From source in a venv
Alternativesourcegit clone https://github.com/smicallef/spiderfoot && cd spiderfoot
python3 -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt && python3 sf.py -l 127.0.0.1:5001
Automated OSINT collection with a reviewable module set
Community. Contributor-submitted. Not every claim has been re-checked. Cross-check against the upstream documentation before relying on a command.
SpiderFoot orchestrates many public data sources behind one interface: run a scan against a domain or IP, choose modules, and read the correlations it draws. The web UI exists so a human can judge each element rather than trusting a summary.
Module quality depends on the API keys you provide, so results are only as complete as your configuration. Every element carries the source and the raw data — use it when you cite anything.
Supported platforms
5
Documented install or usage guidance
Learning curve
intermediate
Difficulty of becoming productive, not of the underlying theory
Tags
osint, modules, correlation, domain, automation
Dataset entry
spiderfoot.ts
Reviewed 2025-12-21
Grouped by platform. Elevation requirements are marked per method.
git clone https://github.com/smicallef/spiderfoot && cd spiderfoot
python3 -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt && python3 sf.py -l 127.0.0.1:5001
docker run --rm -it -p 127.0.0.1:5001:5001 -v ~/.spiderfoot:/root/.spiderfoot ghcr.io/smicallef/spiderfoot:latest
Package availability follows your distribution and enabled repositories. Entry revised 21 Dec 2025 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
The web interface drives scans; the module set and options are chosen per scan.
python3 sf.py -l 127.0.0.1:5001
The sfl-cli client runs a scan without the UI, which is what a scheduled job needs.
python3 sfl-cli -d 'DOMAIN' -m sfp_dns,sfp_whois,sfp_certtrans -s -t 5
Notes
Scan results are available through the HTTP API so exports can go into a notebook.
curl -s http://127.0.0.1:5001/scans | head -c 400
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
Configure keys in Settings, disable modules you cannot feed, and note which sources were unavailable in the report.
Possible causes
Usual fix
Use an SSH tunnel (`ssh -L 5001:127.0.0.1:5001 host`) rather than exposing the UI on a network interface.
Not documented yet: maltego. Request an entry and it will link up automatically.Request a tool
Side-by-side
Where to verify anything on this page. External links open in a new tab.
theHarvester cover adjacent parts of the same job.