Back to updates
New releaseAug 4, 2026

user-scanner v1.4.3

πŸ•΅οΈβ€β™‚οΈ (2-in-1) Email & Username OSINT suite for deep data extraction just from a single Email/Username. Analyzes 375+ scan vectors (150+ email / 225+ username) for security research, investigations, and digital footprinting.

Share

User Scanner

User Scanner Logo

Discord

kaifcodec%2Fuser-scanner | Trendshift


A powerful 2-in-1 OSINT suite engineered for deep Email and Username Intelligence.

With 1080+ total scan vectorsβ€”including 200+ email-integrated sites and 880+ username platformsβ€”you can map digital footprints, analyze target behavior, uncover interests, full metadata of usernames and verify account registrations in seconds.


πŸ’– Sponsored by

WebVetted Sponsor Banner
Go beyond account enumeration. WebVetted turns an email or username into a complete identity investigation with deep OSINT enrichment, breach intel, AI analysis, and an interactive identity graph.
Start an Investigation β†’


banner-github
Comprehensive OSINT platform for professional investigators and analysts. Reverse email, phone number, and username search across 250+ modules. Automate your intelligence gathering with our powerful tools.
Get Started β†’


banner-github
Find beginner-friendly open-source issues and make your first pull request today.
Get Started β†’


✨ Key Features

  • πŸ”Ž Deep Email & Username OSINT: Look up email registrations and perform advanced username profiling across 1080+ platforms.
  • πŸ‘€ Rich Metadata Scraping: Scrapes avatars, bio descriptions, follower counts, UID numbers, seller statuses, and account attributes.
  • πŸ”€ Cross-Scan & Pivot Engine: Mines handles, profile links, and exposed email addresses from initial scans, automatically pivoting across secondary target vectors.
  • πŸ€– Model Context Protocol (MCP) Server: Native AI agent integration for Claude Desktop, Cursor, Antigravity, and LLMs to run autonomous OSINT scans and recursive pivots.
  • πŸ›‘οΈ Hudson Rock Infostealer Breach Intel: Query infostealer malware breach logs using the --hudson flag for high-priority target correlation.
  • ⚑ High-Throughput Parallel Engine: Powered by httpx and curl_cffi for maximum concurrency with automated TLS fingerprint impersonation.
  • πŸ”€ Permutation & Alias Generator: Wildcard-based username variation generation to catch typosquatting or alternative aliases.
  • πŸ“‚ Multi-Format Reports: Automated exports to PDF (with profile photos), JSON, and CSV for pipeline integration.
  • 🌐 Advanced Proxy Pivoting: Built-in proxy rotation with protocol auto-detection (http, socks5) and pre-scan health validation (--validate-proxies).
  • 🎨 Responsive Terminal UI: Dynamic progress tracking, self-adaptive category grids (-lu/-le), and clear status reporting.

πŸš€ Installation

# Upgrade pip and install user-scanner
python3 -m pip install --upgrade pip
pip install user-scanner

# Optional: Install with MCP Server support for AI agents
pip install "user-scanner[mcp]"

πŸ“¦ Virtual Environment Setup

# Create and activate virtual environment
python3 -m venv .venv
source .venv/bin/activate  # On Windows: .venv\Scripts\Activate.ps1

# Install package
pip install user-scanner

❄️ Via Nix (Linux & macOS)

# Run instantly without installing permanently
nix run github:kaifcodec/user-scanner/main -- --help

# Drop into a temporary shell with user-scanner active
nix shell github:kaifcodec/user-scanner/main

πŸ’» Usage Guide

1. Basic Username & Email Scanning

Scan a single username or email address across all available platform modules:

user-scanner -u johndoe             # Single username scan
user-scanner -e [email protected]   # Single email scan
user-scanner -u johndoe --email-domains global  # Try johndoe across provider domains

2. Cross-Scan & Pivot Intelligence

An email scan proves an account exists but rarely reveals a handle. --cross-scan mines exposed handles, profile links, and secondary email addresses from target profiles, pivoting into multi-pass reconnaissance across all matching platforms:

Pivot DirectionWhat it Mines
-e β†’ usernameHandles or social links exposed on an email's registered profile
-u β†’ usernameSecondary aliases advertised across target social profiles
-u β†’ emailPublic email addresses published on target profile pages
-e β†’ emailSecondary addresses exposed by initial email profiles
user-scanner -u johndoe --cross-scan                                  # Pivot from username scan
user-scanner -e [email protected] --cross-scan                        # Pivot from email scan
user-scanner -e [email protected] --cross-scan --cross-links verified # Platform-verified links only
user-scanner -u johndoe --cross-scan --cross-depth 2        # Follow links two hops deep

πŸ’‘ For confidence scoring, link classification rules, and cost models, see docs/CROSS_SCAN.md.

3. Hudson Rock Malware Breach Intelligence

Check if a target username or email address has been exposed in infostealer malware infection logs:

user-scanner -u johndoe --hudson             # Username malware log check
user-scanner -e [email protected] --hudson   # Email malware log check

Categories