walid@portfolio:~/lab/osint-recon-tools$
cd../lab
01ideaOct 2026

A toolkit, a dark-web search engine, and an email lookup

Three reconnaissance tools security people actually use: Z4nzu’s hackingtool, the Ahmia search engine for Tor onion services, and the emailOSINT reverse-email lookup. What each one does, when to reach for it, and the single line that separates research from a crime. Checked against each project’s own pages

Reconnaissance is the first phase of any security assessment: before you test a system you map what is already exposed about it. These three tools each cover a different surface. hackingtool is an all-in-one launcher that installs and runs 215 open-source security tools from one menu, now wrapped in an AI layer. Ahmia is a search engine for the Tor network, run openly since 2014, that indexes onion services and filters abuse material. emailOSINT is a reverse-email lookup that surfaces the accounts and breaches tied to an address. All three are legal to run and useful for defenders, researchers and learners. All three are also only lawful when pointed at systems and people you own, have consent for, or are authorised to test. That line, not the tool, is what matters.

OSINTReconSecurityPentestTorhackingtool (GitHub) ↗Ahmia ↗emailOSINT ↗The Tor Project ↗Ahmia on Wikipedia ↗Have I Been Pwned ↗
!
Authorized use only

This is a reference for penetration testers, blue teams, OSINT researchers, bug-bounty hunters, CTF players, students and anyone checking their own exposure. Reconnaissance against systems or people you do not own, have consent for, or are not authorised to test is illegal in most places, under laws like the US Computer Fraud and Abuse Act and equivalents elsewhere, and profiling people by email engages privacy law such as the GDPR. Nothing below is a walkthrough for attacking anyone. It describes what each tool is and when a professional reaches for it.

Every real assessment starts with reconnaissance: before you touch a target you map what is already visible about it. The three tools here each work a different surface. One is a launcher that collects hundreds of other tools in a single menu. One is a search engine for a part of the web ordinary search engines don’t index. One looks up what a single email address is connected to. None of them breaks into anything by itself; they gather and organise what is already out there, which is exactly why they are as useful to a defender auditing their own exposure as to anyone else.

Checked, not copied

What each project says, on 1 October 2026

Checked against the hackingtool GitHub repository, ahmia.fi and its Wikipedia entry, and the emailOSINT site.

ClaimWhat the source says
hackingtool, the scaleAt 80.0k stars and 9.1k forks, MIT-licensed and written in Python, by the author Z4nzu. The README calls it an all-in-one launcher for 215 tools across 21 categories, rebuilt around an AI layer that maps plain English to the right tool.
hackingtool, the purposeStated plainly: “For authorized security testing only.” The README says it is “Built for penetration testers · red teamers · blue-team/SOC and DFIR analysts · OSINT researchers · bug-bounty hunters · CTF players · security researchers and students — all working legally, on systems they own or are authorised to test.”
Ahmia, what and whoA clearnet search engine for Tor onion services, created by the security researcher Juha Nurmi, who registered ahmia.fi in 2010 and built it out in the 2014 Google Summer of Code with the Tor Project. The crawler (Scrapy), index (Elasticsearch) and website (Django) are all open source.
Ahmia, the abuse policyEnforced, not decorative: “Abuse material is not allowed on Ahmia.” It keeps a blacklist of banned services, removes reported abuse “as soon as possible”, and asks users to report anything they find.
emailOSINT, what it claimsAn AI-powered reverse email lookup that surfaces the footprint behind an address, linked accounts, breach appearances and infostealer-log mentions, with free searches and no signup. Its page is a single app showing only that tagline until you run a search, so the operator, exact data sources and terms couldn’t be verified from the page itself.
Tool 1

hackingtool: the all-in-one launcher

hackingtool is not an exploit. It is a menu. From one Python program it installs and launches 215 separate open-source security tools, grouped into 21 categories, so you don’t hunt down and set up each one by hand. It is the most-starred project of its kind on GitHub, MIT-licensed, and runs on Linux or macOS, the kind of thing people keep on a Kali or Parrot box.

The recent rebuild adds an AI layer over the menu. You describe what you are trying to do in plain English and it maps that to the right tool; a /find command searches its own catalogue and then the GitHub API, and a /goal command breaks an objective into steps. The AI can run against an OpenAI-compatible endpoint or a local Ollama model, and long jobs run in the background through tmux.

The 21 categories it covers

From the README. They map to the phases of an authorized engagement, from staying anonymous through recon to post-exploitation and forensics.

✓Anonymity, information gathering, wordlist generation✓Wireless attacks, SQL injection, XSS, web attacks✓Phishing, payload creation, exploit frameworks✓Post-exploitation, remote administration, DDoS✓Reverse engineering, steganography, forensics✓Active Directory, cloud security, mobile security✓Password and hash cracking, plus a catch-all “other”
When it earns its place

Legitimate use cases

✓Standing up a learning or lab machine fast: one install brings the common tools for each phase instead of a day of setup✓CTF practice and classes, where you want breadth and a map of what exists more than a hand-tuned kit✓An authorized penetration test or red-team engagement, as a launcher for tools you would otherwise run one by one✓Blue-team and DFIR work: seeing the same offensive tooling your adversaries use, so you can detect and defend against it✓Learning the shape of the attack lifecycle, since the menu is organised by phase

Install the launcher

The benign part: this sets up the menu itself on a Linux or macOS box with Python 3.10+. It installs nothing to attack with until you choose a tool, and choosing one doesn’t make using it legal. pipx is the README’s recommended path; a published Docker image and a uv install also exist.

terminal7 lines
# Linux or macOS, Python 3.10+
git clone https://github.com/Z4nzu/hackingtool.git
cd hackingtool
pipx install .

# or run the published Docker image instead
docker run -it --rm hardikzinzu/hackingtool:latest
!
What the launcher does and doesn’t change

It is a convenience wrapper around other people’s tools; it adds reach, not permission. Several categories, phishing, DDoS, remote-administration “RATs”, password cracking and bruteforce, are straightforwardly criminal when aimed at systems or accounts you don’t own or aren’t authorised to test, and bundling them behind one menu doesn’t change that. Keep it to your own lab, a CTF, or an engagement with written scope. Read what any bundled tool does before you run it, since you are responsible for it, not the menu.

Tool 2

Ahmia: a search engine for the Tor network

Most search engines don’t index Tor onion services, the .onion sites that are only reachable over the Tor network. Ahmia does. It has crawled and indexed them since 2014, and you reach Ahmia itself on the ordinary web, then open the results in Tor Browser. It is a long-running, open project by the security researcher Juha Nurmi, built during a Google Summer of Code with the Tor Project, with its crawler, index and site all published.

What sets Ahmia apart from the folklore about “dark web” indexes is that it filters. Its stated policy is that abuse material is not allowed; it keeps a blacklist of banned services and removes reported abuse. That makes it the sober, research-grade way to see what is actually on the network, rather than a directory of the worst of it.

When it earns its place

Legitimate use cases

✓Research into the Tor ecosystem: what kinds of services exist, and how the network is used, with public statistics Ahmia also publishes✓Finding the real onion address of a service that offers one, such as a newsroom’s SecureDrop, a privacy tool, or an official mirror, instead of trusting a link from a forum✓Threat intelligence and brand monitoring: checking whether your organisation, domains or data are being mentioned or offered on indexed onion sites✓Journalism and digital-rights work that needs to reach or cite legitimate onion services✓Teaching how Tor and onion services work, with a source that filters abuse material out of the way
!
A search engine, not a shield

Ahmia indexes and filters, but opening a result still means entering the Tor network, where you are responsible for where you go and what you access. The filtering removes known abuse material; it is not a guarantee a given site is safe or legal to use. Browse with the same judgement and the same law you would anywhere else.

Tool 3

emailOSINT: the footprint behind an address

Give emailOSINT an email address and it looks up what that address is connected to across public and leaked sources: other accounts registered with it, data breaches it has appeared in, and mentions in infostealer logs. It markets itself as AI-powered, fast, free, and usable without signing up. This kind of reverse-email lookup is a staple of OSINT work, and the same job can be done with tools like Have I Been Pwned for the breach side alone.

A note on verification: the site’s page is a single app that shows only its tagline until you run a search, so its operator, exact data sources and terms couldn’t be confirmed from the page. Treat any single lookup service as one input to check against others, not as ground truth.

When it earns its place

Legitimate use cases

✓Checking your own exposure: which accounts and breaches are tied to your address, so you can rotate passwords and lock things down✓Verifying a sender before you trust an email, as part of triaging a suspected phishing or fraud attempt✓Due diligence on a counterparty you are about to transact with, within what the law allows✓Authorized investigations and account recovery, where you have the standing to look✓Security awareness training: showing people how much a single address can reveal, so they compartmentalise
!
Consent is the line here

Reverse-email OSINT is the easiest of these three to misuse, because it profiles a person, not a server. Run it on yourself, on an address you have consent to investigate, or under proper authority. Profiling someone without a lawful basis can breach privacy law such as the GDPR, and using what you find to stalk, dox or harass is a crime regardless of how the data was gathered. The data being public does not make every use of it lawful.

i
The common thread

None of these tools breaks in anywhere. They find and organise what is already exposed: tools that already exist, onion sites already published, data already leaked. That is why they belong to defenders and researchers as much as to anyone, and why the whole of their legality lives in one question you answer before you start: do you own this, have consent for it, or have authority to look? Get that right and they are how you understand your own attack surface. Get it wrong and the tool was never the problem.