Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
iKy — OSINT Project. Collect information from a mail. Gather. Profile. Timeline. | Kitploit
Tools/GitHubGitHub/kennbroorg/iky
OSINT (Open Source Intelligence)ReconnaissancePassword AttacksData ExfiltrationInformation GatheringSocial EngineeringThreat IntelligenceEmail Harvesting
GitHubkennbroorg/iky

iKy

OSINT Project. Collect information from a mail. Gather. Profile. Timeline.

View Repository
963154802 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website
Redis Python Celery FastAPI Node Angular Docker
README Español

Logo

Description   |   Installation   |   Website   |   Modules   |   Issues   |   Supporting


iKy

Description

iKy is an OSINT tool that collects information from an email address or other selectors and displays the results in a visual interface.

(pending update: reflects the previous frontend)
Video Demo

Installation

Prerequisites

  • Docker
  • Docker Compose (included with Docker Desktop)
  • (Optional) just task runner

Quick start

git clone https://gitlab.com/kennbroorg/iKy.git
cd iKy
just build
just up

Open your browser at http://localhost:4300

To stop all services:

just down

just up starts backend, iky-frontend, and redis. No other services are launched by default.

Without Docker (native)

If you cannot run Docker, iKy can run natively: Caddy serves the pre-built frontend and Redis + Celery + Uvicorn run as local processes. Requires redis-server, Python 3.12, curl and tar on the host (Caddy is downloaded automatically).

just setup          # create the venv
just up-native      # installs deps, downloads Caddy + frontend, starts everything

Open your browser at http://localhost:4300. Stop with Ctrl-C or just down-native.

The frontend is pulled from the latest GitHub release — no Node build needed. tor is not launched in native mode; only the darkweb module needs it.

Architecture

ServiceStackPort
backendFastAPI 0.115 + Celery 5.65000
iky-frontendAngular 21 + nginx4300
redisRedis 756379 (host)
torSOCKS5 proxy (darkweb module)internal

Modules

iKy routes 26 modules through backend/module_registry.py:

CategoryModules
Social networkstwitter, linkedin, instagram, tiktok, mastodon, twitch, reddit
Identity / usernamegithub, gitlab, keybase, sherlock, socialscan, holehe, usersearch, skype
Dating / paymentstinder, venmo
Musicspotify
Reputation / data brokerspeopledatalabs, emailrep, fullcontact
Leaks / breachesleaks, leaklookup, darkweb, hudsonrock
Searchsearch

API Keys

Once the application is loaded in the browser, enter your API keys in the settings panel. Below is the full table of fields from backend/factories/apikeys_default.json:

ModuleStatusField in apikeyHow to obtain
LinkedIn🆗 🍪linkedin_cookies (or legacy linkedin_li_at / linkedin_JSESSIONID)just cookies-grab linkedin linkedin.com or just cookies-import linkedin <file>
Twitter🆗 🍪twitter_cookiesjust cookies-grab twitter x.com
TikTok🆗 🍪tiktok_cookiesjust cookies-grab tiktok tiktok.com
PeopleDataLabs🆗peopledatalabs_key🆓 Free API — wiki
Emailrep🆗emailrep_key🆓 Free API — wiki
Leaklookup🆗leaklookup_key🆓 Free API — wiki
Spotify🆗spotify_client_id / spotify_client_secret🆓 Free API — wiki
Twitch🆗twitch_client_id / twitch_client_secret🆓 Free API — wiki
CSE (Google)🆗cse_api_key / cse_cx🆓 Free API — wiki
Brave🆗brave_key🆓 Free API
Instagram⚠️instagram_user / instagram_passUnder revision
Fullcontact🛑fullcontact_apiDiscontinued
HaveIBeenPwned🛑haveibeenpwned_keyDiscontinued

APIs marked with 🍪 use browser session cookies; the rest use service tokens.

Session cookies

Some modules (LinkedIn, Twitter, TikTok) require session cookies from your browser. Cookies are stored in backend/cookies/ (mounted in the container as /app/cookies) and persist across restarts. There are two ways to load them, both via just.

Cookies are personal session tokens: do not share them or commit them to the repository (backend/cookies/ is git-ignored).

Option A: Import a browser export

Export the site cookies with an extension such as Cookie-Editor to a JSON file and import it:

just cookies-import linkedin ~/Downloads/linkedin_cookies.json

Option B: Extract them automatically from the browser

Extracts cookies directly from your local browser. Close the browser before running (an open browser locks its cookie database):

# Try all installed browsers (firefox, chrome, brave, edge)
just cookies-grab linkedin linkedin.com

# Or a specific one
just cookies-grab linkedin linkedin.com brave

The command reports, browser by browser, what it could read and what it could not, and writes the file only if it finds the cookies the module needs. For example, LinkedIn requires li_at and JSESSIONID.

ModuleDomainRequired cookies
LinkedInlinkedin.comli_at, JSESSIONID
Twitterx.comauth_token, ct0
TikToktiktok.commsToken
Download Tool