
An OSINT tool that helps detect members of a company with leaked credentials
EmploLeaks is an OSINT (Open Source Intelligence) tool with a CLI interface, designed to discover and correlate information about employees of a target company. It allows collecting LinkedIn profiles, generating potential corporate emails, searching for leaked credentials in leak databases (ClickHouse internally), verifying known breaches through HaveIBeenPwned, discovering company infrastructure, and profiling employees on social networks. All information is stored locally in SQLite for later analysis.
emploleaks/ ├── emploleaks.py # Script principal (CLI interactiva con cmd2) ├── telegram_sync.py # Daemon userbot de Telegram (Telethon, standalone) ├── requirements.txt # Dependencias de Python ├── README.md ├── .gitignore ├── plugins/ │ ├── linkedin.py # Plugin de LinkedIn (scraping de empleados) │ ├── github.py # Plugin de GitHub (repos, stalk, secrets) │ └── hibp.py # Plugin de HaveIBeenPwned (brechas) ├── utils/ │ ├── logging_format.py # Configuración de logging con colores │ ├── ai_classifier.py # Clasificación de roles con IA (OpenAI/Ollama) │ ├── leak_parser.py # Parser de leaks 100% agéntico (loop de IA, sin regex) │ ├── email_lookup.py # Búsqueda de emails en redes sociales (Holehe) │ ├── profile_lookup.py # Búsqueda de usernames en redes sociales (Maigret) │ └── discovery.py # Enumeración de subdominios (assetfinder + SecurityTrails opcional) ├── clickhouse-docker/ # Docker Compose para levantar ClickHouse │ ├── docker-compose.yml │ └── config/ │ └── users.xml ├── leaks_data/ # Carpeta para archivos de leaks a importar (no en git) ├── config/ # Configuración (autogenerado) │ └── tokens.ini # Tokens y credenciales de plugins (no en git) ├── data/ # Base de datos local (autogenerado) │ └── emploleaks.db # SQLite con toda la información recopilada ├── webapp/ # Webapp administrativa │ ├── backend/ # FastAPI (Python) │ └── frontend/ # Next.js (React/TypeScript) └── logs/ # Archivos de log (autogenerado) └── log.txt
## Requirements
- Python 3.10+
- pip
- Internet connection
- **Optional:** Docker and Docker Compose (to run ClickHouse locally)
- **Optional:** [gitleaks](https://github.com/gitleaks/gitleaks) (for scanning secrets in repos)
- **Optional:** [HaveIBeenPwned](https://haveibeenpwned.com/API/Key) API key
- LinkedIn session cookies (`JSESSIONID` and `li_at`) for the LinkedIn plugin
## Installation
1. Clone the repository:```bash
git clone https://github.com/yourusername/emploleaks.git
cd emploleaks
3. (Optional) Launch ClickHouse with Docker for the leak database:```bash
cd clickhouse-docker
docker compose up -d
cd ..
Run the tool:```bash python emploleaks.py
With debug mode:```bash
python emploleaks.py -d
| Command | Description |
|---|---|
help | Shows general help |
help <command> | Shows help for a specific command |
quit | Exits the application |
| Command | Description |
|---|---|
add_company --name <name> | Adds a new company |
select_company --name <name> | Selects a company to work with |
list_companies | Shows all companies |
delete_company --name <name> | Deletes a company and all its data |
| Command | Description |
|---|---|
use --plugin <name> | Activates a plugin (linkedin, github, hibp) |
deactivate | Deactivates the current plugin |
show options | Shows the active plugin's options |
setopt <option> [value] | Sets a plugin option (if no value is provided, it will be prompted as hidden input) |
autosave --enable / --disable | Enables/disables automatic saving of configuration to config/tokens.ini |
autoload --enable / --disable | Enables/disables automatic loading of configuration from config/tokens.ini |
| Command | Description |
|---|---|
connect_leaks | Connects to ClickHouse using the saved configuration in tokens.ini |
connect_leaks --host <host> --port <port> --save | Connects with specific parameters and saves them for future sessions |
disconnect_leaks | Disconnects from the ClickHouse database |
import_leaks [directory] | Imports credential files to ClickHouse (default: leaks_data/) |
import_leaks --no-ai | Imports only files with a known format, without using AI |
create_db --user <user> --passwd <pass> --dbname <db> [--import-data <dir>] | Creates the ClickHouse database manually (legacy) |
The ClickHouse connection is configured in config/tokens.ini:```ini
[clickhouse]
host = localhost
port = 9000
user = default
passwd =
dbname = credentials_db
If ClickHouse is configured in `tokens.ini`, the connection is established automatically on startup.
### Credential and Breach Search
| Command | Description |
|---------|-------------|
| `find_passwords <mode>` | Searches for credentials in ClickHouse + [ProxyNova COMB](https://www.proxynova.com/tools/comb/) (3.2B credentials). Modes: `find_all`, `only_usernames`, `only_emails` |
| `find_passwords <mode> --no-proxynova` | Searches only in local ClickHouse |
| `find_passwords <mode> --no-clickhouse` | Searches only in ProxyNova COMB (requires no ClickHouse) |
| `find_passwords <mode> --email <email>` | Searches for credentials for a specific email |
| `find_breaches` | Searches for breaches in HIBP for all company emails (requires plugin `hibp` active) |
**ProxyNova COMB** is a public database with 3.2 billion leaked credentials (Combination Of Many Breaches). It requires no API key and is queried automatically on each search. Use `--no-proxynova` to disable it.
### Infrastructure Discovery
| Command | Description |
|---------|-------------|
| `add_domain <domain>` | Associates a domain with the selected company (e.g., `add_domain faradaysec.com`) |
| `discover` | Runs subdomain enumeration against all company domains using `assetfinder` (+ optional SecurityTrails), resolving DNS |
| `print --data domains` | Shows registered domains and the number of subdomains found |
| `print --data subdomains` | Shows all subdomains with their IP, source, and discovery date |