Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
WhatBreach — Strumento OSINT per trovare email violate, database, pastes e informazioni pertinenti | Kitploit
Strumenti/GitHubGitHub/ekultek/whatbreach
OSINT (Open Source Intelligence)RicognizioneEsfiltrazione DatiRaccolta InformazioniRaccolta Email
GitHubekultek/whatbreach

WhatBreach

Strumento OSINT per trovare email violate, database, pastes e informazioni pertinenti

Vedi Repository
1.6k220201 anno faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

WhatBreach

WhatBreach è uno strumento OSINT che semplifica il compito di scoprire in quali violazioni è stato individuato un indirizzo email. WhatBreach fornisce un modo semplice ed efficace per cercare più indirizzi email, o uno singolo, e scoprire tutte le violazioni note in cui questa email è stata vista. Da lì, WhatBreach è in grado di scaricare il database se è disponibile pubblicamente, scaricare i paste in cui l'email è stata vista, o cercare il dominio dell'email per ulteriori indagini. Per eseguire questo compito con successo, WhatBreach sfrutta i seguenti siti web e/o API:

  • WhatBreach sfrutta l'API di haveibeenpwned.com. L'API di HIBP non è più gratuita e costa 3,50 USD al mese. Per ottenere una chiave API, vedere qui
  • WhatBreach sfrutta dehashed.com per scoprire se il database è già stato visto in una violazione. WhatBreach fornisce un collegamento a una ricerca su dehashed per un download efficace
  • WhatBreach sfrutta l'API di hunter.io (richiede un token API gratuito) che consente una ricerca semplice ed efficace del dominio e fornirà ulteriori informazioni sul dominio oggetto della ricerca, oltre a salvare i risultati scoperti in un file per elaborazioni successive
  • WhatBreach sfrutta i paste di pastebin.com trovati da HIBP. Fornirà anche un collegamento al paste in cui è stata vista la violazione ed è in grado di scaricare il paste grezzo se richiesto
  • WhatBreach sfrutta databases.today per scaricare i database dal sito. Ciò consente un modo semplice ed efficace di scaricare database senza dover cercare manualmente
  • WhatBreach sfrutta l'API di weleakinfo.com (richiede un token API gratuito) che fornisce una ricerca aggiuntiva per l'email al fine di scoprire ancora più violazioni pubbliche
  • WhatBreach sfrutta la semplice API aperta di emailrep.io per cercare possibili profili associati a un'email e scarica tutte le informazioni scoperte in un file per ulteriori elaborazioni

Alcune caratteristiche interessanti di WhatBreach includono le seguenti:

  • Capacità di rilevare se l'email è un'email temporanea (ten minute email) o meno e chiedere se elaborarla o meno
  • Verificare lo stato di consegna dell'email tramite hunter.io
  • Capacità di limitare le richieste per aiutare a prevenire il blocco da parte di HIBP
  • Scaricare i database (poiché sono grandi) in una directory a scelta
  • Cercare una singola email o un file di testo contenente un'email per riga

Esempi

Pagina di aiuto:

usage: whatbreach.py [-h] [-e EMAIL] [-l PATH] [-nD] [-nP] [-sH] [-wL] [-dP]
                     [-vH] [-cT] [-d] [-s DIRECTORY-PATH] [--throttle TIME]

optional arguments:
  -h, --help            show this help message and exit

mandatory opts:
  -e EMAIL, --email EMAIL
                        Pass a single email to scan for
  -l PATH, -f PATH, --list PATH, --file PATH
                        Pass a file containing emails one per line to scan

search opts:
  -nD, --no-dehashed    Suppres dehashed output
  -nP, --no-pastebin    Suppress Pastebin output
  -sH, --search-hunter  Search hunter.io with a provided email address and
                        query for all information, this will process all
                        emails found as normal
  -wL, --search-weleakinfo
                        Search weleakinfo.com as well as HIBP for results

misc opts:
  -dP, --download-pastes
                        Download pastes associated with the email address
                        found (if any)
  -vH, --verify-hunter  Verify the emails found on hunter.io for deliverable
                        status
  -cT, --check-ten-minute
                        Check if the provided email address is a ten minute
                        email or not
  -d, --download        Attempt to download the database if there is one
                        available
  -s DIRECTORY-PATH, --save-dir DIRECTORY-PATH
                        Pass a directory to save the downloaded databases into
                        instead of the `HOME` path
  --throttle TIME       Throttle the HIBP requests to help prevent yourself
                        from being blocked

Ricerca semplice di un'email:

python whatbreach.py -e [email protected]

	                                                    _____ 
	   _ _ _ _       _   _____                 _       |___  |
	  | | | | |_ ___| |_| __  |___ ___ ___ ___| |_       |  _|
	  | | | |   | .'|  _| __ -|  _| -_| .'|  _|   |      |_|  
	  |_____|_|_|__,|_| |_____|_| |___|__,|___|_|_|[][][]|_|
	Find emails and their associated leaked databases.. v0.1.5


[ i ] starting search on single email address: [email protected]
[ i ] searching breached accounts on HIBP related to: [email protected]
[ i ] searching for paste dumps on HIBP related to: [email protected]
[ i ] found a total of 9 database breach(es) pertaining to: [email protected]
---------------------------------------------------------------------------
Breach/Paste:	     | Database/Paste Link:
Dailymotion          | https://www.dehashed.com/search?query=Dailymotion
500px                | https://www.dehashed.com/search?query=500px
LinkedIn             | https://www.dehashed.com/search?query=LinkedIn
MyFitnessPal         | https://www.dehashed.com/search?query=MyFitnessPal
Bolt                 | https://www.dehashed.com/search?query=Bolt
Dropbox              | https://www.dehashed.com/search?query=Dropbox
Lastfm               | https://www.dehashed.com/search?query=Lastfm
Apollo               | https://www.dehashed.com/search?query=Apollo
OnlinerSpambot       | N/A                           
---------------------------------------------------------------------------

Ricerca con weleakinfo e haveibeenpwned:

python whatbreach.py -e [email protected] -wL

	                                                    _____ 
	   _ _ _ _       _   _____                 _       |___  |
	  | | | | |_ ___| |_| __  |___ ___ ___ ___| |_       |  _|
	  | | | |   | .'|  _| __ -|  _| -_| .'|  _|   |      |_|  
	  |_____|_|_|__,|_| |_____|_| |___|__,|___|_|_|[][][]|_|
	Find emails and their associated leaked databases.. v0.1.5
Scarica lo strumento