daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

people-search.md (44796B)


      1 ---
      2 title: "People Search & Public Records"
      3 description: "Registries, court records, aggregators and breach data for identifying a person and the records that mention them."
      4 category: osint
      5 subcategory: "People & Identity"
      6 tags: [osint, people, public-records, breach-data]
      7 tools: [hibp, intelx, aleph, alephclient, courtlistener, opensanctions, yente, edgar, ratsit, hitta]
      8 difficulty: intermediate
      9 updated: 2026-10-04
     10 references:
     11   - name: "Bellingcat's Online Investigation Toolkit"
     12     url: "https://bellingcat.gitbook.io/toolkit"
     13     author: "Bellingcat"
     14     license: none
     15     relation: derived
     16     note: "Tool catalogue: names, descriptions, cost flags and links for this area."
     17   - name: "OSINT Newsletter Tools Library"
     18     url: "https://tools.osintnewsletter.com"
     19     author: "The OSINT Newsletter"
     20     license: none
     21     relation: derived
     22     note: "Second tool catalogue, cross-checked against the above."
     23   - name: "Have I Been Pwned API v3"
     24     url: "https://haveibeenpwned.com/API/v3"
     25     author: "Troy Hunt"
     26     relation: link-only
     27     note: "Endpoint paths, required headers and rate-limit behaviour."
     28   - name: "Intelligence X SDK (Python)"
     29     url: "https://github.com/IntelligenceX/SDK/tree/master/Python"
     30     author: "Kleissner Investments"
     31     relation: link-only
     32     note: "CLI flags, API endpoint paths and the sort/media enumerations."
     33   - name: "alephclient documentation"
     34     url: "https://docs.aleph.occrp.org/developers/alephclient/"
     35     author: "OCCRP"
     36     relation: link-only
     37     note: "alephclient subcommands and the ALEPHCLIENT_* environment variables."
     38   - name: "CourtListener REST API v4"
     39     url: "https://wiki.free.law/c/courtlistener/help/api/rest/v4/overview"
     40     author: "Free Law Project"
     41     relation: link-only
     42     note: "Endpoint paths, search type values, throttles and the OPTIONS convention."
     43   - name: "OpenSanctions API reference"
     44     url: "https://api.opensanctions.org/openapi.json"
     45     author: "OpenSanctions"
     46     relation: link-only
     47     note: "Scope paths and query parameters for search, match and statements."
     48   - name: "yente"
     49     url: "https://github.com/opensanctions/yente"
     50     author: "OpenSanctions"
     51     relation: link-only
     52     note: "Self-hosted matching engine: image, port and YENTE_* environment variables."
     53 ---
     54 
     55 ## What this covers
     56 
     57 Finding the records that name a person: civil registries, corporate filings, court dockets,
     58 electoral rolls, phone books, and the commercial aggregators that resell all of it. Coverage is
     59 wildly uneven by country, and the aggregators are frequently wrong, so this is an area where
     60 knowing which source is authoritative matters more than knowing many sources.
     61 
     62 ## Method
     63 
     64 1. **Start with the authoritative registry**, not an aggregator. If a country publishes its company
     65    register or land registry, use it — the aggregator is a stale copy with errors added.
     66 2. **Establish the jurisdiction first.** People-search coverage is national. A US-focused
     67    aggregator has close to nothing on a Swedish resident, and Nordic registries are far more open
     68    than most.
     69 3. **Cross-reference two independent sources** before accepting an address, date of birth or
     70    relationship. Aggregators copy each other, so two of them agreeing means nothing.
     71 4. **Pivot through documents.** A court filing names an address, an employer and often relatives.
     72    One good document beats twenty aggregator hits.
     73 5. **Treat breach data as intelligence, not evidence.** It tells you an email existed on a service
     74    at some point. It does not tell you who typed it in.
     75 
     76 ## Regional registries worth knowing
     77 
     78 Nordic countries publish personal data that is closed almost everywhere else, which makes them
     79 unusually productive:
     80 
     81 - **Sweden** — [Ratsit](https://www.ratsit.se/), [Hitta.se](https://www.hitta.se/), and the
     82   Swedish Name Register give addresses, income brackets and dates of birth.
     83 - **Norway / Finland / Denmark** — equivalents exist; tax records are partly public in Norway.
     84 - **Nigeria** — NigeriaPhonebook for telephone-to-name lookups.
     85 - **United States** — county-level court and property records are the real source; national
     86   aggregators are convenience layers over them.
     87   [Search Systems](https://www.searchsystems.net/) is a directory of the underlying databases,
     88   organised by state and record type.
     89 
     90 None of these publish an API. They do take their search term in the query string, which is worth
     91 knowing because it means a registry lookup can be scripted into a browser or a note template
     92 rather than retyped:
     93 
     94 ```text
     95 https://www.hitta.se/sök?vad=Anna+Andersson        name or address; returns people and companies
     96 https://www.hitta.se/sök?vad=08-555+012+34         reverse telephone, same parameter
     97 ```
     98 
     99 The `vad` parameter is the only one you need; the rest of the query string the site adds is UI
    100 state. Note that the path segment is the Swedish word `sök`, so it percent-encodes to
    101 `s%C3%B6k` when you paste it into `curl` — a shell that mangles the UTF-8 is the usual reason a
    102 hand-built Hitta URL 404s. Ratsit and the US brokers sit behind bot protection that returns 403
    103 to anything without a browser fingerprint, so for those, drive the search box rather than the
    104 URL.
    105 
    106 ## Key tools
    107 
    108 ### Have I Been Pwned
    109 
    110 The reference for which breach corpora hold an address, and the only tool in this area with a
    111 stable documented API. Account lookups sit behind a paid key now — the cheapest tier is a few
    112 dollars a month — while the breach catalogue and the password range endpoint stay free and need
    113 no key at all.
    114 
    115 The keyless half, which is where to start because it costs nothing and tells you what the corpus
    116 even is:
    117 
    118 ```bash
    119 # the breach catalogue: free, no key, useful for dating a corpus
    120 curl -s -H 'user-agent: osint-research' 'https://haveibeenpwned.com/api/v3/breaches' \
    121   | jq -r '.[].Name' | head
    122 
    123 # one breach in detail — when it happened, how big, what fields leaked
    124 curl -s -H 'user-agent: osint-research' 'https://haveibeenpwned.com/api/v3/breach/Adobe' \
    125   | jq '{BreachDate,AddedDate,PwnCount,IsVerified,DataClasses}'
    126 
    127 # which breaches carried the field you actually care about, sorted oldest first
    128 curl -s -H 'user-agent: osint-research' 'https://haveibeenpwned.com/api/v3/breaches' \
    129   | jq -r '[.[] | select(.DataClasses | index("Physical addresses"))]
    130            | sort_by(.BreachDate)[] | "\(.BreachDate)  \(.PwnCount)  \(.Name)"'
    131 
    132 # every breach attributed to one domain — the pivot when you know the employer, not the person
    133 curl -s -H 'user-agent: osint-research' 'https://haveibeenpwned.com/api/v3/breaches?Domain=adobe.com'
    134 
    135 # the field vocabulary, so a report says "Physical addresses" and not "address data"
    136 curl -s -H 'user-agent: osint-research' 'https://haveibeenpwned.com/api/v3/dataClasses' | jq -r '.[]'
    137 
    138 # what was added most recently, for deciding whether a re-run is worth the quota
    139 curl -s -H 'user-agent: osint-research' 'https://haveibeenpwned.com/api/v3/latestBreach' \
    140   | jq '{Name,AddedDate}'
    141 ```
    142 
    143 Then the keyed half. `user-agent` is mandatory on every call and `hibp-api-key` on everything
    144 that names an account:
    145 
    146 ```bash
    147 # confirm which tier the key actually buys before you plan a run around it
    148 curl -s 'https://haveibeenpwned.com/api/v3/subscription/status' \
    149   -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' \
    150   | jq '{SubscriptionName,Rpm,DomainSearchMaxBreachedAccounts}'
    151 
    152 # which breaches hold this address; truncateResponse=false is what gets you the dates
    153 curl -s 'https://haveibeenpwned.com/api/v3/breachedAccount/target@example.com?truncateResponse=false' \
    154   -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' \
    155   | jq -r '.[] | "\(.BreachDate)  \(.Name)"'
    156 
    157 # include unverified corpora — more hits, weaker provenance, so record the flag you used
    158 curl -s 'https://haveibeenpwned.com/api/v3/breachedAccount/target@example.com?truncateResponse=false&IncludeUnverified=true' \
    159   -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' | jq 'length'
    160 
    161 # k-anonymity account search: the address never leaves your machine, only six hex characters do
    162 H=$(printf 'target@example.com' | shasum -a 1 | cut -c1-40 | tr 'a-f' 'A-F')
    163 curl -s "https://haveibeenpwned.com/api/v3/breachedaccount/range/${H:0:6}" \
    164   -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' \
    165   | jq -r --arg suffix "${H:6}" '.[] | select(.hashSuffix == $suffix) | .websites[]'
    166 
    167 # paste sites that carried the address, which often predate the breach being named
    168 curl -s 'https://haveibeenpwned.com/api/v3/pasteAccount/target@example.com' \
    169   -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research'
    170 
    171 # every breached address under a domain you have proven you control
    172 curl -s 'https://haveibeenpwned.com/api/v3/breachedDomain/example.com' \
    173   -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research'
    174 
    175 # which domains you have actually verified, when a run comes back suspiciously empty
    176 curl -s 'https://haveibeenpwned.com/api/v3/subscribedDomains' \
    177   -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' | jq -r '.[].DomainName'
    178 
    179 # stealer-log hits — infostealer output, so far more recent than breach corpora
    180 curl -s 'https://haveibeenpwned.com/api/v3/stealerLogsByEmail/target@example.com' \
    181   -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research'
    182 
    183 # the same, across a verified domain: which of your subject's colleagues ran malware
    184 curl -s 'https://haveibeenpwned.com/api/v3/stealerLogsByEmailDomain/example.com' \
    185   -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research'
    186 
    187 # which sites a stealer-infected machine had credentials for — a browsing-history proxy
    188 curl -s 'https://haveibeenpwned.com/api/v3/stealerLogsByWebsiteDomain/example.com' \
    189   -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research'
    190 ```
    191 
    192 The password range endpoint needs no key, is not rate limited, and never sees the password:
    193 
    194 ```bash
    195 # only the first five SHA-1 characters leave your machine
    196 printf 'hunter2' | shasum -a 1 | tr 'a-f' 'A-F' | cut -c1-5 \
    197   | xargs -I{} curl -s "https://api.pwnedpasswords.com/range/{}" | head -3
    198 
    199 # pad the response with dummy rows so its size tells an observer nothing about the
    200 # prefix; padded rows always carry a count of 0, so discard them before reading
    201 curl -s -H 'Add-Padding: true' 'https://api.pwnedpasswords.com/range/5BAA6' \
    202   | awk -F: '$2 != 0' | head -3
    203 
    204 # NTLM suffixes instead of SHA-1, for checking a dumped AD hash against the corpus.
    205 # NTLM suffixes are 27 characters where SHA-1 suffixes are 35 — a length mismatch
    206 # when you diff against a local list means you queried the wrong mode
    207 curl -s 'https://api.pwnedpasswords.com/range/8846F?mode=ntlm' | head -3
    208 ```
    209 
    210 The k-anonymity account endpoint is the one worth building a habit around: it sends six hex
    211 characters of a SHA-1 and matches the remaining suffix locally, so the address you are
    212 investigating is never transmitted. The response carries `hashSuffix` and `websites` — not
    213 `breaches`, which is the field name people assume and then silently get `null` from.
    214 
    215 Omitting `user-agent` returns 403 rather than a useful error. `breachedAccount` truncates by
    216 default, returning only breach names — if your output has no dates in it, you forgot
    217 `truncateResponse=false`, and a report built on that output cannot say when anything happened. A
    218 429 carries a `retry-after` header in seconds; honour it, because the limit is per key and
    219 hammering it gets the key suspended. And the output tells you a corpus containing that address
    220 was published — not that your subject created the account, not that they still use the address,
    221 and not what the password was.
    222 
    223 ### Intelligence X
    224 
    225 Web-first, and the broadest selector search available without a corporate contract: it indexes
    226 leaks, darknet pages, document dumps and its own historical web crawl, and it searches by
    227 selector type rather than free text. Reach for it when an identifier returns nothing elsewhere.
    228 
    229 Paste the selector at [intelx.io](https://intelx.io/) and read the result pane by bucket — the
    230 left-hand facets split hits into leaks, darknet, web and documents, and the bucket matters more
    231 than the hit count. Selectors it understands:
    232 
    233 ```text
    234 target@example.com          email address
    235 example.com                 domain, including subdomain hits
    236 198.51.100.0/24             CIDR range
    237 +14155550123                phone number, E.164
    238 1BoatSLRHtKNngkdXEeobR76b53LETtpyT   cryptocurrency address
    239 d41d8cd98f00b204e9800998ecf8427e     hash or document selector
    240 ```
    241 
    242 For the record, capture the item's **date added** and its bucket, not just the snippet —
    243 Intelligence X keeps items long after the source is gone, so the snippet alone cannot be re-verified. The API
    244 takes the key from the developer tab of your account in an `x-key` header; phonebook (bulk
    245 selector extraction) and most export volume are paid tiers, and the free tier is metered tightly
    246 enough that you will feel it inside an hour.
    247 
    248 ### OCCRP Aleph and Library of Leaks
    249 
    250 Aleph is a document-and-entity index built for cross-border corruption work: leaked archives,
    251 scraped registries, sanctions lists and court filings normalised into one searchable entity
    252 graph. It beats a people-search aggregator whenever the subject appears in documents rather than
    253 directories. [Library of Leaks](https://search.libraryofleaks.org/) is the same software over a
    254 different, leak-heavy corpus.
    255 
    256 ```bash
    257 pipx install alephclient
    258 
    259 # register free, then take the key from your Aleph user profile — anonymous API calls get a 401
    260 export ALEPHCLIENT_HOST=https://aleph.occrp.org
    261 export ALEPHCLIENT_API_KEY=REPLACE_ME
    262 
    263 # people matching a name, across every dataset you can read
    264 curl -s -G 'https://aleph.occrp.org/api/2/entities' \
    265   -H "Authorization: ApiKey $ALEPHCLIENT_API_KEY" \
    266   --data-urlencode 'q=Sergei Ivanov' --data-urlencode 'filter:schema=Person' \
    267   | jq -r '.results[] | "\(.properties.name[0])  \(.collection.label)"'
    268 
    269 # companies instead of people — the usual pivot off a director's name
    270 curl -s -G 'https://aleph.occrp.org/api/2/entities' \
    271   -H "Authorization: ApiKey $ALEPHCLIENT_API_KEY" \
    272   --data-urlencode 'q=Sergei Ivanov' --data-urlencode 'filter:schema=Company' | jq '.total'
    273 
    274 # which datasets exist, so you can say what you did and did not search
    275 curl -s 'https://aleph.occrp.org/api/2/collections?limit=50' \
    276   -H "Authorization: ApiKey $ALEPHCLIENT_API_KEY" \
    277   | jq -r '.results[] | "\(.foreign_id)  \(.label)"'
    278 
    279 # one entity in full, including the documents it was extracted from
    280 curl -s 'https://aleph.occrp.org/api/2/entities/ENTITY_ID' \
    281   -H "Authorization: ApiKey $ALEPHCLIENT_API_KEY" | jq '.properties'
    282 
    283 # push your own case documents in so they are indexed alongside the public corpora
    284 alephclient crawldir --foreign-id my-case-2026 ./case-documents
    285 ```
    286 
    287 Names in Aleph are transliterated inconsistently because the sources are, so run the variants
    288 from [username and account work](/sheets/osint/usernames-and-accounts) before concluding a name
    289 is absent. An entity is an extraction from a document, which means both the spelling and the
    290 role can be wrong; open the source document before you cite it. Uploading case documents sends
    291 them to someone else's server — check that is acceptable for your material first.
    292 
    293 ### CourtListener and RECAP
    294 
    295 Free, keyless-to-browse access to US federal dockets, opinions and PACER filings that other
    296 researchers have paid for and donated. For a US subject this is the best single documentary
    297 source on this page, because a filing names addresses, employers, counsel and relatives in one
    298 place.
    299 
    300 ```bash
    301 # token from your free account profile; note the literal word "Token"
    302 export CL_TOKEN=REPLACE_ME
    303 
    304 # federal dockets mentioning a name (type=r gives dockets with nested documents)
    305 curl -s -G 'https://www.courtlistener.com/api/rest/v4/search/' \
    306   -H "Authorization: Token $CL_TOKEN" \
    307   --data-urlencode 'q="Dana Whitfield"' --data-urlencode 'type=r' \
    308   | jq -r '.results[] | "\(.dateFiled)  \(.court)  \(.caseName)"'
    309 
    310 # case law opinions instead of dockets
    311 curl -s -G 'https://www.courtlistener.com/api/rest/v4/search/' \
    312   -H "Authorization: Token $CL_TOKEN" \
    313   --data-urlencode 'q="Dana Whitfield"' --data-urlencode 'type=o' | jq '.count'
    314 
    315 # narrow to one court and a date window
    316 curl -s -G 'https://www.courtlistener.com/api/rest/v4/search/' \
    317   -H "Authorization: Token $CL_TOKEN" \
    318   --data-urlencode 'q=Whitfield' --data-urlencode 'type=d' \
    319   --data-urlencode 'court=txwd' --data-urlencode 'filed_after=2020-01-01'
    320 
    321 # judges, for checking who heard a case
    322 curl -s -G 'https://www.courtlistener.com/api/rest/v4/search/' \
    323   -H "Authorization: Token $CL_TOKEN" \
    324   --data-urlencode 'q=Whitfield' --data-urlencode 'type=p'
    325 
    326 # the docket itself, including the parties
    327 curl -s 'https://www.courtlistener.com/api/rest/v4/dockets/?id=12345' \
    328   -H "Authorization: Token $CL_TOKEN" | jq '.results[0] | {case_name,date_filed,assigned_to_str}'
    329 
    330 # page with the cursor the previous response handed back, not an offset
    331 curl -s -G 'https://www.courtlistener.com/api/rest/v4/search/' \
    332   -H "Authorization: Token $CL_TOKEN" \
    333   --data-urlencode 'q=Whitfield' --data-urlencode 'type=r' --data-urlencode 'cursor=CURSOR'
    334 ```
    335 
    336 RECAP holds what somebody has already fetched from PACER, so absence means nobody bought that
    337 document, not that the case does not exist — check PACER's own index before saying there is no
    338 case. Search results are cached for ten minutes, so polling for new filings wastes your quota;
    339 use the Alert API for monitoring. State courts are mostly absent, which is where most US
    340 litigation actually happens.
    341 
    342 ### OpenSanctions
    343 
    344 Sanctions lists, politically-exposed-person data and criminal watchlists, merged and deduplicated
    345 into one entity model with a matching API. Use it to answer "is this person on a list" properly,
    346 rather than eyeballing a dozen national PDFs — and to record a clean negative.
    347 
    348 ```bash
    349 export OS_KEY=REPLACE_ME
    350 
    351 # full-text search, for when you only have a name
    352 curl -s -G 'https://api.opensanctions.org/search/default' \
    353   -H "Authorization: ApiKey $OS_KEY" --data-urlencode 'q=Sergei Ivanov' \
    354   | jq -r '.results[] | "\(.caption)  \(.schema)  \(.datasets|join(","))"'
    355 
    356 # proper screening: describe the entity and let the matcher score candidates
    357 curl -s -X POST 'https://api.opensanctions.org/match/default' \
    358   -H "Authorization: ApiKey $OS_KEY" -H 'Content-Type: application/json' \
    359   -d '{"queries":{"q1":{"schema":"Person","properties":{"name":["Sergei Ivanov"],"birthDate":["1965"],"country":["ru"]}}}}' \
    360   | jq -r '.responses.q1.results[] | "\(.score)  \(.caption)  \(.datasets|join(","))"'
    361 
    362 # one entity in full, with every list that carries it and why
    363 curl -s 'https://api.opensanctions.org/entities/NK-A7z1Z' \
    364   -H "Authorization: ApiKey $OS_KEY" | jq '{caption,datasets,properties}'
    365 
    366 # which lists are in the index, so your negative result has a defined scope
    367 curl -s 'https://api.opensanctions.org/catalog' | jq -r '.datasets[].name' | head -30
    368 ```
    369 
    370 A date of birth or a country code moves the score far more than extra name tokens; a bare name
    371 query on a common name returns confident nonsense. The score is a similarity, not a finding —
    372 anything you publish needs the underlying list entry read by a human. Trial keys come free with
    373 a business email and public-interest keys are granted for journalism and research; if the metering
    374 gets in the way, the matching engine (`yente`) is open source and self-hostable against the same
    375 free bulk data.
    376 
    377 ### EDGAR full-text search
    378 
    379 Free, keyless, and routinely forgotten in people work: every SEC filing since 2001 is full-text
    380 searchable, and filings name directors, officers and beneficial owners with addresses. A
    381 Form D or a proxy statement is a dated, signed document naming a person — which is exactly the
    382 kind of source an aggregator hit is not.
    383 
    384 ```bash
    385 # the SEC requires a descriptive User-Agent with contact details; without one you get blocked
    386 UA='osint-research research@example.com'
    387 
    388 # every filing mentioning a name
    389 curl -s -A "$UA" 'https://efts.sec.gov/LATEST/search-index?q=%22Dana+Whitfield%22' \
    390   | jq -r '.hits.hits[] | "\(._source.file_date)  \(._source.display_names[0])"'
    391 
    392 # restrict to a form type — Form D names the directors of a private placement
    393 curl -s -A "$UA" 'https://efts.sec.gov/LATEST/search-index?q=%22Dana+Whitfield%22&forms=D'
    394 
    395 # date-bounded, which is how you tie a person to a company in a given year
    396 curl -s -A "$UA" \
    397   'https://efts.sec.gov/LATEST/search-index?q=%22Dana+Whitfield%22&dateRange=custom&startdt=2019-01-01&enddt=2021-12-31'
    398 
    399 # every filing by one company, from its CIK
    400 curl -s -A "$UA" 'https://data.sec.gov/submissions/CIK0000320193.json' \
    401   | jq '{name,addresses,formerNames}'
    402 ```
    403 
    404 The browsable version is at [sec.gov/edgar/search](https://www.sec.gov/edgar/search/), and it is
    405 the right place to read a hit. Full-text coverage starts in 2001; older filings are indexed by
    406 company but not searchable by content. A name in a filing is the name as filed, so middle
    407 initials and suffixes are inconsistent across years.
    408 
    409 ### Ratsit
    410 
    411 Web only, Sweden only, and far more revealing than anything equivalent elsewhere: registered
    412 address, year and month of birth, income bracket, property and vehicle flags, and who else is
    413 registered at the address. Swedish population-register data is public, so this is a legitimate
    414 primary source rather than a broker's guess.
    415 
    416 Search the name at [ratsit.se](https://www.ratsit.se/), narrow by county when the name is common,
    417 and read the profile page. For the record, capture these fields and nothing inferred from them:
    418 
    419 ```text
    420 Folkbokförd adress    registered address, i.e. where the state believes they live
    421 Född                  birth year and month (day is withheld on the free view)
    422 Inkomst / Taxeringsår income bracket AND the assessment year it belongs to
    423 Fordon / Fastighet    vehicle and property flags, each a pointer to another register
    424 Personer på adressen  others registered at the same address — household, not family
    425 ```
    426 
    427 The income figure is always a year or two behind and is meaningless without the assessment year
    428 printed beside it.
    429 
    430 **Search logged out.** Ratsit sells subjects a paid feature listing the logged-in users who
    431 looked them up; anonymous searches leave no entry in that log. Mrkoll, the nearest competitor,
    432 shows subjects a profile-view count but not identities. Either way, an account turns a passive
    433 lookup into something the subject can notice.
    434 
    435 ### US people-search aggregators
    436 
    437 [FastPeopleSearch](https://www.fastpeoplesearch.com/), [That's Them](https://thatsthem.com/) and
    438 [Radaris](https://radaris.com/) are free, web only, and the fastest route to a candidate address
    439 and phone for a US subject. They are also data brokers reselling scraped and purchased records of
    440 unknown age.
    441 
    442 Enter the name plus a city or state — a bare name on a common surname is unusable. Read the
    443 result page as three separate claims with separate reliability: current address, phone numbers,
    444 and "possible relatives". The first two are checkable against a county property or voter record;
    445 the third is inference from shared addresses and surnames and is wrong often enough that
    446 repeating it is reckless.
    447 
    448 ```text
    449 Dana Whitfield Austin TX        name + city: the only query form that works
    450 Dana Whitfield 78701            name + ZIP, when the city name is ambiguous
    451 (512) 555-0123                  reverse phone, usually the highest-precision entry point
    452 1200 Example St, Austin TX      reverse address, to enumerate the household
    453 ```
    454 
    455 Capture the page with an archiving tool, because broker pages change without notice — see
    456 [archiving and evidence](/sheets/osint/archiving-and-evidence).
    457 
    458 These sites are also the mechanism by which your subject's data is public in the first place; most
    459 carry an opt-out form, and a subject who has used it will be absent from the broker while still
    460 present in the underlying county record. Absence here means nothing.
    461 
    462 ### Pipl
    463 
    464 **Sales-gated since its pivot to enterprise identity resolution.** There is no self-serve tier,
    465 no web search for individuals, and contracts start in the thousands of dollars a year. Treat the
    466 Pipl entry in the table below as historical. For the same job without a contract, the live
    467 options are the registry-first route above, Intelligence X for selector search, and OSINT
    468 Industries or Osintly if you need a commercial aggregator with per-query pricing.
    469 
    470 ## Breach and leak data
    471 
    472 Useful for confirming that an identifier was in use, and for pivoting between an email, a username
    473 and a phone number. Handle carefully: this is other people's stolen data.
    474 
    475 | Tool | What it does | Cost |
    476 | --- | --- | --- |
    477 | [Have I Been Pwned](https://haveibeenpwned.com/) | Authoritative check for whether an address appears in a known breach. Does not expose passwords. | free |
    478 | [DeHashed](https://dehashed.com/) | Searchable breach aggregator across emails, usernames, names, phones and IPs. | partly free |
    479 | [Intelligence X](https://intelx.io/) | Searches leaks, darknet, document archives and historical web by selector. | partly free |
    480 | [Leak-Lookup](https://leak-lookup.com/) | Breach index with API access. | partly free |
    481 | [DiscordLeaks](https://discordleaks.unicornriot.ninja/) | Searchable archive of leaked far-right Discord servers, maintained by Unicorn Riot. | free |
    482 
    483 Do not put a live target's credentials into a third-party lookup you do not control, and do not
    484 treat a password from a breach as authorisation to use it.
    485 
    486 DeHashed is the one worth a note on access: it is credit-metered now, and the old
    487 basic-auth `api.dehashed.com/search?query=` endpoint that circulates in every scripted wrapper is
    488 retired. The current API is v2, documented behind a login at
    489 [dehashed.com/docs](https://dehashed.com/docs), so check the endpoint there rather than copying a
    490 wrapper. The web search works without any of
    491 that. Leak-Lookup's free tier is a hash-only check; its searchable API is paid.
    492 
    493 ## Tool reference
    494 
    495 | Tool | What it does | Cost |
    496 | --- | --- | --- |
    497 | [192](http://www.192.com/) | Searching for someone's address in the UK, phone number and who they live with according to electoral rolls. | free |
    498 | [Eniro](https://www.eniro.se/) | Yellow Pages (Swedish Edition) | free |
    499 | [Epieos](https://tools.epieos.com/holehe.php) | Checks where an email has been used. Based on Holehe. | paid |
    500 | [FastPeopleSearch](http://fastpeoplesearch.com/) | Mostly good for US. | free |
    501 | [GetContact](https://www.getcontact.com/en/) | Phonenumber ID app - draws from crowdsourced contactbooks | free |
    502 | [Ghunt](https://github.com/mxrch/GHunt) | A command line tool for obtaining information about Google accounts. | free |
    503 | [Hitta.se](https://www.hitta.se/) | Mapping service for Sweden | free |
    504 | [Intelx](http://intelx.io/) | Find user details in data breaches | partly free |
    505 | [NigeriaPhonebook](https://nigeriaphonebook.com/) | Look up by name, state, and phone number. Last names are partially censored for free accounts. | free |
    506 | [Person Lookup](https://personlookup.co.za/) | find individuals, phonenumbers, and adresses | free |
    507 | [Pipl](http://pipl.com/) | Identity information for professionals | paid |
    508 | [Ratsit](https://www.ratsit.se/) | Look up phone numbers/names (Sweden) | free |
    509 | [Search Systems](https://www.searchsystems.net/) | Finding public record information online in over 70,000 databases organized by type and location to help you find property, criminal, court, birth, death… | free |
    510 | [Skopenow](https://www.skopenow.com/) | Social Media Investigations - name, phone, email, username searches. | paid |
    511 | [Spokeo](http://spokeo.com/) | People search through email, phone, name | paid |
    512 | [Swedish Name Register](https://scb.se/hitta-statistik/sverige-i-siffror/namnsok/) | Find out how common a name is in Sweden based on census data | free |
    513 | [The Law Pages](https://www.thelawpages.com/court-cases/court-case-search.php?mode=1) | Search criminal court case details in the UK, such as sentence, hearing, defendant, etc. | free |
    514 | [ThisNumber](https://sur.ly/o/numberway.com/AA000014) | An international directory of white pages and yellow pages phone books, and online directory enquiries. It's a free, independent and up-to-date guide to… | free |
    515 | [TrueCaller](https://www.truecaller.com/) | Truecaller is a caller ID app that identifies incoming calls, blocks unwanted numbers, and gathers phone numbers and names from contact lists. It also… | partly free |
    516 | [TruffleHog](https://trufflesecurity.com/trufflehog) | Find leaked credentials. | free |
    517 | [Worldwide Osint Tools map](https://cipher387.github.io/osintmap/) | Global overview of yellow/white pages, court cases, business registries etc. | free |
    518 | USA court case databases | State-by-state guide for researching criminal and civil court cases | partly free |
    519 
    520 ## Pitfalls
    521 
    522 - **Aggregators invent relatives.** "Possible relatives" lists are inference from shared addresses
    523   and surnames. They are frequently wrong and occasionally defamatory.
    524 - **Stale addresses.** Someone moved five years ago; the aggregator still shows the old address as
    525   current. Date every claim.
    526 - **Name collisions.** Common names across a large population produce confident, wrong matches.
    527   Require a second identifier — date of birth, middle initial, employer.
    528 - **Jurisdiction and legality.** Accessing some records requires a declared lawful purpose. Bulk
    529   collection of personal data about EU residents engages the GDPR regardless of the data being
    530   public.
    531 
    532 ## Worked example
    533 
    534 One datum: the name **Dana Whitfield**, typed under a signature on a PDF that also carries a
    535 Travis County, Texas address block. Nothing else.
    536 
    537 1. **Establish the jurisdiction's real sources.** [Search Systems](https://www.searchsystems.net/)
    538    lists the Travis County clerk, district clerk and appraisal district portals. That tells you
    539    where the authoritative property and civil records live before you touch an aggregator.
    540 2. **Federal dockets.** `type=r` search on CourtListener for `"Dana Whitfield"` returns one 2021
    541    docket in the Western District of Texas. The docket's party block gives a street address and
    542    the name of a law firm — two new pivots, from a dated court document.
    543 3. **Filings.** EDGAR full-text search for the same name, `forms=D`, returns a 2022 Form D naming
    544    her as a director of a private company, with a business address in Austin and a company CIK.
    545 4. **Company side.** The CIK into `data.sec.gov/submissions/CIK….json` gives the company's former
    546    names and address history, which is how you find out the entity was renamed in 2023 — the
    547    reason a plain name search missed it.
    548 5. **Screening, including the negative.** The OpenSanctions `/match/default` call with
    549    `name`, `country=us` and the birth year inferred from the docket returns no result above 0.6.
    550    Record that as a checked negative with the datasets listed, not as "nothing found".
    551 6. **Identifier confirmation.** The business email in the Form D goes into HIBP
    552    `breachedAccount`. Two corpora dated 2019 and 2021 hold it, which confirms the address was in
    553    use across that window — and nothing more.
    554 7. **Aggregator, last.** That's Them on "Dana Whitfield, Austin TX" returns three candidate
    555    addresses, one matching the docket. The other two, and the whole "possible relatives" block,
    556    stay in the notes as unverified inference.
    557 
    558 The whole run, as commands:
    559 
    560 ```bash
    561 UA='osint-research research@example.com'
    562 export CL_TOKEN=REPLACE_ME OS_KEY=REPLACE_ME HIBP_KEY=REPLACE_ME
    563 
    564 curl -s -G 'https://www.courtlistener.com/api/rest/v4/search/' -H "Authorization: Token $CL_TOKEN" \
    565   --data-urlencode 'q="Dana Whitfield"' --data-urlencode 'type=r' | jq -r '.results[].caseName'
    566 
    567 curl -s -A "$UA" 'https://efts.sec.gov/LATEST/search-index?q=%22Dana+Whitfield%22&forms=D' \
    568   | jq -r '.hits.hits[] | "\(._source.file_date)  \(._source.display_names[0])"'
    569 
    570 curl -s -A "$UA" 'https://data.sec.gov/submissions/CIK0001234567.json' | jq '{name,formerNames}'
    571 
    572 curl -s -X POST 'https://api.opensanctions.org/match/default' -H "Authorization: ApiKey $OS_KEY" \
    573   -H 'Content-Type: application/json' \
    574   -d '{"queries":{"q1":{"schema":"Person","properties":{"name":["Dana Whitfield"],"country":["us"]}}}}' \
    575   | jq -r '.responses.q1.results[] | "\(.score)  \(.caption)"'
    576 
    577 curl -s 'https://haveibeenpwned.com/api/v3/breachedAccount/dana@example.com' \
    578   -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' | jq -r '.[].Name'
    579 ```
    580 
    581 What you can assert: a named person, tied by two independent dated documents to one company and
    582 one city, with one address corroborated by a court filing. What you cannot: anything the
    583 aggregator alone said, and any relationship nobody filed.
    584 
    585 What would falsify it: the docket and Form D resolving to different people once a middle name,
    586 date of birth or signature is compared; the apparent address match being a forwarding or business
    587 address shared by unrelated parties; or the filing being amended or withdrawn. The company-and-
    588 city link survives only while the two primary documents point to the same natural person.
    589 
    590 ## Broader catalogues
    591 
    592 - [People OSINT](https://tools.osintnewsletter.com/tool-categories/people-osint)
    593 - [Public Records OSINT](https://tools.osintnewsletter.com/tool-categories/public-records-osint)
    594 - [Breached Data Provider OSINT](https://tools.osintnewsletter.com/tool-categories/breached-data-provider)
    595 
    596 
    597 ## More tools
    598 
    599 Further tools for this area from the OSINT Newsletter Tools Library ([People OSINT](https://tools.osintnewsletter.com/tool-categories/people-osint), [Public Records OSINT](https://tools.osintnewsletter.com/tool-categories/public-records-osint), [Breached Data Provider OSINT](https://tools.osintnewsletter.com/tool-categories/breached-data-provider)), excluding those already listed above.
    600 
    601 | Tool | What it does |
    602 | --- | --- |
    603 | [192.com](https://www.192.com/) | UK-based online directory that helps you find information about people, addresses, businesses, and property records in the UK. |
    604 | [4shared](https://www.4shared.com/) | File-sharing and cloud-storage platform with a public search function. |
    605 | [Aeroleads](https://aeroleads.com/) | A prospecting and contact discovery platform that helps users find professional email addresses, phone numbers, company… |
    606 | [AllPeople](https://allpeople.com/) | A people-search and contact directory tool (US) that aggregates publicly available contact information to help identify… |
    607 | [Analyst Research Tools](https://analystresearchtools.com/) | A browser-based investigative research platform pulling together a collection of free lookup tools to help you gather, organise… |
    608 | [AnyWho](https://www.anywho.com/) | US- focused people-search and directory tool to find publicly available contact information, including names, phone numbers, and… |
    609 | [Australia Public Record](https://www.australiapublicrecord.com/) | Searches Australian public records to uncover people, businesses, properties, court records, and other publicly available… |
    610 | [BeenVerified](https://www.beenverified.com/) | People-search and background research platform that aggregates publicly available records into a single interface. |
    611 | [BIS Data Portal](https://data.bis.org/) | Public platform for exploring, analysing, and downloading international financial and economic statistics. |
    612 | [Business registers in EU countries](https://e-justice.europa.eu/topics/registers-business-insolvency-land/business-registers-eu-countries_en) | An official European Union portal providing access to national business registers across EU Member States. |
    613 | [Buzzglobe](https://buzzglobe.com/) | Social-media search aggregator for discovering publicly indexed profiles, pages, posts and images across multiple platforms. |
    614 | [Congressional Trader](https://congressional-trader.com/) | Search and review public U.S. congressional stock trade disclosures for lawmakers, tickers, states, and recent transactions. |
    615 | [Corp Watch](https://www.corpwatch.org/) | A non-profit investigative research platform that tracks corporate activity, accountability, environmental issues, human rights… |
    616 | [Corporation Wiki](https://www.corporationwiki.com/) | An online corporate intelligence database that aggregates public records on companies, directors, officers, and business… |
    617 | [dilisense](https://dilisense.com/en) | An AML/KYC screening and risk-intelligence platform that consolidates sanctions, PEPs, criminal watchlists, and adverse-media… |
    618 | [District 4 Labs Darkside](https://portal.district4labs.net/search) | An OSINT search platform that aggregates breached data, darknet intelligence, and leaked datasets into one searchable interface. |
    619 | [EDGAR Full Text Search](https://www.sec.gov/edgar/search/#) | Enables search across millions of filings submitted to the U.S. Securities and Exchange Commission (SEC). |
    620 | [EU Sanctions Map](https://www.sanctionsmap.eu/#/main) | An official public resource that provides a user-friendly overview of sanctions regimes adopted by the European Union. |
    621 | [Eyedex](https://www.eyedex.org/) | An open directory search engine that indexes publicly accessible web directories & allows users to search across petabytes of… |
    622 | [Federal Procurement Data System (FPDS)](https://sam.gov/contracting) | Official U.S. government database for federal contract spending. |
    623 | [Footprint IQ](https://footprintiq.app/) | Scans usernames, emails, and phone numbers across 500+ public sources to map a subject's digital footprint and calculate an… |
    624 | [Forebears](https://forebears.io/) | A global surname and genealogy database. |
    625 | [Free Full PDF](https://www.freefullpdf.com/) | Academic search engine focused on locating freely available full-text scientific PDFs, including journal articles, theses… |
    626 | [FreewareWeb FTP Search](https://www.freewareweb.com/copyright.shtml) | A specialised search engine that searches indexed FTP sites for files and directories using filenames, keywords, file types… |
    627 | [Gravatar](https://gravatar.com/site/check) | An avatar service that allows you to determine whether an email address is associated with a publicly available Gravatar profile. |
    628 | [GrayhatWarfare](https://grayhatwarfare.com/) | Search engine for publicly exposed files stored in cloud storage services such as AWS S3, Azure Blob Storage, Google Cloud… |
    629 | [Have I Been Pwned?](https://haveibeenpwned.com/) | Check whether an email address, password, or domain has appeared in known data breaches. |
    630 | [Hippie OSINT Toolkit](https://osint.hippie.cat/) | An OSINT web toolkit that allows you to reverse search a domain, a TikTok post, an image, or username (and more). |
    631 | [Hudson Rock](https://www.hudsonrock.com/) | A cybercrime intelligence platform that lets you search for compromised credentials, infected machines, and exposed corporate… |
    632 | [IDCrawl](https://www.idcrawl.com/) | A free people, username, reverse phone and reverse email search tool. |
    633 | [Import Yeti](https://www.importyeti.com/) | A supply chain intelligence tool that helps users discover who imports products into the United States and which overseas… |
    634 | [Indicia](https://indicia.app) | A Software-as-a-Service (SaaS)) platform for professional investigations, leveraging AI-powered tools to perform digital… |
    635 | [LeakData.io](https://leakdata.io/en) | A breach intelligence platform that checks authorised emails, usernames, phone numbers, and domains against indexed breach data. |
    636 | [Leaker](https://github.com/vflame6/leaker) | A passive reconnaissance CLI tool that aggregates credential leak data from multiple breach databases, supporting searches by… |
    637 | [LeakIX](https://leakix.net/) | Search engine and monitoring platform that indexes exposed services, misconfigurations, and leaked/publicly accessible data from… |
    638 | [Library of Leaks](https://search.libraryofleaks.org/) | A searchable archive of leaked datasets, documents, and exposed information sources. |
    639 | [LittleSis](https://littlesis.org/) | A public-interest database that maps relationships between powerful people and organisations (mostly U.S.) |
    640 | [Lullar](https://com.lullar.com/en/tools) | A free people-search engine that checks a username, email, or name across 170+ social media and online platforms in one query. |
    641 | [Names Directory](https://namesdir.com/) | A web-based name-association search tool to search for first names associated with surnames and surnames associated with first… |
    642 | [NAMINT](https://seintpl.github.io/NAMINT/) | A web app that generates multiple username, email, and naming combinations from a person’s first, middle, and last name. |
    643 | [North Data](https://www.northdata.com/) | A business intelligence platform providing access to company records, corporate structures, financial information and ownership… |
    644 | [Nuwber](https://nuwber.com/) | People-search and data-broker platform used to identify and cross-reference individuals using names, telephone numbers, addresses… |
    645 | [OFAC Sanctions List Search](https://sanctionssearch.ofac.treas.gov/) | The U.S. Office of Foreign Assets Control (OFAC) sanctions database that identifies individuals, companies, vessels and… |
    646 | [OpenCorporates](https://opencorporates.com/) | One of the largest open databases of company information in the world, aggregating official corporate registry data from… |
    647 | [OpenSecrets](https://www.opensecrets.org/) | A non-partisan transparency platform that tracks money in U.S. politics. |
    648 | [OSINT Industries](https://app.osint.industries/) | An all-encompassing OSINT platform that gathers and correlates publicly available digital data such as emails, domains, phone… |
    649 | [OSINT Tools Map](https://cybdetective.com/osintmap/) | An interactive directory of country-specific OSINT resources, including phonebooks, cadastral maps, business registers, court… |
    650 | [Osintly](https://osint.ly/) | A unified OSINT platform that searches for information across pseudonyms, email addresses, phone numbers, IP addresses, domains… |
    651 | [Predicta Search](https://www.predictasearch.com/) | Reverse email, phone number, username or name lookup. |
    652 | [Radaris](https://radaris.com/) | A people-search and information-aggregation service that allows you to search for information associated with individuals… |
    653 | [Sanctions Atlas](https://sanctionsatlas.com/) | A sanctions intelligence platform that brings together global sanctions lists, watchlists and ownership data. |
    654 | [SearchShared](https://www.searchshared.info/) | File-sharing search engine for locating publicly indexed/shared files across multiple hosting services. |
    655 | [Sherlock Eye](https://www.sherlockeye.io/) | AI-powered OSINT assistant that automates investigations, links data, and surfaces insights fast. |
    656 | [SynapsInt](https://synapsint.com/) | A web-based search platform that aggregates publicly available data about people, organisations, domains, IP addresses, email… |
    657 | [That's Them](https://thatsthem.com/) | A free people-search engine (US) to help find individuals through names, phone numbers, emails, and addresses. |
    658 | [The World Bank Open Data Catalog](https://datacatalog.worldbank.org/) | A searchable repository of development-related datasets, providing access to data, metadata, downloadable resources and, for some… |
    659 | [TheBigBrother](https://github.com/chadi0x/TheBigBrother) | All-in-one OSINT toolkit that helps track usernames across the web, investigate emails and domains, extract metadata, and follow… |
    660 | [UN Comtrade Database](https://comtradeplus.un.org/) | United Nations' database of detailed international trade statistics providing official trade data reported by countries and areas. |
    661 | [United States Patent and Trademark Office (USPTO)](https://www.uspto.gov/) | A public database for digging into patents, trademarks, and intellectual property filings. |
    662 | [Wikispooks](https://wikispooks.com/wiki/Main_Page) | An independent, collaboratively edited research wiki focused on people, organisations, events, documents and alleged networks of… |
    663 | [XposedOrNot](https://xposedornot.com/) | Free data breach search engine. |
    664 
    665 ## Sources
    666 
    667 Both catalogues below are maintained by other people and are considerably larger than
    668 this page. Use them as the canonical index; this sheet is a working route through them.
    669 
    670 - [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
    671   review page covering cost, difficulty, requirements and limitations.
    672 - [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
    673 
    674 Neither publishes a licence, so nothing here is copied from them: tool names, one-line
    675 descriptions, cost flags and links are catalogue facts, and the method and commentary are
    676 this site's own. See [credits](/credits).