Find a Person: Their Social Media Profiles and Digital Footprint
Find a person: real identity, correlations and exposure from a username
Investigate the person behind a username: a real name consolidated by source convergence, correlations proving multiple accounts belong to the same person (avatar pHash, cross-referenced email, signed Keybase proof, PGP key), credential exposure, OFAC sanctions, aliases and history. Professional AI report and signed PDF.
jdoe · no @ · alphanumeric (. _ -) · Ideal for due diligence, investigation, journalism and compliance👁 See a full sample report ▾

Real example analyzing the domain google.com: owner identity and WHOIS/RDAP, 4-dimension risk scoring with an actionable executive summary, DNS (SPF, DMARC, CAA), TLS certificate, VirusTotal (0/94), Shodan, DNS blacklists, subdomains and technology infrastructure (WhatWeb + WAF + AXFR).
What is this social media analysis tool?
IntelMind’s OSINT social media tool is an engine that goes beyond listing profiles. It starts from a username and builds a complete picture of the digital identity: which platforms they use, which emails and domains are linked to them, and their level of public exposure.
This social media OSINT tool combines search across 450+ platforms with cross-referenced email correlation (detects if an email appears on GitHub, via Holehe and other sources), reverse search (public repos, Gravatar, email reputation) and ready-to-use investigation dorks on Google and Yandex.
What you get with every lookup
- 450+ platforms: Sherlock (479), Maigret (60 deep), Nexfil (200 modern). Profiles grouped by category: Social, Dev, Gaming, Fediverse.
- Email extraction: GitHub commits, GPG keys, OSGINT. With explained origin and confidence.
- Cross-referenced correlation: Holehe detects platforms where the email is registered. Emails confirmed when found across 2+ sources.
- Personal domains: extracted from profiles, blogs, repos and Gravatar.
- Investigation dorks: Google and Yandex. Types: general, passwords, leaks/pastebins, social media. Ready to click.
- Social APIs: GitHub, GitLab, StackOverflow, YouTube, Mastodon, Bluesky and more.
- 5D scoring + verdict: Footprint, Identity, Exposure, Activity and a final score with a risk level.
- Professional summary · Chat · PDF: explanatory report, 3 questions about the case, exportable.
Quick FAQ
How many platforms does it check?
450+ platforms combining Sherlock (479 sites), Maigret (60 deep analyses) and Nexfil (200 modern sites). Found profiles are grouped into categories: Social, Dev, Gaming and Fediverse.
What are investigation dorks?
Preconfigured advanced searches for Google and Yandex. They help find mentions of the email or username in public pages, forums, pastebins and possible leaks. They appear at the end of the report, ready to click.
What does 5D scoring mean?
Five weighted dimensions: Footprint (presence across major networks), Identity (emails + correlation), Exposure (followers/reach), Activity (recent activity) and a consolidated Final score with a LOW / MEDIUM / HIGH / CRITICAL risk level.
How does email correlation work?
Emails are extracted from GitHub commits, GPG keys and OSGINT. If the same email appears in 2 or more independent sources it’s marked as confirmed. Holehe also checks which platforms that email is registered on, and personal domains are searched for in profiles, repos and Gravatar.
Is it legal to analyze someone’s social media without their consent?
Yes, as long as the analysis is limited to publicly accessible information (OSINT). IntelMind only checks profiles, artifacts and open sources any user could see manually. It doesn’t access private content, doesn’t break authentication, and doesn’t automate actions requiring consent. Using the report for discrimination, harassment or automated decision-making may be subject to regulation (like the GDPR); responsibility for that use rests with the professional issuing the report.
Can a private profile be analyzed, or only public ones?
Only public profiles. If a profile is set to private, IntelMind can’t see its content, followers or posts — just like any other internet user. What it can do is confirm the handle exists on the platform, detect the associated email if it appears in public sources (GitHub, GPG, Gravatar), and correlate it with other services where the same username is public.
Is the user notified when IntelMind analyzes their profile?
No. The analysis is passive and discreet: IntelMind doesn’t send messages, follow profiles, react to posts, or take any action visible to the account holder. It only queries public information the way a human investigator would manually. The profile owner receives no alert or notification from this tool being used.
What is OSINT social media analysis used for in an investigation?
To reconstruct a user’s digital footprint starting from their username. Typical uses: verifying a counterparty’s identity in due diligence, antifraud triage (detecting synthetic or newly created accounts), investigative journalism, SOC/CSIRT teams correlating threat actor handles, missing-person searches, candidate verification in hiring, or reputation analysis. All without breaching privacy or accessing protected content.
Can I investigate an Instagram profile with this tool?
Partially. IntelMind searches the username across 450+ platforms and gathers the associated social media footprint (emails, domains, repos, Gravatar), but it doesn’t access private content or closed profiles. It’s built to find a person across social media and see which public platforms they have a presence on, not to bypass privacy controls.
The complete guide to OSINT social media analysis
Analyzing a user’s social media presence like a professional goes far beyond checking whether a handle exists on Instagram or Twitter. A username is the entry point to a complete digital identity spread across dozens of platforms, repositories, forums and public databases. This guide explains the dimensions IntelMind evaluates on every lookup to deliver an actionable executive verdict — useful for due diligence, antifraud triage, investigative journalism, SOC and security teams.
Multi-platform coverage: Sherlock, Maigret and Nexfil explained
Professional username search combines three complementary OSINT tools. Sherlock checks 479 platforms with HTTP-status or response-pattern verification; Maigret runs a deep analysis on 60 platforms, extracting additional metadata (bio, followers, registration date); Nexfil covers 200 modern sites the other two don’t include. The result is a catalog of 450+ cross-checked sources, grouped by category (Social, Dev, Gaming, Fediverse) and classified by attribution level: likely match, reinforced attribution (when there are additional signals like a matching email), or handle only.
Email and domain correlation: how the digital identity comes together
The same user often leaves their email across different points of the digital ecosystem: GitHub commits, GPG keyservers, packages published on npm/PyPI/crates.io, WHOIS records for personal domains, or Gravatar metadata. IntelMind extracts these emails automatically and flags them with an origin (where it appeared) and a confidence level (high if declared or confirmed by 2+ sources; medium if from registration data; low if from scraping). When the same email appears across two or more independent sources, it’s considered confirmed and strengthens the attribution of the found profiles to the same owner.
Google and Yandex dorks: preconfigured advanced search
Google dorks (and their Yandex equivalents) are advanced search queries combining operators (site:, inurl:, filetype:,
quotes, exclusions) to locate mentions of the username or email in corners generic search doesn’t reach: old forums, pastebins, public leaks, PDF files, etc.
IntelMind automatically generates three families of dorks ready to click: general search, passwords and leaks search (pastebins, GitHub gists, breach compilations),
and social-media-specific search (when native profiles don’t return results). An OSINT investigator used to write these dorks by hand; now they’re one click away.
5D scoring: footprint, identity, exposure, activity and final
IntelMind’s 5D Risk Score evaluates five independent dimensions. Footprint measures the user’s multi-platform presence (how many networks recognize them); Identity measures correlation between emails, handles and public artifacts (how much consistency exists across contact points); Exposure assesses the degree of public exposure (followers, mentions in indirect leaks, presence in compromised databases); Activity measures how current the profile is (recent activity in months); and Final consolidates all four into a score with a LOW / MEDIUM / HIGH / CRITICAL level.
Detecting fake accounts, synthetic identities and impersonation
A fake or synthetic account leaves characteristic signals: a handle registered just days ago, no cross-correlation (it only exists on one platform, no coherent public email, no associated OSINT artifacts), a generic or recycled profile photo, and an atypical activity pattern. IntelMind doesn’t issue a binary «real or fake account» verdict — that requires human verification — but a 5D score with low Footprint and low Identity is a clear signal the handle may not correspond to a real person, or that it’s a recent alias. Impersonation on social media is detected by the reverse pattern: a handle with high Footprint on legitimate platforms and a second, similar handle (typo-squatting) with low Footprint and recent Activity can be an attempt to impersonate the first.
Indirect exposure signals: LeakCheck, HudsonRock and infostealers
Beyond direct analysis, IntelMind checks databases of indirect exposure signals to detect whether the username appears in public data breaches (LeakCheck) or in infostealer logs (malware like RedLine, Raccoon, Vidar — aggregated in HudsonRock). These sources indicate that the handle has appeared in compromised datasets, an important signal for threat investigation. Important: these signals do NOT unambiguously confirm that the records belong to the owner of the analyzed handle — the same username can belong to different people on different platforms. That’s why the report flags these signals as indirect and requires the investigator to add context.
Use cases: due diligence, journalism, SOC, antifraud and HR
OSINT social media analysis delivers very different value depending on the context. A due diligence team uses it to verify a counterparty’s identity and digital reputation before signing a contract or investing; an investigative journalist correlates handles for sources or investigation subjects; a SOC/CSIRT attributes handles to threat actors or phishers; an antifraud team detects synthetic accounts in mass signups; an HR / compliance team verifies a candidate’s digital consistency without violating their privacy (public profiles only). In every case, the same lookup delivers an exportable PDF report with an executive verdict, scoring, profiles, emails, domains and dorks ready to continue the investigation.
Sources and technical references
IntelMind integrates reference OSINT tools and relies on open ecosystem standards. Check the official pages for additional context:
- OSINT Framework — a reference index of OSINT tools by category.
- Sherlock Project — username search across 479 platforms.
- Maigret — deep analysis of social profiles.
- Google hacking (Wikipedia) — an academic explanation of investigation dorks.
- Bellingcat Resources — OSINT investigation methodologies applied to journalism.
Search for a user on social media: real coverage and limitations
Searching for a user on social media with modern OSINT starts with a username or alias and returns, in seconds, the list of platforms where that same handle exists (or doesn’t). IntelMind covers 450+ platforms combining Sherlock, Maigret and Nexfil. Useful coverage includes the major social networks (LinkedIn, Twitter/X, Instagram, Facebook, TikTok), tech forums (GitHub, Stack Overflow, Hacker News, Reddit), creator platforms (YouTube, Twitch, Patreon), specialized professional networks (Behance, Dribbble, Kaggle), and image/video services (Vimeo, Flickr, 500px). Important: a username existing on a platform doesn’t mean it belongs to the person you’re looking for — namesakes are common, and final verification always comes down to correlating email, domain or profile photo.
Finding a profile by email, domain or real name: the correlation workflow
When what you have isn’t a username but an email, a domain or a real name, and you need to find the associated profile, the OSINT workflow changes: (1) start from the email and run Holehe to detect which platforms have a registration with that email; (2) use the email’s local-part alias (the part before the @) to run a username search; (3) cross-check the matches against preconfigured Google and Yandex dorks that IntelMind generates automatically; (4) validate consistency against the profile photo or bio. The professional verdict closes the analysis with an explicit confidence level (high/medium/low) on whether the found profiles belong to the same person or are namesake aliases. This is the pattern HR teams use to verify backgrounds, journalists use to verify sources, and private investigators use to build a dossier.
Username search: from Sherlock as a CLI to a browser-based OSINT suite
Username search is one of the oldest OSINT techniques and remains the entry point for many investigations. Sherlock was the reference tool for years (a free Python CLI, ~480 platforms), but most B2B professionals don’t want to set up Python or maintain forks. IntelMind integrates Sherlock alongside Maigret and Nexfil in a web interface with 5D scoring, cross-referenced identity correlation, preconfigured dorks and a signed PDF export with chain of custody. This turns classic username search into a tool a lawyer, a detective or a journalist without technical training can use, and lets the result be archived as documentary evidence. That’s exactly the difference between searching for someone by their username in a CLI and handing a client a signed report.
