Privacy-focused CLI OSINT toolkit with Tor-aware networking, WHOIS, DNS, indicator extraction, and optional local AI reporting.
Project description
Darkelf OSINT Lite
Darkelf OSINT Lite is a lightweight, terminal-first Open Source Intelligence (OSINT) toolkit inspired by the Darkelf project.
Designed for ethical security research, digital forensics, Capture the Flag (CTF) competitions, and investigative workflows, Darkelf OSINT Lite emphasizes privacy, safer defaults, modular architecture, and a streamlined command-line experience.
The toolkit includes:
- Tor-aware networking
- OSINT search and dorking
- Safe web content retrieval
- Indicator extraction
- WHOIS and DNS lookups
- Local AI-assisted report drafting (optional)
- Structured report exporting
Important: This software is intended solely for lawful and authorized OSINT activities. Users are responsible for complying with all applicable laws and regulations.
Installation
Install from PyPI (Recommended)
pip install darkelf-osint-lite
Launch the application:
darkelf-osint-lite
Install from Source
Clone the repository:
git clone https://github.com/Darkelf-Labs/darkelf-osint-lite.git
cd darkelf-osint-lite
Install dependencies:
pip install -r requirements.txt
Run:
python main.py
Features
-
Privacy-focused command-line interface
-
Tor-aware networking
-
Multi-engine OSINT search
-
DuckDuckGo dork helper
-
Safe web page retrieval
-
Automatic indicator extraction
- Email addresses
- Domains
- IPv4 addresses
- Usernames
- Cryptographic hashes
- Phone numbers
-
WHOIS lookups
- Domain WHOIS
- IP WHOIS
-
DNS lookups
- A
- AAAA
- MX
- TXT
- NS
- CNAME
- SOA
- Reverse DNS (PTR)
- Bulk DNS lookups
-
Darkelf Scribe local AI report drafting (optional)
-
Offline Progressive Web App (PWA) report viewer
-
JSON and Markdown report exports
-
Rich terminal interface
-
Automatic activity logging
Reports are saved to:
~/Documents/Darkelf/
Requirements
- Python 3.10 or newer
- Tor (recommended)
- Ollama (optional for Darkelf Scribe)
Install dependencies manually if needed:
pip install rich requests beautifulsoup4 tldextract phonenumbers dnspython python-whois stem psutil pysocks
Note: Install python-whois, not the unrelated whois package.
Tor Setup
Darkelf OSINT Lite automatically detects Tor if available.
Typical SOCKS ports:
- 9050
- 9052
- 9150
Verify Tor:
curl --socks5-hostname 127.0.0.1:9052 https://check.torproject.org/api/ip
Usage
Launch:
darkelf-osint-lite
The startup banner displays the current status:
Stealth: ON · Tor: enabled · DNS: available · WHOIS: available
Main capabilities include:
- Scan
- Dork
- Fetch
- Indicators
- WHOIS / DNS
- Darkelf Scribe
- Report Viewer
Darkelf Scribe (Optional)
Darkelf Scribe integrates with Ollama to generate structured OSINT investigation drafts entirely on your local machine.
Supported capabilities include:
- Draft investigation summaries
- Evidence organization
- Markdown export
- JSON export
- Offline PWA report viewing
Install Ollama separately:
Security
Darkelf OSINT Lite emphasizes privacy-first defaults.
Features include:
- Tor-aware networking
- Safe subprocess execution
- URL normalization and validation
- Tracker blocking
- Structured logging
- Local AI processing (no cloud dependency)
This Lite edition intentionally excludes destructive or anti-forensic functionality.
Troubleshooting
Tor unavailable
- Ensure Tor is running.
- Verify the SOCKS port.
- Install
pysocks.
WHOIS errors
- Install
python-whois. - Remove the incorrect
whoispackage if installed.
DNS lookup errors
- Install
dnspython.
Contributing
Contributions are welcome.
Please:
- Fork the repository
- Create a feature branch
- Submit a pull request with a clear description
Security improvements, bug fixes, documentation, and usability enhancements are encouraged.
License
Licensed under the GNU Lesser General Public License v3.0 or later (LGPL-3.0-or-later).
See the LICENSE file for details.
Author
Dr. Kevin Moore
Creator of the Darkelf project and the Darkelf family of privacy-focused security and research tools.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file darkelf_osint_lite-3.0.4.tar.gz.
File metadata
- Download URL: darkelf_osint_lite-3.0.4.tar.gz
- Upload date:
- Size: 26.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b480b7bd53c1fb41b96e24120ae8c2dd00e54027d51089aadee947dfe56132e5
|
|
| MD5 |
c2713f045d860b8b3deab0f4ac2b8157
|
|
| BLAKE2b-256 |
59303d0ec3a5f07a6a29b1af390ea419ab9a78755ba0eb39021f0f06698570ed
|
Provenance
The following attestation bundles were made for darkelf_osint_lite-3.0.4.tar.gz:
Publisher:
python-app.yml on Darkelf-Labs/Darkelf-OSINT-Lite
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
darkelf_osint_lite-3.0.4.tar.gz -
Subject digest:
b480b7bd53c1fb41b96e24120ae8c2dd00e54027d51089aadee947dfe56132e5 - Sigstore transparency entry: 2211407978
- Sigstore integration time:
-
Permalink:
Darkelf-Labs/Darkelf-OSINT-Lite@7535b710cba66a343f53495ec29755d4aeba6161 -
Branch / Tag:
refs/tags/v.3.0.4 - Owner: https://github.com/Darkelf-Labs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
python-app.yml@7535b710cba66a343f53495ec29755d4aeba6161 -
Trigger Event:
push
-
Statement type:
File details
Details for the file darkelf_osint_lite-3.0.4-py3-none-any.whl.
File metadata
- Download URL: darkelf_osint_lite-3.0.4-py3-none-any.whl
- Upload date:
- Size: 24.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
0d51bf083619eaa60dd9172696212ab97d617bcd4ba26035977ff3cc15f84f07
|
|
| MD5 |
5e6694163fad53e47e5751d48d61ee28
|
|
| BLAKE2b-256 |
60837e591388295aaf47b761006410eb80fb2d203fb3b01ab4bc30a6d6dac249
|
Provenance
The following attestation bundles were made for darkelf_osint_lite-3.0.4-py3-none-any.whl:
Publisher:
python-app.yml on Darkelf-Labs/Darkelf-OSINT-Lite
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
darkelf_osint_lite-3.0.4-py3-none-any.whl -
Subject digest:
0d51bf083619eaa60dd9172696212ab97d617bcd4ba26035977ff3cc15f84f07 - Sigstore transparency entry: 2211408012
- Sigstore integration time:
-
Permalink:
Darkelf-Labs/Darkelf-OSINT-Lite@7535b710cba66a343f53495ec29755d4aeba6161 -
Branch / Tag:
refs/tags/v.3.0.4 - Owner: https://github.com/Darkelf-Labs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
python-app.yml@7535b710cba66a343f53495ec29755d4aeba6161 -
Trigger Event:
push
-
Statement type: