Flowsint
9.6kAn open-source platform for graph-based OSINT investigations: a domain, email, username, phone number or crypto wallet grows into a map of connections. It runs on your own machine in Docker, so the data never leaves it.
We have not run it ourselves: described from the docs and the repository.
In numbers
What it is
Flowsint turns scattered lookups into a single board. You drop a starting point on the graph, such as a domain, an email or a username, and run enrichers: DNS and WHOIS, subdomain discovery, profiles by username via Maigret and Sherlock, email breaches, wallet transactions. Each result lands on the graph as a new node you can keep exploring from, and the whole web of links is stored in Neo4j on your own server.
What sets it apart from a handful of separate terminal tools is that the connections stay visible and keep building up: there is no need to merge the output of a dozen scripts into a spreadsheet. And for those who work with an agent, the repository ships a Claude Code skill that knows how the project is laid out and helps you write your own enricher for the API you need. The authors state plainly that the tool is meant for lawful investigations and prohibit surveillance and de-anonymising people.
How it works
make prod (on Windows, docker compose -f docker-compose.prod.yml up -d); prebuilt images are pulled from GitHub Container Registry.flowsint-enricher-builder skill tells the agent where the types and base class live and helps wire up a new external API as an enricher.Know before installing
.env and add your host to the nginx allowlist; out of the box the setup is meant for a single machine.


Comments