Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
higernes — a passive OSINT toolkit in python - usernames, emails, domains, ips, phones, hashes. no keys, no logins. | Kitploit
Tools/GitLabGitLab/jankoboy88/higernes
OSINT (Open Source Intelligence)ReconnaissanceNetwork MappingPort ScanningDNS & Subdomain EnumerationHash AnalysisInformation GatheringPrivacyUtilities & FrameworksSubdomain EnumerationEmail Harvesting
10h 26m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitLab
jankoboy88/higernes

higernes

a passive OSINT toolkit in python - usernames, emails, domains, ips, phones, hashes. no keys, no logins.

View Repository

higernes

A passive OSINT toolkit in Python. No API keys, no accounts, no logging in anywhere. Point it at a handle, an email, a domain, an IP, a phone number or a hash and it digs through what's already public.

higernes

What it does

Six modules, all reading public endpoints:

ModuleWhat you get
usernamesweeps a handle across ~700 sites (the WhatsMyName dataset), live-updating as hits land
emailsyntax, MX, disposable check, gravatar, then the bit before the @ as a username
domainA/AAAA/MX/NS/TXT/CNAME, http status and title, subdomains from certificate transparency, whois
ipgeo + ASN, reverse dns, optional scan of common ports
phonevalidity, carrier, region, line type, timezone
hashlength/charset identification
scanfast TCP port scan with banner grabbing, powered by the C++ core

Nothing here touches anything private. It's all DNS, WHOIS, public profile endpoints and certificate logs.

The site database

The username sweep runs off data/wmn-data.json - the community WhatsMyName dataset, ~700 sites with a check rule each (status code plus a string that must, and must not, be present). Swap in a newer copy any time by dropping it over the file; the tool reads it at startup. If it's missing it falls back to a small built-in list.

Narrow a sweep with --cat:

python higernes.py username vqkro --cat social
python higernes.py username vqkro --cat gaming

Run it with no --cat and it hits everything.

The C++ core

The port scanner is too slow in Python, so the heavy lifting lives in core/hcore.cpp

  • a small standalone binary that does threaded connect scans with banner grabs and hostname resolution. higernes.py looks for it next to itself (or in core/, or on PATH) and shells out; if it isn't there, the ip --ports scan quietly falls back to the slower pure-Python version.

Build it (only needed if you're running from source and want the fast path):

# windows (mingw g++)
g++ -O2 -std=c++17 -static -o core/hcore.exe core/hcore.cpp -lws2_32

# linux / macOS
g++ -O2 -std=c++17 -o core/hcore core/hcore.cpp -pthread

Run it directly if you want:

hcore dns github.com
hcore ports example.com --banners
hcore ports example.com --all --threads 1024

The prebuilt .exe on the Releases page already has the core baked in.

Install

Needs Python 3.9 or newer.

Any OS

pip install -r requirements.txt

That pulls in rich, requests, dnspython and aiohttp. phonenumbers is in there too but only the phone module needs it - drop it from the file and the rest still runs. Without aiohttp the username sweep falls back to threads, which is far slower (tens of seconds against hundreds).

Windows (PowerShell, if python isn't on PATH yet)

winget install --id Python.Python.3.13 -e
git clone https://gitlab.com/jankoboy88/higernes
cd higernes
pip install -r requirements.txt
python higernes.py

Linux / macOS

git clone https://gitlab.com/jankoboy88/higernes
cd higernes
python3 -m pip install -r requirements.txt
python3 higernes.py

FreeBSD

pkg install -y python3
git clone https://gitlab.com/jankoboy88/higernes
cd higernes
python3 -m pip install -r requirements.txt

If pip complains about an externally-managed environment, either use a venv:

python3 -m venv .venv && . .venv/bin/activate && pip install -r requirements.txt

or pass --break-system-packages.

Use

Run it bare and you get the menu. Or go straight at a module:

python higernes.py username vqkro
python higernes.py username vqkro --cat coding
python higernes.py email [email protected]
python higernes.py domain example.com
python higernes.py ip 1.1.1.1 --ports
python higernes.py phone +14155552671
python higernes.py hash 5f4dcc3b5aa765d61d8327deb882cf99
python higernes.py scan example.com
python higernes.py scan example.com --all

The screen is all live spinners and coloured tables; the wordmark draws itself on startup.

Notes

  • dnspython and requests are strongly recommended. Without dnspython only the A record resolves (using the stdlib) and every other record type is skipped.
  • The site sweep is heuristic - a "found" just means the endpoint returned its positive signal, so double-check anything you plan to act on.
  • ip-api's free tier throttles to roughly 45 lookups a minute.
  • crt.sh can be slow or down; when it is, that section says so and moves on.

Build a standalone exe

No Python on the target machine? Bundle it:

pip install pyinstaller
pyinstaller --onefile --name higernes --console higernes.py
# -> dist/higernes.exe

That's how the binary on the Releases page is made. Nothing else to configure.

License

MIT. See LICENSE.

Download Tool