Skip to content

Latest commit

Β 

History

20 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

LowHunt

πŸ”Ž Fast Public OSINT for Real Investigations

LowHunt is a native C OSINT tool for authorized investigations on publicly available data. It helps investigators, defenders, analysts, and curious operators move from scattered checks to a structured workflow for username intelligence, passive domain collection, contact discovery, correlation, and reporting.

It is built for public-data-only use. It does not bypass authentication, protections, or access controls.

✨ Why Use LowHunt

LowHunt is designed for people who want:

  • a fast native binary instead of a heavier runtime stack
  • one workflow for username scans, passive domain harvests, and combined investigations
  • engine-driven execution with fault isolation and fallback behavior
  • quieter contact collection with noise reduction and built-in filtering
  • operator-friendly output that still works for automation and reporting

🧩 What It Solves

OSINT work often gets split across too many disconnected steps:

  • one tool for usernames
  • another for passive domain intelligence
  • another script for emails
  • another notebook for summaries
  • another format for reporting

LowHunt reduces that fragmentation. It gives you one CLI that can:

  • scan usernames across a large platform set
  • harvest passive hostname intelligence from public sources
  • collect same-domain public contact emails with filtering
  • correlate profile hits with harvested domain-side artifacts
  • store reusable report bundles for later review

πŸš€ Core Capabilities

Capability What It Does Why It Matters
Username scanning Checks platform manifests for public profile signals Quickly maps a username footprint across many sites
Passive domain harvest Fuses public host intelligence from crtsh, rapiddns, and wayback Builds a broader view of public domain exposure without active intrusion
Contact discovery Collects same-domain public contact emails from contact-oriented pages Helps analysts find business-facing identifiers with less noise
Correlation Compares profile hits with harvested domain-side email identifiers Turns disconnected findings into investigation signals
Execution engines Supports auto, threadpool, parallel, async, fusion, stabilizer, and sync Lets operators bias for speed, steadiness, or safer recovery
Report bundles Stores CLI, TXT, and JSON artifacts per run Makes results easier to revisit, review, and hand off

πŸ› οΈ Why LowHunt Feels Different

Area LowHunt Approach
Performance Native C runtime, multiple execution engines, concurrency-aware presets
Usability Beginner-friendly presets, explain topics, readable summaries, strong defaults
Resilience Engine isolation and fallback behavior so one engine failure does not kill the whole run
Signal quality Built-in contact/email filtering, source overlap confidence, report-side narrative summaries
Workflow coverage Username OSINT, passive domain intelligence, combined investigation mode, bundled reporting

🧭 How the Tool Works

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 1. Operator Input                                                   β”‚
β”‚    usernames, domain, engine, preset, timeout, threads, outputs     β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                 |
                                 v
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 2. Runtime Planning                                                 β”‚
β”‚    preset application β†’ engine selection β†’ resource warning logic   β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                 |
                   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                   v                           v
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 3A. Username Scan Pipeline   β”‚  β”‚ 3B. Passive Harvest Pipeline     β”‚
β”‚ platform manifests loaded    β”‚  β”‚ public sources selected          β”‚
β”‚ scan tasks built             β”‚  β”‚ host intelligence fused          β”‚
β”‚ engine executes requests     β”‚  β”‚ contact pages collected          β”‚
β”‚ results classified           β”‚  β”‚ emails filtered and scored       β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                   |                           |
                   β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                 v
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 4. Correlation Layer                                                β”‚
β”‚ profile hits + harvested hosts + same-domain emails β†’ confidence    β”‚
β”‚ score, overlap analysis, investigation narrative                    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                 |
                                 v
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 5. Output Layer                                                     β”‚
β”‚ terminal output β†’ file output β†’ stored report bundles               β”‚
β”‚ report.cli.txt / report.txt / report.json                           β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

⚑ Quick Start

Build

sudo apt install gcc make libcurl4-openssl-dev
make

Install

Use the managed local installers in install/.

./install/linux.sh install
./install/macos.sh install
./install/termux.sh install

Windows:

powershell -ExecutionPolicy Bypass -File .\install\windows.ps1 install

Or:

install\windows.cmd install

πŸ§ͺ Common Commands

./lowhunt alice --preset beginner
./lowhunt alice --engine fusion -vv
./lowhunt -u alice -o results.json --format json
./lowhunt -d example.com -b all
./lowhunt alice bob -d example.com -b all --intel
./lowhunt alice -d example.com --engine triage --mod-casefile --mod-graph --mod-report --case-id CASE-001
./lowhunt --list-sites
./lowhunt --list-sources
./lowhunt --about
./lowhunt --explain investigate

πŸŽ›οΈ Presets

Preset Behavior Best For
beginner Readable defaults, steadier pacing, intelligence summary enabled New users and careful operator review
balanced Default behavior with no heavy bias Everyday OSINT work
aggressive Higher concurrency floor, fuller visibility, fast-engine bias Large runs where the environment can handle it

🧠 Engines

Engine Role Best Use
auto Picks an engine from workload and network posture General use
threadpool Balanced worker model Steady default scanning
parallel Simple parallel execution Moderate workloads
async Cooperative concurrency for larger I/O-heavy workloads Bigger scans
fusion High-throughput execution bias Fast large runs
stabilizer Lower-pressure pacing Tor, proxies, rate-sensitive work
sync Sequential, simplest path Troubleshooting and tiny runs
triage Runs early high-signal batches first First-pass investigator review and time-boxed triage
campaign Chunks work and writes checkpoint files Large watchlists and resumable case queues

🌐 Passive Harvesting

LowHunt currently supports:

Source Purpose
crtsh Certificate-transparency hostname discovery
rapiddns Public passive subdomain listing
wayback Archived URL hostname extraction
all Fuses all wired public sources and increases confidence when hosts overlap

Noise reduction and filtering behavior:

  • same-domain contact emails only
  • noreply-style addresses suppressed
  • asset-like strings filtered out
  • malformed candidates ignored
  • public contact-oriented pages prioritized

πŸ”— Combined Investigations

When usernames and -d <domain> are supplied together, LowHunt runs a combined case workflow:

  • passive host intelligence is collected
  • contact emails are harvested and filtered
  • username scan results are generated
  • the correlation layer compares usernames against harvested identifiers
  • an investigation confidence score and narrative are printed
  • report bundles are stored for later review

Example:

./lowhunt alice bob -d example.com -b all --intel -o investigation.json --format json

πŸ“¦ Outputs and Report Bundles

Direct output formats:

  • txt
  • json
  • csv

Stored report bundles:

~/.lowhunt/output/reports/<target>/<timestamp>/

Bundle contents:

  • report.cli.txt
  • report.txt
  • report.json

Combined investigations also store a fused investigation bundle with correlation narrative and confidence details.

Investigator Modules

LowHunt can write additional case artifacts after public scan and harvest results are collected.

Flag Artifact
--mod-casefilecase.json with case ID, tag, counts, confidence, and review status
--mod-timelinetimeline.csv with observed public finding events
--mod-graphgraph.dot relationship graph for public profiles, hosts, and emails
--mod-watchlistwatchlist-delta.txt baseline comparison notes
--mod-artifactartifacts.csv normalized public artifact export
--mod-reportinvestigator-report.txt human-readable review summary

Artifacts are written under casefiles/<case-id>/.

🧯 Safety and Scope

LowHunt is intentionally scoped for public-data-only OSINT.

  • no authentication bypass
  • no credential attacks
  • no protection circumvention
  • no hidden active intrusion behavior

Use it only on:

  • assets you own
  • systems you operate
  • targets you have explicit written authorization to assess

πŸ“š Documentation

The full documentation set lives in docs/.

Suggested reading order:

  1. docs/index.md
  2. docs/getting-started.md
  3. docs/cli-reference.md
  4. docs/engines.md
  5. docs/harvest-and-investigation.md
  6. docs/reporting.md
  7. docs/architecture.md

🧾 Manual

After installation:

man lowhunt

Manual source:

🧱 Platform Manifests

Platform metadata lives under platforms/*.json.

Regenerate platform data from the local reference trees with:

powershell -NoProfile -ExecutionPolicy Bypass -File tmp/generate_platforms.ps1

βœ… Validation

Local validation:

powershell -NoProfile -ExecutionPolicy Bypass -File tests/run_all.ps1

Installer parsing checks:

bash -n install/linux.sh
bash -n install/macos.sh
bash -n install/termux.sh

πŸ‘€ Author

  • Author: voltsparx
  • Contact: voltsparx@gmail.com
  • Repository: https://github.com/voltsparx/LowHunt
  • License: MIT

🀝 Final Note

LowHunt is built to help public-data investigations feel faster, cleaner, and more structured. If you want a native tool that can move from first query to stored investigation bundle without turning into a maze of scripts, that is exactly the problem it is meant to solve.

About

Native C-based OSINT tool for public data analysis and information gathering.

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages