
Flowsint is an open-source, self-hosted platform that turns reconnaissance and OSINT entity enrichment into an interactive visual graph, built for authorized investigators and analysts.
| Tool | reconurge/flowsint — self-hosted graph-based OSINT investigation platform with automated entity enrichers |
| Category | OSINT / reconnaissance investigation platform (TypeScript frontend, Python backend) |
| Primary Use | Mapping relationships between Domain, IP, ASN, Email, Organization, and crypto-wallet entities during authorized investigations via a visual graph and automated enrichers |
| Safe Use | Lawful, authorized investigations: security research, journalism, fraud analysis, and internal threat intelligence, per the project's ETHICS.md; all data stays on the operator's own infrastructure |
| Telemetry Note | Fully self-hosted: PostgreSQL, Redis, Neo4j, and the FastAPI backend bind to 127.0.0.1, so external enrichment queries originate from the analyst's own egress IP; defenders observing third-party OSINT enrichment would see standard DNS/WHOIS/crawl traffic from that host |
Flowsint, published at reconurge/flowsint, is an ambitious attempt to rethink what an OSINT workbench looks like. Rather than chaining together CLI utilities and manually pasting results into a notes file, the operator seeds the graph with an initial entity — a Domain, an IP, an email, a crypto wallet — and the platform's automated enrichers expand it into a navigable relationship map. The project bills itself as a tool for ethical investigation, transparency, and verification, backed by an explicit ETHICS.md and a legal-use section that names its intended audiences: cybersecurity researchers, journalists and OSINT investigators, law enforcement and fraud teams, and organizations doing internal threat intelligence. At roughly 8.8k stars and licensed under Apache-2.0, it has clearly struck a nerve in the recon community despite self-describing as early development.
The architecture is the most interesting part of the README for a professional reader. Flowsint is not a monolith but a set of autonomous modules with a strict dependency chain: flowsint-app (the frontend) talks only to flowsint-api, a FastAPI server exposing REST endpoints, authentication, graph database integration, and real-time event streaming. Below that sits flowsint-core, which owns the orchestrator, Celery task execution, the vault that encrypts stored API keys, database connections, and base classes. flowsint-enrichers holds the actual scanning and enrichment logic, while flowsint-types defines the shared Pydantic models. This layering means an enricher never talks to the database directly and the frontend never bypasses the API — a clean separation that should make auditing third-party contributions considerably easier than in typical single-repo recon tools.
The data model is entity-centric, and the README enumerates the full type vocabulary: Domain, IP, ASN, CIDR, Individual, Organization, Email, Phone, Website, social profiles, credentials, crypto wallets, transactions, and NFTs. Enrichers are essentially typed edges: they consume one entity and emit related entities. Domain enrichers cover Reverse DNS Resolution, DNS Resolution, Subdomain Discovery, WHOIS Lookup, root-domain extraction, Domain to ASN, and historical domain data. IP enrichers add geolocation and ASN lookups, ASN enrichers expand to CIDR ranges, and CIDR enrichers enumerate contained IPs — the classic infrastructure-pivot chain, now expressed as graph edges you can traverse visually.
The pivot capability extends well beyond infrastructure. Social enrichment integrates Maigret for username searches across social platforms (the module details also mention Sherlock). Email enrichers map an address to Gravatar profiles, breach database entries, and associated domains; phone numbers can be checked against breach data. Organization enrichers resolve companies to owned ASNs and domains plus general company details. Crypto enrichers pull transaction history and NFT holdings for a wallet. On the web side, a crawler maps site structure, while enrichers extract links, domains, tracking scripts, and text content. There is even an N8n Connector enricher, which lets an investigator wire enrichment results into external automation workflows — a genuinely useful bridge for teams already running N8n pipelines.
Deployment is deliberately container-first. On Linux and macOS the entire path is git clone, cd flowsint, make prod, with Docker and Make as the only prerequisites. Windows users skip Make entirely: copy .env.example into the root and into flowsint-api, flowsint-core, and flowsint-app, then run docker compose -f docker-compose.prod.yml up -d. Production images are pulled pre-built from GitHub Container Registry, so no local compilation is needed, and version pinning is available by setting FLOWSINT_VERSION in .env (for example FLOWSINT_VERSION=1.2.10). After startup, the operator registers the first account at http://localhost:5173/register — there are no default credentials shipped, which is the correct default posture for a tool that may hold sensitive investigation data.
The security design of the network deployment path deserves specific attention, because it is unusually thoughtful for a community OSINT project. Only port 5173 is exposed; PostgreSQL, Redis, Neo4j, and the API bind to 127.0.0.1 and are reachable only through the frontend's internal proxy. The README instructs operators deploying to a network to rotate AUTH_SECRET (token signing, generated with openssl rand -hex 32), MASTER_VAULT_KEY_V1 (which encrypts stored third-party API keys, generated as base64 from 32 bytes of entropy), and NEO4J_PASSWORD. It also documents a Host-header allowlist in flowsint-app/nginx.conf that defaults to localhost/127.0.0.1/[::1] specifically to defend single-user installs against DNS rebinding, with LAN and public deployments required to explicitly opt in their hostname. That is a threat model most tool authors never write down.
The privacy stance is a recurring theme: the README states plainly that everything is stored on the operator's machine, which matters for investigative work where the mere existence of a query can be sensitive. Combined with the encrypted vault for API keys, this positions Flowsint as a legitimate alternative to SaaS investigation platforms for teams that cannot ship case data to a third party. For HTTPS beyond a trusted LAN, the README recommends a reverse proxy in front of 5173 (a Caddy example is given) and binding the app port to localhost in docker-compose.prod.yml so clients can only transit TLS.
Development ergonomics are equally modular. make dev brings up the full development stack, and each module carries its own — admittedly incomplete, per the README — test suite run via uv run pytest. Contributions are expected to follow the module boundaries: new entity types go in flowsint-types, new enrichers in flowsint-enrichers, endpoints in flowsint-api, utilities in flowsint-core, with uv as the mandated dependency manager and checks documented in CONTRIBUTING.md. For a practitioner evaluating supply-chain risk, that structure makes it feasible to review an enricher in isolation before trusting it with your vault keys, and the Pydantic typing layer means malformed enrichment output should fail loudly rather than corrupt the graph.
Where does this fit in an authorized workflow? Think of it as the exploration and hypothesis-generation layer between raw collection and reporting: an analyst scoped to a sanctioned engagement can pivot from a seed domain through subdomains, hosting ASNs, historical registrations, and associated organizations, then branch into breach and social attribution where the engagement's rules allow. What it is not, per its own ethics documentation, is a tool for unauthorized surveillance, doxxing, or targeting of individuals — the README explicitly prohibits those uses, and any professional adoption should mirror that scoping in the engagement's rules of engagement.
Caveats worth noting before adoption: the project self-identifies as early development, test coverage is partial, and the enricher catalog means the tool inherently issues queries to many third-party services (WHOIS, breach databases, blockchain explorers, crawlers), so operators should expect their egress IP to generate a recognizable pattern of enrichment traffic and configure rate discipline accordingly. But as a self-hosted, ethically framed, architecturally clean graph OSINT platform, Flowsint is one of the more serious entries in this category, and its explicit operational-security defaults — localhost-bound datastores, DNS-rebinding defenses, encrypted key vault — set a standard other recon tooling would do well to copy.
reconurge/flowsint.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
Related coverage
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.