Scores you can explain
Each finding shows its match strength, the sources behind it and the reasons it scored the way it did. No black box.
Open-source intelligence platform
Turn scattered usernames, emails and domains into scored, evidenced findings, with every step on the record. UNMASK runs Amass, crt.sh, DuckDuckGo, GitHub, GitLab, Gravatar, Hacker News, IPinfo and 8 more tools as one case, and shows you why every finding scored the way it did.
How it works
Paste usernames, emails, names, domains, phones or IPs. Record who authorised the case and why, or start from a template.
Tools run in parallel. Account hits are checked against their profile pages, duplicates merged, and every lead followed up automatically.
Confirm or rule out findings one key at a time, write your assessment, and export a report, CSV, JSON or STIX 2.1.
Features
Each finding shows its match strength, the sources behind it and the reasons it scored the way it did. No black box.
Same person, different person, not a profile: decide in a keystroke. Your decisions teach it which sites to trust.
See how accounts, emails and domains connect, focus on one node, and export the picture for your report.
Re-scan on a schedule and see exactly what's new, what changed and what disappeared since the last run.
Save a page as it is today with a SHA-256 fingerprint, so your evidence survives when the profile changes.
Reports led by your assessment, CSV, JSON and STIX 2.1 exports, and read-only links that expire.
Honest by design
When a site blocks a request or a tool is cut short, UNMASK tells you, says what to do about it, and keeps what it did find. Unchecked accounts stay out of your best findings, and a site's own social links are never mistaken for the person's.
Trust and responsibility
No case without a written authorisation and a lawful basis. The database itself enforces it.
Identifiers, findings, notes and API keys are encrypted, with keys kept away from the database.
Every decision, export and share-link view is logged against a named person.
Each case has a retention period and is deleted when it ends.
Who it's for
Check that a person or supplier is who they say they are before you sign.
Map an organisation's exposed accounts, hosts and leaked credentials.
Watch for accounts and pages impersonating your people or brand.
Fraud, trust-and-safety and research work that needs evidence, not guesses.
FAQ
A self-hosted open-source intelligence (OSINT) platform. You add what you know about a person or organisation (a username, email address, name, domain, phone number or IP address), and UNMASK runs a set of OSINT tools as one case, then de-duplicates, scores and links what they find.
Username checkers such as Sherlock and Maigret, direct lookups against GitHub, GitLab, Keybase, Hacker News and Gravatar, breach sources, web search, certificate transparency, DNS and domain registration records, and more. Tools that need an API key are added from the Integrations page.
Every account hit is checked against its profile page before it is shown, profiles are compared on names, locations and links, common usernames are scored down, and your own decisions teach it which sites to trust. Scores come with the reasons behind them.
UNMASK is self-hosted, so case data stays on your infrastructure. Identifiers are encrypted at rest, every decision and export is audited, and cases are deleted when their retention period ends.
No. Every case needs a documented lawful basis and authorisation, and the Acceptable Use Policy prohibits stalking, harassment and discrimination. You are responsible for how you use it.
A report built around your written assessment, with the evidence behind it, plus CSV, JSON and STIX 2.1 exports and read-only links that expire.
Sign in to open your first case, or explore the sample case with made-up data.
Sign in