OSINT Recon Suite - Unified Digital Footprint Report
Pricing
Pay per event
OSINT Recon Suite - Unified Digital Footprint Report
Digital footprint report for one target — username, email, domain or phone. Runs Maigret, Sherlock, holehe, theHarvester, WHOIS and dnstwist in one pass and correlates every hit into a risk-scored OSINT report. Those actors run on your account and bill separately — see README.
Pricing
Pay per event
Rating
0.0
(0)
Developer
daehwan kim
Maintained by CommunityActor stats
0
Bookmarked
83
Total users
28
Monthly active users
3 days ago
Last modified
Categories
Share
OSINT Recon Suite — Unified Digital Footprint Report
One target in. One correlated intelligence report out.
Most OSINT actors do one thing — check a username, or an email, or a domain. This actor is a tool of tools: give it a single target and it automatically runs the right specialist tools, fuses their findings, correlates identities, scores risk, and hands you a single readable report plus a structured dataset.
What it does
| You give | It runs | You get |
|---|---|---|
| Username | Maigret + Sherlock | Every social/forum/site profile, deduplicated |
| holehe + (domain pivot) theHarvester · WHOIS · dnstwist | Where the email is registered, plus its domain footprint | |
| Domain | theHarvester + WHOIS + dnstwist | Subdomains, emails, registration facts, look-alike/phishing domains |
| Phone (opt-in) | PhoneInfoga | Carrier, line type, country, web footprint |
Every run also produces:
- Risk score (0–100) with a LOW / MEDIUM / HIGH band
- Correlations — e.g. "same identity confirmed across 7 platforms", "email exposed on 6 services"
- A Markdown intelligence report (in the run's key-value store, key
REPORT) - A structured dataset of every finding
Input
| Field | Description |
|---|---|
target | The username, email, domain, or phone (E.164) to investigate |
targetType | auto (default) or force username / email / domain / phone |
depth | quick, standard (default), or deep (more sources, cross-correlation) |
includePhone | Opt-in to scan phone-number targets (sensitive) |
disclaimerAck | Required. Confirms authorized, lawful use |
Example
{"target": "octocat","targetType": "auto","depth": "standard","disclaimerAck": true}
Pricing (pay-per-event)
This actor charges for orchestration — running the right specialist tools, deduplicating their overlapping results, correlating identities, and fusing everything into one risk-scored report:
- $0.02 per discovered entity (profile, email exposure, subdomain, look-alike domain, phone link), capped at 100 chargeable discoveries per run
- $0.20 per generated report — charged once per run, at the end
The specialist actors run under your own account and bill you separately. This actor starts them with Actor.call(), so those child runs appear in your run list and on your invoice alongside this one. Their current rates:
| Source | Charges | Rate |
|---|---|---|
| Maigret | per account found | $0.02 |
| Sherlock | per account found | $0.02 |
| holehe (Email OSINT Search) | per account found | $0.02 |
| theHarvester | per domain harvested — one domain per run here | $0.05 |
| WHOIS Domain Lookup | per domain looked up — one domain per run here | $0.02 |
| dnstwist | per registered look-alike found | $0.03 |
| PhoneInfoga | per number scanned — one number per run here | $0.05 |
So a domain-side scan carries a flat $0.07 (theHarvester + WHOIS) however many subdomains it returns, while username, email and look-alike findings are charged per item.
What one discovery costs, end to end
| Discovery | Child charge | This actor | Total |
|---|---|---|---|
| Profile on a site (username scan) | $0.02 | $0.02 | $0.04 |
| …found by both Maigret and Sherlock | $0.04 | $0.02 (deduplicated) | $0.06 |
| Email registered on a service | $0.02 | $0.02 | $0.04 |
| Subdomain or related email | $0 extra — covered by theHarvester's flat $0.05 | $0.02 | $0.02 each, plus that one-time $0.05 |
| Look-alike / typosquat domain | $0.03 | $0.02 | $0.05 |
Typical run totals
Findings vary by target, so these are worked examples, not quoted prices. Each includes the $0.20 report and every child charge. The username row, spelled out: $0.20 report + 20 × $0.02 orchestration + 15 Maigret hits × $0.02 + 12 Sherlock hits × $0.02 = $1.14.
| Target type | Sources started | Example run | Estimated total |
|---|---|---|---|
| Username | Maigret + Sherlock | 20 unique profiles | ~$1.14 |
| Username (very common handle) | Maigret + Sherlock | 70 unique profiles | ~$3.60 |
| holehe + theHarvester + WHOIS + dnstwist¹ | 8 registrations, 15 subdomains, 3 related emails, 4 look-alikes | ~$1.15 | |
| Domain | theHarvester + WHOIS + dnstwist | 25 subdomains, 5 emails, 8 look-alikes | ~$1.27 |
| Phone (opt-in) | PhoneInfoga | 1 number | ~$0.27 |
A quiet target costs much less — a username with 10 profiles runs about $0.68, a domain with a dozen findings about $0.66. A loud one costs more: a username on 200 sites hits the 100-discovery cap and lands near $7.60 ($0.20 report + $2.00 capped orchestration + ~$5.40 of Maigret and Sherlock hits). The cap limits this actor's fee, not the underlying tools'.
¹ An email target also pivots to its domain, so it starts the three domain tools as well. At depth: "deep" it additionally runs Maigret and Sherlock on the local part of the address.
Prefer to run the tools yourself?
Every source is a standalone actor you can run directly: Maigret, Sherlock, Email OSINT Search, theHarvester, WHOIS Domain Lookup, dnstwist, PhoneInfoga. Doing that skips this actor's fee; you then handle the deduplication, correlation, and report yourself. Use this actor when one input and one finished report is worth more to you than that work.
Use depth: "quick" to check fewer sites, and the run's Max charge limit to put a hard ceiling on any single run.
Legal / ethical use
This actor queries only publicly available sources. It is intended for authorized security research, penetration testing, brand protection, and personal digital-footprint audits. By setting disclaimerAck: true you confirm you are authorized to investigate the target and will comply with all applicable laws (GDPR, CFAA, and local privacy law). Do not use it for harassment, stalking, doxxing, or any unlawful purpose.