Why You Need to Ditch Sherlock and Holehe for This 2-in-1 OSINT Suite—user-scanner
If you've spent any time doing digital footprinting or target enumeration, your workflow probably looks like this: Fire up Sherlock to see where a handle exists across social media. Realize Sherlock doesn't extract metadata or verify email registrations. Switch over to Holehe to run an email check against recovery endpoints. Manually copy-paste discovered handles or links into a second search.…
Digital footprinting and target enumeration can be a cumbersome process. Tools like Sherlock and Holehe are often used separately, requiring manual copying of discovered handles or links and dealing with rate limits, missing photos, and outdated modules. user-scanner aims to simplify this workflow by combining Sherlock's and Holehe's capabilities into one 2-in-1 OSINT suite. It offers automated target pivoting, breach intel correlation, and a range of features to streamline the process.
The key differentiator of user-scanner is its --cross-scan engine, which automatically bridges the gap between email scans and username scans. After running an initial email scan, user-scanner extracts exposed handles and links, then automatically sweeps these discovered handles to find additional information. This feature classifies link trust and rates hit confidence, allowing users to execute targeted searches with varying levels of precision.
Users can also limit recursion depth to perform high-precision searches without unnecessary guesswork.
In addition to automated target pivoting, user-scanner extracts deep metadata, including profile avatars, UID, follower/following counts, bios, and unparsed text signatures. This information is presented in a comprehensive report, complete with scraped avatar images and formatted in various export formats like TXT, CSV, console, PDF with photos, JSON, and CSV.
For those who prefer to check specific malware logs, user-scanner offers an integrated infostealer malware logs feature powered by Hudson Rock. This allows users to cross-reference their target against global malware infection logs during the same run.
To get started with user-scanner, it can be installed via PyPI or used instantly via Nix without installation. The tool offers common commands for single target scans, developer platform module scans, proxy rotation with health validation, and export of formatted reports. Additionally, user-scanner provides a Python library mode for custom automation pipelines or security agents, allowing users to call the engine directly from Python.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.