Free vs Paid OSINT Tools: What You Actually Get
An honest breakdown of where free OSINT tooling is genuinely enough, where paid platforms earn their price, and how to tell which problem you actually have.
There is a genuinely excellent free OSINT ecosystem, and there are paid platforms costing more than a car. Both are appropriate — for different problems. Here is how to work out which one you have.
What free tooling does well
For a single question against a single identifier, free tools are frequently all you need. Public block explorers, certificate-transparency logs, breach-checking services, DNS lookups and registry search are free, authoritative, and often better than the equivalent inside a commercial suite.
If your work is occasional and self-contained — check this domain, look up this address — paying for a platform buys you very little.
Where free tooling breaks down
It breaks down at scale and at continuity. Specifically:
- •Correlation. Fifteen browser tabs do not tell you that the same email appeared in three of your cases.
- •Memory. Free tools have no notion of your previous investigations.
- •Monitoring. They answer a question now; they do not tell you when the answer changes.
- •Documentation. They produce screenshots, not defensible evidence packages.
- •Breadth. What you find depends entirely on which tool you thought to run.
That last point is the quiet one. Manual OSINT is bounded by the analyst's recall. You do not know what you missed, because you never queried it.
What the expensive platforms charge
The market has a large gap in the middle. Maltego Professional runs to several thousand per seat per year. Blockchain forensics suites like Chainalysis Reactor start around $40,000 per year for a single seat and run well into six figures for enterprise deployments.
Those prices are defensible for a government agency or a large exchange compliance team. They are simply out of reach for an individual investigator, a small fraud team, a journalist or a regional MSP — which is why so much of that work still happens in spreadsheets.
The honest trade-offs of the big platforms
Paying more does not remove every problem. Two consistent criticisms are worth knowing before you buy:
- •Learning curve. Graph-and-transform tools reward training that many teams never budget for, and unused seats are expensive seats.
- •Attribution opacity. Clustering and third-party labelling produce false positives, and labels that are outdated or overly broad are frequently treated as conclusive. Practitioners are explicitly advised to treat such output as investigative leads rather than definitive identifications.
How to decide
Ask yourself three questions:
- 1Do I investigate repeatedly, or occasionally? Repetition is what makes correlation and memory valuable.
- 2Does anyone rely on my output? If a report goes to a client, a court or a regulator, documentation stops being optional.
- 3Do I need to know when something changes? If yes, you need monitoring, and no free tool provides it.
Two or more yeses means tooling will pay for itself. All noes means stay free and spend the money elsewhere.
The middle ground
The useful question is not "free or expensive" but "what is the smallest thing that solves my actual problem". For most people that is: automated breadth so you stop missing sources, correlation across cases, continuous monitoring, and evidence you can hand to someone else — without a five-figure contract or a training course.
Try it without paying
Aletheia has free public tools — screen a crypto wallet against OFAC sanctions, or grade your domain's external attack surface — with no signup. Full tracing, correlation, monitoring and evidence export are the paid platform.