Features

Four Professional OSINT Modules in One Platform

From username search across 2,004 platforms to deep GitHub analysis — each module extracts maximum intelligence from legally accessible public sources.

🌐

IP Geolocation — Complete Analysis

Locate any IPv4 or IPv6 address with precision. Cross-references multiple geolocation databases for maximum accuracy. Includes VPN, proxy, and Tor detection — essential for determining whether a user is masking their real location.

  • Country, region, city, postal code, approximate GPS coordinates
  • ISP, ASN (Autonomous System Number), network owner
  • Time zone and local time
  • VPN detection: matches against commercial VPN ASN list
  • Proxy detection: public SOCKS and HTTP proxies
  • Tor exit node detection
  • Datacenter detection: AWS, GCP, Azure, OVH, Hetzner…
  • Reverse DNS and WHOIS records

Use cases

  • Analyze IP from a suspicious email header
  • Identify geographic origin of server connection logs
  • Detect bots: is the IP a datacenter?
  • Verify if a contact is hiding their real location
Detection Accuracy
Country>99%
Region / State~90%
City~75%
VPN / Proxy / Tor✓ Active detection
📞

Phone Lookup — International + Facebook Detection

Analyze any international phone number. Technical validation combined with carrier identification and Facebook account detection — one of the most effective OSINT techniques for linking a phone number to a real identity.

  • E.164 format validation and international normalization
  • Carrier identification by prefix (or number portability)
  • Country, international dialing code, geographic attribution zone
  • Line type: mobile, landline, VoIP, premium, toll-free
  • Associated time zone
  • Facebook account detection via Meta's account recovery procedure

Use cases

  • Identify carrier and location of an unknown number
  • Link a phone number to a Facebook identity
  • Investigate numbers used in scams or fraud
  • Verify phone number provided in a form or application
Facebook Lookup Mechanism

Meta's "Forgot Password" recovery flow accepts a phone number and reveals: first name and last initial, partially masked email, profile photo. This is an official, public Meta feature — no security exploit.

🐙

GitHub Intelligence — Deep OSINT Analysis

GitHub is a goldmine for OSINT investigations involving developers or tech organizations. Vestigo uses the public GitHub API to build a comprehensive profile: activity, skills, accidentally exposed contacts, and affiliations.

  • Full profile: bio, declared location, company, personal blog
  • Public repositories: top repos by stars, languages, descriptions
  • Emails exposed in commit history (often not shown on profile)
  • Public GPG and SSH keys added to the profile
  • GitHub organization memberships (reveals employer/projects)
  • Statistics: repo count, followers, contribution frequency
  • Top programming languages and temporal activity
  • Public gists (often contain revealing config snippets)

Use cases

  • Find professional or personal email of a developer
  • Verify technical skills of a job candidate
  • Security audit: exposed secrets in commits (API keys, tokens)
  • Code attribution: identify the author of an anonymous repository
Why commit emails matter

Git associates every commit with the name and email configured on the developer's machine. A developer committing from both work and home may expose both professional and personal emails in a single public repository's history.

Try all 4 OSINT modules now

One subscription, one dashboard. Start with a week for €9.90, no commitment.

Sign up — €9.90 How it works