
Multi-platform OSINT scanner for email and username reconnaissance across 295+ vectors. Extracts profile metadata, checks account registrations, and integrates breach intelligence for digital footprint analysis.
A powerful 2-in-1 OSINT suite engineered for deep Email and Username Intelligence.
With 1080+ total scan vectors—including 200+ email-integrated sites and 880+ username platforms—you can map digital footprints, analyze target behavior, uncover interests, full metadata of usernames and verify account registrations in seconds.
Go beyond account enumeration. WebVetted turns an email or username into a complete identity investigation with deep OSINT enrichment, breach intel, AI analysis, and an interactive identity graph.
Start an Investigation →
Comprehensive OSINT platform for professional investigators and analysts. Reverse email, phone number, and username search across 250+ modules. Automate your intelligence gathering with our powerful tools.
Get Started →
Find beginner-friendly open-source issues and make your first pull request today.
Get Started →
--hudson flag for high-priority target correlation.httpx and curl_cffi for maximum concurrency with automated TLS fingerprint impersonation.http, socks5) and pre-scan health validation (--validate-proxies).-lu/-le), and clear status reporting.# Upgrade pip and install user-scanner
python3 -m pip install --upgrade pip
pip install user-scanner
# Optional: Install with MCP Server support for AI agents
pip install "user-scanner[mcp]"
# Create and activate virtual environment
python3 -m venv .venv
source .venv/bin/activate # On Windows: .venv\Scripts\Activate.ps1
# Install package
pip install user-scanner
# Run instantly without installing permanently
nix run github:kaifcodec/user-scanner/main -- --help
# Drop into a temporary shell with user-scanner active
nix shell github:kaifcodec/user-scanner/main
Scan a single username or email address across all available platform modules:
user-scanner -u johndoe # Single username scan
user-scanner -e [email protected] # Single email scan
user-scanner -u johndoe --email-domains global # Try johndoe across provider domains
An email scan proves an account exists but rarely reveals a handle. --cross-scan mines exposed handles, profile links, and secondary email addresses from target profiles, pivoting into multi-pass reconnaissance across all matching platforms:
| Pivot Direction | What it Mines |
|---|---|
-e → username | Handles or social links exposed on an email's registered profile |
-u → username | Secondary aliases advertised across target social profiles |
-u → email | Public email addresses published on target profile pages |
-e → email | Secondary addresses exposed by initial email profiles |
user-scanner -u johndoe --cross-scan # Pivot from username scan
user-scanner -e [email protected] --cross-scan # Pivot from email scan
user-scanner -e [email protected] --cross-scan --cross-links verified # Platform-verified links only
user-scanner -u johndoe --cross-scan --cross-depth 2 # Follow links two hops deep
💡 For confidence scoring, link classification rules, and cost models, see docs/CROSS_SCAN.md.
Check if a target username or email address has been exposed in infostealer malware infection logs:
user-scanner -u johndoe --hudson # Username malware log check
user-scanner -e [email protected] --hudson # Email malware log check