A privacy-first, terminal-based personal data exposure monitor.
Check if your information has been leaked, sold, or exposed โ without leaving your terminal, without paying a subscription, and without handing your data to another company in the process.
When you use other sites to check if your data was breached:
- ๐ธ You pay
- ๐ You hand another company your information while trying to clean up the first ones
- ๐ Your query leaves your machine and hits their servers
d4rkw3b solves all three. Everything runs locally. Results stay on your device. Nothing phones home.
No passwords required. All checks use publicly indexed breach data โ the same approach used by Google One, IntelX, and similar services.
| Target | Method | Stored in .env |
|---|---|---|
| Email addresses | HIBP breach lookup | โ Yes |
| Usernames | HIBP + GitHub public code scan | โ Yes |
| Phone numbers | HIBP breach lookup | โ Yes |
| Platform usernames | HIBP + paste sites (Discord, Steam, Reddit, Instagram + more) | Runtime prompt |
| Passwords | k-anonymity โ only 5-char hash prefix transmitted, never your full password | Runtime prompt |
| API tokens & keys | GitHub public code exposure scan | Runtime prompt |
| Layer | Approach |
|---|---|
| Breach checks | HIBP k-anonymity API โ only a 5-char SHA-1 hash prefix is transmitted, never your full password |
| Paste site checks | Clearnet only โ breach data surfaces on clearnet fast, no dark web access needed or used |
| Local cache | 24hr breach intelligence cache stored in SQLite on your machine โ most searches never hit the network |
| Offline mode | Search local cache with zero network exposure after first run |
| Dark web crawling | Not included by design โ public breach intelligence is sufficient and legally clean |
Security โ Privacy/OPSEC โ Usability. That is the order of priority in every decision this tool makes.
The password k-anonymity check uses SHA-1 hashing. This is not a security decision โ it is a requirement of the HIBP k-anonymity API protocol. Only the first 5 characters of the hash are ever transmitted. Your full password never leaves your machine. usedforsecurity=False is set explicitly in the code to document this intent.
This tool is built entirely on free, public APIs. No hidden costs. No subscriptions required.
All sources included at time of development use free tiers only. If you need deeper intelligence, see the Premium Tools section below.
| Source | Checks | API Key Required |
|---|---|---|
| HaveIBeenPwned | Email, username, phone โ breach history | Yes (free at haveibeenpwned.com/API/Key) |
| LeakCheck | Email, username, phone โ 7B+ records | No (free tier) |
| BreachDirectory | Email, username โ passwords and hashes | No (free) |
| Emailrep.io | Email โ reputation, breach history, social profiles | Yes (free at emailrep.io/key) |
| OSINTLeak | Email, username โ stealer logs, dark web forums | Yes (free starter at osintleak.com) |
| psbdmp.ws | Email, username โ paste site dumps | No |
| Category | Platforms |
|---|---|
| ๐ฎ Gaming | Steam, PlayStation Network, Xbox, Roblox, Twitch |
| ๐ฌ Social | Discord, Reddit, Twitter/X, Instagram, TikTok, Facebook, LinkedIn, Snapchat, YouTube, Telegram, Spotify |
| ๐ฉโ๐ป Developer | GitHub |
- Python 3.10+
- Terminal (macOS, Linux, or Windows WSL2)
macOS / Linux:
git clone https://github.com/commit-issues/darkweb-exposure-toolkit.git
cd darkweb-exposure-toolkit
pip3 install -r requirements.txt --break-system-packages
cp .env.example .envWindows (PowerShell):
git clone https://github.com/commit-issues/darkweb-exposure-toolkit.git
cd darkweb-exposure-toolkit
pip install -r requirements.txt
copy .env.example .envOpen .env in any text editor and fill in your values.
๐ New to this? See the full step-by-step guide: docs/setup.md
HIBP_API_KEY=your_key_here
GITHUB_TOKEN=your_token_here
EMAILS_TO_CHECK=you@example.com
USERNAMES_TO_CHECK=yourusername
PHONES_TO_CHECK=+12125551234python3 src/run_all_checks.pyForce a cache refresh before scanning:
python3 src/run_all_checks.py --refreshdarkweb-exposure-toolkit/ โ โโโ .env.example โ Copy to .env, fill in your keys โโโ .gitignore โ Protects .env and data/ from commits โโโ requirements.txt โโโ setup.cfg โ Linter configuration โโโ NOTICE โ Attribution โ required to keep on forks โ โโโ src/ โ โโโ run_all_checks.py โ Main entry point โ โโโ tui.py โ Terminal UI, banner, pulse spinner โ โโโ hibp_check.py โ HIBP breach + k-anonymity password check โ โโโ github_search.py โ GitHub public code exposure scan โ โโโ platform_check.py โ Platform username checks (Discord, Steam + more) โ โโโ breach_scraper.py โ Multi-source breach intelligence scraper โ โโโ scheduler.py โ 24hr cache refresh scheduler โ โโโ validator.py โ Input validation and sanitization โ โโโ notifier.py โ Console output formatter โ โโโ db_utils.py โ Local SQLite operations โ โโโ init_db.py โ Database setup โ โโโ verify.py โ Integrity verification โ โโโ data/ โ Local results DB (gitignored)
- All results stored locally only in
data/exposure.db - Your
.envfile is in.gitignoreโ it will never be committed - Delete
data/exposure.dbat any time to wipe all local results - No telemetry, no analytics, no third-party data collection
- Passwords use k-anonymity โ your full password hash never leaves your machine
- Tokens and keys are entered at runtime only and never written to disk
These tools are used by law enforcement, private investigators, security researchers, and journalists for deeper investigations. They are not included in this tool โ no paid services are ever called without your explicit configuration.
| Tool | Used By | Free Tier | API | Best For |
|---|---|---|---|---|
| IntelX (intelx.io) | Law enforcement, Bellingcat, journalists | 10 results/search | Paid | Dark web indexing, full breach records, historical WHOIS |
| OSINT Industries | 5,000+ law enforcement departments | No | Paid | Real-time social footprint across 1,500+ sources |
| DeHashed | Security researchers, pentesters | Basic only | Paid | Largest breach database โ IP, email, username, address |
| Snusbase | Developers, researchers | No | Paid | Fast cleartext passwords, hashes, salts, IPs |
| LeakCheck Pro | OSINT researchers | Limited | Paid | 7B+ records with full credential detail |
| OSINTLeak Pro | Security teams, law enforcement | Free starter | Paid | Stealer logs, continuous monitoring, dark web forums |
Your Discord got compromised and you want to trace it: โ Start here (free, local, private) โ If you need full credential history: LeakCheck Pro or DeHashed
You're a journalist investigating a public figure: โ IntelX for dark web indexing and historical WHOIS โ OSINT Industries for social footprint across 1,500+ sources
You're a security researcher doing a full OSINT sweep: โ DeHashed + Snusbase for deepest credential coverage
You're a PI or law enforcement: โ OSINT Industries (used by 5,000+ departments worldwide) โ IntelX for dark web and archived content
You just want to check your personal exposure for free: โ This tool. That's what it's for.
| Guide | Link |
|---|---|
| Full setup guide (API keys, step by step) | docs/setup.md |
| GitHub account + SSH setup | secure-your-repo |
| Code audit standards | code-audit |
This tool is for personal security awareness only.
โ Check your own accounts and credentials โ Educational use and learning โ Personal OPSEC and exposure monitoring โ Do not scan accounts you do not own โ Do not use for bulk or automated scanning of others
All source files pass the full audit stack:
black ยท flake8 ยท pylint 10/10 ยท mypy ยท bandit ยท pip-audit ยท detect-secrets ยท vulture ยท radon
Dependencies are pinned and CVE-free at time of release.
Original author: SudoCode by SudoChef (commit-issues)
Original repo: https://github.com/commit-issues/darkweb-exposure-toolkit
Created: April 2025
If you fork or build upon this work, you are required to retain the NOTICE file and original copyright notice in LICENSE per MIT License terms. Authorship is embedded in the source code, database, and signed git history.
MIT โ see LICENSE.
Built by SudoCode
Security first. Privacy always.