Hadi bd734f11af format
Signed-off-by: Hadi <[email protected]>
2025-05-20 15:32:20 +02:00
2025-05-20 15:28:32 +02:00
2025-05-09 18:49:36 +02:00
2025-05-09 18:49:36 +02:00
2025-05-20 15:30:08 +02:00
2025-05-20 15:28:32 +02:00
2025-05-20 15:28:32 +02:00
2025-05-09 18:49:36 +02:00
2025-05-20 15:32:20 +02:00
2025-05-20 15:28:32 +02:00

GH-Recon

Latest Release GoDoc GoReportCard

Project Overview

Fetches and aggregates public OSINT data for a GitHub user, leveraging Go and the GitHub API.

Features

  • Retrieve basic user profile information (username, ID, avatar, bio, creation dates)
  • List organizations and roles
  • Fetch SSH and GPG keys
  • Enumerate social accounts
  • Extract unique commit authors (name + email) in both chronological orders
  • Find close friends
  • Search using an email address
  • Export results to JSON
  • Deep scan option (clone repositories, regex search, analyze licenses, etc.)

Disclaimer

This tool is intended for educational purposes only. Use responsibly and ensure you have permission to access the data you are querying.

Prerequisites

  • Go 1.18+
  • GitHub Personal Access Token (recommended for higher rate limits): Create a GitHub API token with no permissions/no scope. This will be equivalent to public GitHub access, but it will allow access to use the GitHub Search API.

Installation

With Go

go get github.com/anotherhadi/gh-recon

With Nix/NixOS

From anywhere (using the repo URL):

nix run github:anotherhadi/gh-recon -- --username TARGET_USER [--token YOUR_TOKEN]

Permanent Installation:

# add the flake to your flake.nix
{
  inputs = {
    gh-recon.url = "github:anotherhadi/gh-recon";
  };
}

# then add it to your packages
environment.systemPackages = with pkgs; [ # or home.packages
  gh-recon
];

Usage

gh-recon --username TARGET_USER [--token YOUR_TOKEN]

Flags

  • --token: Personal Access Token (optional but recommended)
  -deep
     Enable deep scan (clone repos, regex search, analyse licenses, etc.)
  -email string
     Search accounts by email address
  -json string
     Write results to specified JSON file
  -only-commits
     Display only commits with author info
  -silent
     Suppress all non-essential output
  -token string
     GitHub personal access token (e.g. ghp_...)
  -username string
     GitHub username to analyze

Example

gh-recon --username anotherhadi --token ghp_ABC123...
gh-recon --email [email protected] --token ghp_ABC123...
gh-recon --username anotherhadi --json output.json --deep

Todo

Feel free to contribute!

Todo:

  • Find and parse licenses
S
Description
Retrieves and aggregates public OSINT data about a GitHub user using Go and the GitHub API. Finds hidden emails in commit history, previous usernames, friends, other GitHub accounts, and more.
Readme MIT
767 KiB
Languages
Go 97%
Nix 3%