Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
LinkedInDumper β€” Python 3 script to dump/scrape/extract company employees from LinkedIn API | Kitploit
Tools/GitHubGitHub/l4rm4nd/linkedindumper
OSINT (Open Source Intelligence)ReconnaissanceInformation GatheringEmail HarvestingCrawler
GitHubl4rm4nd/linkedindumper

LinkedInDumper

Python 3 script to dump/scrape/extract company employees from LinkedIn API

View Repository
60661351 month agoReviewed by Kitploit

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share
Website

LinkedInDumper

Python 3 script to dump company employees from LinkedIn API





Buy Me A Coffee

πŸ’¬ Description

LinkedInDumper is a Python 3 script that dumps employee data from the LinkedIn social networking platform.

The results contain firstname, lastname, position (title), location and a user's profile link. Only 2 API calls are required to retrieve all employees if the company does not have more than 10 employees. Otherwise, we have to paginate through the API results. With the --email-format CLI flag one can define a Python string format to auto generate email addresses based on the retrieved first and last name.

✨ Requirements

LinkedInDumper talks with the unofficial LinkedIn Voyager API, which requires authentication. Therefore, you must have a valid LinkedIn user account. To keep it simple, LinkedInDumper just expects a cookie value provided by you. Doing it this way, even 2FA protected accounts are supported. Furthermore, you are tasked to provide a LinkedIn company URL to dump employees from.

Retrieving LinkedIn Cookie

  1. Sign into www.linkedin.com and retrieve your li_at session cookie value e.g. via developer tools
  2. Specify the cookie value either persistently in the python script's variable li_at or temporarily during runtime via the CLI flag --cookie

Retrieving LinkedIn Company URL

  1. Search your target company on Google Search or directly on LinkedIn
  2. The LinkedIn company URL should look something like this: https://www.linkedin.com/company/apple

πŸŽ“ Usage

usage: linkedindumper.py [-h] --url <linkedin-url> [--cookie <cookie>] [--quiet] [--include-private-profiles] [--include-contact-infos] [--jitter] [--email-format <mail-format>] [--output-json <json-file>] [--output-csv <csv-file>]

options:
  -h, --help            show this help message and exit
  --url <linkedin-url>  A LinkedIn company url - https://www.linkedin.com/company/<company>
  --cookie <cookie>     LinkedIn 'li_at' session cookie
  --include-private-profiles
                        Show private accounts too
  --include-contact-infos
                        Query each employee individually and retrieve contact infos
  --jitter              Add a random jitter to HTTP requests to bypass rate limiting
  --email-format <mail-format>
                        Python string format for emails; for example:
                        --email-format '{0}.{1}@example.com' --> [email protected]
                        --email-format '{0[0]}.{1}@example.com' --> [email protected]
                        --email-format '{1}@example.com' --> [email protected]
                        --email-format '{0}@example.com' --> [email protected]
                        --email-format '{0[0]}{1[0]}@example.com' --> [email protected]
  --output-json <json-file>
                        Store results in json output file
  --output-csv <csv-file>
                        Store results in csv output file                        

🐳 Example 1 - Docker Run

docker run --rm l4rm4nd/linkedindumper:latest --url 'https://www.linkedin.com/company/apple' --cookie '<cookie>' --email-format '{0}.{1}@apple.de'

🐍 Example 2 - Native Python

# install dependencies
pip install -r requirements.txt

python3 linkedindumper.py --url 'https://www.linkedin.com/company/apple' --cookie '<cookie>' --email-format '{0}.{1}@apple.de'

πŸ’Ž Outputs

The script will return employee data as semi-colon separated values (like CSV):

 β–ˆβ–ˆβ–“     β–ˆβ–ˆβ–“ β–ˆβ–ˆβ–ˆβ–„    β–ˆ  β–ˆβ–ˆ β–„β–ˆβ–€β–“β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β–“β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–„  β–ˆβ–ˆβ–“ β–ˆβ–ˆβ–ˆβ–„    β–ˆ β–“β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–„  β–ˆ    β–ˆβ–ˆ  β–ˆβ–ˆβ–ˆβ–„ β–„β–ˆβ–ˆβ–ˆβ–“ β–ˆβ–ˆβ–“β–ˆβ–ˆβ–ˆ  β–“β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ  β–ˆβ–ˆβ–€β–ˆβ–ˆβ–ˆ  
β–“β–ˆβ–ˆβ–’    β–“β–ˆβ–ˆβ–’ β–ˆβ–ˆ β–€β–ˆ   β–ˆ  β–ˆβ–ˆβ–„β–ˆβ–’ β–“β–ˆ   β–€ β–’β–ˆβ–ˆβ–€ β–ˆβ–ˆβ–Œβ–“β–ˆβ–ˆβ–’ β–ˆβ–ˆ β–€β–ˆ   β–ˆ β–’β–ˆβ–ˆβ–€ β–ˆβ–ˆβ–Œ β–ˆβ–ˆ  β–“β–ˆβ–ˆβ–’β–“β–ˆβ–ˆβ–’β–€β–ˆβ–€ β–ˆβ–ˆβ–’β–“β–ˆβ–ˆβ–‘  β–ˆβ–ˆβ–’β–“β–ˆ   β–€ β–“β–ˆβ–ˆ β–’ β–ˆβ–ˆβ–’
β–’β–ˆβ–ˆβ–‘    β–’β–ˆβ–ˆβ–’β–“β–ˆβ–ˆ  β–€β–ˆ β–ˆβ–ˆβ–’β–“β–ˆβ–ˆβ–ˆβ–„β–‘ β–’β–ˆβ–ˆβ–ˆ   β–‘β–ˆβ–ˆ   β–ˆβ–Œβ–’β–ˆβ–ˆβ–’β–“β–ˆβ–ˆ  β–€β–ˆ β–ˆβ–ˆβ–’β–‘β–ˆβ–ˆ   β–ˆβ–Œβ–“β–ˆβ–ˆ  β–’β–ˆβ–ˆβ–‘β–“β–ˆβ–ˆ    β–“β–ˆβ–ˆβ–‘β–“β–ˆβ–ˆβ–‘ β–ˆβ–ˆβ–“β–’β–’β–ˆβ–ˆβ–ˆ   β–“β–ˆβ–ˆ β–‘β–„β–ˆ β–’
β–’β–ˆβ–ˆβ–‘    β–‘β–ˆβ–ˆβ–‘β–“β–ˆβ–ˆβ–’  β–β–Œβ–ˆβ–ˆβ–’β–“β–ˆβ–ˆ β–ˆβ–„ β–’β–“β–ˆ  β–„ β–‘β–“β–ˆβ–„   β–Œβ–‘β–ˆβ–ˆβ–‘β–“β–ˆβ–ˆβ–’  β–β–Œβ–ˆβ–ˆβ–’β–‘β–“β–ˆβ–„   β–Œβ–“β–“β–ˆ  β–‘β–ˆβ–ˆβ–‘β–’β–ˆβ–ˆ    β–’β–ˆβ–ˆ β–’β–ˆβ–ˆβ–„β–ˆβ–“β–’ β–’β–’β–“β–ˆ  β–„ β–’β–ˆβ–ˆβ–€β–€β–ˆβ–„  
β–‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–’β–‘β–ˆβ–ˆβ–‘β–’β–ˆβ–ˆβ–‘   β–“β–ˆβ–ˆβ–‘β–’β–ˆβ–ˆβ–’ β–ˆβ–„β–‘β–’β–ˆβ–ˆβ–ˆβ–ˆβ–’β–‘β–’β–ˆβ–ˆβ–ˆβ–ˆβ–“ β–‘β–ˆβ–ˆβ–‘β–’β–ˆβ–ˆβ–‘   β–“β–ˆβ–ˆβ–‘β–‘β–’β–ˆβ–ˆβ–ˆβ–ˆβ–“ β–’β–’β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–“ β–’β–ˆβ–ˆβ–’   β–‘β–ˆβ–ˆβ–’β–’β–ˆβ–ˆβ–’ β–‘  β–‘β–‘β–’β–ˆβ–ˆβ–ˆβ–ˆβ–’β–‘β–ˆβ–ˆβ–“ β–’β–ˆβ–ˆβ–’
β–‘ β–’β–‘β–“  β–‘β–‘β–“  β–‘ β–’β–‘   β–’ β–’ β–’ β–’β–’ β–“β–’β–‘β–‘ β–’β–‘ β–‘ β–’β–’β–“  β–’ β–‘β–“  β–‘ β–’β–‘   β–’ β–’  β–’β–’β–“  β–’ β–‘β–’β–“β–’ β–’ β–’ β–‘ β–’β–‘   β–‘  β–‘β–’β–“β–’β–‘ β–‘  β–‘β–‘β–‘ β–’β–‘ β–‘β–‘ β–’β–“ β–‘β–’β–“β–‘
β–‘ β–‘ β–’  β–‘ β–’ β–‘β–‘ β–‘β–‘   β–‘ β–’β–‘β–‘ β–‘β–’ β–’β–‘ β–‘ β–‘  β–‘ β–‘ β–’  β–’  β–’ β–‘β–‘ β–‘β–‘   β–‘ β–’β–‘ β–‘ β–’  β–’ β–‘β–‘β–’β–‘ β–‘ β–‘ β–‘  β–‘      β–‘β–‘β–’ β–‘      β–‘ β–‘  β–‘  β–‘β–’ β–‘ β–’β–‘
  β–‘ β–‘    β–’ β–‘   β–‘   β–‘ β–‘ β–‘ β–‘β–‘ β–‘    β–‘    β–‘ β–‘  β–‘  β–’ β–‘   β–‘   β–‘ β–‘  β–‘ β–‘  β–‘  β–‘β–‘β–‘ β–‘ β–‘ β–‘      β–‘   β–‘β–‘          β–‘     β–‘β–‘   β–‘ 
    β–‘  β–‘ β–‘           β–‘ β–‘  β–‘      β–‘  β–‘   β–‘     β–‘           β–‘    β–‘       β–‘            β–‘               β–‘  β–‘   β–‘     
                                      β–‘                      β–‘                                         β–‘ by LRVT      

[i] Company Name: apple
[i] Company X-ID: 162479
[i] LN Employees: 1000 employees found
[i] Dumping Date: 17/10/2022 13:55:06
[i] Email Format: {0}.{1}@apple.de

Firstname;Lastname;Email;Position;Gender;Location;Profile
Katrin;Honauer;[email protected];Software Engineer at Apple;N/A;Heidelberg;https://www.linkedin.com/in/katrin-honauer
Raymond;Chen;[email protected];Recruiting at Apple;N/A;Austin, Texas Metropolitan Area;https://www.linkedin.com/in/raytherecruiter

[i] Successfully crawled 2 unique apple employee(s). Hurray ^_-

Optionally, you can use the CLI parameters --output-json and --output-csv to store the results as JSON or CSV.

πŸ’₯ Limitations

LinkedIn will allow only the first 1,000 search results to be returned when harvesting contact information. You may also need a LinkedIn premium account when you reached the maximum allowed queries for visiting profiles with your freemium LinkedIn account.

Download Tool