SHERLOCK
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Username OSINT tool that searches 400+ social media sites and websites for accounts matching a given username.
INSTALLATION#
# pip pip install sherlock-project # From source git clone https://github.com/sherlock-project/sherlock cd sherlock pip install -r requirements.txt # Docker docker pull sherlock/sherlock docker run --rm sherlock/sherlock username # Kali sudo apt install sherlock
BASIC USAGE#
# Search single username sherlock username # Search multiple usernames sherlock user1 user2 user3 # From file sherlock --file usernames.txt
OUTPUT OPTIONS#
# Save results to file sherlock username --output results.txt # CSV output sherlock username --csv # JSON output (includes all metadata) sherlock username --json results.json # Save to specific folder sherlock username --folderoutput ./results/ # Print all sites (including not found) sherlock username --print-all # Print found only (default behavior) sherlock username --print-found
SEARCH FILTERS#
# Search specific sites only sherlock username --site github sherlock username --site twitter --site instagram --site reddit # Exclude specific sites (avoid false positives) sherlock username --exclude site1 site2 # Timeout per request (seconds) sherlock username --timeout 10 # Use Tor for anonymity sherlock username --tor # Use proxy sherlock username --proxy http://127.0.0.1:8080 sherlock username --proxy socks5://127.0.0.1:9050
ADVANCED OPTIONS#
# NSFw sites included sherlock username --nsfw # Browse results (opens in browser) sherlock username --browse # Verbose output sherlock username --verbose # No color output sherlock username --no-color # Local copy of site data sherlock username --local # List all supported sites sherlock --list-sites
SUPPORTED SITE CATEGORIES#
Category Examples
-------- --------
Social Media Twitter/X, Instagram, Facebook, TikTok,
Mastodon, Threads, Bluesky
Development GitHub, GitLab, Bitbucket, Stack Overflow,
Dev.to, Codepen, Replit, HackerRank
Gaming Steam, Xbox, PSN, Twitch, Discord,
Epic Games, Battle.net, Roblox
Creative DeviantArt, Behance, Dribbble, ArtStation,
Flickr, 500px, Unsplash
Video/Music YouTube, Vimeo, SoundCloud, Spotify,
Bandcamp, Mixcloud, Dailymotion
Forums Reddit, HackerNews, Quora, Medium,
Keybase, Discourse
Professional LinkedIn, AngelList, Crunchbase, About.me
Dating OKCupid, Tinder (limited)
Finance CashApp, Venmo, PayPal.me
Shopping eBay, Etsy, Poshmark
Other Gravatar, Telegram, Signal, Keybase,
Pastebin, Archive.org, Wikipedia
INTERPRETING RESULTS#
# Output legend [+] Found # Account exists with this username [-] Not Found # No account or page returned 404 [!] Error # Connection error or timeout [*] Checking # Currently checking site # False positives - Some sites return 200 for any username (generic profile page) - Check claimed profiles manually before reporting - --print-all shows which sites had errors vs not found
USERNAME GENERATION STRATEGIES#
# Common patterns to try john.smith # Full name jsmith # Initial + last johnsmith # No separator john_smith # Underscore john-smith # Hyphen smith.john # Reversed smithj # Last + initial j.smith.1990 # With birth year johnsmith42 # With numbers # From discovered email: user@example.com → try "user" # From metadata: document author "J. Smith" → try variations # From social media: linked accounts often share usernames
WORKFLOW INTEGRATION#
# 1. Discover usernames from other OSINT # - Document metadata (FOCA, exiftool) # - Email addresses (prefix before @) # - LinkedIn, company websites # - Breach data # 2. Run Sherlock on discovered usernames sherlock discovered_user --csv --json results.json # 3. Analyze results # - Cross-reference found accounts # - Check profile details, posts, connections # - Look for password reuse hints # - Find additional personal info # 4. Pivot on new findings # - New usernames from connected accounts # - Email addresses from profiles # - Real names for further OSINT
AUTOMATION EXAMPLE#
#!/bin/bash
# Batch username OSINT
while IFS= read -r user; do
echo "[*] Checking: $user"
sherlock "$user" --csv --folderoutput ./results/ --timeout 15
done < usernames.txt
# Combine results
cat ./results/*.csv | sort -u > all_results.csv
SIMILAR TOOLS#
maigret # Sherlock fork with 3000+ sites, more features whatsmyname # Web-based username checker namechk # Username availability checker social-analyzer # Social media analysis with API support holehe # Check if email is registered on sites
TIPS#
- Start with known usernames, then try variations - Use --tor or --proxy for anonymity - Increase --timeout for slow sites - Use --csv for easy import into spreadsheets - False positives are common; verify manually - Cross-reference with Holehe (email-based lookups) - Username reuse is extremely common - Gaming platforms often reveal real identity - Check profile creation dates for chronology - Archived profiles (Wayback Machine) may reveal deleted content - maigret is a more maintained fork with additional sites