Back to Blog

OSINTsearch Review (2026): The osint.industries Rival Built on History

547 profiles on richard, 446 on meme, 329 on cia, 770 endpoints in 29.2 seconds. We opened every OSINTsearch export from a Sep 5 run to see what it adds to the username search field.

Bob Adams

Threat Analyst at Revealer

OSINTsearch returned 547 profiles on richard, 446 on meme and 329 on cia on 2026-09-05, and its davidbombal run scanned 770 endpoints in 29.2 seconds with 59 found, 662 not found and 47 that could not be checked. Those are the headline numbers from the seven exports we opened for this OSINTsearch review. osintsearch.org is a live username, email and phone search engine that launched publicly in 2026 and markets itself as an osint.industries alternative. Its pitch is not a bigger module pool. It is that every row carries account history: former usernames, join dates, and whether the account is banned, suspended or deleted, where sources still provide them.

We build Revealer.US. Assume bias and check the exports. Where OSINTsearch beats us, this article says so.

What OSINTsearch is and who it is for

The site's tagline is "A live data search engine. Live username search across public profiles." You type a handle, an email or a phone number, the OSINT search runs against live endpoints rather than a stored index, and you get a results table with an identity summary on top and three export formats underneath.

The intended user is the investigator who already runs osint.industries or fingerprint.to and wants two things those tools do not put in a fixed column: the names an account used to have, and the state it is in now. The second audience is anyone who wants a free username search engine with a real weekly quota.

What we looked at

Seven subjects, all run on 2026-09-05, all exported as JSON. richard, meme and cia are dictionary handles that resolve to thousands of people, the same three from our earlier 11-engine benchmark, where OSINTsearch was not tested. davidbombal is a public YouTube educator and the handle OSINTsearch used in its own benchmark. srhoe and deadcatx3 are rarer handles we discuss as handles only. surfinup8 was run against the email corpus.

Counts are exactly what the export files report in meta.profiles_found. We opened the same-day fingerprint.to and Revealer exports for davidbombal, srhoe and deadcatx3, the Aug 26 osint.industries export for richard, and one investigation case file for structure only. No number below is estimated.

The 758-endpoint sweep

OSINTsearch says a username search queries 758 endpoints across six categories: Social and messaging, Creator and media, Developer and tech, Gaming, Commerce and links, and Long tail. The davidbombal export from the evening of Sep 5 reports endpoints_scanned: 770, so the pool had grown by 12 between the marketing page and the run.

The search block is the most honest denominator we have seen in a username tool. It lists found: 59, not_found: 662 and could_not_check: 47, and the 47 are itemized in an errors array with the platform, an outcome and the reason: 20 timeouts, 20 errors and 7 rate-limited outcomes, including one lookup API flagged as moved or blocked. fingerprint.to prints "759/759" checked on the same handle. OSINTsearch admits to 47 it could not reach, which is the more useful number.

OSINTsearch's own blog benchmark reports 29.2 seconds on davidbombal against fingerprint.to at 20.6 seconds over 759 endpoints. Our export agrees: duration_ms: 29164. Email search runs 203 modules and phone search 24 by the site's count.

Results from the Sep 5 runs

Subject Corpus profiles_found What stood out in the export
richard username 547 164 rows with a bio, 76 with a location, 365 with a user_id, 346 with an avatar, 52 with linked_socials
meme username 446 130 bios, 71 locations, 282 user_ids, 40 linked_socials, banned: true in raw on 2 rows (Kongregate, Grailed)
cia username 329 100 bios, 51 locations, 221 user_ids, 29 linked_socials, former usernames on Steam and Instagram
davidbombal username 59 26 rows with created_at, 41 user_ids, 9 linked_socials, 1 wallet, davidbombal.eth as a variant
srhoe username 37 (09:24 run), 31 (21:20 and 21:24 runs) 5rh0e added as a variant from TikTok, srhoe.com surfaced from Stack Overflow, 7 linked_socials
deadcatx3 username 21 a real created_at on 9 of 21 rows and a 0001-01-01 placeholder on the other 12, nervequake added as a variant from archive.org
surfinup8 email 14 11 rows carry the email, 1 masked phone, sources include Snapchat, 9GAG and a Facebook email module

The richard number, 547, is 64 more than fingerprint.to's 483 from Aug 26, and srhoe dropped from 37 to 31 between a morning and an evening run, which is the drift every live engine shows and the reason we print run times.

Same-day comparisons: davidbombal returned 69 on fingerprint.to and 57 from 813 sources on Revealer against OSINTsearch's 59. srhoe returned 46 on fingerprint.to and 35 on Revealer against 37 and 31. deadcatx3 returned 22 on fingerprint.to and 28 in Revealer's Sep 4 export against 21. OSINTsearch does not win on count. It wins on what each row carries.

The identity block

Every username export opens with an identity object: probable_name with a confidence score, probable_location with its own confidence and source list, probable_email where the corpus produced one, username_variants with a per-platform source list for each variant, websites, profile_pictures, and platforms_agreeing.

On richard the probable name comes back at 0.01 with 547 platforms "agreeing", which is the tool telling you that 547 different people share the handle. On cia it names "Central Intelligence Agency" at 0.01. On davidbombal, a single-owner handle, confidence rises to 0.31 and the location reads United Kingdom at 0.05 from AudioJungle, YouTube and CodersRank. deadcatx3 resolves Australia at 0.14 from Scratch, eBay and Instagram. They are the tool showing its arithmetic, not conclusions.

The variant list is the practical part. davidbombal picked up davidbombal.eth from ENS. deadcatx3 picked up nervequake from archive.org, with the source named so you can check it. srhoe picked up 5rh0e from TikTok. Each variant is a pivot the tool found and attributed to a platform before you spend a search on the next handle.

Former usernames and banned accounts as first-class fields

This is the section OSINTsearch is built around. The former usernames and banned and suspended accounts posts cover the method. Here are the rows from the exports that show the fields in use.

richard, osu. former_usernames: ["thegame98"], created_at: 2013-04-08, and the raw block still holds osu's own key, previous_usernames. The normalized field and the source field sit side by side in the same row.

cia, Steam. former_usernames: ["GammaCIA"], created_at: 2004-07-26, and raw.name_history carrying Steam's own entry with a change date of 26 Dec 2010. raw.trade_ban_state is present and reads "None", which is a positive statement that Steam answered the question.

cia, Instagram. former_usernames: ["mollyhalecia"] on a profile created 2019-04-01. This one comes from the primary scan, not a cross-reference.

meme, Kongregate. raw.banned: true, created_at: 2022-11-11. Grailed on the same handle also reports banned: true. On richard, Lolz reports is_banned: true. On cia, ActBlue reports deleted: true. A status-code checker would list all of these as found and stop.

davidbombal, YouTube and Twitter. YouTube returns created_at: 2008-02-06 with the platform's own "Joined Feb 6, 2008" string kept in raw, and Twitter returns created_at: 2009-07-12 with verified: true, next to a NameMC row that carries raw.name_history and no date. Join dates are returned where the platform returns them.

The honest framing, which OSINTsearch itself uses, is "where sources still provide them". The history comes from the platforms that publish it: Steam, osu, Instagram, Roblox, Ubisoft, Vinted, Grailed, Kongregate, Lolz, NameMC, Bluesky and archive.org. fingerprint.to surfaces the same signals in its extras block, and on richard its export carries is_banned for Vinted and Lolz and the osu former name thegame98, so OSINTsearch is not finding history the other tool cannot. What it does differently is normalize it. Every CSV row has account_status, account_status_reason, account_banned, is_deleted, is_suspended, former_usernames, former_usernames_count and former_usernames_truncated in fixed positions. None of the other exports we opened, from fingerprint.to, osint.industries or Revealer, carry a normalized column for any of them.

The deleted-profile case is the sharpest version of this. OSINTsearch's Sep 5 blog post on a banned Instagram handle from a public DOJ wire-fraud case shows the tool returning the user ID, a banned_or_disabled flag, the bio, the profile picture and the placeholder name "Instagram User" from a page that is no longer available. Its caution is the right one: "A matching account ID can support continuity between records; it does not establish who operated the account or whether the allegations are true."

What the JSON and CSV exports contain

The JSON (schema 2, with schema 3 on the evening runs adding search, errors and not_found) has three parts.

meta holds tool, site, subject, corpus and profiles_found. identity is the block described above. platforms[] is one row per profile with platform, platform_label, username, user_id, display_name, profile_url, verified, followers, following, posts, bio, location, created_at, last_active, avatar_url, banner_url, source (primary scan, bio_link or cross_reference), scraped_at, former_usernames, and a raw object holding the untouched source payload. Keys we saw inside raw include name_history, former_names, previous_usernames, banned, is_banned, trade_ban_state, account_status, deleted, status and last_status_at.

The CSV is wider: 88 columns. Beyond the status columns already listed, it carries linked_socials, linked_handles, wallets, real_name, age, gender, company, headline, school, repos, karma, reputation, steam_level, games_owned, gamerscore, vac_banned, trade_ban, online_state, last_active, last_active_days_ago, last_active_source, three provider_matrix columns, email_leads_count, email_leads_undetermined_count, source, source_kind, alias, the deep search lineage columns seed_username, seed_depth, seed_kind and seed_evidence, then masked, mask_level, scraped_at and extras. The seed columns record which handle produced each row and at what depth, so a pivot never loses its provenance.

The investigation case-file export

Paid accounts can bundle searches into an investigation and export it as one case file (schema investigation-1). The JSON has five top-level keys: meta, people, platforms, evidence and searches, and meta.note repeats that a shared identifier does not establish that accounts belong to the same person.

We read one real case file for structure only. The PDF is 30 pages, labelled "EVIDENCE-ONLY EDITION", with four sections: 01 Report overview, 02 People source records, 03 Social evidence, 04 Search journal. The overview states "1 People Search source record, 2 included social profiles and 3 search runs" and "441 REPORTED CHECKS", and notes "No AI summary is included in this edition". People source records carry a name, aliases, current and past addresses with property details, and phone numbers with carrier and line type. The report's caution reads: "A shared email, phone number or username is an investigative lead. It does not establish that records belong to the same person." The investigation reports post walks the sections page by page.

Pricing

Plan Price Searches What you get
Free $0 15 per week Preview access, basic exports
Starter $20 per month 50 per week Full profiles, partial breach records, AI summaries in PDF
Pro $49.99 per month 500 per week Full breach records with identifiers, deep search depths 1 to 4, priority support
Enterprise Custom Unlimited REST API, account manager, SLA

Yearly billing is up to 17 percent off. Quotas reset Monday at 00:00 UTC. PDF, JSON and CSV export are available on every account, including Free, per the pricing page as of September 2026. The Free plan has its own post; the pricing page is the source for all four rows.

Where OSINTsearch is weaker

Probable name confidence is near zero on generic handles. 0.01 on richard and cia, 0.02 on meme. Correct behaviour, but the field only earns its place on single-owner handles, and even davidbombal reached only 0.31.

Its own benchmark run listed 47 errors. 47 of 770 endpoints could not be checked on davidbombal, 6.1 percent of the pool. Reported, but not clean.

No breach records on Free. Breach data is partial on Starter and full on Pro, and the username export has no breach section at all. Revealer's davidbombal report from the same day carried 3 breach rows next to the profiles; its srhoe report carried none.

Quotas are weekly. 15, 50 and 500 per week, resetting Monday. Deep search draws on the same pool: the srhoe 21:24 run requested depth 3, cost 6 searches, swept four derived handles and discovered zero new profiles.

The raw block is bulky. The richard JSON is 650 KB for 547 rows. That is what makes each row auditable, and also what makes the file slow in a spreadsheet. created_at is a 0001-01-01 placeholder wherever the platform returned no date, which is 280 of richard's 547 rows.

Counts on rare handles trail fingerprint.to. 59 against 69, 31 to 37 against 46, 21 against 22.

Verdict

Against osint.industries. OSINTsearch wins on exports and denominators. The osint.industries richard export from Aug 26 is 400 rows across 310 modules with no checked total and no timestamp; OSINTsearch prints found, not found and could-not-check with an error list. osint.industries keeps its mailbox-existence checks, 93 of those 400 rows across its Microsoft, Mail.ru, Zoho, Apple and Proton modules, which OSINTsearch does not replicate. The head-to-head has the full table.

Against fingerprint.to. fingerprint.to returned more rows on every rare handle and was faster on davidbombal, 20.6 seconds against 29.2. Its extras block carries the same ban and former-name signals. OSINTsearch flattens them into fixed columns, keeps the raw payload beside them, and retains metadata from banned or deleted profiles. If your workflow ends in a spreadsheet or a case file, that is a real difference. If it ends on a results page, fingerprint.to is the stronger enumerator. The three-way comparison scores it line by line.

Against Revealer.US. Revealer returned 57 on davidbombal and 35 on srhoe from 813 sources; OSINTsearch returned 59 and 37 or 31. Even on count. Revealer's schema has no former-username column, no account-status column and no identity block with confidence scores; OSINTsearch has all three. Revealer keeps breach and stealer-log correlation in the same result set with AI Deep Search on top. Run both. On a handle with a history, run OSINTsearch first.

Revealer is not a consumer reporting agency. Its data may not be used for employment, tenant, credit, or insurance eligibility decisions.

Frequently asked questions

Is OSINTsearch a good osint.industries alternative? On username search, yes. It returned 547 profiles on richard against 400 rows for osint.industries, prints a full denominator with an error list, and exports JSON, CSV and PDF on every paid tier. osint.industries keeps its mailbox-existence checks.

Does OSINTsearch show former usernames? Where the platform still publishes them. On Sep 5 it returned thegame98 on osu for richard, GammaCIA on Steam and mollyhalecia on Instagram for cia, and "African Anger" on osu for meme, each in a normalized former_usernames field with the platform's own key preserved in raw.

Can OSINTsearch find banned accounts? It returns the ban flag the platform exposes. On Sep 5 that meant banned: true on Kongregate and Grailed for meme, is_banned: true on Lolz for richard and deleted: true on ActBlue for cia. Its blog also documents a banned Instagram profile returned with user ID, status flag, bio and picture.

How much does OSINTsearch cost? Free is $0 for 15 searches a week. Starter is $20 a month for 50. Pro is $49.99 a month for 500 with full breach records and deep search. Enterprise is custom with a REST API. Yearly is up to 17 percent off.

Should I use OSINTsearch or Revealer.US? Both. OSINTsearch gives you former usernames, account status and an identity block on every row. Revealer gives you a wider pool and breach and stealer-log correlation in the same result set. They matched within two profiles on davidbombal (57 against 59) and on the morning srhoe run (35 against 37) on Sep 5.

Get started

Ready to check your exposure?

Create a free account. Every result is pulled live, in real time, from public sources and endpoints we do not own. We do not retain your search data. Items you choose to save, publish, or monitor are kept until you delete them.

Create account