# MrTuxx/SocialPwned

SocialPwned is an OSINT tool that allows to get the emails, from a target, published in social networks such as Instagram, Linkedin and Twitter to find possible credentials leaks in PwnDB or Dehashed  and obtain Google account information via GHunt.

Repository: https://github.com/MrTuxx/SocialPwned
Canonical: https://ross.abutalabs.com/products/socialpwned
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: osint, social-engineering, pentesting-tools, hacking, twint, instagram-api, linkedin-api, haveibeenpwned, pwndb, ghunt, dehashed, instagram
Archived: true
Last push: 2025-01-28T19:07:29+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 3, release rhythm 8, longevity 100
- inputs: {"age_days": 2339, "days_push": 582, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1320, forks 125 (observed 2026-08-28T04:04:21.709437+00:00)

## What it is
SocialPwned is a Python-based OSINT tool that harvests emails published on Instagram, LinkedIn, and Twitter to find credential leaks via PwnDB, Dehashed, and HaveIBeenPwned, and gathers Google account info via GHunt. It is designed for the footprinting phase of ethical hacking engagements.

## Use cases
- find leaked credentials for emails published on social networks
- harvest employee emails from a target company on LinkedIn
- scrape emails from Instagram user profiles
- search tweets for published email addresses
- check email breaches on HaveIBeenPwned and Dehashed
- gather Google account information with GHunt
- generate possible username combinations for an organization

## When to choose
- you are doing footprinting/recon in an authorized penetration test
- you want a single tool chaining social-network email harvesting with breach lookups
- you need to identify password reuse patterns of a target organization

## When to avoid
- you lack authorization to test the target - using this on others is illegal
- you need a maintained scraping solution - it relies on unofficial APIs that frequently break
- you want a GUI or non-interactive workflow
- you are unwilling to provide social media accounts or pay for Dehashed API access

## Facets
- artifact type: cli-tool
- maturity: active
- function: osint, security, web-scraping, cli
- domain: security, osint, penetration-testing, social-media
- platform: python, cli
- tags: osint, social-engineering, credential-leak-search, instagram, linkedin, twitter, pentesting, email-harvesting, linux

## Member repositories
- MrTuxx/SocialPwned (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:21.709437+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:47:25.141079+00:00, confidence not recorded.
  - readme: https://github.com/MrTuxx/SocialPwned (fetched 2026-08-28T04:04:21.709437+00:00, sha 99a9e0154741)
- Data as of 2026-08-30T08:39:29.467469+00:00.
