Un outil OSINT en ligne de commande : on lui donne un pseudo, il vérifie plus de 400 sites en parallèle et liste les comptes trouvés. A command-line OSINT tool: give it a username, it checks over 400 sites in parallel and lists the accounts it finds.
Retrouver les comptes liés à un pseudo, c'est souvent la première étape d'une enquête OSINT. Sherlock le fait déjà en Python. Je voulais la même chose en un seul binaire, sans dépendances, et apprendre la concurrence en Go au passage. La liste de sites de départ vient de Sherlock.
Finding the accounts tied to a username is often the first step of an OSINT investigation. Sherlock already does it in Python. I wanted the same thing as a single binary with no dependencies, and to learn Go concurrency along the way. The starting site list comes from Sherlock.
Trois façons de savoir si un compte existe. Chaque site déclare sa méthode dans sites.json : le code HTTP, l'URL après redirection (renvoyé vers une page d'erreur, le compte n'existe pas), ou un message dans la page comme « user not found ». La lecture du corps est limitée à 1 Mo.
Three ways to tell if an account exists. Each site declares its method in sites.json: the HTTP status, the URL after redirects (sent to an error page means no account), or a message in the page such as "user not found". Reading the body is capped at 1 MB.
// main.go, simplified
switch site.ErrorType {
case "status_code": // 2xx: the account exists
found = resp.StatusCode >= 200 && resp.StatusCode < 300
case "response_url": // redirected to the error page: it doesn't
found = resp.Request.URL.String() != errorURL
case "message": // "user not found" in the first MB of the page
found = !containsAny(body, site.ErrorMsg)
}
Concurrence bornée. Une goroutine par site, mais un canal bufferisé sert de sémaphore : 20 requêtes en même temps par défaut, réglable avec -c. Les erreurs passagères (5xx, 429, réseau) sont retentées.
Bounded concurrency. One goroutine per site, with a buffered channel as a semaphore: 20 requests at once by default, tunable with -c. Transient errors (5xx, 429, network) are retried.
Fait pour les rapports. Plusieurs pseudos d'un coup ou depuis un fichier, listes d'exclusion, filtre NSFW, et sortie en texte, JSON, CSV ou Markdown.
Built for reports. Several usernames at once or from a file, exclusion lists, an NSFW filter, and output as text, JSON, CSV or Markdown.
Twitter/X, Instagram, LinkedIn ou Discord renvoient des résultats peu fiables à cause de leurs protections anti-bot. Plutôt que d'afficher des faux positifs, Hermes les ignore et les documente dans BROKEN_SITES.md, avec les URLs pour vérifier à la main.
Twitter/X, Instagram, LinkedIn or Discord return unreliable results because of their anti-bot protections. Rather than show false positives, Hermes skips them and documents them in BROKEN_SITES.md, with URLs to check by hand.