Open-source intelligence platform

Discover. Correlate. Investigate.

Turn scattered usernames, emails and domains into scored, evidenced findings, with every step on the record. UNMASK runs Amass, crt.sh, DuckDuckGo, GitHub, GitLab, Gravatar, Hacker News, IPinfo and 8 more tools as one case, and shows you why every finding scored the way it did.

  • Self-hosted
  • Encrypted at rest
  • Every step audited
A case in UNMASK: a summary of the likely matches above findings listed with their match strength, source reliability and the tools that reported them.

16 tools, one case

  • Amass
  • crt.sh
  • DuckDuckGo
  • GitHub
  • GitLab
  • Gravatar
  • Hacker News
  • IPinfo
  • Keybase
  • LeakCheck
  • Maigret
  • Domain registration (RDAP)
  • Sherlock
  • SpiderFoot
  • theHarvester
  • Wayback Machine

How it works

From a username to a defensible answer

  1. Add what you know

    Paste usernames, emails, names, domains, phones or IPs. Record who authorised the case and why, or start from a template.

  2. Scan and correlate

    Tools run in parallel. Account hits are checked against their profile pages, duplicates merged, and every lead followed up automatically.

  3. Review and report

    Confirm or rule out findings one key at a time, write your assessment, and export a report, CSV, JSON or STIX 2.1.

Features

Built for investigators who have to show their work

Scores you can explain

Each finding shows its match strength, the sources behind it and the reasons it scored the way it did. No black box.

One-key review queue

Same person, different person, not a profile: decide in a keystroke. Your decisions teach it which sites to trust.

Relationship graph

See how accounts, emails and domains connect, focus on one node, and export the picture for your report.

Timeline and watch mode

Re-scan on a schedule and see exactly what's new, what changed and what disappeared since the last run.

Evidence that lasts

Save a page as it is today with a SHA-256 fingerprint, so your evidence survives when the profile changes.

Share and export

Reports led by your assessment, CSV, JSON and STIX 2.1 exports, and read-only links that expire.

Honest by design

A blocked tool never reads as "nothing found"

When a site blocks a request or a tool is cut short, UNMASK tells you, says what to do about it, and keeps what it did find. Unchecked accounts stay out of your best findings, and a site's own social links are never mistaken for the person's.

Trust and responsibility

Careful use is the default

Authorised first

No case without a written authorisation and a lawful basis. The database itself enforces it.

Encrypted at rest

Identifiers, findings, notes and API keys are encrypted, with keys kept away from the database.

Everything on the record

Every decision, export and share-link view is logged against a named person.

Nothing kept forever

Each case has a retention period and is deleted when it ends.

How we protect your data · Acceptable use

Who it's for

One platform, many investigations

Due diligence

Check that a person or supplier is who they say they are before you sign.

Security teams

Map an organisation's exposed accounts, hosts and leaked credentials.

Brand protection

Watch for accounts and pages impersonating your people or brand.

Investigations

Fraud, trust-and-safety and research work that needs evidence, not guesses.

FAQ

Questions, answered

What is UNMASK?

A self-hosted open-source intelligence (OSINT) platform. You add what you know about a person or organisation (a username, email address, name, domain, phone number or IP address), and UNMASK runs a set of OSINT tools as one case, then de-duplicates, scores and links what they find.

Which tools does it run?

Username checkers such as Sherlock and Maigret, direct lookups against GitHub, GitLab, Keybase, Hacker News and Gravatar, breach sources, web search, certificate transparency, DNS and domain registration records, and more. Tools that need an API key are added from the Integrations page.

How does it cut false positives?

Every account hit is checked against its profile page before it is shown, profiles are compared on names, locations and links, common usernames are scored down, and your own decisions teach it which sites to trust. Scores come with the reasons behind them.

Is my data safe?

UNMASK is self-hosted, so case data stays on your infrastructure. Identifiers are encrypted at rest, every decision and export is audited, and cases are deleted when their retention period ends.

Can I use it on anyone?

No. Every case needs a documented lawful basis and authorisation, and the Acceptable Use Policy prohibits stalking, harassment and discrimination. You are responsible for how you use it.

What do I get at the end?

A report built around your written assessment, with the evidence behind it, plus CSV, JSON and STIX 2.1 exports and read-only links that expire.

Discover. Correlate. Investigate.

Sign in to open your first case, or explore the sample case with made-up data.

Sign in