A powerful 2-in-1 OSINT suite engineered for deep Email and Username Intelligence.
With 380+ total scan vectorsβincluding 155+ email-integrated sites and 225+ username platformsβyou can map digital footprints, analyze target behavior, uncover interests, full metadata of usernames and verify account registrations in seconds.
Go beyond account enumeration. WebVetted turns an email or username into a complete identity investigation with deep OSINT enrichment, breach intel, AI analysis, and an interactive identity graph.
Start an Investigation β
- π Deep Email & Username OSINT: Look up email registrations and perform advanced username profiling across 380+ platforms.
- π€ Rich Metadata Scraping: Scrapes avatars, bio descriptions, follower counts, UID numbers, seller statuses, and account attributes.
- π Cross-Scan & Pivot Engine: Mines handles, profile links, and exposed email addresses from initial scans, automatically pivoting across secondary target vectors.
- π‘οΈ Hudson Rock Infostealer Breach Intel: Query infostealer malware breach logs using the
--hudsonflag for high-priority target correlation. - β‘ High-Throughput Parallel Engine: Powered by
httpxandcurl_cffifor maximum concurrency with automated TLS fingerprint impersonation. - π Permutation & Alias Generator: Wildcard-based username variation generation to catch typosquatting or alternative aliases.
- π Multi-Format Reports: Automated exports to PDF (with profile photos), JSON, and CSV for pipeline integration.
- π Advanced Proxy Pivoting: Built-in proxy rotation with protocol auto-detection (
http,socks5) and pre-scan health validation (--validate-proxies). - π¨ Responsive Terminal UI: Dynamic progress tracking, self-adaptive category grids (
-lu/-le), and clear status reporting.
# Upgrade pip and install user-scanner
python3 -m pip install --upgrade pip
pip install user-scanner# Create and activate virtual environment
python3 -m venv .venv
source .venv/bin/activate # On Windows: .venv\Scripts\Activate.ps1
# Install package
pip install user-scanner# Run instantly without installing permanently
nix run github:kaifcodec/user-scanner/main -- --help
# Drop into a temporary shell with user-scanner active
nix shell github:kaifcodec/user-scanner/mainScan a single username or email address across all available platform modules:
user-scanner -u johndoe # Single username scan
user-scanner -e johndoe@gmail.com # Single email scanAn email scan proves an account exists but rarely reveals a handle. --cross-scan mines exposed handles, profile links, and secondary email addresses from target profiles, pivoting into multi-pass reconnaissance across all matching platforms:
| Pivot Direction | What it Mines |
|---|---|
-e β username |
Handles or social links exposed on an email's registered profile |
-u β username |
Secondary aliases advertised across target social profiles |
-u β email |
Public email addresses published on target profile pages |
-e β email |
Secondary addresses exposed by initial email profiles |
user-scanner -u johndoe --cross-scan # Pivot from username scan
user-scanner -e johndoe@gmail.com --cross-scan # Pivot from email scan
user-scanner -e johndoe@gmail.com --cross-scan --cross-links verified # Platform-verified links only
user-scanner -u johndoe --cross-scan --cross-depth 2 # Follow links two hops deepπ‘ For confidence scoring, link classification rules, and cost models, see docs/CROSS_SCAN.md.
Check if a target username or email address has been exposed in infostealer malware infection logs:
user-scanner -u johndoe --hudson # Username malware log check
user-scanner -e johndoe@gmail.com --hudson # Email malware log checkπΌοΈ To view output terminal screenshots and visual previews, see docs/EXAMPLES.md.
Scan specific categories or individual modules, or list available modules in a responsive grid:
user-scanner -u johndoe -c dev # Developer platforms only
user-scanner -e johndoe@gmail.com -m github # Single module check
user-scanner -u johndoe -m github,instagram # Specific comma-separated modules
user-scanner -lu # List user categories & modules grid
user-scanner -le # List email categories & modules gridScan multiple targets from an input file (one target per line):
user-scanner -uf usernames.txt # Bulk username scan
user-scanner -ef emails.txt # Bulk email scan# Export results to PDF, JSON, or CSV
user-scanner -u johndoe -f pdf -o report.pdf
user-scanner -u johndoe -f json -o results.json
# Verbose URL reporting and show all results (including not found)
user-scanner -u johndoe -v --all
# Rotate proxies with pre-scan validation check
user-scanner -u johndoe -P proxies.txt --validate-proxiesExplore detailed documentation guides in the docs/ directory:
- π CLI Flags Reference β Complete breakdown of every CLI flag and option.
- π Cross-Scan & Pivoting Guide β In-depth guide to multi-pass cross-scan reconnaissance.
- π Pattern Syntax Guide β Wildcard and permutation patterns for username generation.
- π Library Mode Guide β Calling the Python engine programmatically from your own scripts.
- π Proxy & Network Guide β Proxy rotation formats, health checks, and regional VPN troubleshooting.
- πΌοΈ Media & Output Gallery β Video demonstrations, terminal recordings, and screenshot previews.
Integrate the User Scanner engine directly into your Python scripts:
import asyncio
from user_scanner.core import engine
from user_scanner.email_scan.shopping import etsy
async def main():
# Engine validates target against module and returns Result object
result = await engine.check(etsy, "test@gmail.com")
print(result.to_json())
asyncio.run(main())π‘ For complete Python API documentation and batch category checking examples, see docs/USAGE.md.
Web platforms constantly update authentication flows. Maintaining over 380+ scan modules requires around-the-clock commitment to keep the suite reliable and free for the cybersecurity community.
If user-scanner has saved you hours of manual pivoting or aided your investigations, consider supporting the project:
π Sponsor on GitHub
Huge thanks to our amazing sponsors who support the ongoing development of user-scanner!
@soxoj |
@hienyimba |
@InDieTasten |
We welcome community contributions! Please read our Contributing Guidelines before opening a PR or submitting new scan modules.
This tool is provided strictly for educational purposes, authorized security research, and defensive OSINT investigations. The developers assume no liability and are not responsible for any misuse, unintended consequences, or legal actions resulting from the deployment of this software.
