SocialPwned is an OSINT tool designed to gather publicly exposed email addresses from social networks and analyze them for potential credential leaks. It helps security researchers and penetration testers identify vulnerable targets during the footprinting phase of ethical hacking engagements. It collects email addresses associated with individuals or organizations from platforms such as Instagram, LinkedIn, and Twitter. Once emails are discovered, SocialPwned searches for leaked credentials using breach databases like PwnDB and Dehashed to determine whether those accounts have appeared in data leaks. SocialPwned also integrates with GHunt to retrieve additional public information related to Google accounts linked to the discovered emails. By combining social media intelligence with breach data analysis, SocialPwned helps investigators identify reused passwords and patterns that may indicate potential security weaknesses.
Features
- Extracts email addresses published on social networks such as Instagram, LinkedIn, and Twitter
- Searches credential leak databases like PwnDB and Dehashed for compromised accounts
- Integrates with GHunt to retrieve public Google account information
- Uses Twint to analyze tweets and discover email addresses without requiring a Twitter account
- Generates username combinations for organizations based on LinkedIn employee data
- Produces structured output files containing discovered emails, leaks, and related intelligence