My OSINT Training
Free bookmarklets for open source intelligence investigators
Tools are essential for efficient OSINT work, and they don't always have to come at a cost! We make and share custom tools to help you perform tasks faster and more effectively. More detailed descriptions and walkthroughs are on our blog.
- Micah & Griffin
Install every bookmarklet in your browser in one step — no dragging required.
Bookmarklets last generated: checking...
Download HTML file then import into your Bookmarks ManagerVisit our blog for detailed walkthroughs, screenshots, and real-world examples of these tools.
Visit blog.myosint.training Watch on YouTube| Drag to bookmarks bar | Description | Script Type | Platform / Tags | Sample Output | Last updated (Version) |
|---|---|---|---|---|---|
| Extracts Airbnb user profile information and recent review history. Works on: https://*.airbnb.*/users/show/##### and https://*.airbnb.*/users/profile/##############
Tip: Wait for /users/show/ pages to fully load before running. Right-click the profile image in the modal and open it in a new tab for a larger, uncropped version — useful for reverse image searches. |
Active |
|
![]() | 2026-07-15 (v2) | |
| Extracts BandLab user profile information. Works on: https://bandlab.com/XXXXXXX |
Active |
BandLab |
![]() | 2026-07-15 (v2) | |
| Looks up the profile page for a Bluesky user based on their ID. Works on: https://bsky.app/profile/did:plc:XXXXXXX |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Extracts Bluesky user profile information. Works on: https://bsky.app/profile/XXXXXXX |
Passive |
|
![]() | 2026-07-15 (v1) | |
| Extracts Cash App user profile information. Works on: https://cash.app/$XXXXXXX
Note: Works differently than other bookmarklets to bypass CSP — it sends the extracted data to our My OSINT Training viewer page (hosted on GitHub), which combines it with the profile image for display. We do not log or track your OSINT work on that viewer page.
|
Passive |
|
![]() | 2026-07-13 (v2) | |
| Extracts Facebook user profile information. Works on: https://facebook.com/XXXXXXX |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Redirects a regular Facebook profile page to its Marketplace profile, then extracts join-date information from that page. Works on: https://www.facebook.com/XXXXXXX
Warning: Requires you to be logged in to Facebook.
Warning: Click once on a regular profile page to go to its Marketplace profile, then click the bookmarklet again on that page to extract the join date. May not work if the account uses the new Facebook interface (no creation date shown there).
Credit: Idea suggested by Craig Silverman.
|
Passive |
|
![]() | 2026-07-15 (v2) | |
| Displays the highest-resolution version of a 'locked' Facebook profile's photo in a new tab. | Passive |
|
![]() | 2026-07-15 (v2) | |
| Enables Facebook's profile 'Search' feature when the button is missing. Works on: https://facebook.com/XXXXXXX |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Extracts Fansly user profile information. Works on: https://fansly.com/XXXXXXX
Warning: This bookmarklet may surface explicit/adult content from the site. |
Active |
|
![]() | 2026-07-15 (v2) | |
| Extracts Flickr user profile information. Works on: https://www.flickr.com/people/XXXXXXX/
Warning: Reload the page before running this bookmarklet.
Credit: Submitted by community member Anthony Lisek. |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Extracts GitHub user or organization profile information via GitHub's public REST API. Works on: https://github.com/XXXXXXX
Warning: Unauthenticated GitHub API requests are capped at 60 per hour per IP — you'll get an alert if that limit is hit, or if the username doesn't exist. |
Active |
|
![]() | 2026-07-15 (v1) | |
| Reveals the exact date and time a Google review was posted. Works on: Google review pages (e.g. a review's permalink from Google Maps). Credit: Based on Yoni's LinkedIn post explaining this technique. |
Passive |
|
![]() | 2026-07-13 (v1) | |
| Opens the currently-selected Google Maps photo, video thumbnail, or 360° image in a new tab at full resolution. Works on: Google Maps location pages with a media viewer open. Credit: Submitted by community member Uzayr Kader.
|
Active |
|
![]() | 2026-07-15 (v2) | |
| Extracts hidden IMVU user profile data not shown in the web interface. Works on: https://www.imvu.com/next/av/XXXXXXX/ |
Active |
|
![]() | 2026-07-15 (v2) | |
| Reveals the exact dates/times for Instagram posts, stories, and comments instead of relative times. Works on: https://www.instagram.com/p/XXXXXXX/ |
Passive |
|
![]() | 2026-07-10 (v1) | |
| Reveals the exact dates/times for posts on an Instagram profile instead of relative times. Works on: https://www.instagram.com/XXXXXXX/ |
Active |
|
![]() | 2026-07-10 (v1) | |
| Opens the full-size image from an Instagram post in a new tab. | Passive |
|
![]() | 2026-07-15 (v2) | |
| Extracts Instagram user profile information. Works on: https://instagram.com/XXXXXXX/ |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Saves the single image from an Instagram post. Works on: Instagram post pages with a single image. |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Adds the destination URL next to each link on a Linktree profile page. Works on: https://linktr.ee/XXXXXXX |
Passive |
|
![]() | 2026-07-15 (v1) | |
| Extracts OnlyFans user profile information. Works on: https://onlyfans.com/XXXXXXX/
Warning: This bookmarklet may surface explicit/adult content from the site. |
Passive |
|
![]() | 2026-07-15 (v3) | |
| Extracts PayPal.me user profile information. Works on: https://www.paypal.com/paypalme/USERNAME |
Passive |
|
![]() | 2026-07-15 (v1) | |
| Extracts Pinterest user profile information. Works on: https://www.pinterest.com/XXXXXXX/ |
Active |
|
![]() | 2026-07-15 (v2) | |
| Reveals the last-updated date/time for each Poshmark listing — present in the page source but not shown in the UI. Works on: https://poshmark.com/closet/XXXXXXX/ |
Passive |
|
![]() | 2026-07-13 (v1) | |
| Extracts Poshmark user profile information. Works on: https://poshmark.com/closet/XXXXXXX/ |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Extracts Quora user profile information. Works on: https://www.quora.com/profile/XXXXXXX/ |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Extracts Smule user profile information via Smule's own API. Works on: https://www.smule.com/XXXXXXX
|
Active |
Smule |
![]() | 2026-07-15 (v3) | |
| Simplifies viewing previous versions of a Snapchat Bitmoji avatar. Works on: https://snapchat.com/@XXXXXXX
Note: Builds on Griffin's 2022 technique for viewing previous Bitmoji versions and Micah's Backmoji proof of concept. |
Active |
|
![]() | 2026-07-15 (v2) | |
| Adds the exact date/time to each story and Spotlight video on a Snapchat profile. Works on: https://snapchat.com/@XXXXXXX |
Passive |
|
![]() | 2026-07-13 (v1) | |
| Adds the exact date/time to a Snapchat Spotlight post, plus a direct link to download the video. Works on: https://www.snapchat.com/@XXXXXXX/spotlight/XXXXXXX
Credit: Idea suggested by Lisette Abercrombie. |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Extracts Snapchat user profile information. Works on: https://snapchat.com/@XXXXXXX |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Extracts SoundCloud user profile information. Works on: https://soundcloud.com/XXXXXXX |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Extracts Telegram channel/user profile information. Works on: https://t.me/XXXXXXX
Tip: Use this when the page shows a '...' instead of full details at the bottom. |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Finds a target's Threads profile from their Instagram profile, even when the two aren't linked. Works on: https://www.instagram.com/XXXXXXX/
Note: Some Instagram users have a same-username Threads account that isn't linked from their Instagram profile. Griffin found and reported this — this bookmarklet tries to visit that Threads profile directly. |
Passive |
|
![]() | 2026-07-15 (v2) | |
| Extracts Threads user profile information. Works on: https://www.threads.com/@XXXXXXX
Warning: You may need to reload the Threads page before running this.
|
Passive |
|
![]() | 2026-07-15 (v2) | |
| Adds the exact date/time (and alt-tag data) to each video on a TikTok profile. Works on: https://www.tiktok.com/@XXXXXXX |
Passive |
|
![]() | 2026-07-15 (v1) | |
| Extracts TikTok user profile information. Works on: https://www.tiktok.com/@XXXXXXX |
Active |
|
![]() | 2026-07-15 (v2) | |
| Decodes the timestamp embedded in a TikTok photo/video URL's ID number. Works on: https://www.tiktok.com/@XXXXXXX/photo/################### (or similar TikTok URLs with a large ID number).
Credit: Based on Bellingcat's TikTok timestamp tool. |
Passive |
|
![]() | 2026-07-15 (v1) | |
| Extracts Tinder profile information. Works on: https://tinder.com/@XXXXXXX
Credit: Submitted by community member Anthony Lisek. |
Passive |
|
![]() | 2026-07-15 (v1) | |
| Extracts Trello user profile information. Works on: https://trello.com/u/XXXXXXX/activity |
Active |
|
![]() | 2026-07-15 (v1) | |
| Extracts Venmo user profile information. Works on: https://account.venmo.com/u/XXXXXXX |
Passive |
|
![]() | 2026-07-15 (v1) | |
| Extracts VK user profile information. Works on: https://vk.com/idXXXXXXX |
Passive |
|
![]() | 2026-07-15 (v1) | |
| Extracts X (Twitter) user profile information. Works on: https://x.com/XXXXXXX
Credit: Submitted by community member Anthony Lisek.
Note: The values shown are exactly what X.com's own page provides — you, the analyst, still need to judge the confidence of this data.
|
Active |
|
![]() | 2026-07-15 (v2) | |
Removes CSS blur classes (e.g. class="blur", class="blur-sm", class="blur-lg") that some sites use to obfuscate content, which may reveal the real data underneath. |
Passive | Deblurring |
![]() | 2026-07-10 (v1) | |
Have a domain that you need to find other data on? This bookmarklet pops up 1 window asking you to input the domain (do not include the www or https; just a domain like example.com). Then it opens multiple browser tabs and runs searches on different sites.
|
Active |
|
![]() | 2026-07-10 (v2) | |
| Finds all images on the current page and lets you reverse-image-search any of them via Google Lens, Yandex, TinEye, Bing, ImgOps, SauceNAO, IQDB, or Trace.moe.
Credit: Submitted by community member "Zycher" via our submission link. |
Active |
|
![]() | 2026-07-13 (v2) | |
| Extracts JSON data embedded in a page's source that isn't rendered in the browser. Works on: any webpage (e.g. https://wikipedia.org/wiki/Bookmarklet).
Credit: Submitted by a community member via our submission link. |
Passive |
|
![]() | 2026-07-15 (v1) | |
| Detects all <table> elements on a page, scores them by row count, column count, and content density, and presents the best candidate in a draggable overlay. Cycle through all detected tables, toggle columns on or off, preview up to 200 rows, and export the full dataset as a CSV file. | Passive |
|
![]() | 2026-07-15 (v1) | |
| This bookmark pops up 3 windows in succession asking you to input the first name, then last name, then a US State you are searching. It queries different people search sites in one click. | Active |
|
![]() | 2026-07-15 (v2) | |
| This bookmark pops up 3 windows in succession asking you to input the area code, then prefix, then the last 4 of the number of the United States phone number you are searching. It queries different phone search sites in one click.
Warning: Some sites default to their search page when no result is found. |
Active |
|
![]() | 2026-07-15 (v2) | |
|
Checks whether a site is running WordPress, shows the indicators found, and offers to view site authors if available. Works on: WordPress sites (e.g. https://hatless1der.com).
Warning: Some WordPress administrators can see visitor activity by IP address — best to run this while using a VPN or other masking technology.
Warning: This is an Active script — it makes up to 6 additional requests to the site to check various files.
|
Active |
|
![]() | 2026-07-15 (v2) |
Bookmarklets live in your browser's bookmarks bar. Pick the method that works best for you:
Bookmarklets don't self-update. Re-download and re-import when you want the latest version.
Quick reference for the labels and indicators used throughout the bookmarklet table.
An Active bookmarklet makes additional web requests — it contacts the website's servers or a third-party API to fetch data beyond what is already loaded in your browser. Because it sends network traffic, the target site may log or detect its use.
A Passive bookmarklet only reads and processes data already present in your browser — it never sends additional requests to external servers. It extracts information from the page source or existing browser memory without leaving any additional network trace.
Several bookmarklets highlight dates that fall within the past 7 days with a 🚨 red siren indicator. This is a visual alert to draw your attention to very recent account activity, post dates, or timestamps — which may be significant in an investigation. The indicator appears inside the bookmarklet's popup window next to the relevant date; it does not affect the underlying data in any way.
Send us an email and we'll review it as soon as we can.
Submit an issue on GitHub — you'll be prompted for everything we need to review it. We'll reply by email. Thank you!
By using these bookmarklets, you acknowledge that you have read and agree to these disclaimers.