attribution
Credits & sources
Command One is built on top of the open-source OSINT community. Below is every project, dataset and service that powers or informs a module in the console. Command One does not redistribute these tools' code; where a tool must run natively, it is executed by an operator-owned worker under that project's own licence.
Username enumeration
Command One's native sweep engine uses its own HTTP prober, but its platform catalogue and detection heuristics are informed by these projects.
- SherlockMIT
Reference site catalogue and existence-detection patterns for username hunting.
- MaigretMIT
Extended site database, tagging and profile-parsing concepts.
- Snoop ProjectAGPL-3.0
Additional regional platform coverage and search strategy inspiration.
- WhatsMyNameCC BY 4.0
Community-maintained web-account discovery dataset conventions.
- BlackbirdMIT
Curated username/email site list with metadata extraction on positive hits.
- marpleMIT
Search-engine driven username discovery across multiple engines in one pass.
- NetSoc_OSINTMIT
Social-network account discovery sweep for a single handle.
- socialscanMIT
Registration checks against official platform signup endpoints for accurate in-use results.
Email & phone attribution
Free modules that turn a single email address or phone number into the list of services it is registered with.
- HoleheGPL-3.0
Account-existence checks across 120+ sites for an email address, without notifying the owner.
- IgnorantGPL-3.0
Phone-number registration checks against consumer platforms.
- PhoneInfogaGPL-3.0
Number validation, carrier and line-type detail plus public footprint scanning.
Domain & infrastructure mapping
Passive reconnaissance modules used to map the estate behind a domain without touching the target.
- theHarvesterGPL-2.0
Passive collection of emails, hosts and staff names from search engines and certificate logs.
- Sublist3rGPL-2.0
Subdomain enumeration from public search and certificate sources.
- subfinderMIT
Fast passive subdomain enumeration across dozens of public sources.
- OWASP AmassApache-2.0
Passive attack-surface mapping and DNS enumeration for a domain estate.
- recon-ngGPL-3.0
Modular reconnaissance framework driven headlessly for hosts and contacts.
- bbotGPL-3.0
Recursive OSINT scanner mapping subdomains, hosts and addresses behind a domain.
- xnLinkFinderMIT
Extracts links, endpoints and parameters from a target's pages.
- git-houndMIT
Searches public GitHub code and commits for leaked keys and target references.
- sn0intGPL-3.0
Scriptable OSINT framework correlating certificate logs and public sources.
- ExifToolArtistic/GPL
Reads embedded metadata such as camera, GPS and author from hosted files.
Correlation & investigation workflow
The unified findings schema, confidence scoring and corroboration lift draw on established correlation modelling.
- SpiderFootMIT
Correlation-rule design and entity/event modelling for automated OSINT.
- GHuntAGPL-3.0
Approach to enriching an email address into linked public account artefacts.
Optional external archive/search adapter for operators with their own API access.
Public data sources
Live lookups performed by the native engine against openly available infrastructure.
Subdomain discovery via public certificate logs.
DNS-over-HTTPS resolution for MX, A and TXT record recon.
Avatar and profile discovery from email hashes.
Platform & interface
Libraries the console itself is built on.
- ReactMIT
UI runtime.
Routing, data loading and server functions.
- Tailwind CSSMIT
Design-token styling layer.
- shadcn/uiMIT
Accessible component primitives.
- LucideISC
Iconography.
If you maintain a project listed here and would like the attribution amended or removed, get in touch and we will action it.
