Flowsint: Open-Source Graph-Based OSINT Investigation Platform
An open-source OSINT platform for cybersecurity analysts to explore entity relationships through an interactive graph canvas and chain 30+ automated enrichers i
Flowsint, an open-source OSINT (Open Source Intelligence) and reconnaissance platform designed for cybersecurity analysts and investigators, is gaining traction across the digital investigation community. Highlighted on October 5, 2026, by open-source curator Tom Dörr (@tom_doerr), Flowsint (GitHub: reconurge/flowsint, TypeScript) addresses the friction of fragmented reconnaissance scripts and siloed analysis workflows by providing an interactive graph canvas where investigators can visually explore, connect, and analyze entity relationships.

Image source: @tom_doerr via X (reconurge/flowsint)
In conventional OSINT practices, tools frequently appear, evolve, and disappear, while fragile custom scripts often break when target interfaces change. This instability forces investigators to spend excessive time manually correlating disparate artifacts across isolated utilities. Flowsint resolves this maintenance overhead by establishing a persistent, unified investigation baseline: external tools become interchangeable extensions that can be plugged in or swapped without disrupting the underlying knowledge graph.
Graph-Based Entity Visualization and 30+ Built-in Enrichers
At the core of Flowsint is an interactive graph interface where entities such as domain names, IP addresses, organizations, and personas are represented as nodes, with interdependencies mapped as edges.
- Centralized Knowledge Graph: Instead of juggling separate output logs, all gathered intelligence accumulates within a single interactive visual canvas, allowing analysts to spot hidden clusters and contextual relationships at a glance.
- 30+ Automated Enrichers: Flowsint includes over thirty pre-configured enrichers tailored for data gathering. Selecting an entity initiates automated queries against configured sources to pull intelligence and expand the graph structure dynamically.
- Investigation Continuity: When data sources or external APIs change, previous investigation trees and validated node relationships remain intact, safeguarding investigative context across long-running analyses.
'Flows' Chaining: Visual Automation for Multi-Step Reconnaissance
Beyond manual single-entity queries, Flowsint introduces "Flows"—a visual chaining mechanism where the structured output of one enricher automatically serves as the input for subsequent enrichers.
This architecture enables investigators to systematically widen the scope or deepen the reconnaissance fidelity of an investigation through automated pipelines.
- Canvas-Based Flow Builder: Using the local web dashboard (
http://localhost:5173/dashboard/flows), users can drag and drop an input entity type onto the canvas and link multiple enrichers sequentially to form custom execution graphs. - Reproducible and Scalable Research: Configured flows function as reusable investigative templates. When new entities of the same type are uncovered, analysts can re-apply established pipelines to maintain consistent, repeatable reconnaissance standards.
Privacy-First Local Storage and Modular Architecture (Types, Tools, Enrichers)
Investigative integrity and operational security demand that sensitive queries and target identities remain confidential. Flowsint adheres to a privacy-first design model, maintaining all case data and intelligence graphs entirely within the user's local data storage.
Its codebase enforces a clean separation of concerns across a three-tier modular architecture:
- Types: Define core entity schemas and structured data models.
- Tools: Act as low-level abstraction wrappers executing local Docker containers, system utilities, and third-party APIs.
- Enrichers: Orchestrate end-to-end intelligence workflows by invoking tools, validating collected records, inserting graph database nodes and edges, and returning structured datasets.
This modular structure allows developers to easily implement custom enrichers and tools, integrating specialized proprietary APIs or internal utilities into their local deployment.
Operational requirements should be noted: utilizing enrichers backed by external APIs or containerized utilities requires configuring corresponding service credentials and maintaining an active local runtime environment (such as Docker). Additionally, as an open-source framework built for transparent, verifiable, and ethical investigation, users are expected to deploy Flowsint strictly within authorized legal and professional boundaries.
Sources
- GitHub Repository: reconurge/flowsint
- Flowsint Official Documentation: Flowsint Documentation - Overview & Flows
- Tom Dörr Official Post on X: @tom_doerr (2026-10-05) - Flowsint Introduction