
user-scanner v1.4.3
π΅οΈββοΈ (2-in-1) Email & Username OSINT suite for deep data extraction just from a single Email/Username. Analyzes 375+ scan vectors (150+ email / 225+ username) for security research, investigations, and digital footprinting.
User Scanner
A powerful 2-in-1 OSINT suite engineered for deep Email and Username Intelligence.
With 1080+ total scan vectorsβincluding 200+ email-integrated sites and 880+ username platformsβyou can map digital footprints, analyze target behavior, uncover interests, full metadata of usernames and verify account registrations in seconds.
π Sponsored by
Go beyond account enumeration. WebVetted turns an email or username into a complete identity investigation with deep OSINT enrichment, breach intel, AI analysis, and an interactive identity graph.
Start an Investigation β
Comprehensive OSINT platform for professional investigators and analysts. Reverse email, phone number, and username search across 250+ modules. Automate your intelligence gathering with our powerful tools.
Get Started β
Find beginner-friendly open-source issues and make your first pull request today.
Get Started β
β¨ Key Features
- π Deep Email & Username OSINT: Look up email registrations and perform advanced username profiling across 1080+ platforms.
- π€ Rich Metadata Scraping: Scrapes avatars, bio descriptions, follower counts, UID numbers, seller statuses, and account attributes.
- π Cross-Scan & Pivot Engine: Mines handles, profile links, and exposed email addresses from initial scans, automatically pivoting across secondary target vectors.
- π€ Model Context Protocol (MCP) Server: Native AI agent integration for Claude Desktop, Cursor, Antigravity, and LLMs to run autonomous OSINT scans and recursive pivots.
- π‘οΈ Hudson Rock Infostealer Breach Intel: Query infostealer malware breach logs using the
--hudsonflag for high-priority target correlation. - β‘ High-Throughput Parallel Engine: Powered by
httpxandcurl_cffifor maximum concurrency with automated TLS fingerprint impersonation. - π Permutation & Alias Generator: Wildcard-based username variation generation to catch typosquatting or alternative aliases.
- π Multi-Format Reports: Automated exports to PDF (with profile photos), JSON, and CSV for pipeline integration.
- π Advanced Proxy Pivoting: Built-in proxy rotation with protocol auto-detection (
http,socks5) and pre-scan health validation (--validate-proxies). - π¨ Responsive Terminal UI: Dynamic progress tracking, self-adaptive category grids (
-lu/-le), and clear status reporting.
π Installation
π Via PyPI (Recommended)
# Upgrade pip and install user-scanner
python3 -m pip install --upgrade pip
pip install user-scanner
# Optional: Install with MCP Server support for AI agents
pip install "user-scanner[mcp]"
π¦ Virtual Environment Setup
# Create and activate virtual environment
python3 -m venv .venv
source .venv/bin/activate # On Windows: .venv\Scripts\Activate.ps1
# Install package
pip install user-scanner
βοΈ Via Nix (Linux & macOS)
# Run instantly without installing permanently
nix run github:kaifcodec/user-scanner/main -- --help
# Drop into a temporary shell with user-scanner active
nix shell github:kaifcodec/user-scanner/main
π» Usage Guide
1. Basic Username & Email Scanning
Scan a single username or email address across all available platform modules:
user-scanner -u johndoe # Single username scan
user-scanner -e [email protected] # Single email scan
user-scanner -u johndoe --email-domains global # Try johndoe across provider domains
2. Cross-Scan & Pivot Intelligence
An email scan proves an account exists but rarely reveals a handle. --cross-scan mines exposed handles, profile links, and secondary email addresses from target profiles, pivoting into multi-pass reconnaissance across all matching platforms:
| Pivot Direction | What it Mines |
|---|---|
-e β username | Handles or social links exposed on an email's registered profile |
-u β username | Secondary aliases advertised across target social profiles |
-u β email | Public email addresses published on target profile pages |
-e β email | Secondary addresses exposed by initial email profiles |
user-scanner -u johndoe --cross-scan # Pivot from username scan
user-scanner -e [email protected] --cross-scan # Pivot from email scan
user-scanner -e [email protected] --cross-scan --cross-links verified # Platform-verified links only
user-scanner -u johndoe --cross-scan --cross-depth 2 # Follow links two hops deep
π‘ For confidence scoring, link classification rules, and cost models, see docs/CROSS_SCAN.md.
3. Hudson Rock Malware Breach Intelligence
Check if a target username or email address has been exposed in infostealer malware infection logs:
user-scanner -u johndoe --hudson # Username malware log check
user-scanner -e [email protected] --hudson # Email malware log check