Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
工具/GitHubGitHub/infobyte/emploleaks
OSINT (开源情报)密码破解侦察数据泄露信息收集Web安全渗透测试社会工程学威胁情报子域名枚举电子邮件收集
78864304个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHub
infobyte/emploleaks

emploleaks

一款OSINT工具,用于检测公司成员是否存在泄露凭证。

查看仓库网站

EmploLeaks

EmploLeaks 是一款 OSINT(开源情报)工具,配备 CLI 界面,旨在发现并关联目标企业员工的相关信息。它能够收集 LinkedIn 个人资料、生成潜在的企业电子邮件、在泄露数据库中(内部基于 ClickHouse)搜索已泄露的凭证、通过 HaveIBeenPwned 验证已知漏洞、发现企业基础设施并在社交媒体中描绘员工画像。所有信息均本地存储在 SQLite 中,以供后续分析。

特性

  • 从 LinkedIn 搜索和枚举员工(使用会话 Cookie 进行爬取)
  • 自动生成潜在的企业电子邮件,支持自定义格式
  • 在自有 ClickHouse 数据库中搜索已泄露的凭证
  • 使用 HaveIBeenPwned API 验证已知漏洞
  • 使用 gitleaks 扫描 GitHub/GitLab 仓库中的密钥
  • 基础设施发现: 使用 assetfinder + SecurityTrails 枚举子域名
  • 社交媒体画像: 通过电子邮件搜索(Holehe,约 120 个平台)和用户名搜索(Maigret,500+ 平台)
  • Telegram 爬虫 (userbot): 独立运行的后台守护进程,自动加入已授权的 Telegram 频道并下载凭证文件
  • 100% 智能化的泄露解析器: 无需硬编码正则表达式。AI 代理提出 schema,基于样本得分进行验证,接收包含错误示例的反馈,并反复尝试直至收敛。自动检测 UTF-16/UTF-8、ASCII art 横幅、国家代码前缀、偷窃日志(Redline/Lumma/Raccoon)、任意 email/user/url 格式
  • 将所有信息本地存储在 SQLite 中
  • 生成包含个人资料照片的交互式 HTML 报告
  • 使用 AI(OpenAI、Ollama 等)自动按部门分类员工
  • 导出结果至 CSV
  • 模块化插件系统(LinkedIn、GitHub、HIBP)
  • 插件配置的自动保存和加载
  • 使用 FastAPI + Next.js 构建的管理 Web 应用,用于结果分类

项目结构```

emploleaks/ ├── emploleaks.py # Script principal (CLI interactiva con cmd2) ├── telegram_sync.py # Daemon userbot de Telegram (Telethon, standalone) ├── requirements.txt # Dependencias de Python ├── README.md ├── .gitignore ├── plugins/ │ ├── linkedin.py # Plugin de LinkedIn (scraping de empleados) │ ├── github.py # Plugin de GitHub (repos, stalk, secrets) │ └── hibp.py # Plugin de HaveIBeenPwned (brechas) ├── utils/ │ ├── logging_format.py # Configuración de logging con colores │ ├── ai_classifier.py # Clasificación de roles con IA (OpenAI/Ollama) │ ├── leak_parser.py # Parser de leaks 100% agéntico (loop de IA, sin regex) │ ├── email_lookup.py # Búsqueda de emails en redes sociales (Holehe) │ ├── profile_lookup.py # Búsqueda de usernames en redes sociales (Maigret) │ └── discovery.py # Enumeración de subdominios (assetfinder + SecurityTrails opcional) ├── clickhouse-docker/ # Docker Compose para levantar ClickHouse │ ├── docker-compose.yml │ └── config/ │ └── users.xml ├── leaks_data/ # Carpeta para archivos de leaks a importar (no en git) ├── config/ # Configuración (autogenerado) │ └── tokens.ini # Tokens y credenciales de plugins (no en git) ├── data/ # Base de datos local (autogenerado) │ └── emploleaks.db # SQLite con toda la información recopilada ├── webapp/ # Webapp administrativa │ ├── backend/ # FastAPI (Python) │ └── frontend/ # Next.js (React/TypeScript) └── logs/ # Archivos de log (autogenerado) └── log.txt

## 要求

- Python 3.10+
- pip
- 互联网连接
- **可选:** Docker 和 Docker Compose(用于本地启动 ClickHouse)
- **可选:** [gitleaks](https://github.com/gitleaks/gitleaks)(用于仓库中的密钥扫描)
- **可选:** [HaveIBeenPwned](https://haveibeenpwned.com/API/Key) 的 API 密钥
- LinkedIn 插件所需的会话 Cookie(`JSESSIONID` 和 `li_at`)

## 安装

1. 克隆仓库:```bash
git clone https://github.com/yourusername/emploleaks.git
cd emploleaks
  1. 安装依赖:```bash pip install -r requirements.txt
3. (可选) 使用 Docker 启动 ClickHouse 用于泄露数据库:```bash
cd clickhouse-docker
docker compose up -d
cd ..

用法

运行工具:```bash python emploleaks.py

使用调试模式:```bash
python emploleaks.py -d

通用命令

命令描述
help显示通用帮助
help <命令>显示特定命令的帮助
quit退出应用程序

公司管理

命令描述
add_company --name <名称>添加一家新公司
select_company --name <名称>选择一家公司进行操作
list_companies显示所有公司
delete_company --name <名称>删除一家公司及其所有数据

插件管理

命令描述
use --plugin <名称>激活一个插件(linkedin、github、hibp)
deactivate停用当前插件
show options显示当前插件的选项
setopt <选项> [值]设置插件选项(若未提供值,则通过隐藏提示输入)
autosave --enable / --disable启用/禁用将配置自动保存到 config/tokens.ini
autoload --enable / --disable启用/禁用从 config/tokens.ini 自动加载配置

连接泄露数据库 (ClickHouse)

命令描述
connect_leaks使用保存在 tokens.ini 中的配置连接到 ClickHouse
connect_leaks --host <主机> --port <端口> --save使用特定参数连接并保存以供后续会话使用
disconnect_leaks断开与 ClickHouse 数据库的连接
import_leaks [目录]将凭证文件导入 ClickHouse(默认目录:leaks_data/)
import_leaks --no-ai仅导入已知格式的文件,不使用 AI
create_db --user <用户> --passwd <密码> --dbname <数据库> [--import-data <目录>]手动创建 ClickHouse 数据库(遗留方法)

ClickHouse 的连接配置在 config/tokens.ini 中设置:```ini [clickhouse] host = localhost port = 9000 user = default passwd = dbname = credentials_db

如果 ClickHouse 在 `tokens.ini` 中进行了配置,连接将在启动时自动建立。

### 凭证与泄露搜索

| 命令 | 描述 |
|---------|-------------|
| `find_passwords <modo>` | 在 ClickHouse + [ProxyNova COMB](https://www.proxynova.com/tools/comb/)(32 亿凭证)中搜索凭证。模式:`find_all`、`only_usernames`、`only_emails` |
| `find_passwords <modo> --no-proxynova` | 仅在本地 ClickHouse 中搜索 |
| `find_passwords <modo> --no-clickhouse` | 仅在 ProxyNova COMB 中搜索(无需 ClickHouse) |
| `find_passwords <modo> --email <email>` | 搜索特定邮箱的凭证 |
| `find_breaches` | 在 HIBP 中搜索公司所有邮箱的泄露事件(需启用 `hibp` 插件) |

**ProxyNova COMB** 是一个包含 32 亿条泄露凭证的公共数据库(多泄露综合库)。无需 API 密钥,每次搜索时自动查询。使用 `--no-proxynova` 可禁用它。

### 基础设施发现

| 命令 | 描述 |
|---------|-------------|
| `add_domain <dominio>` | 将域名关联到所选公司(例如:`add_domain faradaysec.com`) |
| `discover` | 针对公司所有域名执行子域名枚举,使用 `assetfinder`(可选 SecurityTrails),并解析 DNS |
| `print --data domains` | 显示已注册的域名及发现的子域名数量 |
| `print --data subdomains` | 显示所有子域名及其 IP、来源和发现日期 |

发现模块将被动枚举委托给 [`assetfinder`](https://github.com/tomnomnom/assetfinder),它内部聚合了 crt.sh、HackerTarget、BufferOver 及其他无需 API 密钥的来源的结果。需确保该二进制文件在 `$PATH` 中(安装方式:`go install github.com/tomnomnom/assetfinder@latest`)。

可选地,如果你配置了 SecurityTrails 的 API 密钥,其子域名将与 assetfinder 的结果合并。```ini
[discovery]
# securitytrails_key = your_key_here

社交媒体画像

命令描述
lookup_emails使用Holehe在约120个平台上搜索已确认的电子邮件
lookup_emails --include-potential也包含生成的电子邮件
lookup_emails --email [email protected]搜索特定电子邮件
lookup_emails --all在120+个平台上搜索(不仅限于已配置的)
lookup_emails --list-platforms列出所有可用平台
lookup_profiles使用Maigret按用户名搜索个人资料(需要已加载的用户名)
lookup_profiles --employee "Juan"仅搜索特定员工

Holehe(电子邮件查找):使用“忘记密码”技术来确定电子邮件是否在每个平台上注册,而不会提醒用户。平台在tokens.ini中配置:```ini [holehe] platforms = google, discord, github, instagram, twitter, spotify, ...

**Maigret**(用户名查找):搜索用户名是否存在于500多个社交平台。用户名由员工通过webapp手动添加。平台可在 `tokens.ini` 中选择性过滤:```ini
[maigret]
# platforms = instagram, twitter, facebook, tiktok, reddit, github

可视化与导出

ComandoDescripción
print --data emails显示已确认和潜在的电子邮件
print --data passwords显示找到的凭据
print --data breaches显示HIBP泄露事件
print --data gits显示GitHub账户
print --data twitters显示Twitter/X账户
print --data phones显示电话号码
print --data websites显示网站
print --data secrets显示在仓库中找到的机密
print --data domains显示注册的域名
print --data subdomains显示发现的子域名
print --data all显示按员工合并的所有数据
print --data all --html生成包含照片的交互式HTML报告
print --data all --html --ai生成使用AI按部门分组员工的HTML报告
print --data <tipo> --export将数据导出为带时间戳的CSV文件

AI与分类配置

ComandoDescripción
set_ai --endpoint <url> --key <key> --model <modelo>配置AI提供商
classify使用AI将员工分类到部门(保存到数据库)
classify --force即使已分配部门也重新分类

AI分类分析员工的职称/角色,并按部门分组(如Engineering、Security、Sales等)。部门信息持久化存储在SQLite中,并在HTML报告和Web应用中可见。

支持的提供商(任何兼容OpenAI的API):

  • Ollama(本地,默认): set_ai --endpoint http://localhost:11434/v1 --model llama3
  • OpenAI: set_ai --endpoint https://api.openai.com/v1 --key sk-... --model gpt-4o-mini
  • 其他兼容的: LM Studio、Together AI等。

Telegram Scraper(Userbot)

独立守护进程,使用个人Telegram账户(通过Telethon)加入已批准的频道/群组,下载 .txt/.csv/.dat/.zip/.gz 文件并放入 leaks_data/telegram/<chat>/。后续的 import_leaks 使用智能解析器将数据导入ClickHouse。与CLI解耦 — 作为独立进程运行,因此可以24/7运行而无需打开CLI。

下载工具