OSINTLY Launched: All-in-One OSINT Investigation Workspace with Parallel Multi-Identifier Queries and Real-Time Streaming
OSINTLY has launched as an all-in-one digital reconnaissance workspace that queries usernames, emails, phone numbers, IPs, domains, and crypto addresses in para
A web-based digital investigation workspace named OSINTLY (osint.ly) has officially launched, consolidating fragmented open-source intelligence (OSINT) tools into a unified analysis interface. Demonstrated across cybersecurity analyst communities, OSINTLY enables investigators to conduct parallel reconnaissance across six core identifier categories—pseudonyms, email addresses, phone numbers, IP addresses, domains, and cryptocurrency wallet addresses—through a single query.

Image source: @d4rk_intel
Digital reconnaissance workflows have traditionally required analysts to jump between disconnected CLI tools and disparate web portals for domain DNS queries, social media username enumerations, breach database checks, and IP routing lookups. Varying input requirements and inconsistent output formats created significant manual friction when correlating entities and maintaining casework context. OSINTLY addresses this bottleneck by querying multiple verified providers concurrently from a single input and streaming normalized intelligence in real time.
Parallel Multi-Identifier Reconnaissance and Real-Time SSE Streaming Architecture
At the core of the OSINTLY workspace is a parallel query engine paired with real-time event streaming.
When an analyst enters an identifier and selects its corresponding type, the platform concurrently dispatches the query across all connected providers mapped to that category.
- Six Core Identifier Types: Natively supports Pseudonyms (usernames/handles), Email Addresses, Phone Numbers, IP Addresses, Domains, and Cryptocurrency Wallet Addresses.
- Server-Sent Events (SSE) Streaming: Rather than waiting for all external providers to complete before rendering the page, results stream directly into the browser interface as each provider responds.
- Unified Casework and Trail Preservation: Findings, notes, and correlated entities remain tied directly to their original sources within a consolidated investigation file. Analysts can hand casework over to colleagues without losing the audit trail or investigative context.
50+ Email OSINT Modules and the Dedicated Tools API
Beyond aggregation, OSINTLY incorporates specialized modules for deep-dive investigation.
In the email intelligence domain, OSINTLY has published over 50 dedicated modules, including integrations for Google, Microsoft Teams, Flickr, Garmin Connect, and NPM. Its rebuilt Google module goes beyond basic account discovery to resolve email addresses into structured intelligence, surfacing Google account identifiers, account classifications, and associated public services where exposed.
For engineering teams looking to integrate reconnaissance capabilities into internal pipelines, the platform provides the unified Osintly API:
- Normalized JSON and BYOK Support: Built around a single
search_id, the API supports status retrieval, real-time event streaming, leak provider output inspection, webhook delivery, and Bring Your Own Key (BYOK) orchestration across external providers. - Focused Tools API: Enables direct, single-observable lookups without spinning up full investigation searches. Key endpoints include 'IP Intelligence' for geolocation, network ownership, routing, and threat telemetry, alongside 'Domain Intelligence' for DNS records, SSL/TLS certificates, registration data, and infrastructure exposure.
Free Preview Access Path and Plan-Dependent Limitations
OSINTLY provides an immediate evaluation path that does not require an upfront account or active subscription.
- No-Signup Free Preview: Users can navigate directly to the search interface on osint.ly and run a limited 'Free Preview' on pseudonyms and email addresses without creating an account.
- Casework Persistence and Volume Lookups: Running full searches across all providers and persisting search history and casework requires an account and plan credits or subscriptions.
- Tools API Licensing Requirements: Calling direct enrichment endpoints via the Tools API—including routes flagged as free—requires a paid API subscription with the
toolscapability enabled. - Provider Freshness Variance: Because OSINTLY aggregates data across diverse public data providers, result recency and accuracy naturally vary depending on the upstream source, making primary source cross-validation essential.
Sources
- Osintly Official Overview: About Osintly
- Osintly Documentation: OSINT Search Documentation
- Osintly Official Blog: Email OSINT on Osintly: 50+ Modules
- D4rk_Intel on X: OSINTLY Release and Real-Time Reconnaissance Demo (@d4rk_intel)