a passive OSINT toolkit in python usernames, emails, domains, ips, phones, hashes. no keys, no logins.
passive osint toolkit in python. no api keys, no accounts, no logging into anything. give it a handle, an email, a domain, an ip, a phone number or a hash and it goes through what's already public.

username sweeps a handle across about 700 sites, using the community WhatsMyName list. each entry in that list knows how to tell a hit from a miss, so the results aren't guesses. email checks the syntax and mx, looks for disposable domains, tries gravatar, then runs the part before the @ through the username sweep. domain pulls the dns records, the http status and title, subdomains out of certificate transparency and whois. ip gives geo and asn, reverse dns, and scans ports if you ask it to. phone does carrier, region, line type and timezone. hash just tells you what it probably is.
it's all public data. dns, whois, profile pages, cert logs.
needs python 3.9 or newer. then:
pip install -r requirements.txt
that gets you rich, requests, dnspython and aiohttp. phonenumbers comes along too but only the phone module touches it, so you can take it out of the file if you want. without aiohttp the username sweep falls back to threads and gets a lot slower, so keep it.
on windows, if python isn't on your path yet:
winget install --id Python.Python.3.13 -e
git clone https://gitlab.com/vqkro/higernes
cd higernes
pip install -r requirements.txt
python higernes.py
linux and mac are the same thing with python3 instead:
git clone https://gitlab.com/vqkro/higernes
cd higernes
python3 -m pip install -r requirements.txt
python3 higernes.py
on freebsd do pkg install -y python3 first.
if pip complains about an externally managed environment, either make a venv
python3 -m venv .venv && . .venv/bin/activate && pip install -r requirements.txt
or pass --break-system-packages and move on.
no arguments and you get the menu. or go straight at something:
python higernes.py username vqkro
python higernes.py username vqkro --cat coding
python higernes.py email [email protected]
python higernes.py domain example.com
python higernes.py ip 1.1.1.1 --ports
python higernes.py phone +14155552671
python higernes.py hash 5f4dcc3b5aa765d61d8327deb882cf99
python higernes.py scan example.com
python higernes.py scan example.com --all
a category only narrows the username sweep. leave it off and it hits all 700.
data/wmn-data.json is the WhatsMyName dataset. swap in a newer copy any time, it gets read at startup. if the file isn't there it falls back to a short list baked into the script so things still run.
the port scanner in python is slow, so that part lives in core/hcore.cpp and compiles to a small binary. higernes looks for it next to itself, in core/, or on path, and shells out. if it isn't there, ip --ports falls back to the slower python version. you only need to build it if you're running from source and want the fast path:
# windows
g++ -O2 -std=c++17 -static -o core/hcore.exe core/hcore.cpp -lws2_32
# linux / mac
g++ -O2 -std=c++17 -o core/hcore core/hcore.cpp -pthread
it stands on its own too:
hcore dns github.com
hcore ports example.com --banners
hcore ports example.com --all --threads 1024
the exe on the releases page already has it inside.
dnspython and requests are worth having. without dnspython only the A record resolves, everything else just gets skipped. ip-api's free endpoint throttles around 45 lookups a minute. crt.sh is slow or down half the time, and when it is the domain scan just says so and carries on.
pip install pyinstaller
pyinstaller --onefile --name higernes --console higernes.py
that's how the one on the releases page was built.
MIT, see LICENSE.