Back to Blog
Threat Intelligence10 min readAug 26, 2026

Top OSINT Sites in 2026: Ranked with Real Data

We searched the handle richard on the same day across paid OSINT sites, self-hosted CLIs, and free web checkers. fingerprint.to ranks first. Revealer.US ranks second. The numbers, and the extraction test, explain why.

B

Bob Adams

Threat Analyst at Revealer

We ranked the top OSINT sites in 2026 with one handle and one afternoon. The handle was richard. fingerprint.to is first. Revealer.US is second. That order is the point of this article, not a typo.

Revealer.US returned more rows (488 against 483) and checked more sources (751 against 620). fingerprint.to posted the best hit rate in the set, 77.9 percent, on a pool 17 percent smaller, and it passed the same extraction test we use to tell a hit counter from an investigation tool. We build Revealer.US. Ranking our own product first on a raw-count lead of five would be marketing. Ranking it second is the honest read of the same-day run.

Disclosure up front: we build Revealer.US, including AI Deep Search, data breach lookup, and stealer logs. Paid self-serve is on pricing. The API is for pipelines. Assume bias and check the numbers. Every count below is a real run on 2026-08-26, not a vendor datasheet.

The ranked list, then the scoreboard, then why the order holds.

  1. fingerprint.to
  2. Revealer.US
  3. osint.industries
  4. infobreach.net
  5. Maigret (self-hosted CLI)
  6. Sherlock (self-hosted CLI)
  7. Blackbird (self-hosted CLI)

Free web checkers sit after the ranked seven. They are useful. They are not in the same league.

How we tested

One handle, chosen to hurt. richard is a common English given name that thousands of people use as a username. Soft 404s, parked profiles, and surname collisions all show up at once. A rare handle makes any tool look accurate. This one does not.

Same day, consecutive runs. Paid tiers wherever the platform sells one. Fresh CLI installs for Maigret, Sherlock, and Blackbird. No reruns to shop for a better number. No handle shopping. Whatever the tool reported is the number in this article.

Counts as each tool reports them. Module pools are not comparable across vendors, so every hit rate is a tool measured against its own pool. Revealer.US and fingerprint.to counts come from JSON exports. osint.industries and infobreach.net counts come from the results page, because those two offer no export.

This is a snapshot of one common handle on one day. Module lists change. Run your own handle before you spend money.

The scoreboard

Platform Sources checked Profiles found Hit rate Tier
fingerprint.to 620 483 77.9% Paid
Revealer.US 751 488 65.0% Paid
osint.industries 396 301 76.0% Premium
infobreach.net 332 231 69.6% Paid
Maigret ~500 (default set) 319 ~63.8% CLI, free
Sherlock 413 236 57.1% CLI, free
Blackbird 716 281 39.2% CLI, free

Maigret's 319 is on its default set of about 500 sites, not its full database of about 3,300. Treat that row as a default-install result, not a ceiling.

Profiles found for the username richard, one run each. Bars are scaled to Revealer.US at 488.

Revealer.US 488 paid
fingerprint.to 483 paid
Maigret 319 CLI · free
osint.industries 301 premium
Blackbird 281 CLI · free
Sherlock 236 CLI · free
infobreach.net 231 paid
WhatsMyName.io 228 web · free
usersearch.org 138 free
instantusername.com 63 free
idcrawl.com 32 free
namecheckup.com 22 free

Why fingerprint.to is first

Hit rate is how often a tool agrees with its own module list. Reach is how big that list is. Both numbers are true. This ranking weights three things that actually decide a case: detection quality, whether the tool reads the page it found, and how much extra work the result dump creates.

fingerprint.to posted 483 profiles from 620 sources, 77.9 percent hit rate, 481 unique URLs, zero duplicate URL groups. It sat within five rows of the raw-count leader on a pool 131 sources smaller (17 percent smaller than 751). And it passed the guns.lol extraction test. That combination is first place.

Revealer.US posted 488 profiles from 751 sources, 65.0 percent hit rate, 486 unique URLs, two duplicate rows (0.4 percent). Widest reach in the set. The same export also carried 500 breach-database hits and 503 stealer-log hits, and the stealer search surfaced 129 email addresses. It passed extraction too. That is a strong second, and it is the product we would still run first on a messy case that needs the historical record. It is not first on this ranking, because the hit rate is lower, the raw-count lead is five, and we wrote the list.

osint.industries posted a sharp 76.0 percent on 396 modules and still finished 187 profiles behind the leader. A high hit rate on a smaller pool still misses the accounts the larger pools never stopped looking for. infobreach.net is an honest mid-tier. The CLIs are free, auditable, and slower to a finished lead. None of them parsed the guns.lol card.

When your case turns on the account the subject forgot they had, you do not get partial credit for the hits you never attempted. When it turns on a Telegram handle buried in a profile-card page, you do not get credit for finding the page and stopping. First place in this ranking is the tool that was accurate, close on count, and actually read the page.

1. fingerprint.to

If you strip our own product out of the test, fingerprint.to still wins the day. If you leave it in, it still wins the ranking.

483 from 620 is the sharpest paid detector we ran. 77.9 percent agreement with its own pool, a unique-URL export that needed no cleanup, and the same guns.lol parse that only one other tool produced. Result rows carry real enrichment: names, profile names, locations, follower counts, post counts, account creation dates. The export is clean enough to hand to someone who did not run the search.

The limit is the rest of the loop. This snapshot is live enumeration plus extraction. It is not the 500 / 503 / 129 correlation set. If your workflow is "find every live account on this handle, parse the interesting ones, export, move on," this is the first tool to open. If your workflow is "turn a handle into emails, stealer rows, and former exposures without changing windows," you still want the second-place tool next to it.

2. Revealer.US

We build it, so grade this section against the raw numbers.

488 from 751 is the widest sweep and the highest count. 65.0 percent is the unflattering number in the table, and it is worth saying plainly. A lower rate on a bigger list can mean more false starts to triage. On a collision-prone handle like richard, holding two-thirds of 751 sources without drowning in junk is still the harder job, and the export backs that up: 486 unique profile URLs, two duplicate rows, 0.4 percent. Those two dupes were hackaday.io and namemc.com each listed twice via different modules, not a padded leaderboard.

Three things in the same result set are why it sits at second instead of third or fourth.

Extraction. It passed the guns.lol test. Display names, bios, locations, linked accounts, and follower counts come back parsed, not just detected.

Breach and stealer-log correlation. The same export carried 500 breach-database hits and 503 stealer-log hits. The stealer search surfaced 129 email addresses. Those are leads on a common name, not 129 confirmed identities. An email from a stealer row is a second query. A password reuse pattern is a third. The graph grows inside one report.

Reach. 751 sources vs 396 is not a rounding error. The forgotten account has to be on the attempt list before anyone can extract it.

Start on username search. Adjacent work lives on data breach lookup and stealer logs. AI Deep Search takes an identifier found in round one and runs it as a query in round two until the graph stops growing. Paid self-serve is on pricing. The API is for pipelines.

Revealer is not a consumer reporting agency, and its data may not be used for employment, tenant, credit, or insurance eligibility decisions.

3. osint.industries

A good product with the second-best paid hit rate in this test. The premium run checked 396 modules and confirmed 301 accounts, 76.0 percent agreement with its own pool. There is no export, so we could not audit unique URLs the way we did for the two leaders.

Its superpower showed up outside the raw counts. Feed it an identifier and its email-provider module set tells you whether that identifier is registered across Microsoft's consumer domains, Outlook, and a set of other mail providers. That registration-existence check is hard to do at scale without tripping abuse controls, and in this test nobody else matched its coverage. If you need to know whether a subject holds a Microsoft account, that module set alone can justify the seat.

Where the run fell short: reach and extraction. 396 modules is a small pool next to 751 and 620. 187 profiles fewer than the leader on the same handle. In the guns.lol test it confirmed the page existed and stopped. Detection without extraction turns a lead back into a browser tab.

Keep it for mailbox existence. Do not keep it as your only username engine.

4. infobreach.net

231 profiles from 332 sources at a 69.6 percent hit rate. An honest mid-tier showing. The pool is less than half of Revealer's 751 sources, so treat it as a fast second aggregator's opinion, not the primary sweep. Useful when you want another paid read without a second full-price seat. Not useful as the only pass on a case that might turn on a buried Telegram handle. It found the guns.lol page. It did not return the contacts inside it.

5. Maigret (self-hosted CLI)

319 accounts on a fresh default install, against a set of about 500 sites. That is the deepest free sweep in this ranking, and it beat osint.industries on raw count (319 vs 301) with no subscription.

Two caveats, both load-bearing. First, 319 is the default subset, not the full database of about 3,300 sites. A longer Maigret run would change the number. We did not run that, so we do not claim it. Second, a CLI hit is an existence check you still have to open. Maigret did not parse the guns.lol card. You get coverage and auditability. You do not get extraction, breach correlation, or an export that already did the reading.

If you can run Python and you want the best free first pass, this is it.

6. Sherlock (self-hosted CLI)

236 of 413 sites, 57.1 percent. The best-known username CLI, and still a sensible baseline. The site list is smaller than Blackbird's and the hit count is lower than Maigret's. What it has is familiarity, a huge install base, and a dataset that half the hosted tools above it still consume. Fine as a second free engine. Not the first CLI to reach for after this run.

7. Blackbird (self-hosted CLI)

281 of 716 sites, 39.2 percent. Widest CLI attempt list in the test, lowest CLI hit rate. That is the reach-vs-precision trade in one row: more sites tried, more misses (or more conservative matching, or more dead modules) to sort. 281 found still beats Sherlock and sits just behind Maigret. Same limit as the other CLIs. Existence, not extraction.

Free web checkers

No install, no rank slot. Same afternoon, same handle.

Tool Sources checked Found for richard
WhatsMyName.io 483 228
usersearch.org 315 138
instantusername.com 85 63
idcrawl.com ~36 32
namecheckup.com 63 22

WhatsMyName.io is the free web result that belongs in a serious bookmark folder: 228 of 483, close to Sherlock and infobreach.net, no account required. usersearch.org ran a clean 138 of 315 with no captcha. instantusername.com and namecheckup.com are availability checkers (taken vs available), not ownership evidence. idcrawl.com checked a tiny pool and returned the richest free cards of the no-install group: names, bios, photos, locations, follower counts.

Free checkers confirm a footprint exists. Paid platforms identify. 228 vs 483 vs 488 on the same handle is the coverage gap. A favicon and a URL vs a parsed row carrying Telegram handles and breach history is the workflow gap. Use them to test a hypothesis. Do not close a case on them.

The guns.lol test: the page everyone found and almost nobody read

This test is why the ranking is not a sorted count column.

One of the richard hits was a guns.lol page. guns.lol is a profile-card host out of the Discord scene. Users get a single fast-loading page with a background image, music, badges, and whatever links they want to pin. Threat actors adopted the format heavily, because the page looks like a harmless aesthetic flex while it holds every contact point they operate.

Every paid tool in this comparison has a guns.lol module. Every one of them found the page. Finding it is a status code. Reading it is the product.

Exactly two platforms, fingerprint.to and Revealer.US, returned the contact handles buried in the page body: a Telegram handle, a Discord ID plus username, a GitHub. osint.industries reported the profile and stopped. infobreach.net did the same kind of existence check. The CLIs and the free web checkers never entered this test as parsers.

Here is a trimmed version of what a parsed hit looks like (Discord ID partially redacted):

{
  "account_created": 1717026322,
  "badges": ["premium", "gifter", "christmas_2024", "christmas_2025"],
  "custom_metadata": {
    "description": "t.me/imlostt4words",
    "title": "richard"
  },
  "discord": {
    "id": "4042034437******",
    "username": "lacieismine",
    "user_badges": ["HypeSquad Bravery", "Discord Nitro"]
  },
  "page_views": 556,
  "second_tab": {
    "discord": "discord.gg/rayhitta",
    "github": "github.com/lostwordss"
  },
  "typewriter": ["t.me/cybrcriminal", "cybersec", "dms off"]
}

Count the new identifiers in that one hit. Two Telegram handles, one sitting in the typewriter rotation and one in the page metadata where almost nobody looks. A Discord account with its ID, username, and badge list. A GitHub. An invite server. The creation timestamp and view count for timing analysis.

One of those Telegram handles resolved to an active threat-actor channel. A platform that returned the page without the handles returned none of that. You can stare at 301 confirmed accounts and still miss the pivot that names the operator.

The five-profile gap between Revealer.US and fingerprint.to did not decide this case. The parse did. Both leaders passed. That is why they occupy the top two slots, and why a premium hit rate on a smaller pool is not the same thing as a finished lead.

How to choose

You need Start with
Best hit rate plus extraction, first paid seat fingerprint.to
Widest sweep plus breach and stealer correlation Revealer.US
Microsoft / Outlook registration-existence checks osint.industries
Fast paid second opinion, smaller pool infobreach.net
Deepest free CLI sweep Maigret
Well-known free CLI baseline Sherlock
Widest free CLI attempt list Blackbird
No-install free web check WhatsMyName.io, then usersearch.org
API access for a pipeline Revealer.US (see API docs)

Two rules held up. Never build a conclusion on one tool's negative result, because a miss is usually a module difference, not a contradiction. And never confuse "we found the page" with "we read the page." Budget for a second engine on work you will stand behind. fingerprint.to and Revealer.US were five profiles apart and both parsed the card. Their module lists still do not overlap cleanly.

Frequently asked questions

What is the best OSINT site in 2026? On this run, fingerprint.to. 483 profiles from 620 sources, 77.9 percent hit rate, a clean unique-URL export, and it passed the guns.lol extraction test. Revealer.US is second: 488 from 751, plus 500 breach hits, 503 stealer-log hits, and 129 emails from the stealer search, with the same extraction pass. We build Revealer.US, which is why second is the conservative slot.

Why is Revealer.US not number one if it found more profiles? Five extra rows on a 17 percent larger pool, at a 65.0 percent hit rate against fingerprint.to's 77.9 percent. Reach and the breach / stealer bundle are real advantages. They are not enough to put our own product first when the leader was more accurate, nearly tied on count, and passed the same extraction test.

What did the guns.lol test show? Every paid tool found the guns.lol profile-card page. Only fingerprint.to and Revealer.US returned the Telegram handle, Discord ID and username, and GitHub buried in the body. osint.industries reported the profile and stopped. One of those Telegram handles resolved to an active threat-actor channel.

What is the best free OSINT username tool? Maigret if you can run a CLI (319 on the default set of about 500 sites). WhatsMyName.io if you want a no-install web check (228 of 483). Neither one extracts profile-card contacts or carries breach data. That is the trade.

Why did the platforms return such different counts for the same username? Different module pools and different detection rules. A tool that checks 396 modules cannot return more hits than it attempts, and one tool's "found" can be another's "unverified" depending on how it reads the response. That is why this article reports sources checked and profiles found side by side.

Can I use these tools for background checks? Not Revealer. It is not a consumer reporting agency, and its data may not be used for employment, tenant, credit, or insurance eligibility decisions. Use an FCRA-compliant provider for those purposes.

Get started

Ready to check your exposure?

Create a free account. Every result is pulled live, in real time, from public sources and endpoints we do not own. We do not retain your search data. Items you choose to save, publish, or monitor are kept until you delete them.

Create account