Git Product home page Git Product logo

pockint's Introduction

Icon

made with python Supported platforms GitHub release GitHub last commit GitHub All Releases Twitter Follow

POCKINT (a.k.a. Pocket Intelligence) is the OSINT swiss army knife for DFIR/OSINT professionals. A lightweight and portable GUI program, it provides users with essential OSINT capabilities in a compact form factor: POCKINT's input box accepts typical indicators (URL, IP, MD5) and gives users the ability to perform basic OSINT data mining tasks in an iterable manner.

demo

Installation

You can grab the latest version from the releases page. POCKINT is provided as a single executable that can be stored and run anywhere on computers. POCKINT is available for Windows only.

Features

Why use it? POCKINT is designed to be simple, portable and powerful.

โญ Simple: There's plenty of awesome OSINT tools out there. Trouble is they either require analysts to be reasonably comfortable with the command line (think pOSINT) or give you way too many features (think Maltego). POCKINT focuses on simplicity: INPUT > RUN TRANSFORM > OUTPUT ... rinse and repeat. It's the ideal tool to get results quickly and easily through a simple interface.

๐Ÿ“ฆ Portable: Most tools either require installation, a license or configuration. POCKINT is ready to go whenever and wherever. Put it in your jump kit USB, investigation VM or laptop and it will just run.

๐Ÿš€ Powerful: POCKINT combines cheap OSINT sources (whois/DNS) with the power of specialised APIs. From the get go you can use a suite of in-built transforms. Add in a couple of API keys and you can unlock even more specialised data mining capabilities.

The latest version is capable of running the following data mining tasks:

Hostnames

Source Transform API key needed?
DNS IP lookup โŒ
DNS MX lookup โŒ
DNS NS lookup โŒ
DNS TXT lookup โŒ
WHOIS Domain dnssec status โŒ
WHOIS Domain creation โŒ
WHOIS Domain expiration โŒ
WHOIS Domain emails โŒ
WHOIS Domain registrar โŒ
WHOIS Registrant location โŒ
WHOIS Registrant org โŒ
WHOIS Registrant name โŒ
WHOIS Registrant address โŒ
WHOIS Registrant zipcode โŒ
crt.sh Subdomains โŒ
Virustotal Downloaded samples โœ”๏ธ
Virustotal Detected URLs โœ”๏ธ
Virustotal Subdomains โœ”๏ธ
OTX Passive DNS โœ”๏ธ
OTX malicious check โœ”๏ธ
OTX Malware type โœ”๏ธ
OTX Malware hash โœ”๏ธ
OTX Observed urls โœ”๏ธ
OTX Geolocate โœ”๏ธ

IP Adresses

Note: Only IPv4 Addresses are supported

Source Transform API key needed?
DNS Reverse lookup โŒ
Shodan Ports โœ”๏ธ
Shodan Geolocate โœ”๏ธ
Shodan Coordinates โœ”๏ธ
Shodan CVEs โœ”๏ธ
Shodan ISP โœ”๏ธ
Shodan City โœ”๏ธ
Shodan ASN โœ”๏ธ
Virustotal Network report โœ”๏ธ
Virustotal Communicating samples โœ”๏ธ
Virustotal Downloaded samples โœ”๏ธ
Virustotal Detected URLs โœ”๏ธ
OTX Passive DNS โœ”๏ธ
OTX Malicious check โœ”๏ธ
OTX Malware type โœ”๏ธ
OTX Malware hash โœ”๏ธ
OTX Observed urls โœ”๏ธ
OTX Geolocate โœ”๏ธ

Urls

Source Transform API key needed?
DNS Extract hostname โŒ
Virustotal Malicious check โœ”๏ธ
Virustotal Reported detections โœ”๏ธ
OTX Geolocate โœ”๏ธ
OTX Parse url โœ”๏ธ
OTX malicious check โœ”๏ธ
OTX Http response analysis โœ”๏ธ

Hashes

Note: Both MD5 and SHA256 hashes are supported

Source Transform API key needed?
Virustotal Malicious check โœ”๏ธ
Virustotal Malware type โœ”๏ธ
OTX Malicious check โœ”๏ธ

Emails

Source Transform API key needed?
N/A Extract domain โŒ

New APIs and input integrations are in the works, consult the issues page to check out what's brewing or feel free to propose your own.

Like it?

If you like the tool please consider contributing.

The tool received a few "honourable" mentions, including:

Please note: There have been a small number of reports indicating that pockint triggers false positives on antivirus protected systems (to date Avast, AVG and Norton). The issue seems to be caused by pyinstaller, the python package used to freeze and distribute pockint. If pockint triggers your antivirus please submit an issue and the author will submit a false positive report to the concerned antivirus provider.

pockint's People

Contributors

netevert avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.