Advanced Breach & Dark Web Intelligence Framework
For authorised security research and ethical penetration testing only.
βββββββ βββββββββββ βββ βββββββ βββββββββββββββ ββββββββββββ
ββββββββββββββββββββββββ βββββββββββββββββββββββββ ββββββββββββ
ββββββββββββββββ ββββββ βββ ββββββββββββββββββββ βββ βββ
ββββββββββββββββ ββββββ βββ ββββββββββββββββββββββββ βββ
βββ βββββββββββββββ βββ βββββββββββββββββββββββ ββββββ βββ
βββ ββββββββββββββ βββ βββββββ ββββββββββββββ βββββ βββ
| Layer | What it does |
|---|---|
| Breach DBs | HIBP (k-anon + API), BreachDirectory, ProxyNova COMB, LeakCheck, GhostProject, Snusbase, IntelX |
| Reputation | EmailRep, Hunter.io, URLScan, VirusTotal, Shodan InternetDB, crt.sh |
| Paste sites | Pastebin (psbdmp API), paste.ee, JustPaste.it, paste2, rentry, controlc β raw-content credential extraction |
| Code search | GitHub code dork across multiple query patterns |
| Surface dorking | Google, Bing, DuckDuckGo, Startpage, Yahoo β proxy rotation, UA randomisation, 2captcha/anticaptcha |
| Social/phone | WhatsMyName (150+ platforms), NumVerify/AbstractAPI |
| Dark web engines | Ahmia, Torch, Haystak, DarkSearch, NotEvil, Phobos, Excavator, Kilos, OnionSearchEngine β paginated |
| Dark web crawl | Depth-2 breadth-first onion crawler β forum posts, marketplace listings, paste dumps, credential extraction |
| PwnDB | Direct hidden-service credential lookup |
| Output | JSON + CSV + TXT per scan, saved to output/results/ |
rsx-osint/
βββ main.py
βββ requirements.txt
βββ README.md
βββ LICENSE
βββ install.sh Linux / macOS installer
βββ install.ps1 Windows installer
βββ config/
β βββ settings.yaml
β βββ proxies.txt
β βββ useragents.txt
βββ modules/
β βββ utils/ tui Β· config Β· proxy Β· dedup Β· export Β· http Β· menu
β βββ scraper/ breach Β· paste Β· social
β βββ dorking/ engines Β· dorks Β· captcha
β βββ darkweb/ engines Β· crawler Β· parser
βββ output/
βββ results/
- Python 3.10+
- Tor (required for dark web mode only)
- Playwright (optional β for JS-heavy pages)
1. Install Python 3.10+
Download from https://www.python.org/downloads/ β check "Add Python to PATH" during install.
2. Run the installer
Open PowerShell in the rsx-osint folder:
Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass
.\install.ps1The script will:
- Detect Python 3.10+ from
python3.12down topython - Create a
venv\virtualenv and install all pip packages inside it - Check if Tor is in PATH and test SOCKS5 connectivity on
127.0.0.1:9050 - Run a module import check to confirm everything is working
- Generate both a
run.bat(CMD) andrun.ps1(PowerShell) launcher
3. Run the tool
.\run.batOr with flags:
.\run.bat -q user@example.com -t email --clearnet
.\run.bat -q targetuser -t username --both --tor 127.0.0.1:90501. Install Python 3.10+
sudo apt install python3 python3-pip # Debian/Ubuntu/Kali
sudo pacman -S python # Arch/Manjaro
sudo dnf install python3 # Fedora2. Run the installer
chmod +x install.sh && ./install.shThe script will:
- Detect your distro (Kali, Debian, Ubuntu, Arch, Fedora) and use the right package manager
- Install Tor and build dependencies via
apt/pacman/dnf - Create a
venv/virtualenv and install all pip packages inside it - Attempt to start the Tor service via
systemctland verify SOCKS5 connectivity - Run a module import check to confirm everything is working
- Generate a
run.shlauncher
3. Run the tool
./run.shOr with flags:
./run.sh -q user@example.com -t email --clearnet
./run.sh -q targetuser -t username --both --tor 127.0.0.1:9050git clone https://github.com/thhackerthathacks/rsx-osint.git
cd rsx-osint
python3 -m venv venv
source venv/bin/activate # Linux/macOS
venv\Scripts\activate.bat # Windows CMD
venv\Scripts\Activate.ps1 # Windows PowerShell
pip install -r requirements.txt
python3 main.pyTor is only required for --darkweb and --both modes.
Download the Tor Expert Bundle (not Tor Browser) from: https://www.torproject.org/download/tor/
Extract it, then run:
tor.exeTor will listen on 127.0.0.1:9050 by default.
sudo apt install tor
sudo systemctl start torcurl --socks5-hostname 127.0.0.1:9050 https://check.torproject.org/api/ipShould return {"IsTor":true,...}.
.\run.bat -q target@email.com -t email --darkweb --tor 127.0.0.1:9500Or set permanently in config/settings.yaml:
tor_proxy: "127.0.0.1:9500"Add proxies to config/proxies.txt β one per line:
http://45.77.123.45:3128
socks5://192.168.1.100:1080
http://user:pass@gate.example.com:8000
Supported formats: http://, https://, socks5:// with or without credentials.
Proxies rotate per request. On a 429 or CAPTCHA the current proxy is marked bad and the next is tried automatically.
For reliable dorking without captcha blocks, use a paid rotating proxy service (Oxylabs, Bright Data, Smartproxy) β enter the gateway as a single line in proxies.txt.
- Sign up at https://2captcha.com
- Add to
config/settings.yaml:
captcha_service: "2captcha"
captcha_api_key: "YOUR_KEY"- Sign up at https://anti-captcha.com
- Add to
config/settings.yaml:
captcha_service: "anticaptcha"
captcha_api_key: "YOUR_KEY"Configure in config/settings.yaml under api_keys::
| Key | Source | Cost | Enables |
|---|---|---|---|
hibp |
https://haveibeenpwned.com/API/Key | $3.50/mo | Full email breach detail |
hunter |
https://hunter.io | Free 25/mo | Domain email enumeration |
virustotal |
https://virustotal.com | Free tier | IP/domain/hash analysis |
snusbase |
https://snusbase.com | Paid | Large password DB search |
leakix |
https://leakix.net | Free tier | Leak DB search |
breachdirectory |
https://breachdirectory.org | Free tier | Breach credential lookup |
The tool runs with ~70% of sources active without any API keys.
.\run.bat-q / --query Target string
-t / --type email | username | password | hash | ip | domain | phone | name
--clearnet Surface web only
--darkweb Dark web (Tor) only
--both Both surface + dark web
--tor ADDR Tor SOCKS5 proxy (default: 127.0.0.1:9050)
--no-save Skip writing output files
--config PATH Config file path (default: config/settings.yaml)
--depth N Dark web crawl depth 1-3 (default: 2)
--threads N Override worker count
--proxy-file PATH Override proxy file path
.\run.bat -q user@example.com -t email --clearnet
.\run.bat -q targetuser -t username --clearnet
.\run.bat -q example.com -t domain --both --tor 127.0.0.1:9050
.\run.bat -q 1.2.3.4 -t ip --clearnet
.\run.bat -q 5f4dcc3b5aa765d61d8327deb882cf99 -t hash --clearnet
.\run.bat -q target@mail.com -t email --both --depth 2 --no-saveResults saved to output/results/<type>_<query>_<timestamp>/:
output/results/email_user_example_com_20240315_143022/
βββ results.json
βββ results.csv
βββ results.txt
Edit config/settings.yaml:
workers: 20 # Surface web concurrent coroutines
dark_workers: 8 # Tor concurrent coroutines
dark_crawl_depth: 2 # Onion crawl hops (1=fast, 3=thorough)
dark_crawl_pages: 5 # Pages per dark web engine
min_delay: 1.2 # Min seconds between surface requests
max_delay: 4.5 # Max seconds between surface requests
dark_min_delay: 2.0 # Min seconds between Tor requests
dark_max_delay: 7.0 # Max seconds between Tor requestsA full --both scan with defaults takes 4β10 minutes.
This tool is for authorised security research, penetration testing, and defensive threat intelligence only. You must have explicit permission before investigating any individual or system. The author accepts no liability for any misuse of this software. Unauthorised use may violate the CFAA, CMA, GDPR, and other laws.
MIT β see LICENSE