Noeron turns one selector — email, domain, username, phone, IP, wallet or company — into a live intelligence graph. 40+ plugins (most needing no API key) run automatically and expand findings. Native SwiftUI for Mac, iPad & iPhone. Open source, MIT.
👋 Maker here. I built Noeron because every OSINT tool I tried was either a paywalled web app that eats your queries, or a pile of Python scripts each needing its own API key. I wanted to paste an email and just get answers — locally, on my Mac.
So Noeron is:
Keyless-first — ~27 of its 40+ plugins need no API key. Paste a selector → it runs everything applicable → the graph builds itself and auto-expands new findings.
Native & private — pure SwiftUI/SwiftData for macOS, iPad & iPhone. Your investigation lives on your device, not our server (we don't have one).
Open source (MIT) — the plugin protocol is ~one Swift struct. Fork it, add a source, send a PR.
It handles emails, domains/subdomains, usernames, phones, IPs, crypto wallets and companies — DNS, certs, subdomain enumeration, breach checks, on-chain balances (BTC/ETH/SOL), company registries, and more. Court-ready reports export to Markdown/HTML/PDF.
Free forever. GitHub in the links 👇 I'll be here all day — would love your plugin ideas and honest feedback. What source should I add next?
Report
Curious how you keep the plugin results trustworthy when a bunch run without an API key, like is there scoring across sources or do I just trust whatever each plugin spits out?
@smeyye214197 Great question — "keyless" doesn't mean "unverified," and that distinction is the whole design.
A few things:
1. Keyless ≠ low-trust. Most of the free sources are primary data, not guesses — DNS records, Certificate Transparency logs, public blockchains, WHOIS, government company registries. Those are often more authoritative than a paid aggregator that's just reselling them.
2. Every finding is sourced + scored. Nothing is anonymous: each entity carries a confidence value and the exact plugin that produced it, and there's a full provenance/audit log of every run. Anything from a stubbed or sample source is explicitly flagged so you never mistake it for live intel.
3. You stay in control. You can adjust a finding's confidence, discard false positives (they won't be re-discovered), and merge duplicates — so the graph reflects your judgment, not blind plugin output. Reports even embed the confidence + discard state.
So today it's "sourced, scored, and curatable," not "trust whatever it spits out."
Report
Tried a quick email lookup and the graph view is genuinely satisfying, watching the related domains and breaches just light up as plugins run in the background. The no-API-key setup is a nice touch too.
@odilsizogl69529 Love this, thank you 🙏 The "watch it light up as plugins run" moment is the one thing I optimized hardest for — findings stream onto the graph live as each source returns, so it feels like the investigation is building itself rather than a progress bar you wait on.
And the no-key setup is the core bet: the highest-signal OSINT sources (DNS, cert transparency, breach indices, on-chain data) are actually free — they're just scattered. Wiring them together so it all works the second you install is the whole point.
If you want to see it really fan out, drop in a domain next — subdomains, certs and hosting light up fast. And I'm all ears on which source you'd want added. 🚀
Report
Plugged in a random wallet address and watched the graph build out across chains in seconds, which is way more fun than my usual block explorer. The native Mac app feels snappy too.
@blentgkek1bb1 Ha, "more fun than a block explorer" is high praise — thank you 🙏 That was the goal: an explorer makes you read, the graph lets you see — balances, held tokens, first/last activity and recent transactions all laid out as nodes you can pivot from, across Bitcoin, Ethereum and Solana.
And it stays keyless — public RPCs and explorers, no account, no key. It even resolves human-readable names (ENS and friends) so wallets aren't just hex.
If you keep playing: pivot off one of the counterparties it surfaces, or try an ENS name as the seed and watch it resolve back to the address. Snappiness is all the native SwiftUI — glad it landed. 🚀
Omnistat 2
Curious how you keep the plugin results trustworthy when a bunch run without an API key, like is there scoring across sources or do I just trust whatever each plugin spits out?
Omnistat 2
@smeyye214197 Great question — "keyless" doesn't mean "unverified," and that distinction is the whole design.
A few things:
1. Keyless ≠ low-trust. Most of the free sources are primary data, not guesses — DNS records, Certificate Transparency logs, public blockchains, WHOIS, government company registries. Those are often more authoritative than a paid aggregator that's just reselling them.
2. Every finding is sourced + scored. Nothing is anonymous: each entity carries a confidence value and the exact plugin that produced it, and there's a full provenance/audit log of every run. Anything from a stubbed or sample source is explicitly flagged so you never mistake it for live intel.
3. You stay in control. You can adjust a finding's confidence, discard false positives (they won't be re-discovered), and merge duplicates — so the graph reflects your judgment, not blind plugin output. Reports even embed the confidence + discard state.
So today it's "sourced, scored, and curatable," not "trust whatever it spits out."
Tried a quick email lookup and the graph view is genuinely satisfying, watching the related domains and breaches just light up as plugins run in the background. The no-API-key setup is a nice touch too.
Omnistat 2
@odilsizogl69529 Love this, thank you 🙏 The "watch it light up as plugins run" moment is the one thing I optimized hardest for — findings stream onto the graph live as each source returns, so it feels like the investigation is building itself rather than a progress bar you wait on.
And the no-key setup is the core bet: the highest-signal OSINT sources (DNS, cert transparency, breach indices, on-chain data) are actually free — they're just scattered. Wiring them together so it all works the second you install is the whole point.
If you want to see it really fan out, drop in a domain next — subdomains, certs and hosting light up fast. And I'm all ears on which source you'd want added. 🚀
Plugged in a random wallet address and watched the graph build out across chains in seconds, which is way more fun than my usual block explorer. The native Mac app feels snappy too.
Omnistat 2
@blentgkek1bb1 Ha, "more fun than a block explorer" is high praise — thank you 🙏 That was the goal: an explorer makes you read, the graph lets you see — balances, held tokens, first/last activity and recent transactions all laid out as nodes you can pivot from, across Bitcoin, Ethereum and Solana.
And it stays keyless — public RPCs and explorers, no account, no key. It even resolves human-readable names (ENS and friends) so wallets aren't just hex.
If you keep playing: pivot off one of the counterparties it surfaces, or try an ENS name as the seed and watch it resolve back to the address. Snappiness is all the native SwiftUI — glad it landed. 🚀