National Cyber Warfare Foundation (NCWF)

user-scanner for email and username footprint mapping


0 user ratings
2026-10-07 17:28:52
milo
Red Team (CNA)
"user-scanner

user-scanner maps a subject's digital footprint across thousands of platforms from a single email or username, built for authorized OSINT investigations and defensive identity research.








Toolkaifcodec/user-scanner — 2-in-1 email and username OSINT suite with native MCP support
CategoryOSINT / identity reconnaissance (Python)
Primary UseAuthorized account-discovery and identity mapping: enumerating registrations, scraping profile metadata, and pivoting across exposed handles and emails
Safe UseStrictly for authorized assessments, investigations of one's own accounts, and defensive research such as exposure audits and threat-intel enrichment
Telemetry NoteGenerates thousands of registration-check requests from the operator's IP unless --validate-proxies and -P rotation are used; defenders see scanning patterns in WAF and rate-limit logs, and site-side anomaly detection can flag enumeration bursts

user-scanner, published at kaifcodec/user-scanner, is a Python OSINT suite that fuses two traditionally separate recon tasks into a single engine: email-based account discovery and username enumeration across a very large platform corpus. The README advertises 2720+ total scan vectors, split into 210+ email-integrated sites and 2510+ username platforms, which immediately tells you the tool is not a thin wrapper around a handful of APIs but a maintained site-module framework along the lines of sherlock or holehe, with considerably wider combined coverage. Version 1.5.2.1 is distributed on PyPI, runs on Linux, Windows, and Termux, and ships under an MIT license, with roughly 4.8k stars indicating solid community traction.


The core workflow is deliberately simple: user-scanner -u runs a username sweep across all modules, while -e performs email registration checking. What elevates the tool beyond simple existence checks is the metadata scraping layer — for confirmed hits it harvests avatars, bio text, follower counts, UID numbers, seller statuses, and account attributes. For an authorized investigator this is the difference between knowing an account exists and being able to build a behavioral profile of the person behind it, which is where the real analytical value of the corpus lies.


The most interesting architectural feature documented in the README is the cross-scan and pivot engine, invoked with --cross-scan. The design acknowledges a classic OSINT gap: an email scan confirms registration but rarely reveals the handle, and a username scan rarely surfaces associated addresses. The pivot matrix covers four directions — email-to-username, username-to-username, username-to-email, and email-to-email — mining handles, profile links, and publicly exposed addresses from initial results and automatically re-scanning against secondary targets. Flags like --cross-depth 2 for two-hop traversal and --cross-links verified for platform-verified links only, plus a dedicated docs/CROSS_SCAN.md covering confidence scoring and cost models, suggest the author has thought seriously about pivot quality rather than just volume.


A second capability worth flagging for defensive professionals is the --hudson flag, which queries Hudson Rock infostealer breach logs to correlate a target email or username with compromised-machine infection records. From a threat-intelligence standpoint this is a high-signal enrichment: presence in infostealer logs indicates the credentials and session cookies associated with that identity may already be circulating in criminal ecosystems, which is exactly the context a blue team needs when prioritizing credential resets or monitoring for anomalous logins. Note that this is a query against existing breach data, not any form of collection, and it should be handled under the same authorization and data-protection constraints as any breach-intel workflow.


The networking layer is engineered for throughput and evasion of crude fingerprinting. The README credits httpx and curl_cffi as the concurrency stack, with curl_cffi providing automated TLS fingerprint impersonation so that scanner traffic more closely resembles ordinary browser sessions. Proxy support includes rotation from a file via -P, protocol auto-detection for http and socks5, and a pre-scan health validation mode with --validate-proxies — a practical touch, since dead proxies are the usual failure mode of large-scale enumeration jobs. The flip side, covered below, is that this is a loud tool from the target platforms' perspective.


The permutation engine rounds out the username side: wildcard-based alias generation produces typo and variant handles to catch alternative accounts a subject may maintain, documented further in docs/PATTERNS.md. Scoping controls are granular — -c dev restricts a scan to developer platforms, -m github,instagram targets specific comma-separated modules, and -lu/-le render self-adaptive grids of all available categories and modules. Bulk mode accepts -uf usernames.txt and -ef emails.txt for one-target-per-line files, and exports go to PDF (including profile photos), JSON, and CSV, which makes pipeline integration straightforward for report-heavy investigative workflows.


The headline differentiator in this release cycle is native Model Context Protocol (MCP) support. Running user-scanner-mcp starts an stdio server that exposes three tools to AI agents — scan_username, scan_email, and list_available_modules — with per-call parameters for category, module, cross_scan recursion, custom proxies, and loudness toggles. Configuration snippets are provided for Claude Desktop, Cursor, Antigravity, and Open-WebUI. This is a meaningful shift: instead of an analyst manually interpreting enumeration output, an LLM agent can query the module catalog dynamically, launch scoped scans, and recurse through pivots autonomously. It also concentrates risk — recursive autonomous OSINT against a target multiplies request volume quickly, so operators should constrain agent behavior deliberately and keep scopes within authorized boundaries.


There is also a library mode for programmatic use: importing user_scanner.core.engine and calling await engine.check(module, target) returns a Result object with to_json() serialization, documented in docs/USAGE.md. This makes the tool composable into larger Python investigation frameworks rather than forcing CLI-only usage. The docs hub — docs/FLAGS.md, docs/PROXIES.md, docs/EXAMPLES.md — is comparatively thorough for a project of this type, which usually correlates with maintainability when site modules break as platforms change their response behavior.


Installation is conventional: pip install user-scanner from PyPI, or pip install "user-scanner[mcp]" for the extra agent dependencies, with nix run github:kaifcodec/user-scanner/main available for ephemeral use on Linux and macOS. No exotic dependencies or build steps are required, and the Termux support means analysts can run field scans from an Android device. One caution from the README's own sponsorship section: the repository heavily promotes commercial OSINT platforms such as webvetted.com and related services, so readers should treat those calls-to-action as advertising rather than endorsement, and the companion phonsint project is cross-promoted for phone-number pivots.


From a defensive standpoint, user-scanner is best understood as a loud, wide-net enumerator that any organization can also point at its own exposure. The natural blue-team use is auditing which of your staff's corporate or recycled-personal identities are registered on platforms outside policy, and whether any appear in infostealer logs via --hudson — both feed directly into credential-hygiene and phishing-simulation programs. Operationally, defenders should note the telemetry the tool produces: thousands of sequential registration probes, TLS profiles impersonating common browsers via curl_cffi, and optionally proxied sources, all of which are visible to rate limiters, WAF rules, and per-account enumeration detection on the receiving platforms. Used responsibly — with written authorization, scoped targets, and awareness that pivots can sweep in unrelated third parties — it is a capable and unusually well-documented addition to the identity-reconnaissance toolkit.



Official project repository for kaifcodec/user-scanner.

Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.






Source: OffensiveSec
Source Link: https://www.offsecblog.com/2026/10/user-scanner-for-email-and-username.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.