As9xm/OSY

Advanced Open-Source Intelligence Tool

★ 1Forks 0PythonGitHub ↗Compare

README

OSY - Open-Source Intelligence Tool

License Python

A comprehensive OSINT (Open-Source Intelligence) tool for discovering and analyzing online presence across multiple platforms using username searches.

⚠️ Disclaimer

This tool is designed for legitimate OSINT research, security investigations, and educational purposes only.

  • Use responsibly and ethically
  • Respect privacy and platform terms of service
  • Comply with applicable laws and regulations
  • Do not use for harassment, stalking, or malicious purposes

The developers are not responsible for misuse of this tool.

✨ Features

Core OSINT Capabilities

  • 22+ Platform Support: Searches across social media, gaming platforms, developer sites, and forums
  • Real-Time Async Search: Concurrent searches across all platforms for maximum speed
  • Multiple Output Formats: JSON, CSV, Markdown, and plain text
  • Rate Limiting: Built-in intelligent rate limiting to respect platform limits
  • Rich CLI Interface: Beautiful progress bars, tables, and formatted output

Email Enumeration

  • Automatically extracts emails from profile bios and metadata
  • Generates email patterns based on username and real name
  • Common provider pattern generation (Gmail, Yahoo, Outlook, etc.)

Breach Database Integration

  • Checks emails against Have I Been Pwned (HIBP) database
  • Password breach checking via Pwned Passwords API
  • Identifies data leaks and compromised credentials

Cross-Platform Correlation

  • Analyzes profile similarities across platforms
  • Calculates confidence scores for same-person identification
  • Uses multiple factors: username, display name, bio, location, avatars
  • Provides evidence-based conclusions

Export & Reporting

  • Exportable results to files for analysis
  • Detailed profile extraction: followers, bio, location, verification, metadata
  • Advanced analytics and correlation data

🎯 Supported Platforms (29)

Social Media (16)

  • Instagram
  • Twitter (X)
  • GitHub
  • Reddit
  • YouTube
  • TikTok
  • LinkedIn
  • Pinterest
  • Tumblr
  • Medium
  • Spotify
  • SoundCloud
  • VK (VKontakte)
  • DeviantArt
  • Behance
  • Last.fm

Gaming (4)

  • Steam
  • Twitch
  • Minecraft (Mojang API)
  • Roblox

Developer Platforms (5)

  • GitLab
  • npm Registry
  • PyPI
  • Keybase
  • Kaggle

Forums & Communities (4)

  • Telegram
  • Quora
  • Stack Overflow
  • Goodreads

📦 Installation

Prerequisites

  • Python 3.8 or higher
  • pip package manager

Install from source

# Clone the repository
git clone <repository-url>
cd OSY

# Install dependencies
pip install -r requirements.txt

# Install the package
pip install -e .

🚀 Usage

Basic Usage

Search for a username across all platforms:

python -m osy johndoe

Advanced Options

# Search with optional real name and country
python -m osy johndoe --real-name "John Doe" --country "US"

# Specify output format
python -m osy johndoe --output-format json
python -m osy johndoe -f markdown

# Save to specific file
python -m osy johndoe --output-file report.json

# Search specific platforms only
python -m osy johndoe --platforms "instagram,twitter,github"

# Quiet mode (no progress output)
python -m osy johndoe --quiet

# Export to all formats
python -m osy johndoe -f all

# Don't save to file, only print to console
python -m osy johndoe --no-save

# Email enumeration from profiles
python -m osy johndoe --find-emails

# Check discovered emails for breaches (requires HIBP API key)
python -m osy johndoe --find-emails --check-breaches --hibp-api-key YOUR_API_KEY

# Cross-platform correlation analysis
python -m osy johndoe --correlate

# Full advanced scan (all features)
python -m osy johndoe --advanced-scan

# Combine with specific platforms
python -m osy johndoe --platforms "github,gitlab,npm" --find-emails --correlate

# Generate username variations (200+ patterns)
python -m osy johndoe --username-variants

# Google Dorking automation (50+ dork queries)
python -m osy johndoe --google-dork --real-name "John Doe"

# Check Wayback Machine for historical snapshots
python -m osy johndoe --wayback

# Reverse image search on avatars
python -m osy johndoe --reverse-image

# Find duplicate avatars across platforms
python -m osy johndoe --find-similar-avatars

# FULL ULTRA SCAN (all features)
python -m osy johndoe --advanced-scan --username-variants --google-dork --wayback --reverse-image

Command Line Options

Option Short Description
--real-name -r Real name of the person (optional)
--country -c Country where the person is from (optional)
--output-format -f Output format: json, csv, markdown, text, all (default: text)
--output-file -o Custom output file path
--platforms -p Comma-separated list of specific platforms to search
--quiet -q Suppress progress output
--no-save Don't save results to file

📊 Output Examples

Terminal Output

╔═══════════════════════════════════════╗
║   OSY - OSINT Search Tool             ║
╚═══════════════════════════════════════╝

Target Username: johndoe

Searching for johndoe... ████████████████████ 100%

┏━━━━━━━━━━━━┳━━━━━━━━━━━━━━┳━━━━━━━━━━━┳━━━━━━━━━━┳━━━━━━━━━━━━━━┓
┃ Platform   ┃ Display Name ┃ Followers ┃ Verified ┃ URL          ┃
┡━━━━━━━━━━━━╇━━━━━━━━━━━━━━╇━━━━━━━━━━━╇━━━━━━━━━━╇━━━━━━━━━━━━━━┩
│ GitHub     │ John Doe     │     1,234 │    -     │ github.com/  │
│ Twitter    │ @johndoe     │    10,523 │    ✓     │ twitter.com/ │
└────────────┴──────────────┴───────────┴──────────┴──────────────┘

✓ Results saved to: results/johndoe_20241130_043200.text

JSON Output

{
  "username": "johndoe",
  "real_name": null,
  "country": null,
  "profiles": [
    {
      "username": "johndoe",
      "platform": "github",
      "url": "https://github.com/johndoe",
      "status": "found",
      "display_name": "John Doe",
      "bio": "Software Developer",
      "followers": 1234,
      "following": 567,
      "verified": null,
      "metadata": {
        "public_repos": 42,
        "source": "github_api"
      }
    }
  ],
  "total_found": 1,
  "total_searched": 15
}

Markdown Output

# OSINT Report: johndoe

**Search Started:** 2024-11-30 04:32:00

## Summary

- **Total Platforms Searched:** 15
- **Profiles Found:** 3
- **Success Rate:** 20.0%

## Found Profiles

### GitHub

- **URL:** [https://github.com/johndoe](https://github.com/johndoe)
- **Display Name:** John Doe
- **Bio:** Software Developer
- **Followers:** 1,234
- **Following:** 567

🏗️ Architecture

OSY/
├── osy/
│   ├── core/              # Core engine and models
│   │   ├── engine.py      # Main search orchestrator
│   │   ├── models.py      # Data models
│   │   └── config.py      # Configuration management
│   ├── modules/           # Platform-specific search modules
│   │   ├── social_media/  # Instagram, Twitter, GitHub, etc.
│   │   ├── gaming/        # Steam, Twitch, Minecraft
│   │   └── forums/        # Telegram, Quora, Stack Overflow
│   ├── utils/             # Utilities
│   │   ├── http_client.py # Async HTTP client with retry logic
│   │   └── rate_limiter.py# Rate limiting implementation
│   ├── output/            # Output formatters
│   └── cli/               # CLI interface
├── requirements.txt       # Python dependencies
└── README.md             # This file

🔧 How It Works

  1. Input: User provides a username (and optionally real name and country)
  2. Concurrent Search: Tool simultaneously searches all enabled platforms using async I/O
  3. Rate Limiting: Respects platform-specific rate limits to avoid being blocked
  4. Data Extraction: Scrapes public profiles or uses APIs to extract information
  5. Aggregation: Combines results from all platforms
  6. Output: Presents results in chosen format (JSON, CSV, Markdown, or Text)

Search Methods

  • Public APIs: GitHub, Reddit, Stack Overflow, Minecraft (Mojang)
  • Web Scraping: Instagram, Twitter, YouTube, TikTok, LinkedIn, Steam, Twitch, etc.
  • URL Enumeration: Checks if profile URLs exist and are accessible

🛡️ Privacy & Ethics

This tool only accesses publicly available information. It does not:

  • Bypass authentication or access private profiles
  • Store or transmit personal data
  • Violate platform terms of service
  • Enable tracking or surveillance

Use responsibly:

  • Obtain proper authorization before investigating individuals
  • Respect privacy rights and data protection laws (GDPR, CCPA, etc.)
  • Use for legitimate purposes only (security research, due diligence, etc.)
  • Do not use for stalking, harassment, or other malicious activities

🤝 Contributing

Contributions are welcome! To add support for new platforms:

  1. Create a new module in osy/modules/
  2. Implement the search() function following existing module patterns
  3. Add the platform to Platform enum in models.py
  4. Register the module in engine.py

📝 License

This project is licensed under the MIT License - see the LICENSE file for details.

🐛 Known Limitations

  • Some platforms may block automated requests (use with moderation)
  • Rate limiting may slow down searches on some platforms
  • Private profiles cannot be accessed
  • Some platforms require authentication for full data (not implemented)
  • Accuracy depends on public information availability

📞 Support

For issues, questions, or feature requests, please open an issue on GitHub.

Contributors

As9xm

Issues