Skip to content
aicoolies logo
Sherlock logo

Sherlock

Hunt down social media accounts by username across 400+ platforms

Sherlock is a Python CLI tool that searches for a given username across 400+ social networks and websites simultaneously. It is widely used in OSINT investigations, security audits, red teaming exercises, and digital footprint analysis. Sherlock is included in Kali Linux and Parrot Security distributions and has over 76,000 GitHub stars, making it one of the most popular open-source security tools.

About Sherlock

Sherlock is an open-source command-line intelligence tool that automates username enumeration across hundreds of online platforms. Given a username, it systematically queries over 400 social networks, forums, coding platforms, and web services to determine where accounts with that name exist. The results include direct URLs to discovered profiles, making it an essential utility for security professionals conducting reconnaissance, penetration testers mapping attack surfaces, and investigators performing digital forensics.

The tool operates by maintaining a curated database of site definitions, each specifying how to detect account existence through HTTP status codes, response content patterns, or redirect behavior. This approach yields high accuracy with minimal false positives compared to naive URL guessing. Sherlock supports concurrent requests for fast enumeration, proxy routing for operational security, output in multiple formats including CSV and JSON, and Tor network integration for anonymous lookups.

Sherlock has become a standard component in security-focused Linux distributions including Kali Linux and is referenced in OSINT training curricula worldwide. With over 76,000 GitHub stars, it is one of the highest-traction open-source security tools in existence. The project is MIT licensed and maintained by an active community. Beyond pure security use cases, developers use Sherlock for brand protection monitoring, pre-registration username availability checks, and building automated identity verification pipelines.

Pricing & Platform Specs

Pricing Summary

100% free and open-source OSINT username reconnaissance tool under the MIT license ($0 software cost). Runs locally via CLI or Docker with no account or API keys required.

full pricing breakdown →

Supported Platforms

Windows, Linux, macOS (Python CLI)

Explore categories, tags & use cases

Open-source secret detection for Git repositories

Gitleaks is an open-source secret scanner with 27K+ GitHub stars that detects hardcoded passwords, API keys, tokens, and private keys in Git repositories, files, directories, and full Git history. It integrates via GitHub Actions, pre-commit hooks, CI/CD pipelines, and single-binary local scans.

Open Source

Google's vulnerability scanner using the OSV database

OSV-Scanner is Google's official open-source vulnerability scanner that checks your project's dependencies against the OSV.dev database — the largest open vulnerability database covering all major ecosystems. Written in Go, it supports lockfiles from npm, pip, Maven, Cargo, Go modules, and more, providing actionable remediation guidance and CI/CD integration for automated security scanning.

Open Source

Comprehensive open-source vulnerability scanner

Trivy is an open-source vulnerability scanner with 24K+ GitHub stars by Aqua Security that scans container images, file systems, Git repositories, Kubernetes clusters, and IaC configurations for security issues. Detects OS package and language-specific vulnerabilities, misconfigurations, secrets, and license violations in a single tool. Runs as a simple CLI with zero configuration needed. Supports SBOM generation, VEX for vulnerability filtering, and CI/CD integration.

Open Source

Fast open-source SAST with custom rules

Semgrep is an AppSec platform with a widely used open-source engine for readable code rules plus commercial SAST, supply-chain and secrets workflows. Current product positioning emphasizes AI-assisted detection, triage and remediation, CI/pull-request integration and managed governance for security teams.

freemiumOpen Source

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is Sherlock?

Sherlock is a Python CLI tool that searches for a given username across 400+ social networks and websites simultaneously. It is widely used in OSINT investigations, security audits, red teaming exercises, and digital footprint analysis. Sherlock is included in Kali Linux and Parrot Security distributions and has over 76,000 GitHub stars, making it one of the most popular open-source security tools.

Is Sherlock free?

Yes — Sherlock is open source and free to use. 100% free and open-source OSINT username reconnaissance tool under the MIT license ($0 software cost). Runs locally via CLI or Docker with no account or API keys required.

Is Sherlock open source?

Yes — Sherlock is open source.

Is Sherlock still maintained?

Yes — Sherlock is active. Its listing was last verified on September 6, 2026.

What are the best Sherlock alternatives?

The first editor-selected Sherlock alternatives are Gitleaks, osv-scanner, Trivy, and more.