Information Gathering

sherlock

sherlock answers a narrow, useful question: given a username, where does it exist? It checks a name against hundreds of sites — social networks, forums, developer platforms, gaming services — and reports the accounts it finds. For people-focused OSINT it’s often the fastest first move: one handle can unravel into a whole online presence across services the target forgot they signed up for.

Installed from the AUR; Security → Information Gathering → sherlock. Note the built-in --tor and --proxy options — recon on people is exactly when you want to route through Tor.

The help it prints

usage: sherlock [-h] [--version] [--verbose] [--folderoutput FOLDEROUTPUT]
                [--output OUTPUT] [--tor] [--unique-tor] [--csv] [--xlsx]
                [--site SITE_NAME] [--proxy PROXY_URL] [--dump-response]
                [--json JSON_FILE] [--timeout TIMEOUT] [--print-all]
                [--print-found] [--no-color] [--browse] [--local] [--nsfw]
                [--no-txt] [--ignore-exclusions]
                USERNAMES [USERNAMES ...]

Sherlock: Find Usernames Across Social Networks (Version 0.16.0)

positional arguments:
  USERNAMES             One or more usernames to check with social networks.
                        Check similar usernames using {?} (replace to '_',
                        '-', '.').

options:
  -h, --help            show this help message and exit
  --version             Display version information and dependencies.
  --verbose, -v, -d, --debug
                        Display extra debugging information and metrics.
  --folderoutput, -fo FOLDEROUTPUT
                        If using multiple usernames, the output of the results
                        will be saved to this folder.
  --output, -o OUTPUT   If using single username, the output of the result
                        will be saved to this file.
  --tor, -t             Make requests over Tor; increases runtime; requires
                        Tor to be installed and in system path.
  --unique-tor, -u      Make requests over Tor with new Tor circuit after each
                        request; increases runtime; requires Tor to be
                        installed and in system path.
  --csv                 Create Comma-Separated Values (CSV) File.
  --xlsx                Create the standard file for the modern Microsoft
                        Excel spreadsheet (xlsx).
  --site SITE_NAME      Limit analysis to just the listed sites. Add multiple
                        options to specify more than one site.
  --proxy, -p PROXY_URL
                        Make requests over a proxy. e.g.
                        socks5://127.0.0.1:1080
  --dump-response       Dump the HTTP response to stdout for targeted
                        debugging.
  --json, -j JSON_FILE  Load data from a JSON file or an online, valid, JSON
                        file. Upstream PR numbers also accepted.
  --timeout TIMEOUT     Time (in seconds) to wait for response to requests
                        (Default: 60)
  --print-all           Output sites where the username was not found.
  --print-found         Output sites where the username was found (also if
                        exported as file).
  --no-color            Don't color terminal output
  --browse, -b          Browse to all results on default browser.
  --local, -l           Force the use of the local data.json file.
  --nsfw                Include checking of NSFW sites from default list.
  --no-txt              Disable creation of a txt file
  --ignore-exclusions   Ignore upstream exclusions (may return more false
                        positives)

Examples

# Check one username everywhere
sherlock johndoe

# Several usernames in one run
sherlock johndoe jdoe john.doe

# Only report found accounts, and save them to a file
sherlock johndoe --print-found --output johndoe.txt

# Route the checks through Tor, new circuit per request
sherlock johndoe --unique-tor

# Export structured results
sherlock johndoe --csv