← All cheat sheets

SHERLOCK

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Username OSINT tool that searches 400+ social media sites and
websites for accounts matching a given username.

INSTALLATION#

# pip
pip install sherlock-project

# From source
git clone https://github.com/sherlock-project/sherlock
cd sherlock
pip install -r requirements.txt

# Docker
docker pull sherlock/sherlock
docker run --rm sherlock/sherlock username

# Kali
sudo apt install sherlock

BASIC USAGE#

# Search single username
sherlock username

# Search multiple usernames
sherlock user1 user2 user3

# From file
sherlock --file usernames.txt

OUTPUT OPTIONS#

# Save results to file
sherlock username --output results.txt

# CSV output
sherlock username --csv

# JSON output (includes all metadata)
sherlock username --json results.json

# Save to specific folder
sherlock username --folderoutput ./results/

# Print all sites (including not found)
sherlock username --print-all

# Print found only (default behavior)
sherlock username --print-found

SEARCH FILTERS#

# Search specific sites only
sherlock username --site github
sherlock username --site twitter --site instagram --site reddit

# Exclude specific sites (avoid false positives)
sherlock username --exclude site1 site2

# Timeout per request (seconds)
sherlock username --timeout 10

# Use Tor for anonymity
sherlock username --tor

# Use proxy
sherlock username --proxy http://127.0.0.1:8080
sherlock username --proxy socks5://127.0.0.1:9050

ADVANCED OPTIONS#

# NSFw sites included
sherlock username --nsfw

# Browse results (opens in browser)
sherlock username --browse

# Verbose output
sherlock username --verbose

# No color output
sherlock username --no-color

# Local copy of site data
sherlock username --local

# List all supported sites
sherlock --list-sites

SUPPORTED SITE CATEGORIES#

Category             Examples
--------             --------
Social Media         Twitter/X, Instagram, Facebook, TikTok,
                     Mastodon, Threads, Bluesky
Development          GitHub, GitLab, Bitbucket, Stack Overflow,
                     Dev.to, Codepen, Replit, HackerRank
Gaming               Steam, Xbox, PSN, Twitch, Discord,
                     Epic Games, Battle.net, Roblox
Creative             DeviantArt, Behance, Dribbble, ArtStation,
                     Flickr, 500px, Unsplash
Video/Music          YouTube, Vimeo, SoundCloud, Spotify,
                     Bandcamp, Mixcloud, Dailymotion
Forums               Reddit, HackerNews, Quora, Medium,
                     Keybase, Discourse
Professional         LinkedIn, AngelList, Crunchbase, About.me
Dating               OKCupid, Tinder (limited)
Finance              CashApp, Venmo, PayPal.me
Shopping             eBay, Etsy, Poshmark
Other                Gravatar, Telegram, Signal, Keybase,
                     Pastebin, Archive.org, Wikipedia

INTERPRETING RESULTS#

# Output legend
[+] Found          # Account exists with this username
[-] Not Found      # No account or page returned 404
[!] Error          # Connection error or timeout
[*] Checking       # Currently checking site

# False positives
  - Some sites return 200 for any username (generic profile page)
  - Check claimed profiles manually before reporting
  - --print-all shows which sites had errors vs not found

USERNAME GENERATION STRATEGIES#

# Common patterns to try
john.smith                                  # Full name
jsmith                                      # Initial + last
johnsmith                                   # No separator
john_smith                                  # Underscore
john-smith                                  # Hyphen
smith.john                                  # Reversed
smithj                                      # Last + initial
j.smith.1990                                # With birth year
johnsmith42                                 # With numbers

# From discovered email: user@example.com → try "user"
# From metadata: document author "J. Smith" → try variations
# From social media: linked accounts often share usernames

WORKFLOW INTEGRATION#

# 1. Discover usernames from other OSINT
#    - Document metadata (FOCA, exiftool)
#    - Email addresses (prefix before @)
#    - LinkedIn, company websites
#    - Breach data

# 2. Run Sherlock on discovered usernames
sherlock discovered_user --csv --json results.json

# 3. Analyze results
#    - Cross-reference found accounts
#    - Check profile details, posts, connections
#    - Look for password reuse hints
#    - Find additional personal info

# 4. Pivot on new findings
#    - New usernames from connected accounts
#    - Email addresses from profiles
#    - Real names for further OSINT

AUTOMATION EXAMPLE#

#!/bin/bash
# Batch username OSINT
while IFS= read -r user; do
    echo "[*] Checking: $user"
    sherlock "$user" --csv --folderoutput ./results/ --timeout 15
done < usernames.txt

# Combine results
cat ./results/*.csv | sort -u > all_results.csv

SIMILAR TOOLS#

  maigret          # Sherlock fork with 3000+ sites, more features
  whatsmyname      # Web-based username checker
  namechk          # Username availability checker
  social-analyzer  # Social media analysis with API support
  holehe           # Check if email is registered on sites

TIPS#

  - Start with known usernames, then try variations
  - Use --tor or --proxy for anonymity
  - Increase --timeout for slow sites
  - Use --csv for easy import into spreadsheets
  - False positives are common; verify manually
  - Cross-reference with Holehe (email-based lookups)
  - Username reuse is extremely common
  - Gaming platforms often reveal real identity
  - Check profile creation dates for chronology
  - Archived profiles (Wayback Machine) may reveal deleted content
  - maigret is a more maintained fork with additional sites