PhantomSignal :: Open-Source OSINT Intelligence Framework
Project description
PhantomSignal
Open-source OSINT intelligence framework — "Map the surface. Own the signal."
⚡ What's New in v1.24.0
Streamlined to two themes
The web console now ships two carefully tuned themes built on semantic role tokens — Dark (a deep-slate federal console, the default) and Light (clean and print-friendly). Switch from the ☀ / ☾ segmented control in the nav; your choice persists in the browser and is applied before first paint, so there's no flash on reload. Every token in both themes is validated to WCAG AA contrast.
Plain-language interface
The web UI was rewritten from codenames to clear, function-first labels — Dashboard, New Scan, Scans, Profiler, Integrations — so a first-time user can tell what everything does. Findings, Risk Score, Data Sources, and consistent severity language throughout.
Roboto type + signal mark
Roboto for UI text (tables, terminal, and code stay monospace for alignment), a font-based ∿ signal glyph replacing the old ASCII logo, and a PS-monogram favicon.
Clickable dashboard + one-click re-scan
Dashboard stat cards are now links into the matching view, and any completed scan can be re-run against the same target with its original profile, modules, and options — from the results page or any Scans-list row.
Honest risk gradient
The Risk Score meter now runs a true green → amber → red ramp, so a low score reads green (safe) at a glance in every theme.
🎬 A Scan in Action
A single command runs the full pipeline — DNS and WHOIS resolution, port and service scanning, technology fingerprinting, threat-intelligence correlation across 45+ sources, and a web-surface crawl — then rolls every finding into a single Risk Score and writes a shareable HTML report.
$ phantomsignal scan example.com --profile standard --format html
◈ Target : example.com (domain)
◈ Profile : standard (~2–5 min)
◈ Modules : dns_recon port_scan tech_detect api_hunt web_crawl intel
[1/6] DNS & WHOIS ......... 42 records · 7 subdomains
[2/6] Port scan .......... 6 open · 22 80 443 8080 …
[3/6] Tech fingerprint ... nginx · Cloudflare · React · WordPress
[4/6] Threat intel ....... 31 sources queried · 0 malicious
[5/6] Web crawl .......... 128 URLs · 3 exposed endpoints
[6/6] Scoring ............ Risk Score 34 / 100 (MEDIUM)
✓ Report written → ./reports/example.com.html
Stages run concurrently where possible and degrade gracefully — a module without a configured API key returns empty rather than failing the scan.
Web UI — Theme Options
The web console ships with two built-in themes, selectable from the segmented switch (☀ / ☾) in the top navigation bar. Your preference is saved automatically and applied before first paint, so there's no flash on reload. Every token in every theme is validated to WCAG AA contrast.
| Theme | Description |
|---|---|
| Dark (default) | Deep-slate federal console — federal-blue hero, gold accents, restrained glow |
| Light | Clean daytime / print-friendly — white surfaces, federal-blue accents, flat (no glow) |
⚡ What is PhantomSignal?
PhantomSignal is a community-powered, open-source OSINT intelligence framework built for security researchers, penetration testers, investigators, and enthusiasts. It combines web scraping, network reconnaissance, people intelligence aggregation, and threat analysis into a single cohesive platform.
LEGAL DISCLAIMER: PhantomSignal is for authorized security research, OSINT investigations, and educational purposes only. Only scan targets you have explicit permission to test. You are solely responsible for compliance with all applicable laws. The developers assume NO liability for misuse.
🔥 Features
🕷 Web Reconnaissance
- Scrapy-powered deep web crawler with JavaScript rendering support
- Technology detection — fingerprints 50+ technologies (CMS, frameworks, CDNs, WAFs)
- API endpoint hunter — discovers REST APIs, GraphQL, Swagger docs, admin panels,
.envleaks - Security header analysis with graded posture scoring
- Email, phone, link, and comment harvesting
🌐 Network Intelligence
- nmap-powered port scanner — full service-version detection and OS fingerprinting via nmap (
-sV -O); pure-Python async TCP fallback when nmap unavailable — no config required - Expanded port coverage — 99 common ports by default, 1,000+ port profile, or full 65,535; covers WinRM, Webmin, InfluxDB, Docker API, Kubernetes, and more
- DNS recon — A/AAAA/MX/NS/TXT/SOA/CAA, zone transfer attempts, subdomain brute-force
- Certificate transparency via crt.sh — uncover subdomains via SSL history
- SPF/DMARC analysis — identify email spoofing vulnerabilities
- Reverse DNS and co-hosted domain discovery
🔬 Intelligence APIs (46+ Integrations)
| Category | APIs |
|---|---|
| Network Scanning | Shodan, Censys, ZoomEye, BinaryEdge |
| Threat Intelligence | VirusTotal, AbuseIPDB, GreyNoise, AlienVault OTX, Intelligence X |
| Email & Breach | Hunter.io, HaveIBeenPwned, EmailRep |
| Domain/Web | SecurityTrails, URLScan.io, WhoisXML, Local WHOIS |
| Geolocation | IPInfo.io |
| Phone | Abstract API phone validation |
| People Search | Pipl, FullContact, WhitePages, Spokeo, Clearbit |
| Social | GitHub, Twitter/X, Reddit, Mastodon, Keybase, Gravatar, HackerNews, Twitch, YouTube, Instagram, TikTok, LinkedIn, Tumblr, Flickr, Spotify, Steam, VK, Telegram, Discord, Facebook |
| Custom | Bring your own API via plugin architecture |
👤 Profiler (People Intelligence)
LexisNexis-style identity aggregation from public records:
- Cross-correlates data from multiple people-search APIs
- Discovers emails, phones, addresses, relatives, employers
- Breach data correlation via HIBP and other sources
- Social media profile linking
- Risk Score — digital exposure quantification (0-100)
- Social graph building and timeline reconstruction
📦 Export Formats
| Format | Description |
|---|---|
| JSON | Raw machine-readable data |
| CSV | Spreadsheet-compatible |
| HTML | Self-contained styled report |
| Professional dossier via ReportLab | |
| XML | Structured data |
| XLSX | Excel workbook |
| STIX 2.1 | Threat intelligence sharing format |
| Markdown | Human-readable report |
All formats support ZIP compression and AES-256-GCM encryption.
🌑 Covert Recon
- Low-and-slow Covert scan profile to minimize noise
- Identity rotation via user-agent spoofing
- Tor proxy integration (Docker compose profile:
covert) - Configurable request jitter and delays, toggled via Evasive mode
🔔 Additional Features
- Real-time live feed — WebSocket-powered terminal during scans
- Risk Score — composite risk/exposure scoring
- Scheduled Phantoms — recurring automated scans
- API health monitor — dashboard showing configured APIs and rate limits
- Light / Dark themes — switch between the default Dark console and a clean Light mode from the ☀ / ☾ segmented control in the nav; preference persisted in localStorage and applied before first paint
- Full REST API — integrate PhantomSignal into your own toolchain
- CLI interface —
phantomsignal scan,phantomsignal profile,phantomsignal export - Docker — single-command deployment
🚀 Quick Start
Option 1: Docker (Recommended)
git clone https://github.com/getphantomsignal/phantomsignal
cd phantomsignal
docker-compose up -d
# Open http://localhost:5000
Option 2: Manual Installation
# Python 3.10+ required
git clone https://github.com/getphantomsignal/phantomsignal
cd phantomsignal
pip install -e .
phantomsignal init
phantomsignal web --open-browser
Option 3: CLI Scan
# Quick scan
phantomsignal scan example.com --profile quick
# Full spectrum with export
phantomsignal scan 192.168.1.1 --type ip_recon --format html --output ./reports
# People intelligence
phantomsignal profile --email target@company.com --first-name John --last-name Doe
⚙️ Configuration
Environment Variables (Recommended for API Keys)
export SHODAN_API_KEY="your-shodan-key"
export VIRUSTOTAL_API_KEY="your-vt-key"
export HUNTER_API_KEY="your-hunter-key"
export HIBP_API_KEY="your-hibp-key"
export GREYNOISE_API_KEY="your-greynoise-key"
export IPINFO_TOKEN="your-ipinfo-token"
export ABUSEIPDB_API_KEY="your-abuseipdb-key"
export ALIENVAULT_API_KEY="your-otx-key"
export GITHUB_TOKEN="your-github-token"
export SECURITYTRAILS_API_KEY="your-st-key"
# See config/phantomsignal.yaml for full list
Config File
Copy config/phantomsignal.yaml to ~/.phantomsignal/config.yaml and customize.
🔌 Adding Custom APIs
PhantomSignal uses a plugin architecture. Adding a new intelligence source takes ~20 lines:
# phantomsignal/intel/apis/my_api.py
from phantomsignal.intel.apis.base import BaseIntelAPI, register_api, APICategory, APITier
@register_api
class MyAPI(BaseIntelAPI):
NAME = "myapi"
DESCRIPTION = "My custom intelligence source"
REQUIRES_KEY = True
TIER = APITier.FREE_LIMITED
CATEGORIES = [APICategory.NETWORK]
BASE_URL = "https://api.myservice.com/v1"
SIGN_UP_URL = "https://myservice.com/signup"
async def search(self, query: str, **kwargs):
data = await self._get(
f"{self.BASE_URL}/search",
params={"q": query, "key": self._api_key}
)
return [self._wrap_result("my_result", data)]
Then import it in phantomsignal/intel/orchestrator.py and it auto-registers.
🏗 Architecture
phantomsignal/
├── core/ — Engine, config, database, models
├── scrapers/ — Scrapy crawler, tech detector, port scanner, API hunter, DNS recon
├── intel/
│ ├── apis/ — 46+ API integrations (plugin architecture)
│ └── people/ — People intelligence aggregation
├── exporters/ — JSON/CSV/PDF/HTML/XML/XLSX/STIX + crypto wrapper
└── web/
├── routes/ — Flask blueprints (dashboard, scans, intel, settings, export, REST API)
├── templates/ — Jinja2 templates
└── static/ — CSS (role-token themes), JS (terminal, app)
🛡 REST API
# Create a scan
curl -X POST http://localhost:5000/api/v1/scans \
-H "Content-Type: application/json" \
-d '{"target": "example.com", "scan_type": "web_recon"}'
# Get results
curl http://localhost:5000/api/v1/scans/{scan_id}
# List all APIs
curl http://localhost:5000/api/v1/apis
# Health check
curl http://localhost:5000/api/v1/health
🤝 Contributing
PhantomSignal thrives on community contributions. Ways to help:
- Add API integrations — Follow the plugin pattern above
- Improve detection signatures — Expand
tech_detector.py - Bug reports — GitHub Issues
- Documentation — Improve the wiki
- Translations — Internationalize the UI
See CONTRIBUTING.md for guidelines. Please also review our Code of Conduct and Security Policy.
📖 Documentation
- Usage Guide — full walkthroughs, usage scenarios, CLI reference, and per-platform troubleshooting (Linux / macOS / Windows / Docker)
⚠️ Legal & Ethics
PhantomSignal is a dual-use tool. Operators are responsible for:
- Obtaining explicit authorization before scanning any system
- Complying with applicable laws (CFAA, GDPR, CCPA, ECPA, local laws)
- Respecting privacy and data protection regulations
- Not using this tool for harassment, stalking, or unauthorized surveillance
The developers provide this software as-is with no warranty. Misuse is your responsibility.
🏷 Topics
🤝 Community
| Document | Description |
|---|---|
| Code of Conduct | Community standards and expectations |
| Contributing Guidelines | How to contribute to PhantomSignal |
| Security Policy | Reporting vulnerabilities responsibly |
| License | MIT License terms |
📜 License
MIT License — see LICENSE
Built with questionable amounts of caffeine. "Map the surface. Own the signal." Some ghosts leave no trace. This one left commits. — Claude
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file phantomsignal-1.24.0.tar.gz.
File metadata
- Download URL: phantomsignal-1.24.0.tar.gz
- Upload date:
- Size: 334.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
fbed2efda140c90e666a78dfc5c226c7a02861441e3bce2bb72e2e146fb1ee5e
|
|
| MD5 |
82e4786ec6bdbcad0a576483a23f8c0a
|
|
| BLAKE2b-256 |
e49ab178fcd11b8b2fcc050b716c9375c96f9ad102e6ec77cd1ecbba4edd7003
|
File details
Details for the file phantomsignal-1.24.0-py3-none-any.whl.
File metadata
- Download URL: phantomsignal-1.24.0-py3-none-any.whl
- Upload date:
- Size: 364.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c7e5a332d79411e870a3da7015d21a9cf1f6ca6a9480ae51ded171717d00a077
|
|
| MD5 |
f9513f4d49bf1157903eed5e02ec9650
|
|
| BLAKE2b-256 |
52d24c8d47e0ae2a367383d884f644ec7146efbde43f420e4a648754d2708516
|