一个用 Python 编写的被动式 OSINT 工具包,支持用户名、邮箱、域名、IP、电话、哈希。无需密钥,无需登录。
用 Python 编写的被动式 OSINT 工具包。无需 API 密钥、无需账户、无需登录任何东西。给它一个用户名、一个邮箱、一个域名、一个 IP、一个电话号码或一个哈希值,它就会去查那些已经公开的信息。

username 会在大约 700 个站点上扫描一个用户名,使用的是社区维护的 WhatsMyName 列表。该列表中的每个条目都知道如何区分命中与未命中,所以结果不是靠猜的。email 会检查语法和 MX 记录,查找一次性邮箱域名,尝试 gravatar,然后把 @ 前面的部分拿去跑一遍用户名扫描。domain 会拉取 DNS 记录、HTTP 状态码和标题、从证书透明度日志中提取子域名,以及 whois。ip 会给出地理位置和 ASN、反向 DNS,如果你要求的话还会扫描端口。phone 会给出运营商、地区、线路类型和时区。hash 只是告诉你它大概是什么。
全都是公开数据。DNS、whois、个人资料页面、证书日志。
需要 Python 3.9 或更新版本。然后:
pip install -r requirements.txt
这会装上 rich、requests、dnspython 和 aiohttp。phonenumbers 也会一并装上,但只有 phone 模块会用到它,所以如果你愿意,可以从文件里把它去掉。没有 aiohttp 的话,用户名扫描会退回到多线程模式,速度会慢很多,所以还是留着吧。
在 Windows 上,如果 Python 还没加到你的 PATH 里:
winget install --id Python.Python.3.13 -e
git clone https://gitlab.com/vqkro/higernes
cd higernes
pip install -r requirements.txt
python higernes.py
Linux 和 Mac 是一样的,只是把 python 换成 python3:
git clone https://gitlab.com/vqkro/higernes
cd higernes
python3 -m pip install -r requirements.txt
python3 higernes.py
在 FreeBSD 上先执行 pkg install -y python3。
如果 pip 抱怨外部管理的环境,要么建一个 venv
python3 -m venv .venv && . .venv/bin/activate && pip install -r requirements.txt
要么加上 --break-system-packages 然后继续。
不带参数就会进入菜单。或者直接对某个目标下手:
python higernes.py username vqkro
python higernes.py username vqkro --cat coding
python higernes.py email [email protected]
python higernes.py domain example.com
python higernes.py ip 1.1.1.1 --ports
python higernes.py phone +14155552671
python higernes.py hash 5f4dcc3b5aa765d61d8327deb882cf99
python higernes.py scan example.com
python higernes.py scan example.com --all
分类只会缩小用户名扫描的范围。不指定的话就会扫全部 700 个站点。
data/wmn-data.json 是 WhatsMyName 数据集。随时可以换入更新的副本,它在启动时会被读取。如果文件不存在,它会退回到脚本内置的一个简短列表,这样仍然能运行。
Python 写的端口扫描器很慢,所以那部分放在 core/hcore.cpp 里,会编译成一个小的二进制文件。higernes 会在自身旁边、core/ 目录下或 PATH 中查找它,然后调用它。如果找不到,ip --ports 会退回到较慢的 Python 版本。只有当你从源码运行并且想要快速路径时,才需要编译它:
# windows
g++ -O2 -std=c++17 -static -o core/hcore.exe core/hcore.cpp -lws2_32
# linux / mac
g++ -O2 -std=c++17 -o core/hcore core/hcore.cpp -pthread
它也可以独立使用:
hcore dns github.com
hcore ports example.com --banners
hcore ports example.com --all --threads 1024
发布页面上的 exe 已经内置了它。
dnspython 和 requests 值得装上。没有 dnspython 的话,只有 A 记录能解析,其他都会被跳过。ip-api 的免费端点大约每分钟限流 45 次查询。crt.sh 有一半时间很慢或者挂掉,遇到这种情况域名扫描会直接说明然后继续。
pip install pyinstaller
pyinstaller --onefile --name higernes --console higernes.py
发布页面上的那个就是这么构建的。
MIT,见 LICENSE。