Information Gathering
sherlock
sherlock answers a narrow, useful question: given a username, where does it
exist? It checks a name against hundreds of sites — social networks, forums,
developer platforms, gaming services — and reports the accounts it finds. For
people-focused OSINT it’s often the fastest first move: one handle can unravel
into a whole online presence across services the target forgot they signed up for.
Installed from the AUR; Security → Information Gathering → sherlock. Note the
built-in --tor and --proxy options — recon on people is exactly when you want
to route through Tor.
The help it prints
usage: sherlock [-h] [--version] [--verbose] [--folderoutput FOLDEROUTPUT]
[--output OUTPUT] [--tor] [--unique-tor] [--csv] [--xlsx]
[--site SITE_NAME] [--proxy PROXY_URL] [--dump-response]
[--json JSON_FILE] [--timeout TIMEOUT] [--print-all]
[--print-found] [--no-color] [--browse] [--local] [--nsfw]
[--no-txt] [--ignore-exclusions]
USERNAMES [USERNAMES ...]
Sherlock: Find Usernames Across Social Networks (Version 0.16.0)
positional arguments:
USERNAMES One or more usernames to check with social networks.
Check similar usernames using {?} (replace to '_',
'-', '.').
options:
-h, --help show this help message and exit
--version Display version information and dependencies.
--verbose, -v, -d, --debug
Display extra debugging information and metrics.
--folderoutput, -fo FOLDEROUTPUT
If using multiple usernames, the output of the results
will be saved to this folder.
--output, -o OUTPUT If using single username, the output of the result
will be saved to this file.
--tor, -t Make requests over Tor; increases runtime; requires
Tor to be installed and in system path.
--unique-tor, -u Make requests over Tor with new Tor circuit after each
request; increases runtime; requires Tor to be
installed and in system path.
--csv Create Comma-Separated Values (CSV) File.
--xlsx Create the standard file for the modern Microsoft
Excel spreadsheet (xlsx).
--site SITE_NAME Limit analysis to just the listed sites. Add multiple
options to specify more than one site.
--proxy, -p PROXY_URL
Make requests over a proxy. e.g.
socks5://127.0.0.1:1080
--dump-response Dump the HTTP response to stdout for targeted
debugging.
--json, -j JSON_FILE Load data from a JSON file or an online, valid, JSON
file. Upstream PR numbers also accepted.
--timeout TIMEOUT Time (in seconds) to wait for response to requests
(Default: 60)
--print-all Output sites where the username was not found.
--print-found Output sites where the username was found (also if
exported as file).
--no-color Don't color terminal output
--browse, -b Browse to all results on default browser.
--local, -l Force the use of the local data.json file.
--nsfw Include checking of NSFW sites from default list.
--no-txt Disable creation of a txt file
--ignore-exclusions Ignore upstream exclusions (may return more false
positives)
Examples
# Check one username everywhere
sherlock johndoe
# Several usernames in one run
sherlock johndoe jdoe john.doe
# Only report found accounts, and save them to a file
sherlock johndoe --print-found --output johndoe.txt
# Route the checks through Tor, new circuit per request
sherlock johndoe --unique-tor
# Export structured results
sherlock johndoe --csv