offensive-tools/osint/sherlock/SKILL.md
Auth/lab ref: Hunt username presence across 400+ social networks and output found profile URLs.
npx skillsauth add aeondave/malskill sherlockInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Username hunter across 400+ social platforms.
pip install sherlock-project
# Search single username
sherlock username
# Search multiple usernames
sherlock user1 user2 user3
# Output to file
sherlock username --output results.txt
# JSON output
sherlock username --json
| Flag | Purpose |
|------|---------|
| --timeout N | Per-site timeout (default: 60s) |
| --print-found | Only show found accounts |
| --print-all | Show all (including not found) |
| --output FILE | Save results |
| --json | JSON format |
| --site NAME | Search specific site only |
| --csv | CSV output |
| -x XLSX | Excel output |
Hunt username from breach data:
sherlock johndoe_83 --print-found --output johndoe_found.txt
Multiple username variants:
sherlock "john.doe" johndoe john_doe jdoe --print-found
Targeted site lookup:
sherlock johndoe --site twitter --site github --site linkedin
From breach data — test common variations at once:
sherlock john.doe johndoe john_doe j.doe jdoe83 --print-found --timeout 10
Given a real name "John Doe" or email [email protected]:
johndoe, john.doe, john_doe, jdoe, j.doe, johndoe83, jdoe83
firstname+lastname, firstnamelastname, last.first
Add: year of birth, numbers 1/2/_, common suffixes (_real, _official)
| | sherlock | maigret | |--|---------|---------| | Sites | ~400 | 2800+ | | Output | URL list | Full dossier (scraped data) | | Speed | Fast | Slower | | Best for | Quick platform sweep | Deep profile building |
Use sherlock for fast sweep, maigret for deep investigation.
| File | When to load |
|------|--------------|
| references/username-techniques.md | Username generation, variation tools, pivot strategies, platform-specific tips |
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.