Skip to main content

Privacy-focused CLI OSINT toolkit with Tor-aware networking, WHOIS, DNS, indicator extraction, and optional local AI reporting.

Project description

Darkelf OSINT Lite

Darkelf OSINT Lite is a lightweight, terminal-first Open Source Intelligence (OSINT) toolkit inspired by the Darkelf project.

Designed for ethical security research, digital forensics, Capture the Flag (CTF) competitions, and investigative workflows, Darkelf OSINT Lite emphasizes privacy, safer defaults, modular architecture, and a streamlined command-line experience.

The toolkit includes:

  • Tor-aware networking
  • OSINT search and dorking
  • Safe web content retrieval
  • Indicator extraction
  • WHOIS and DNS lookups
  • Local AI-assisted report drafting (optional)
  • Structured report exporting

Important: This software is intended solely for lawful and authorized OSINT activities. Users are responsible for complying with all applicable laws and regulations.


Installation

Install from PyPI (Recommended)

pip install darkelf-osint-lite

Launch the application:

darkelf-osint-lite

Install from Source

Clone the repository:

git clone https://github.com/Darkelf-Labs/darkelf-osint-lite.git
cd darkelf-osint-lite

Install dependencies:

pip install -r requirements.txt

Run:

python main.py

Features

  • Privacy-focused command-line interface

  • Tor-aware networking

  • Multi-engine OSINT search

  • DuckDuckGo dork helper

  • Safe web page retrieval

  • Automatic indicator extraction

    • Email addresses
    • Domains
    • IPv4 addresses
    • Usernames
    • Cryptographic hashes
    • Phone numbers
  • WHOIS lookups

    • Domain WHOIS
    • IP WHOIS
  • DNS lookups

    • A
    • AAAA
    • MX
    • TXT
    • NS
    • CNAME
    • SOA
    • Reverse DNS (PTR)
    • Bulk DNS lookups
  • Darkelf Scribe local AI report drafting (optional)

  • Offline Progressive Web App (PWA) report viewer

  • JSON and Markdown report exports

  • Rich terminal interface

  • Automatic activity logging

Reports are saved to:

~/Documents/Darkelf/

Requirements

  • Python 3.10 or newer
  • Tor (recommended)
  • Ollama (optional for Darkelf Scribe)

Install dependencies manually if needed:

pip install rich requests beautifulsoup4 tldextract phonenumbers dnspython python-whois stem psutil pysocks

Note: Install python-whois, not the unrelated whois package.


Tor Setup

Darkelf OSINT Lite automatically detects Tor if available.

Typical SOCKS ports:

  • 9050
  • 9052
  • 9150

Verify Tor:

curl --socks5-hostname 127.0.0.1:9052 https://check.torproject.org/api/ip

Usage

Launch:

darkelf-osint-lite

The startup banner displays the current status:

Stealth: ON · Tor: enabled · DNS: available · WHOIS: available

Main capabilities include:

  • Scan
  • Dork
  • Fetch
  • Indicators
  • WHOIS / DNS
  • Darkelf Scribe
  • Report Viewer

Darkelf Scribe (Optional)

Darkelf Scribe integrates with Ollama to generate structured OSINT investigation drafts entirely on your local machine.

Supported capabilities include:

  • Draft investigation summaries
  • Evidence organization
  • Markdown export
  • JSON export
  • Offline PWA report viewing

Install Ollama separately:

https://ollama.com


Security

Darkelf OSINT Lite emphasizes privacy-first defaults.

Features include:

  • Tor-aware networking
  • Safe subprocess execution
  • URL normalization and validation
  • Tracker blocking
  • Structured logging
  • Local AI processing (no cloud dependency)

This Lite edition intentionally excludes destructive or anti-forensic functionality.


Troubleshooting

Tor unavailable

  • Ensure Tor is running.
  • Verify the SOCKS port.
  • Install pysocks.

WHOIS errors

  • Install python-whois.
  • Remove the incorrect whois package if installed.

DNS lookup errors

  • Install dnspython.

Contributing

Contributions are welcome.

Please:

  • Fork the repository
  • Create a feature branch
  • Submit a pull request with a clear description

Security improvements, bug fixes, documentation, and usability enhancements are encouraged.


License

Licensed under the GNU Lesser General Public License v3.0 or later (LGPL-3.0-or-later).

See the LICENSE file for details.


Author

Dr. Kevin Moore

Creator of the Darkelf project and the Darkelf family of privacy-focused security and research tools.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

darkelf_osint_lite-3.0.4.tar.gz (26.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

darkelf_osint_lite-3.0.4-py3-none-any.whl (24.7 kB view details)

Uploaded Python 3

File details

Details for the file darkelf_osint_lite-3.0.4.tar.gz.

File metadata

  • Download URL: darkelf_osint_lite-3.0.4.tar.gz
  • Upload date:
  • Size: 26.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for darkelf_osint_lite-3.0.4.tar.gz
Algorithm Hash digest
SHA256 b480b7bd53c1fb41b96e24120ae8c2dd00e54027d51089aadee947dfe56132e5
MD5 c2713f045d860b8b3deab0f4ac2b8157
BLAKE2b-256 59303d0ec3a5f07a6a29b1af390ea419ab9a78755ba0eb39021f0f06698570ed

See more details on using hashes here.

Provenance

The following attestation bundles were made for darkelf_osint_lite-3.0.4.tar.gz:

Publisher: python-app.yml on Darkelf-Labs/Darkelf-OSINT-Lite

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file darkelf_osint_lite-3.0.4-py3-none-any.whl.

File metadata

File hashes

Hashes for darkelf_osint_lite-3.0.4-py3-none-any.whl
Algorithm Hash digest
SHA256 0d51bf083619eaa60dd9172696212ab97d617bcd4ba26035977ff3cc15f84f07
MD5 5e6694163fad53e47e5751d48d61ee28
BLAKE2b-256 60837e591388295aaf47b761006410eb80fb2d203fb3b01ab4bc30a6d6dac249

See more details on using hashes here.

Provenance

The following attestation bundles were made for darkelf_osint_lite-3.0.4-py3-none-any.whl:

Publisher: python-app.yml on Darkelf-Labs/Darkelf-OSINT-Lite

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page