Pull the archived index
waybackurls reads the Wayback Machine's index for the host while gau aggregates additional public URL sources — no traffic is sent at the target.
archive module
Point Command One at a domain or host and the archive stage replays everything the archived web still remembers — a year-bucketed timeline of URLs from waybackurls and gau, the paths, extensions and parameters extracted from them, and a “what changed” panel comparing the archive against today’s live observation.
public sources only · free registration
how the archive stage runs
waybackurls reads the Wayback Machine's index for the host while gau aggregates additional public URL sources — no traffic is sent at the target.
Every record is normalised and grouped into a year-by-year timeline, so the site's growth, redesigns and quiet removals become visible at a glance.
Paths, file extensions and query parameters are broken out of the URLs, exposing endpoints, upload directories and legacy sections that no longer appear in navigation.
The archived view is diffed against the current DNS and HTTP observation to flag what is live but unarchived, and what is archived but no longer answering.
engines behind it
Both archive modules write into the same normalised schema as the rest of the recon stages, so duplicate URLs merge, entities correlate and everything exports together.
Reads the Wayback Machine's URL index for a host, the deepest single source of archived paths for long-lived domains.
Aggregates several public URL indexes at once, catching records the Wayback index alone misses.
Records bucketed by year, so you can date when a section of the site existed rather than only that it once did.
Extensions, directories and query parameters pulled out of archived URLs to reveal the historical surface of the site.
Hosts and paths present now but unarchived, and archived but unobserved, each reported as a lead with its own detail line.
Direct Wayback and archive links generated for the target so every archived record can be confirmed by hand.
questions
Archive OSINT reads historical copies of a site that public archives already hold, rather than the version that is online today. It surfaces pages, paths and parameters that were removed, renamed or quietly retired, which is often where the useful lead sits.
Two worker modules: waybackurls, which reads the Wayback Machine's index for a host, and gau, which aggregates several public URL indexes. Both are passive — they query archives, not the target.
Archived URLs are bucketed by year into a timeline, then broken out by path, file extension and query parameter, so you can see when a section of the site appeared or disappeared and which endpoints once existed.
It flags hosts and paths that respond now but are absent from the archive index, and ones present in the archive that this sweep did not observe live. Archives are incomplete by construction, so absence is a lead to check, never proof.
Recon presets set the depth: a quick pass keeps the most recent records, a standard pass takes full archive coverage, and a deep pass widens the record limit much further for long-lived domains.
Registration is free with a daily credit allowance, and the archive modules cost one credit each on the worker fleet.
Create a free account, enter a domain and watch the archive timeline, extracted paths and live comparison fill the case file. Lawful research and due-diligence use only.