp) 8,600+ servers via JSON-RPC or REST API. Useful for pivoting between OSINT MCP tools. MCP: https://nothumansearch.ai/mcp
  • πŸ“¦πŸ†“ Claudii Exploratores β€” OSINT suite exposing 898 curated OSINT tools across 24 categories (people, usernames, email, domains, IP, phones, companies, crypto, IBAN, media, social platforms…) as both a Claude Agent Skill and an MCP server. Auto-classifies an indicator, builds only the search URLs that fit it, and includes an offline ISO 13616 IBAN verifier and a reversible PII redactor. Python / FastMCP, AGPL-3.0. Alpha.

Blockchain Intelligence

  • πŸ’° TWZRD Agent Intel β€” Blockchain OSINT for AI agent trust scoring β€” reads public Solana on-chain data (wallet history, transaction patterns) to score agent trustworthiness. Free preflight + paid signed V5 trust receipts via x402 micropayments. MCP: https://intel.twzrd.xyz/mcp
  • πŸ’° The Stall β€” Multi-tool blockchain OSINT server: OFAC sanctions screening (19,000+ SDN entries, fuzzy name match + AKA aliases), wallet risk scoring, agent KYA trust scoring, EVM and Solana transaction intelligence, and token security analysis. Pay-per-call via x402 USDC micropayments on Base β€” no accounts or API keys. MCP: https://the-stall.intuitek.ai/mcp

Market & Trading

  • πŸ“¦πŸ†“πŸ’° Helium MCP β€” 37-dimensional news bias scoring across 216 sources, market data, and ML options pricing. Remote MCP + REST. Demo Β· docs

Contributing

Contributions are welcome! Please open a pull request to add a new OSINT MCP server to the list.

License

MIT

from github.com/soxoj/awesome-osint-mcp-servers

Installing Awesome Osint Mcp Servers

This server has no published package β€” it is built from source. Open the repository and follow its README.

β–Έ github.com/soxoj/awesome-osint-mcp-servers

FAQ

Is Awesome Osint Mcp Servers MCP free?

Yes, Awesome Osint Mcp Servers MCP is free β€” one-click install via Unyly at no cost.

Does Awesome Osint Mcp Servers need an API key?

No, Awesome Osint Mcp Servers runs without API keys or environment variables.

Is Awesome Osint Mcp Servers hosted or self-hosted?

Self-hosted: the server runs locally on your machine via the install command above.

How do I install Awesome Osint Mcp Servers in Claude Desktop, Claude Code or Cursor?

Open Awesome Osint Mcp Servers on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install β€” the config is generated automatically, no JSON editing.

Related MCPs

Compare Awesome Osint Mcp Servers with

Not sure what to pick?

Find your stack in 60 seconds

Author?

Embed badge for your README

Browse similar

All ai MCPs