Disclaimer: This article is for education and for lawful, authorised professional research. Use these methods only where you have a legitimate purpose and a lawful basis, and follow the laws and platform terms that apply to you, including data protection law such as the UK GDPR and EU GDPR. See our Terms of Service.
TL;DR
- The problem: Manual OSINT (typing a handle into one site after another, copying results into a spreadsheet) is slow, error-prone and easy to get wrong when you are tired.
- The approach: UserSearch 2.0 gives you 18 Search types and access to 100+ third-party data sources through one account, and OneScan runs one input across several sources with source attribution.
- Key concepts: We explain OneScan, Cases (Forensic Mode and Private mode), SargeBot and the main Search types you will use first.
- The outcome: By the end of this guide you will know how to run a structured first piece of research on a handle, an email address or a domain, and how to record it properly.
2.1 From Noise to Signal: Why Beginners Struggle
Open Source Intelligence (OSINT) used to be the domain of government agencies and specialist consultancies. Today the data is out there, in company registers, public social accounts, domain records and archived web pages, but the challenge has shifted from access to noise. A single web search for a company name or a handle can return thousands of results. How do you find the right one? How do you connect a handle on a forum to the business behind a website?
That is why we built UserSearch. The platform brings dozens of manual checks into one structured workflow. Whether you are a journalist verifying a source, a compliance analyst checking a new merchant or a beginner learning the craft, this guide shows you how to run your first professional piece of research with UserSearch.
2.2 How the UserSearch Platform Fits Together
Before you look at individual Search types, it helps to understand the engine you are driving. UserSearch 2.0 is a web platform for professional OSINT research. It has 18 Search types and about 107 visible Modules, and it gives you access to 100+ third-party data sources through one UserSearch account, so you do not need separate accounts with each provider.
OneScan: One Input, Several Sources
You will see Modules labelled OneScan (for example, "Username OneScan"). OneScan runs one input across several data sources that you select, then merges the results with source attribution, so you can see which source said what.
For example, if you run the handle CryptoKing_88 through OneScan, several sources are asked the same question at once: where does this handle appear, and what public account details sit alongside it? The Credit cost of a OneScan is the sum of the sources you select, and it is shown to you before you run it.
We then show the results side by side. This cross-referencing matters for verification. If three independent sources all connect CryptoKing_88 to the same email address, you have a much stronger lead than a single hit. It is still a lead to corroborate, not a fact: coverage and freshness depend on each third-party source.
Private Mode vs Forensic Mode in Cases
When you start a new Case, you choose how it records your work. This choice matters.
- Private mode: Your search history is not stored. This suits quick, one-off checks where you do not need a record.
- Forensic Mode: Your search history and bookmarks are stored in the Case. This gives you a record of what you searched and what you saved. If your research feeds a legal matter, a compliance file or a client report, use Forensic Mode so you can show how you reached your findings.
Turn on two-step verification for sign-in. If you work in a team, shared Cases and a common Credit pool controlled by the team leader keep everyone on the same file.
2.3 Why Structured OSINT Matters: Real-World Stakes
Why move from ad hoc web searches to a structured platform? The answer comes down to attribution and consistency. In professional research, the hard part is rarely finding one data point. It is showing, clearly and repeatably, how a handle, an email address, a domain and a registered company connect to each other.
Manual work breaks down in predictable ways: five sites checked on Monday, three on Friday, and a note that says "found on a forum" with no date or link. That does not survive a challenge from a client or a regulator.
For a fraud and insurance team, missing the link between a "clean" merchant email and a forum account promoting a dubious scheme can mean onboarding a business that should have been declined. For a journalist, failing to verify where a video was filmed can undo a story's credibility. Structured OSINT reduces these risks by making sure you check the same sources, in the same order, every time, and record what you found.
2.4 The Toolbelt: The Search Types You Will Use First
UserSearch has 18 Search types. Below we walk through the ones beginners reach for most often, with what each is for and how we suggest you use it.
1. Username Intelligence: Where a Handle Appears
What it does: Checks where a handle or alias appears across the web.
People and businesses rarely invent a new handle for every site. They reuse them. Username Intelligence checks a handle across thousands of websites, from large platforms to niche forums, to show where it exists.
Tip: Watch for "soft 404s". Some basic tools report that an account exists just because a page loaded. Open the result and confirm it is a real account page before you rely on it. Then compare the bio text, links and avatar between two sites to judge whether they belong to the same operator. For a longer walkthrough, read our username research guide.
2. Email Intelligence: The Anchor Point
What it does: Shows where an email address is registered and what public account details sit around it.
An email address is often the most useful single identifier you have. Email Intelligence Modules check whether an address is registered on well-known services. This is a "presence check": it tells you where the address has been used, not what is inside those accounts. Gravatar is a good example of a public source here, because it can return the display name and avatar a user chose to publish.
Analyst insight: For more depth, see our email research guide.
3. Phone Intelligence
What it does: Checks carrier details and whether a number is associated with public social or messaging accounts.
Phone numbers are widely used for sign-up and two-factor authentication, so they often connect to accounts. Phone Intelligence Modules check whether a number such as +44 7700 900123 is associated with public accounts on major platforms. Even where an account is private, the fact that a link exists tells you the number is active and in use, which is useful when you are verifying the contact details a business has given you.
4. Corporate Intelligence: Companies and Officers
What it does: Maps company records, officers and corporate structures.
Use this to vet companies. Company Modules draw on sources such as OpenCorporates to show whether a company is active or dissolved and where it is registered. Officer searches let you see which other companies a named director is appointed to, a classic check for spotting shell structures or conflicts of interest in due diligence. Keep the personal data you record to what your purpose needs: the professional role, not the private life.
5. Product Intelligence: Trends, Patents and Apps
What it does: Covers trends, patents, scholarly material and app listings.
Product Intelligence helps when your research is about what an organisation makes or claims. A patent search can confirm whether a company really holds the technology it advertises. App listings show who publishes an app and how long it has been available.
6. Chat Messaging (Telegram)
What it does: Searches public Telegram channels, groups and messages.
Telegram is a major hub for public channels, from news outlets and activists to groups promoting dubious investment schemes. The Chat Messaging Modules search public Telegram content. You can search for a keyword, such as a specific crypto wallet address or a brand name, to see where it has been mentioned in public groups. For a full workflow, read our Telegram OSINT guide.
7. Public Forums (Reddit)
What it does: Reviews public Reddit accounts and their posting history.
Reddit is where people and brands discuss products, services and complaints in their own words. The Public Forums Modules return account age and karma, and let you filter public comments by keyword. For brand protection, this is a quick way to find where a counterfeit product or a copycat website is being discussed, and which accounts are promoting it.
8. Picture: Verifying Images
What it does: Reverse image search, geolocation and synthetic-image checks.
Have an image from a seller's listing or a viral post? Run a reverse image search to see where else it appears and whether it predates the claim being made. Use the geolocation tools to verify where a photo was taken, and the synthetic-image checks to judge whether an image has been generated or edited.
9. Cryptocurrency
What it does: Checks wallet addresses for public reports and web references.
Crypto transactions are pseudonymous, not private: every transaction on a public chain is visible. Use the Cryptocurrency Modules to check whether a Bitcoin or Ethereum address has been reported in public scam report databases, and to find which websites reference that address as a payment or donation page. That connects the money to a web presence you can research further. Our guide to linking wallets and infrastructure goes deeper.
10. Vehicle Lookup
What it does: Checks vehicle history and specifications (UK focus).
In the UK, entering a registration mark (VRM) into Vehicle Lookup returns details such as make, model, colour and MOT status. For insurance and fleet teams, this is a quick way to check that a vehicle described in a claim or a sales listing matches the official record, and to spot a listing where the details do not add up.
11. Threat Intelligence
What it does: Checks IP addresses and domains for reputation signals.
This is for security teams. Threat Intelligence Modules check whether an IP address or domain appears on reputation and blocklist sources. If a domain sending invoices to your finance team has a poor reputation history, that is a strong reason to pause and verify before a payment is made.
12. Cyber Intelligence and IP Intelligence
What it does: Shodan Modules for internet-facing services, plus IP ownership and network details.
Cyber Intelligence uses Shodan Modules to show which services are open on an internet-facing host, such as 203.0.113.10. IP Intelligence adds who operates the network and where it is registered. Together they help a security team understand an organisation's internet-facing estate, or check whether a dubious website shares hosting with other sites.
13. Wireless Device
What it does: Searches WiGLE data for Wi-Fi network names and identifiers.
Every Wi-Fi access point broadcasts a network name (SSID) and an identifier (BSSID). Community wardriving projects such as WiGLE map where these networks have been observed. A practical business use: checking whether a guest network named after a company has been recorded near the premises the company says it operates from. It is a supporting signal for due diligence, not proof on its own, and the data can be years old. Our wireless OSINT guide explains the limits.
14. Domain Intelligence
What it does: Covers domain ownership, history and favicon matching.
Who operates a website? Domain ownership records give you current and historic registration data where it is published. Website history, drawing on archives such as the Wayback Machine, lets you see how a site looked years ago. Favicon search is an overlooked gem: it finds other websites that use the exact same favicon image, which often reveals a network of copycat sites run by the same group. See our domain and WHOIS guide for the manual method.
15. SargeBot: The AI Research Assistant
What it does: Helps you plan and run searches, and can generate a PDF report.
SargeBot is the AI research assistant inside the platform. You choose the AI model (Claude, GPT or Grok), set a lawful objective, and it helps you build entity searches and pull results into a PDF report. Treat its output like any other lead: you are responsible for verifying it before it goes into a finding.
2.5 Execution: Running Your First Piece of Research
Let us put these Search types together. We will walk through two common beginner scenarios: researching a handle linked to a dubious online scheme, and establishing which organisation sits behind an email address.
Walkthrough 1: Researching a Handle Promoting a Dubious Scheme
Context: You work in the brand protection team at Harrowgate Mutual, a fictional building society. Customers have reported a forum account, CryptoKing_88, promoting an "investment club" that uses the society's name and logo.
Step 1: Choose the Module
Open a new Case in Forensic Mode. Select Username Intelligence as the Search type and choose a username Module, or a Username OneScan if you want several sources at once. Check the Credit cost shown before you run it.
Step 2: Run the search
Enter CryptoKing_88 and run the search.
Step 3: Triage the results
You might see dozens of hits. Filter by category to focus. Example: hits on a gaming platform and a crypto forum, plus a Telegram channel with the same name. The crypto forum account links to harrowgate-club.example.com, a site the society does not own.
Step 4: Bookmark
Bookmark the results that matter. In Forensic Mode they are saved to your Case with your search history. Capture the forum page and the copycat site with Forensic Capture so you have timestamped, SHA-256-fingerprinted copies.
Outcome: The team now has a documented set of accounts and one domain using the society's brand, which it can pass to its legal team and to the relevant platforms for takedown.
Walkthrough 2: From an Email Address to the Organisation Behind It
Context: The copycat site lists a contact address, [email protected]. The team wants to know which organisation operates the site.
Step 1: Email Intelligence
Run the address through an Email Intelligence Module. It is registered on a payment platform and a business networking site, which suggests it is used for commercial activity rather than a one-off sign-up.
Step 2: Domain Intelligence
Switch to Domain Intelligence and run example.com. Registration history shows the domain moved to a new registrar six months ago. A favicon search returns two more sites using the same icon, both promoting similar "clubs" with other lenders' names.
Step 3: Corporate Intelligence
One of the sister sites names a limited company in its footer. A Corporate Intelligence search shows the company was incorporated recently and has a single officer who is also appointed to a dissolved company with a similar name.
Outcome: Harrowgate Mutual's report now shows three connected domains, one registered company and a clear chain of evidence from the original forum account. The findings are corroborated across independent sources and ready for the legal team.
2.6 Advanced Strategies and Visualisation
Experienced analysts do not just read lists; they look at connections. The Graph view helps you make sense of a large set of results.
Working With the Graph
Step 1: Open the Graph
After running your searches, open the results panel and switch to the Graph tab.
Step 2: Read the nodes
Your search term sits in the centre. Connected to it are the results you found (websites, handles, email addresses). Items connected to each other, such as the same handle on two different sites, are highlighted, and bookmarked items are marked so you can see what you have already saved.
Step 3: Expand the network
Select a node (for example, the email address you found) and search on it. The new results join the graph, expanding it outward. This is how you map a network of connected accounts, domains and companies step by step.
Common Mistakes (and How to Avoid Them)
- The common-name problem
Mistake: Searching a common company or brand name without narrowing it.
Fix: Add secondary selectors. Pair the name with a registration number, a domain or a country, and use the filters in each Module to narrow by country or category. - Ignoring false positives
Mistake: Assuming every result belongs to the entity under review.
Fix: Corroborate. The same handle on two sites does not mean the same operator. Look for a matching bio, link, avatar or contact detail before you connect them. - Visiting live sites carelessly
Mistake: Clicking through to a live account page while signed in to your own personal accounts.
Fix: Review results inside the platform first. If you must visit the live page, use a dedicated research browser set up under your organisation's policy, and capture what you see with Forensic Capture so you do not need to go back.
2.7 Legal and Ethical Guardrails
Good tools need good governance. The fact that data is public does not, on its own, justify collecting it.
- Authorised research only: Use these techniques for security research, authorised due diligence and compliance work, brand protection or journalism in the public interest. Write down your purpose before you start, and keep your searches proportionate to it.
- Data protection: When your research touches personal data, the UK GDPR and EU GDPR still apply. Collect only what your purpose needs, and use Private mode for quick checks where you do not need to keep a search history.
- Record keeping: If your work may support a legal matter or a formal report, use Forensic Mode so your search history and bookmarks are stored in the Case, and capture key pages with Forensic Capture for timestamped evidence.
- Verify before you rely: Results are leads to corroborate, not facts. Coverage and freshness depend on each third-party source.
2.8 Your Next Step: Run Your First Case
The era of manual OSINT, opening fifty tabs and copying data into a spreadsheet, is ending. A structured platform lets you research faster and more consistently, and it lets you spend your time on the analysis rather than the collection.
Whether you are checking where a handle appears across thousands of sites or connecting a crypto wallet to the websites that promote it, UserSearch puts 100+ third-party data sources behind one account, with OneScan to query several at once, Cases to keep your work in order and reports to share what you found.
Stop guessing. Start researching with UserSearch at usersearch.com.