User-Scanner Command-Line Options: Complete OSINT Flag Reference
The user-scanner CLI from kaifcodec provides over 20 command-line flags for target selection, reconnaissance depth, and output formatting, all parsed in user_scanner/__main__.py and orchestrated through the modular core engine.
The kaifcodec/user-scanner repository is a powerful OSINT tool designed for automated username and email investigations across digital platforms. Mastering the user-scanner command-line options enables security researchers to execute precise reconnaissance workflows while controlling proxy rotation, concurrency limits, and cross-platform pivoting behaviors. All supported flags are cataloged in docs/FLAGS.md and implemented across the user_scanner/core/ package.
Target Selection Options
The CLI supports four mutually exclusive input methods defined in the argument parser within user_scanner/__main__.py.
Single Target Scanning
Use -u, --username USERNAME to scan a single username across every supported platform, or -e, --email EMAIL to investigate a single email address. These flags dispatch to core/orchestrator.py and core/email_orchestrator.py respectively.
Bulk Target Scanning
For scale, use -uf, --username-file FILE or -ef, --email-file FILE to ingest newline-delimited lists. The orchestrators iterate through each entry, applying the same network and filtering options to every target.
Scanning Control and Cross-Platform Pivoting
Advanced reconnaissance is handled by the cross-scan engine in core/cross_scan.py, which enables automated pivoting from discovered data.
Behavioral Flags
--allow-loudenables sites that may trigger email notifications or security alerts during scanning.--no-nsfwexcludes adult-rated platforms from the scan scope.--hudsonor--hudson-scanqueries the Hudson Rock breach-intelligence API for compromised credential data.
Cross-Scan Configuration
The --cross-scan flag initiates recursive investigation, following discovered usernames, links, and emails for additional leads. This is controlled by several parameters:
--cross-links {all,verified,none}determines which hyperlinks trigger pivoting (default:all).--cross-emails {all,verified,none}filters which email addresses are pursued (default:verified).--cross-depth Nsets the number of recursive follow rounds (default:1).--cross-sweep Ndefines sweep passes across modules (default:3, where0disables sweeping).
Scope and Module Filtering
Restrict execution to specific data sources or generate target variations using the scope flags.
-c, --category CATEGORYlimits the scan to specific platform categories, accepting comma-separated values.-m, --module MODULEruns only specified modules, useful for targeted investigations against single platforms.-p, --permute PERMUTEgenerates username permutations based on patterns or suffixes before scanning.-s, --stop STOPcaps the number of generated permutations to prevent combinatorial explosion.
Network Configuration and Performance Tuning
The async engine in core/engine.py handles all HTTP concurrency, respecting the following flags:
-P, --proxy-file FILEloads a list of proxies (one per line) for request rotation.--validate-proxiestests each proxy againstgoogle.combefore scanning begins, filtering out dead routes.-d, --delay DELAYinserts a sleep interval (in seconds) between HTTP requests to avoid rate limiting.-t, --timeout TIMEOUToverrides the default request timeout value.-C, --concurrency CONCadjusts the maximum concurrent worker count processed by the engine.
Output Formats and Reporting
Results are aggregated into Result objects defined in core/result.py and formatted according to these options:
-f, --format {csv,json,pdf}selects the output serialization format.-o, --output OUTPUTwrites results to a file path, inferring format from the extension if-fis omitted.-v, --verbosedisplays detailed request URLs and real-time progress indicators.--allincludes negative results ("Not Found"), errors, and skipped entries in the final report.
Maintenance and Version Control
System-level flags are handled by core/version.py and the entry point dispatcher:
-U, --updatepulls and installs the latest released version from the repository.--versionprints the current installed version string.
Practical Usage Examples
Execute single-target investigations with custom timeouts:
user-scanner -u johndoe -t 30
user-scanner -e admin@example.com --no-nsfw
Process bulk lists with proxy validation and increased concurrency:
user-scanner -uf usernames.txt -P proxies.txt --validate-proxies -C 20
user-scanner -ef emails.txt -f json -o bulk_results.json
Enable recursive cross-scanning with verified-link pivoting and depth limiting:
user-scanner -u alice --cross-scan --cross-depth 2 \
--cross-links verified --cross-emails verified --verbose
Generate permutations and export as PDF:
user-scanner -u bob -p "_{year}" -s 100 -f pdf -o bob_report.pdf
Show complete results including negative findings:
user-scanner -e charlie@example.com --all -f csv -o full_scan.csv
Summary
- user-scanner accepts usernames via
-u/--usernameand emails via-e/--email, with bulk file inputs supported via-ufand-ef. - The cross-scan engine (
core/cross_scan.py) enables recursive pivoting through--cross-scan, controlled by depth, link quality, and sweep parameters. - Network behavior is managed through proxy files (
-P), validation (--validate-proxies), delays (-d), and concurrency limits (-C) handled bycore/engine.py. - Output formats include CSV, JSON, and PDF, configured via
-fand-o, with verbose (-v) and complete (--all) reporting modes available. - All arguments are parsed in
user_scanner/__main__.pyand dispatched to specialized orchestrators that coordinate module execution and result aggregation.
Frequently Asked Questions
How do I scan multiple usernames at once with user-scanner?
Use the -uf, --username-file FILE flag to specify a text file containing one username per line. The orchestrator in core/orchestrator.py processes each entry sequentially while applying your selected network and filtering options uniformly across the batch.
What is the difference between --cross-scan and --cross-links?
--cross-scan activates the recursive pivoting engine defined in core/cross_scan.py, enabling the tool to follow discovered entities for additional scans. --cross-links is a sub-parameter that filters which discovered hyperlinks qualify for pivoting, accepting all, verified, or none to control signal quality during recursion.
How does user-scanner handle proxy validation?
When --validate-proxies is provided alongside -P, --proxy-file, the engine tests each proxy against google.com before initiating the scan. Only responsive proxies are retained, ensuring that the concurrency pool in core/engine.py contains valid exit nodes before OSINT requests begin.
Where are the command-line arguments parsed in the source code?
Argument parsing occurs in user_scanner/__main__.py, which instantiates the CLI parser and dispatches to core/orchestrator.py for username targets or core/email_orchestrator.py for email targets. The canonical reference for all flags is maintained in docs/FLAGS.md.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →