Sherlock for OSINT Username Hunting

Tool · OSINT

A common OSINT CTF task is: here's a username, find out everything else this person is connected to online. Checking a few hundred sites by hand doesn't scale. Sherlock automates exactly that — it tries the username against a huge list of platforms and reports back which ones have a matching account.

1. Installing and running it

Sherlock is a Python tool, installed straight from its repository:

git clone https://github.com/sherlock-project/sherlock.git
cd sherlock
pip install -r requirements.txt
python3 sherlock.py target_username

2. Reading the output

Sherlock prints one line per site, marking each as found or not found, and saves the found ones to a results file:

[+] GitHub: https://github.com/target_username
[+] Twitter: https://twitter.com/target_username
[-] Pinterest: Not Found!

A hit doesn't always mean it's the same real person using the handle — treat it as a lead to manually verify (profile photo, bio, posting history) rather than a confirmed identity match on its own.

3. Narrowing down false positives

Some sites return a generic "not found" page with a 200 status instead of a proper 404, which can trick automated checkers into reporting a false hit. Sherlock maintains per-site detection rules to avoid most of these, but when a result looks surprising, open the link yourself before trusting it in a writeup or a report.

4. Pivoting from a hit

Once you've confirmed a real account, that platform often leaks more than the username alone did — a linked email, a real name, other linked accounts, or a profile photo you can run through a reverse image search. Each confirmed account is a new starting point, not an endpoint.

Wrapping up

Sherlock is a breadth-first tool — it's built to tell you where to look next, not to finish the investigation by itself. Pair it with metadata extraction on anything you find attached to those accounts, and treat every hit as a lead to verify rather than a conclusion.

← Back to Blog