edit readme

Signed-off-by: Hadi <[email protected]>
This commit is contained in:
Hadi
2025-05-28 10:10:42 +02:00
parent 0041c0c132
commit 274b393e53
+12 -11
View File
@@ -4,7 +4,7 @@
<br> <br>
# GH-Recon # GH-Recon 🔍
<p> <p>
<a href="https://github.com/anotherhadi/gh-recon/releases"><img src="https://img.shields.io/github/release/anotherhadi/gh-recon.svg" alt="Latest Release"></a> <a href="https://github.com/anotherhadi/gh-recon/releases"><img src="https://img.shields.io/github/release/anotherhadi/gh-recon.svg" alt="Latest Release"></a>
@@ -12,11 +12,12 @@
<a href="https://goreportcard.com/report/github.com/anotherhadi/gh-recon"><img src="https://goreportcard.com/badge/github.com/anotherhadi/gh-recon" alt="GoReportCard"></a> <a href="https://goreportcard.com/report/github.com/anotherhadi/gh-recon"><img src="https://goreportcard.com/badge/github.com/anotherhadi/gh-recon" alt="GoReportCard"></a>
</p> </p>
## Project Overview ## 🧾 Project Overview
Fetches and aggregates public OSINT data for a GitHub user, leveraging Go and the GitHub API. Retrieves and aggregates public OSINT data about a GitHub user using Go and the GitHub API.
Finds hidden emails in commit history, previous usernames, friends, other GitHub accounts, and more.
## Features ## 🚀 Features
- Retrieve basic user profile information (username, ID, avatar, bio, creation dates) - Retrieve basic user profile information (username, ID, avatar, bio, creation dates)
- List organizations and roles - List organizations and roles
@@ -28,16 +29,16 @@ Fetches and aggregates public OSINT data for a GitHub user, leveraging Go and th
- Export results to JSON - Export results to JSON
- Deep scan option (clone repositories, regex search, analyze licenses, etc.) - Deep scan option (clone repositories, regex search, analyze licenses, etc.)
## Disclaimer ## ⚠️ Disclaimer
This tool is intended for educational purposes only. Use responsibly and ensure you have permission to access the data you are querying. This tool is intended for educational purposes only. Use responsibly and ensure you have permission to access the data you are querying.
## Prerequisites ## 📋 Prerequisites
- Go 1.18+ - Go 1.18+
- GitHub Personal Access Token (recommended for higher rate limits): Create a GitHub API token with no permissions/no scope. This will be equivalent to public GitHub access, but it will allow access to use the GitHub Search API. - GitHub Personal Access Token (recommended for higher rate limits): Create a GitHub API token with no permissions/no scope. This will be equivalent to public GitHub access, but it will allow access to use the GitHub Search API.
## Installation ## 📦 Installation
### With Go ### With Go
@@ -74,7 +75,7 @@ environment.systemPackages = with pkgs; [ # or home.packages
</details> </details>
## Usage ## 🧪 Usage
```bash ```bash
gh-recon --username TARGET_USER [--token YOUR_TOKEN] gh-recon --username TARGET_USER [--token YOUR_TOKEN]
@@ -95,7 +96,7 @@ gh-recon --username TARGET_USER [--token YOUR_TOKEN]
-j, --json string Write results to specified JSON file -j, --json string Write results to specified JSON file
``` ```
## Example ## 💡 Examples
```bash ```bash
gh-recon --username anotherhadi --token ghp_ABC123... gh-recon --username anotherhadi --token ghp_ABC123...
@@ -103,7 +104,7 @@ gh-recon --email [email protected]
gh-recon --username anotherhadi --json output.json --deep gh-recon --username anotherhadi --json output.json --deep
``` ```
## Cover your tracks ## 🕵️‍♂️ Cover your tracks
Understanding what information about you is publicly visible is the first step to managing your online presence. gh-recon can help you identify your own publicly available data on GitHub. Here’s how you can take steps to protect your privacy and security: Understanding what information about you is publicly visible is the first step to managing your online presence. gh-recon can help you identify your own publicly available data on GitHub. Here’s how you can take steps to protect your privacy and security:
@@ -118,6 +119,6 @@ You can also use a tool like [TruffleHog](github.com/trufflesecurity/trufflehog)
- [Blocking command line pushes that expose your personal email address](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/blocking-command-line-pushes-that-expose-your-personal-email-address) - [Blocking command line pushes that expose your personal email address](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/blocking-command-line-pushes-that-expose-your-personal-email-address)
- [No-reply email address](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/setting-your-commit-email-address) - [No-reply email address](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/setting-your-commit-email-address)
## Contributing ## 🤝 Contributing
Feel free to contribute! See [CONTRIBUTING.md](CONTRIBUTING.md) for details. Feel free to contribute! See [CONTRIBUTING.md](CONTRIBUTING.md) for details.