OSINT
Capture a target's public footprint and data-leak / breach exposure
OSINT
The OSINT scan captures a target's open-source-intelligence footprint — exposed emails, hosts and subdomains, leaked secrets in public source, account and username presence — along with its data-leak and breach exposure. It queries public data sources only; it does not probe the target's own systems, so it can be run from anywhere.
Prerequisites
- The Safeguard CLI installed and signed in.
- Authorization (
--i-am-authorised).
Usage
Inputs are classified by shape, so one command fans out to the right sources. You can pass a domain, an email, a username, or a combination:
safeguard osint example.com --i-am-authorised
safeguard osint example.com jane@example.com janedoe --i-am-authorised| Input | What it collects |
|---|---|
A domain (example.com) | Public footprint — hosts, subdomains, exposed emails |
An email (jane@example.com) | Which public services the address is registered on, and breach exposure |
A username (janedoe) | Cross-platform account presence |
Breach-data providers
Free public sources run automatically. Breach-data providers run only when you supply your own API key, so nothing paid or legally sensitive runs implicitly:
SG_HIBP_API_KEY=your-key safeguard osint jane@example.com --i-am-authorisedNo credential value is ever stored in a finding — only the fact of exposure.
What you get
- Findings — public footprint, leaked secrets, and breach / data-leak exposure for the target.
Results upload to a project in your console when the scan completes.
Notes
- Run OSINT only against domains, addresses, and identities you own or are authorized to assess.