Skip to content

Sherlock

Search public platforms for a username

VerifiedOSINT· Username InvestigationBeginnerMITOpen sourceEntry revised 14 Jan 2026
  • Linux
  • macOS
  • Windows
  • Kali
  • Parrot
  • Arch
  • Docker
  • Source

Overview

7 commands documented

Sherlock takes one identifier and checks whether it resolves on a large, maintained list of public sites, reporting the URLs that respond. It automates the tedious part of username research — opening 400 profiles by hand.

Results are only hints: sites return misleading status codes, require JavaScript, or block automation. Every hit needs to be opened and read before it means anything. Treat all output as public information about accounts, and handle it accordingly.

Supported platforms

8

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

osint, username, profiles, recon

Dataset entry

sherlock.ts

Reviewed 2026-01-14

Installation

Grouped by platform. Elevation requirements are marked per method.

Clone and install

Recommendedgit + pip

The project's documented Windows path: a local clone plus a virtual environment. Windows Terminal is suggested for colour output.

git clone https://github.com/sherlock-project/sherlock.git
cd sherlock
python -m venv .venv
.venv\Scripts\activate
pip install -r requirements.txt

Package availability follows your distribution and enabled repositories. Entry revised 14 Jan 2026 — confirm the current release on the project's own download page.

Commands

7 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Check one username

bash

Queries the enabled sites and prints a per-site status line with the profile URL.

sherlock targethandle

Example output

Illustrative only — real output depends on the target, version and your position on the network.

[+] GitHub: https://github.com/targethandle [404]
[+] GitLab: https://gitlab.com/targethandle [200]

Notes

  • A 200 result means the site's check matched — not that the account belongs to the person you are researching.

02Bound the run

bash

Per-request and overall timeouts keep a run from stalling on sites that never answer.

sherlock targethandle --timeout 7 --max-time 120

Notes

  • Many sites rate-limit repeated automated lookups. A timeout is courtesy as much as efficiency.

03Save output and a CSV

bash

Writes one text file per target plus a combined CSV for later correlation.

sherlock targethandle otherhandle -o results/ -c results/handles.csv

Notes

  • Keep output directories inside your case folder; the files contain research notes about real people.

04Restrict the site list

bash

Exclude adult sites, or limit the run to an explicit subset of sites.

sherlock targethandle --nsfw -t 200

Notes

  • `--nsfw` includes adult sites; the default excludes them. Use `--site github,gitlab,reddit` to test only platforms that matter for your question.

05Process a list of identifiers

bash

Reads one identifier per line, which is how you handle a set of candidate handles.

sherlock -t 30 --unique --print-all -f handles.txt

Notes

  • `--unique` collapses duplicate site names, `--print-all` keeps the negative results too.

06Route through a proxy

bash

Sends requests via Tor or an upstream proxy when your research environment requires it.

sherlock targethandle --proxy http://127.0.0.1:9050

Notes

  • Exits that many sites already throttle will produce more false negatives; re-check positives in a browser.

07Interpret results with site data

bash

Inspect which sites are enabled and how each is detected before trusting a verdict.

sherlock targethandle --list-engines

Notes

  • Detection methods differ per site (status code, valid/invalid string match). A site added recently may still produce false hits — check the repository issue tracker if results look wrong.

Worked examples

Sequences of commands in the order they are used, with what you should expect to learn from each.

Attribution check for an incident handle

A threat actor reuses the handle 'quickferret42' across a phishing page and a forum post. Establish where else that public identifier appears, for the report.

  1. 1

    Automated sweep

    sherlock quickferret42 --timeout 6 -o case/ -c case/handles.csv
  2. 2

    Open every 200 result manually and screenshot it

    python3 -c "print(open('case/quickferret42.txt').read())"
  3. 3

    Record registration dates and profile text separately from the URL list

    grep -v '\[404\]' case/quickferret42.txt

A verified list of matching public profiles with dates, plus an explicit note of which candidates could not be confirmed.

What it is used for

  • Brand protection research

    Locate public accounts impersonating an organisation.

  • Threat-intelligence triage

    Map identifiers an actor has already published.

  • OSINT learning

    Understand how public profile enumeration and false positives work.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

ModuleNotFoundError: No module named 'requests' (or similar)Cause 1/3

Possible causes

  • Running from a clone without installing requirements, or invoking the wrong Python.

Usual fix

Activate the virtual environment first, or install through pipx so dependencies are isolated.

python3 -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
Sites you know exist report 404 for every queryCause 2/3

Possible causes

  • The site changed its response pattern or blocks non-browser user agents.
  • Rate limiting from a shared IP (common on cloud VMs).

Usual fix

Update the project (`git pull` or `pipx upgrade sherlock-project`), verify the URL in a browser, and record the false negative in your notes instead of concluding the account does not exist.

HTTP 429 / connection reset after a few dozen sitesCause 3/3

Possible causes

  • Upstream rate limiting, typically from cloud provider IP ranges.

Usual fix

Lower `--timeout`, reduce `-t` threads, split the run with `--site`, and space repeats out.

Tips

  • Never conclude 'account does not exist' from a negative run. Absence of a hit is not absence of an account.
  • Note the timestamp of every sweep — Sherlock's site list changes weekly.
  • Prefer a deliberately small site set (`--site`) for anything that will end up in a report; you can defend each result individually.
  • Handle results as personal data: store them in the case folder, restrict access, delete when the engagement ends.

Alternatives & comparisons

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in OSINT