Innovative OSINT Solutions for Cybersecurity Experts
Focused reconnaissance tooling for penetration testers and security researchers —
built to be fast, scriptable, and API-first.
xReverseLabs builds focused OSINT (Open Source Intelligence) tooling for security professionals. We simplify the complexity of information gathering and domain reconnaissance, so researchers can spend less time stitching tools together and more time doing actual analysis.
Available at xreverselabs.org with free and paid tiers, plus full API access:
| Tool | Description |
|---|---|
| Reverse IP / Reverse IPv6 | Discover domains hosted on a given IP address |
| Subdomain Scanner | Enumerate subdomains for a target domain |
| WHOIS Database | Historical and current WHOIS record lookups |
| Phone Number Lookup | OSINT lookup on phone numbers |
| Proxy Scraper | Collect and validate live proxies |
| Domain by Date | Find domains registered within a given date range |
A fast, concurrent reconnaissance toolkit written in Go — built for reliable, large-scale domain and subdomain enumeration during penetration tests.
- High-speed scanning with concurrent workers
- Minimal resource footprint
- Structured output for easy pipelining into other tools
An automated Google/Bing dorking tool for OSINT reconnaissance, built to run large batches of dork queries without getting stuck on captchas.
- Automated dork query execution across search engines
- Captcha-resilient by design
- Useful for surfacing exposed files, panels, and misconfigurations at scale
The domain discovery engine behind Discover — finds related and adjacent domains for a given target.
- Expands a single target into a wider domain footprint
- Built for feeding downstream recon tools
- Second-generation rewrite focused on speed and accuracy
The API layer behind our OSINT toolkit — reverse IP, subdomain discovery, WHOIS, and more, available as a single, well-documented REST API for integration into your own workflows and tooling.
- One API for the full OSINT toolkit
- Full documentation
- Scales from single lookups to bulk operations
Beyond the core toolkit, the xReverseLabs team maintains a small set of related products:
| Product | Description |
|---|---|
| Opendata | Daily-updated domain list for bulk OSINT research |
| Discover | Domain discovery engine |
| DataSentry | Check whether an email has appeared in known data breaches |
| xLabsCloud | Dedicated infrastructure hosting for researchers |
| xDorker | Google Dorking tools proxyless |
| Discovery Domain V2 | Domain Discovery Engine, Auto Grab Fresh Domains |
- Performance — tools are built for speed and low overhead, so you get results without delay.
- Reliability — we prioritize accurate, dependable output over noisy false positives.
- Community-driven — our open-source projects evolve with contributions from security researchers worldwide.
- API-first — everything we build is designed to be scripted, not just clicked through.
- Create a free account at xreverselabs.org/clientarea/register.
- Explore the free toolkit, or check the pricing page for higher limits and API access.
- Read the API documentation to integrate the toolkit into your own workflow.
- For our open-source tools, check each repository's README for setup instructions.
- Telegram Group: t.me/xReverseLabs
- Telegram Channel: t.me/xReverseLabs_Ch
- GitHub: github.com/xReverseLabs
We welcome contributions to our open-source projects — bug fixes, documentation improvements, and new features are all appreciated.
- Fork the repository and create your branch:
git checkout -b feature/AmazingFeature - Commit your changes:
git commit -m 'Add some AmazingFeature' - Push to the branch:
git push origin feature/AmazingFeature - Open a pull request
Our community brings together security researchers and developers to share techniques, tooling, and practical experience with OSINT and reconnaissance workflows. Join us on Telegram to ask questions, share findings, or just follow along with what we're building.
We take security seriously. If you discover a vulnerability in any of our tools or services, please report it privately rather than opening a public issue — reach out via Telegram or open a private security advisory on the relevant repository. We aim to acknowledge reports promptly and credit responsible disclosures.
- The xReverseLabs community — for continuous feedback, contributions, and support.
Built with care by the xReverseLabs Team
