CodeariaAcademy
GitHub repositorycommit this monthAnalyticsAutomation

Flowsint

9.6k

An open-source platform for graph-based OSINT investigations: a domain, email, username, phone number or crypto wallet grows into a map of connections. It runs on your own machine in Docker, so the data never leaves it.

We have not run it ourselves: described from the docs and the repository.

In numbers

GitHub stars as of 6 October 2026
enrichers in the code
release of 26 August 2026
licence

What it is

Flowsint turns scattered lookups into a single board. You drop a starting point on the graph, such as a domain, an email or a username, and run enrichers: DNS and WHOIS, subdomain discovery, profiles by username via Maigret and Sherlock, email breaches, wallet transactions. Each result lands on the graph as a new node you can keep exploring from, and the whole web of links is stored in Neo4j on your own server.

What sets it apart from a handful of separate terminal tools is that the connections stay visible and keep building up: there is no need to merge the output of a dozen scripts into a spreadsheet. And for those who work with an agent, the repository ships a Claude Code skill that knows how the project is laid out and helps you write your own enricher for the API you need. The authors state plainly that the tool is meant for lawful investigations and prohibit surveillance and de-anonymising people.

How it works

make prod
Clone the repository and run make prod (on Windows, docker compose -f docker-compose.prod.yml up -d); prebuilt images are pulled from GitHub Container Registry.
localhost:5173
The interface opens on port 5173 and there are no default accounts: the first user signs up on their own.
Neo4j
The graph lives in Neo4j, service data in PostgreSQL, and enricher jobs run through Redis and Celery; only the interface port is exposed.
vault
Keys for external services (HIBP, Dehashed, Etherscan, WhoisXML and others) are kept in an encrypted vault inside the app.
.claude/skills
The flowsint-enricher-builder skill tells the agent where the types and base class live and helps wire up a new external API as an enricher.

Know before installing

Breach lookups and some other enrichers only work with your own keys for paid services; without them you mostly get DNS, WHOIS and username search.
The authors call the project early-stage: the enricher list in the README lags behind the code, and test coverage is incomplete.
Before exposing it to a network, change the secrets in .env and add your host to the nginx allowlist; out of the box the setup is meant for a single machine.

Comments