OSINT and information gathering tool — IP geolocation, phone intelligence, username enumeration, email breach lookup, domain recon, and Instagram OSINT via authenticated session.
Version 3.0
# Linux (Debian/Ubuntu)
sudo apt-get install git python3 python3-pip
# Termux
pkg install git python3git clone https://github.com/HunxByts/GhostTrack.git
cd GhostTrack
pip3 install -r requirements.txt
python3 GhostTR.py- Geolocation from two independent sources (ipwho.is + ip-api.com fallback)
- VPN / Proxy / Tor / Hosting detection
- Reverse DNS resolution
- Google Maps link from coordinates
- ASN, ISP, ORG, domain info
- Direct reference links to Shodan and AbuseIPDB
Tip: combine with Seeker to capture the target's real IP.
Displays your current public IP address.
- Carrier / operator identification
- Country, region, timezone
- Number type (Mobile, Fixed Line, VoIP, etc.)
- E.164 / International / mobile-dial formatting
- Quick links to verify presence on WhatsApp, Truecaller, and Telegram
- Checks 25 platforms concurrently (15 threads) — significantly faster than sequential checks
- Platform-specific detection signatures — minimizes false positives
- GitHub bonus: if the username exists on GitHub, automatically attempts to extract email addresses from public commit events
Platforms checked: GitHub, Twitter/X, Instagram, TikTok, LinkedIn, Pinterest, Tumblr, YouTube, SoundCloud, Twitch, Reddit, Medium, Quora, Flickr, Dribbble, Behance, GitLab, Telegram, Steam, Pastebin, HackerNews, ProductHunt, Keybase, Dev.to, Snapchat
- Have I Been Pwned — breach lookup (shows breach name and date)
- GitHub — searches if the email is linked to any public account
- Gravatar — checks if the email has a globally registered avatar profile
- ProtonMail — checks if the username portion is registered
- Derived info: username guess, domain, manual reference links
- WHOIS — registrar, creation/expiry dates, nameservers, org, abuse email
- DNS records — A, MX, TXT, NS
- Subdomain enumeration via Certificate Transparency logs (crt.sh) — no brute force, no API key required
- Wayback Machine — earliest archived snapshot of the domain
- Reference links to Shodan and VirusTotal
Authenticated session using instagrapi. Uses a burner account — session is saved locally to avoid repeated logins.
| Option | What it does |
|---|---|
| Full profile info | Followers, following, post count, verified, business, bio, profile pic URL |
| Followers list | Fetch N followers with username and full name |
| Following list | Fetch N following with username and full name |
| Tagged posts | Posts where the target is tagged — reveals location metadata |
| Posts metadata | Date, location, like/comment count, caption for each post |
| Business contact info | Extracts public email and phone number from Business/Creator accounts |
| Mutual followers | Cross-reference followers between two accounts |
| Stories info | Active stories with timestamp, media type, location, and mentions |
The session file (
.ig_session_<username>.json) is excluded from version control via.gitignore.
- Instagram OSINT requires
instagrapi:pip install instagrapi - Use a dedicated burner account for Instagram to avoid risking your main account
- Some platforms (Twitter/X, LinkedIn) aggressively block automated requests — results may vary
- HIBP programmatic access requires an API key; the tool falls back to a manual reference link if no key is set
requests
phonenumbers
python-whois
instagrapi



