Disclaimer: All information provided in this article is for educational purposes and authorized security research only. The tools and techniques discussed should only be used on systems you own or have explicit permission to test. Unauthorised information gathering may violate laws such as the Computer Fraud and Abuse Act (CFAA), GDPR, or the Investigatory Powers Act.
TL;DR
- The Problem: Manual OSINT (Googling names, checking social sites one by one) is slow, prone to errors, and misses hidden connections.
- The Solution: UserSearch acts as an OSINT orchestration engine, running 50+ checks (OneScan) simultaneously to link usernames, emails, and phones to real identities.
- Key Concepts: We explain OneScan (federated search), Forensic Mode (for legal audits), and the 15 core intelligence modules.
- The Outcome: By the end of this guide, you will know how to run a complete "Username to Identity" investigation using professional workflows.
2.1 The OSINT Landscape: From Noise to Signal
Open Source Intelligence (OSINT) used to be the domain of elite government agencies and specialized private investigators. Today, the data is out there—billions of public records, social media profiles, and leaked credentials—but the challenge has shifted from access to noise. A simple Google search for a name often returns 10,000 results. How do you find the right one? How do you link a username on Reddit to an email address in a breach?
Enter UserSearch. We built this platform to be the operating system for modern investigations. It unifies dozens of manual checks into a single, automated workflow. Whether you are a journalist verifying a source, a fraud analyst checking a customer, or just a curious beginner, this guide will teach you how to run your first professional-grade investigation using UserSearch.
2.2 The UserSearch Ecosystem
Before diving into individual search types, you must understand the engine you are driving. UserSearch is an OSINT Orchestration Engine. It connects to over 50 different data providers—some public, some commercial (like Pipl and Predicta), and some proprietary internal datasets.
OneScan (Federated Search)
You will see modules labeled OneScan (e.g., "Username OneScan"). This is our most powerful feature. It allows you to query multiple premium data providers at once.
For example, if you search for the username CoolGuy99 using OneScan, we simultaneously ask:
- OSINT Industries: "Do you see this user on social media?"
- UserSearch: "Do we have internal records for this user?"
- Predicta Search: "Do you have enriched profile data for this user?"
- Pipl: "Is this linked to a verified identity?"
We then display the results side-by-side. This cross-referencing is essential for verifying data. If three different providers all link CoolGuy99 to the same email address, you can be highly confident in that finding.
Privacy Mode vs. Forensic Mode
When you start a new Case, you are asked to choose a mode. This matters.
- Privacy Mode (Default): We do not log your search history or store your bookmarks permanently. Once you close the session, the data is gone. This is ideal for quick, sensitive checks where you want zero trail.
- Forensic Mode: We log every search, result, and bookmark into a secure, encrypted Case File. This creates an Audit Trail. If you are investigating for a legal case or a corporate report, you must use Forensic Mode to prove when and how you found the information.
2.3 Why Structured OSINT Matters: Real-World Stakes
Why move from Google searches to a structured platform? The answer lies in attribution and speed. In modern cybersecurity, the ability to link a digital indicator (like an IP or handle) to a human identity is the bottleneck.
Consider the 2023 23andMe Credential Stuffing Attack. As reported by Wired, attackers didn't "hack" the company's servers directly; they used old usernames and passwords reused by customers from previous breaches. If the victims (or defenders) had run a routine Username and Public Leaks check, they would have seen that their credentials were exposed years ago.
For a fraud analyst, missing a link between a "clean" email and a "scam" forum profile can mean approving a fraudulent loan. For a journalist, failing to verify the location of a video source can ruin a story's credibility. Structured OSINT reduces these risks by ensuring you check every available source, every time, without fatigue.
2.4 The Toolbelt: Core Intelligence Modules
UserSearch is divided into 15 specific intelligence categories. Understanding the nuance of each is key to becoming a master analyst.
1. Username Intelligence: The Digital Fingerprint
What it does: Traces a handle/alias across the web.
Key Modules: Enriched Search, OneScan (OSINT Ind, UserSearch, Predicta, Pipl), Twitter History.
Users rarely invent new usernames for every site. They reuse them. The Username Search (Enriched) module scans over 3,000 websites—from massive platforms like Instagram to niche forums like Bitcointalk—to find where a specific handle exists.
Pro Tip: Look for "soft 404s". Some manual tools report a user exists just because the page loaded. UserSearch analyzes the page content to confirm it is a real profile. Use the Graph view to see if the bio on the Github profile matches the bio on the Reddit profile.
2. Email & Identity: The Anchor
What it does: Finds the person behind an email and their security history.
Key Modules: Reverse Email (Fast), Email-to-Name (Gravatar), ProtonMail Analyse.
An email is the golden key. Our Reverse-Email (Fast) module checks internal databases to see if the email is registered on major social sites (Facebook, Skype, Spotify). This is a "presence check". To get a name, use Email-to-Name (Gravatar), which often returns a photo and real name if the user ever set up a WordPress or Gravatar profile.
Analyst Insight: See our full Reverse Email OSINT Guide for deep-dive techniques on tracing burner addresses.
3. Phone Intelligence
What it does: Links a number to a name, location, or social profile.
Key Modules: US Background Check, Global Social OneScan.
Phone numbers are heavily tied to identity due to 2FA (Two-Factor Authentication). Our Phone (OneScan) module queries global datasets to see if a number is linked to a Twitter or Facebook account. Even if the profile is private, the existence of the link confirms the number is active and social-connected.
4. People Search: Identity Resolution
What it does: Finds contact info and background data starting from a Name + Location.
Key Modules: Pipl Social, Pipl Business, Voter Records.
When you only have a name ("David Smith in London"), this is your starting point. The Pipl modules are the industry standard for identity resolution. They aggregate billions of records to triangulate the correct "David Smith" by cross-referencing age, relatives, and job history.
5. Business & Corporate Intelligence
What it does: Maps corporate structures, directors, and intellectual property.
Key Modules: OpenCorporates, Google Patents, Trademark Search.
Use this to vet companies. The Company Search module (via OpenCorporates) reveals if a company is active or dissolved, and lists its registered address. The Director Search allows you to reverse-search a person to see all companies they manage—a classic technique for finding shell companies or conflicts of interest.
6. Chat Messaging (Telegram)
What it does: Searches users, channels, and messages on Telegram.
Key Modules: Channel Lookup, User Lookup, Message Search.
Telegram is the hub of modern cybercrime and activism. Our Telegram Chat Messages module searches billions of public messages. You can search for a keyword (e.g., a specific crypto wallet address) to see every time it was mentioned in public groups. For a complete workflow, read our Telegram OSINT Guide.
7. Public Forums (Reddit)
What it does: Profiles Reddit users and their activity timelines.
Key Modules: User Profile, Comment History, Activity Timeline.
Reddit is where people share their true thoughts. Our Reddit User Profile module pulls account age and karma. The Comment History search allows you to filter thousands of comments by keyword. The Activity Timeline visualizes when they post—helping you determine their likely timezone and sleeping habits.
8. Picture Forensics
What it does: Verifies images and finds faces.
Key Modules: FaceCheck.id, Fake Image Check, Exif Data.
Have a photo of a suspect? Run it through FaceCheck.id (OneScan) to find their social media profiles across the web. Suspect a document is forged? Upload it to Fake Image Check (ELA - Error Level Analysis) to see if pixels have been digitally altered.
9. Cryptocurrency
What it does: Checks wallet addresses for scam reports and web links.
Key Modules: Address Lookup, Websites by Address.
Crypto isn't anonymous; it's pseudonymous. Use Address Lookup to check if a Bitcoin or Ethereum wallet has been reported in scam databases. Use Websites by Address to find which domains act as faucets or donation pages for that specific wallet, linking the money to a web infrastructure.
10. Vehicle Intelligence
What it does: Checks car history and specs (focus on UK).
Key Modules: Vehicle Lookup (Enriched), Vehicle Owner (Pipl).
In the UK, entering a License Plate (VRM) into Vehicle Lookup returns the exact make, model, colour, and MOT status. This is vital for verifying if a car seen in a photo is legitimate or a "clone" (stolen car with fake plates).
11. Threat Intelligence
What it does: Checks IPs and Domains for compromise and reputation.
Key Modules: HudsonRock (Compromise Check), SpamHaus (Reputation).
This is for the defenders. Use Domain Threat (HudsonRock) to see if employees of a specific company have been compromised by malware. If 50 employees of target-company.com have infected computers, that company is at high risk of a ransomware attack.
12. Wireless Geolocation
What it does: Locates routers and devices via Wi-Fi/Bluetooth signals.
Key Modules: Wigle (SSID/BSSID Search).
Every Wi-Fi router has a BSSID (MAC address). Wardriving databases like Wigle map these. If you know the BSSID of a target's home router, you can enter it here to find its physical coordinate on a map. This works even if the target has moved, as people often take their routers with them.
13. Website Forensics
What it does: Analyzes domain ownership and history.
Key Modules: Domain Ownership, Website Change History, Favicon Search.
Who owns a site? Domain Ownership gives you current and historic WHOIS data. Website Change History (Wayback Machine) lets you see the site as it looked 5 years ago. Favicon Search is a hidden gem: it finds other websites that use the exact same favicon image, often revealing a network of scam sites run by the same group.
14. Public Leaks (Breach Mining)
What it does: Searches stolen data (without the dark web).
Key Modules: IntelX, Dehashed, HIBP.
This is where you find passwords. Searching an email in Public Leaks (OneScan) queries databases of leaked credentials. You aren't hacking; you are searching data that hackers have already dumped. This reveals passwords, IP addresses, and physical addresses linked to the email.
15. Court Records
What it does: Searches global litigation and judgments.
Key Modules: UK/US/France/Canada Court Search.
Finally, check the legal footprint. Our Court Records modules search national archives for judgments involving the target's name. This is critical for due diligence. Does your potential business partner have a history of bankruptcy or fraud convictions?
2.5 Execution: Running Your First Investigation
Let’s put these modules together. We will walk through two common scenarios: tracing a username and investigating an email.
Walkthrough 1: Tracing a Suspicious Username
Scenario: You have found a suspicious user on a forum with the handle CryptoKing_88.
Step 1: Select the Module
Go to the Search Card (left side). Select Username from the category list. Choose Username Search (Enriched). This scans over 3,000 websites.
Step 2: Run the Search
Enter CryptoKing_88 and click Search Now. Watch the progress bar. It takes 10–60 seconds because we are actively scanning live sites, not just looking at a static list.
Step 3: Triage Results
Look at the Search Results card. You might see 50 hits. Use the Category filter to focus.
Example: You see hits on "Steam" (Gaming) and "Bitcointalk" (Crypto). This establishes a profile: likely a male, gamer, interested in finance.
Step 4: Bookmark
Click the star icon next to the most interesting results. This saves them to your Case.
Walkthrough 2: From Email to Identity
Scenario: You found an email address on one of those forum profiles: [email protected].
Step 1: Public Leaks Check
Switch the search category to Public Leaks. Select Public Leaks (OneScan). This searches databases of stolen credentials (like IntelX and Dehashed).
Step 2: Analyze the Breach
You find a record from a 2021 database dump. It shows the password associated with this email was SarahJones1988!.
Analysis: The handle says "King", but the password suggests "Sarah Jones". This is a pivot point. The user might be Sarah, or "King" is a fake persona.
Step 3: Enrichment
Switch to Email Search and run Email-To-Name (Gravatar). It returns a profile picture of a woman. You can now download that picture and run it through our FaceCheck.id module (under Picture search) to see if she appears elsewhere on the web under her real name.
2.6 Advanced Strategies and Visualization
Professional investigators don't just look at lists; they look at connections. The Graph tab helps you make sense of the data chaos.
Visualizing with the Graph
Step 1: Open the Graph
After running your searches, click the Profile card and switch to the Graph tab.
Step 2: Read the Nodes
You will see your search term in the center. Connected to it are all the results you found (websites, usernames, emails).
Red Borders: Indicate items that are connected to each other (e.g., the same username found on two different sites).
Green Borders: Indicate items you have Bookmarked.
Step 3: Expand the Network
Right-click on a node (e.g., the specific email you found) and select "Search this item". UserSearch will recursively run a new search on that data point, expanding your graph outward. This is how you map a network of connected accounts.
Common Mistakes (and How to Avoid Them)
- The "John Smith" Problem
Mistake: Searching for a common name without filtering.
Fix: Use Secondary Selectors. Don't just search "John Smith". Search "John Smith" + "London" + "Architect". Use the filters in the search module to narrow by country or category. - Ignoring False Positives
Mistake: Assuming every result belongs to your target.
Fix: Corroboration. Just becauseCoolGuy99is on Twitter and Tinder doesn't mean they are the same person. Look for a matching bio, location, or profile picture to confirm the link. - Using Active Mode Accidentally
Mistake: Clicking a link to a target's LinkedIn profile while logged into your own personal account.
Fix: UserSearch shows you the data within our platform (passive). If you must visit the live site, use a burner account and a VPN. We provide "Snapshots" (cached images) in the Profile view so you don't have to visit the site directly.
2.7 Legal & Ethical Guardrails
With great power comes the requirement for strict governance. Just because you can map a life doesn't mean you should without cause.
- Authorized Research Only: Use these techniques for defensive security, authorized fraud investigation, or journalism in the public interest. Do not use them for harassment or stalking.
- Data Sovereignty & GDPR: When investigating EU subjects, be mindful of PII retention. Use our Privacy Mode to ensure that your search artifacts (bookmarks, history) are not permanently stored in the case log once the session ends.
- Chain of Custody: If you are building a legal case, use Forensic Mode. This logs the timestamp, the exact search parameters, and the result state, creating an immutable audit trail that can stand up in a report.
2.8 Conclusion: Start Your Investigation
The era of manual OSINT—opening 50 tabs and copy-pasting data into Excel—is over. By using a structured, orchestrated platform, you can investigate faster, deeper, and safer. You can focus on the analysis of the data, rather than the collection.
Whether you are tracking a username across 3,000 sites or unmasking the owner of a scam crypto wallet, UserSearch gives you the tools to turn noise into intelligence.
Stop guessing. Start investigating. Run structured identity OSINT with UserSearch at https://www.usersearch.com.