A toolkit, a dark-web search engine, and an email lookup
Three reconnaissance tools security people actually use: Z4nzu’s hackingtool, the Ahmia search engine for Tor onion services, and the emailOSINT reverse-email lookup. What each one does, when to reach for it, and the single line that separates research from a crime. Checked against each project’s own pages
Reconnaissance is the first phase of any security assessment: before you test a system you map what is already exposed about it. These three tools each cover a different surface. hackingtool is an all-in-one launcher that installs and runs 215 open-source security tools from one menu, now wrapped in an AI layer. Ahmia is a search engine for the Tor network, run openly since 2014, that indexes onion services and filters abuse material. emailOSINT is a reverse-email lookup that surfaces the accounts and breaches tied to an address. All three are legal to run and useful for defenders, researchers and learners. All three are also only lawful when pointed at systems and people you own, have consent for, or are authorised to test. That line, not the tool, is what matters.
This is a reference for penetration testers, blue teams, OSINT researchers, bug-bounty hunters, CTF players, students and anyone checking their own exposure. Reconnaissance against systems or people you do not own, have consent for, or are not authorised to test is illegal in most places, under laws like the US Computer Fraud and Abuse Act and equivalents elsewhere, and profiling people by email engages privacy law such as the GDPR. Nothing below is a walkthrough for attacking anyone. It describes what each tool is and when a professional reaches for it.
Every real assessment starts with reconnaissance: before you touch a target you map what is already visible about it. The three tools here each work a different surface. One is a launcher that collects hundreds of other tools in a single menu. One is a search engine for a part of the web ordinary search engines don’t index. One looks up what a single email address is connected to. None of them breaks into anything by itself; they gather and organise what is already out there, which is exactly why they are as useful to a defender auditing their own exposure as to anyone else.
What each project says, on 1 October 2026
Checked against the hackingtool GitHub repository, ahmia.fi and its Wikipedia entry, and the emailOSINT site.
hackingtool: the all-in-one launcher
hackingtool is not an exploit. It is a menu. From one Python program it installs and launches 215 separate open-source security tools, grouped into 21 categories, so you don’t hunt down and set up each one by hand. It is the most-starred project of its kind on GitHub, MIT-licensed, and runs on Linux or macOS, the kind of thing people keep on a Kali or Parrot box.
The recent rebuild adds an AI layer over the menu. You describe what you are trying to do in plain English and it maps that to the right tool; a /find command searches its own catalogue and then the GitHub API, and a /goal command breaks an objective into steps. The AI can run against an OpenAI-compatible endpoint or a local Ollama model, and long jobs run in the background through tmux.
The 21 categories it covers
From the README. They map to the phases of an authorized engagement, from staying anonymous through recon to post-exploitation and forensics.
Legitimate use cases
Install the launcher
The benign part: this sets up the menu itself on a Linux or macOS box with Python 3.10+. It installs nothing to attack with until you choose a tool, and choosing one doesn’t make using it legal. pipx is the README’s recommended path; a published Docker image and a uv install also exist.
It is a convenience wrapper around other people’s tools; it adds reach, not permission. Several categories, phishing, DDoS, remote-administration “RATs”, password cracking and bruteforce, are straightforwardly criminal when aimed at systems or accounts you don’t own or aren’t authorised to test, and bundling them behind one menu doesn’t change that. Keep it to your own lab, a CTF, or an engagement with written scope. Read what any bundled tool does before you run it, since you are responsible for it, not the menu.
Ahmia: a search engine for the Tor network
Most search engines don’t index Tor onion services, the .onion sites that are only reachable over the Tor network. Ahmia does. It has crawled and indexed them since 2014, and you reach Ahmia itself on the ordinary web, then open the results in Tor Browser. It is a long-running, open project by the security researcher Juha Nurmi, built during a Google Summer of Code with the Tor Project, with its crawler, index and site all published.
What sets Ahmia apart from the folklore about “dark web” indexes is that it filters. Its stated policy is that abuse material is not allowed; it keeps a blacklist of banned services and removes reported abuse. That makes it the sober, research-grade way to see what is actually on the network, rather than a directory of the worst of it.
Legitimate use cases
Ahmia indexes and filters, but opening a result still means entering the Tor network, where you are responsible for where you go and what you access. The filtering removes known abuse material; it is not a guarantee a given site is safe or legal to use. Browse with the same judgement and the same law you would anywhere else.
emailOSINT: the footprint behind an address
Give emailOSINT an email address and it looks up what that address is connected to across public and leaked sources: other accounts registered with it, data breaches it has appeared in, and mentions in infostealer logs. It markets itself as AI-powered, fast, free, and usable without signing up. This kind of reverse-email lookup is a staple of OSINT work, and the same job can be done with tools like Have I Been Pwned for the breach side alone.
A note on verification: the site’s page is a single app that shows only its tagline until you run a search, so its operator, exact data sources and terms couldn’t be confirmed from the page. Treat any single lookup service as one input to check against others, not as ground truth.
Legitimate use cases
Reverse-email OSINT is the easiest of these three to misuse, because it profiles a person, not a server. Run it on yourself, on an address you have consent to investigate, or under proper authority. Profiling someone without a lawful basis can breach privacy law such as the GDPR, and using what you find to stalk, dox or harass is a crime regardless of how the data was gathered. The data being public does not make every use of it lawful.
None of these tools breaks in anywhere. They find and organise what is already exposed: tools that already exist, onion sites already published, data already leaked. That is why they belong to defenders and researchers as much as to anyone, and why the whole of their legality lives in one question you answer before you start: do you own this, have consent for it, or have authority to look? Get that right and they are how you understand your own attack surface. Get it wrong and the tool was never the problem.