Acquire the target
Enter whatever you have — a username, email address, phone number, real name, domain, IP address, CIDR range or ASN. Command One picks the modules that can act on that identifier.
command one · identity, infrastructure & archive recon
Command One is an open-source-intelligence (OSINT) web app for people search and infrastructure recon. You sign in with your account, enter a username, email address, phone number, real name, domain, IP address, CIDR range or ASN, and Command One runs public-source checks — 165+ platforms probed natively in-console, and up to 3,000+ once the fleet modules join in — plus subdomain, DNS, live-host, port, ASN, exposure and archived-web stages for infrastructure targets. Everything merges into one case file with sources, confidence scores and exportable PDF or CSV reports.
Google sign-in is used only to create and access your Command One account: we read your name, email address and profile picture to identify you in the console. Command One never reads your Gmail, Drive or contacts.
free registration · public sources only
share this page
what this is
Identity work normally means juggling a dozen open-source scripts, each with its own install, output format and quirks — and infrastructure work means a second toolchain on top. Command One replaces both with one investigation surface: enter a username, email, phone number, name, domain, IP, ASN or CIDR range, and the console plans the right modules for that target. Subdomain discovery, DNS and HTTP fingerprinting, port scanning, ASN mapping and archived-web recovery feed the same entity graph as the identity sweeps, so an account and the server behind it end up in one case file.
Everything runs against public and licensed sources — no scraping behind logins. Each result keeps the source that produced it, so any conclusion can be traced back and re-verified by someone else. Free accounts get 50 credits a day; Premium Unlimited runs every module, including new ones as they ship, for £49.99 a month.
46
enabled modules
36
enabled fleet modules
1
workers online
51,096
source checks completed
14,394
findings normalised
coverage breakdown
Which platforms sit in the in-console checks, and which arrive with the fleet modules.
how it works
Acquire the target
Enter whatever you have — a username, email address, phone number, real name, domain, IP address, CIDR range or ASN. Command One picks the modules that can act on that identifier.
Run the sweep or recon pipeline
Identity targets fan out to a parallel sweep across public sources. Infrastructure targets run as an ordered pipeline instead, each stage feeding the next; heavier tools are dispatched to your own self-hosted worker fleet.
Correlate
Raw hits are normalised into unified entities — accounts, identities, hosts, addresses, services, archive snapshots — and linked by typed relationships. Matching entities merge and gain confidence.
Report
Each investigation becomes a case file with scan logs, per-source evidence, raw payloads and an audit trail you can hand over.
infrastructure & historical recon
Each stage feeds the next instead of running blind: discovered hosts become resolution input, resolved addresses become probe input, and every result is folded into one connected model of entities and relationships you can pivot from. Historical stages read the archived web, so you can see what a target looked like years before today.
Username sweep
Handle enumeration across hundreds of platforms — Sherlock, Maigret, Snoop, WhatsMyName, socialscan, Blackbird, marple and Sylva.
Account & email intel
Where an address is registered, and what its Google profile exposes — Holehe, GHunt, mosint, email2phonenumber.
Phone intel
Carrier, line format and account registration signals — PhoneInfoga and Ignorant.
Social footprint
Profile detail and public posting activity on the accounts the sweep found — Social Analyzer, snscrape, Toutatis, Osintgram, NetSoc, CupidCr4wl.
Subdomain discovery
Passive enumeration across certificate transparency and index providers.
DNS resolution
A, AAAA, CNAME, MX, NS, TXT and PTR records for every discovered host.
Live hosts
HTTP/HTTPS probing — status, title, server, TLS, technologies and CDN.
Ports & services
Authorized TCP discovery over resolved addresses.
ASN & network
Autonomous system, owning organization and announced prefixes.
Shodan enrichment
Previously observed services, products, versions and banner metadata.
Historical web
Archived URLs, paths, parameters and assets across time.
Cross-source correlation
Broad multi-source sweep that ties identity and infrastructure findings together.
modules
One target — domain, host, IP, CIDR range or ASN — mapped end to end by an ordered pipeline: subfinder subdomains, dnsx resolution, httpx live hosts and TLS, authorized naabu port discovery, asnmap ownership and Shodan exposure.
How subdomain discovery works →Native probes across 150+ platforms, plus Sherlock, Maigret, Snoop, Blackbird, socialscan and WhatsMyName on the worker fleet — all confidence scored.
How reverse username lookup works →Mail-exchange validation, disposable-provider detection, Gravatar discovery, handle derivation and Holehe registration checks across hundreds of services.
How reverse email lookup works →E.164 normalisation, country and carrier hints, then Ignorant registration checks against messaging and consumer platforms.
Inside phone number OSINT →waybackurls and gau replay everything the archived web still remembers about a host: a year-bucketed timeline of URLs, paths, extensions and parameters, plus a "what changed" panel comparing the archive against today's live observation.
DNS records, certificate-transparency subdomains, plus theHarvester and Sublist3r passive enumeration for the full external footprint.
How the subdomain finder works →Turn a real name into ranked handle candidates and sweep each one; GHunt resolves Google account artefacts from an address.
New on the fleet: Sylva pivots a handle, email or phone across dozens of aggregated sources, Social Analyzer scores profile matches 0-100%, and CupidCr4wl sweeps dating-platform surfaces.
Toutatis and Osintgram pull Instagram account artefacts — obfuscated email and phone hints, ids, bio and follower counters — while snscrape harvests public social posts for a name or handle.
mosint aggregates multi-source email reconnaissance in one pass, and email2phonenumber recovers masked recovery-number digits from provider password-reset flows.
Instant, native: a curated Social-Media-OSINT toolbox of manual verification links — Facebook, X, Instagram, TikTok, LinkedIn, Reddit, Telegram, WhatsApp, search dorks, Wayback, WHOIS and company registers.
A dedicated workspace — not a panel inside a case — where any investigation becomes a pan-and-zoom relationship graph you can filter by confidence, collapse into clusters, and annotate with notes, flags, tags, manual links and private evidence. Your layout, zoom and filters are saved per case.
Inside CommandDeck →The newest worker bundle: Wayback CDX rebuilds a host's archived URL history, urlscan.io returns submitted scans, page structure and observed infrastructure, and VirusTotal adds reputation, resolutions and related domains — chained as domain → IP → ASN → certificate → archived URL.
Intelligence X searches leak, darknet and archive collections (20 credits), and Phone Intelligence returns carrier, line type, risk scoring and SMS gateway data (15 credits). Both run on purchased credits.
SpiderFoot correlation feeds the same schema as every other module: deduplicated entities, filterable facets, CSV and branded PDF case reports.
Tool credits and licences are listed on the credits page.
module roster
Native modules run the moment you hit go. Fleet modules dispatch to a self-hosted worker, and API modules call a keyed provider server-side. Modules marked are premium and draw on purchased credits — see what the premium modules do.
Native — instant, no setup
300+ platforms, per-site rules
MX, disposable, Gravatar
parsing, country, line type
handle candidates from a name
DNS, MX, certificate surface
manual verification URLs
leak, darknet and archive search
breach exposure and hash hints
carrier, line type, routing
Worker fleet — open-source tools
400+ site username hunt
3000+ site dossier
large-scale enumeration
community site list
username + email sweep
official signup endpoints
120+ email registrations
phone-number accounts
Google account artefacts
multi-source correlation
~350 sites, match rating
dating-platform sweep
200+ modules, correlation
emails and hosts per domain
passive subdomains
Instagram account artefacts
Instagram profile intel
public social post scraping
multi-source email recon
masked recovery digits
phone footprint + carrier
search-engine username hunt
social network sweep
attack-surface mapping
hosts and contacts framework
recursive attack-surface scan
links, endpoints, parameters
public GitHub code leaks
image and document metadata
scriptable source correlation
Infrastructure & archive pipeline
passive subdomain discovery
A, AAAA, CNAME, MX, NS, TXT
live hosts, titles, tech, TLS
authorized port discovery, public IPs only
ASN owner and announced prefixes
exposed services and banners per IP
Wayback Machine URL history
archive URLs from multiple indexes
new in the console
CommandDeck workspace
Its own authenticated workspace with a case selector: pan, zoom and drag the graph, search and filter by confidence, collapse clusters, and keep the arrangement you built — layout, zoom and filter state are saved per case and restored on any device.
Analyst notes, flags & tags
Record your reasoning against the evidence itself. Notes, flags and tags persist with the case and stay private to your account; raw scan findings are never edited.
Manual links & private evidence
Draw the relationships you believe hold — rendered visually distinct from collected evidence — and attach screenshots or documents to the case in private storage.
Source provenance & confidence
Every finding keeps its module, raw payload, timestamp and confidence score, so any claim can be traced to the source that produced it and independently re-checked.
Reliable exports
PDF case reports and CSV exports save properly on the web and in the mobile apps — written to your device and handed to the system share sheet, with an honest result either way.
Watchlists
Save targets you care about and re-sweep them on a schedule; new findings surface as changes against the last run rather than a fresh pile of results.
Scan notifications
In-app alerts when a sweep finishes, plus an email summary from notify.com1.cloud so long worker jobs don't need babysitting.
Shareable case files
Generate a read-only link to a case so a colleague or client can review the findings and evidence without an account — revoke it any time.
Credits meter & billing
The header meter shows your daily allowance, its reset countdown and your purchased balance separately. Top up, review purchase history and manage your account in one place.
working the results
Faceted intel feed
Slice every finding by category, module, execution mode, target type, case, confidence band or recency — with a socials-only shortcut for footprint work.
Grouping & sorting
Group results by category, module, target, case or confidence, and sort by confidence, corroboration, recency or platform.
Corroboration scoring
Independent modules that agree on the same entity merge into one record and lift its confidence; single-source hits stay flagged as leads.
Evidence trail
Each record keeps its source module, raw payload and timestamps, so anything you report can be re-verified by someone else.
Reports & sharing
Export the visible set as CSV, generate a branded PDF case file with executive summary and findings register, or hand over a revocable read-only link.
CommandDeck workspace
Open any case in the dedicated CommandDeck workspace to pan, zoom, filter, cluster and annotate the relationship graph without changing the underlying scan evidence.
Agent integration
A read-only agent endpoint lets your own AI tooling list cases and search findings under your account, secured with OAuth.
who uses it
Due diligence
Verify that a counterparty, contractor or applicant is who they claim to be before you sign.
Fraud & trust and safety
Link throwaway accounts, spot recycled handles and map the infrastructure behind a scam network.
Journalism & research
Trace a public figure's footprint across platforms with citable sources for every claim.
Personal exposure audit
Run yourself as the target and see exactly what an outsider can assemble about you.
pricing
Standard modules run on your free daily allowance. Premium modules — paid data sources such as Intelligence X, BreachDirectory and Phone Intelligence — run on purchased credits.
free
£0
forever
credit top-up
£4.99
per 50 credits · one-off
premium unlimited
£49.99
per month · cancel any time
Prices in GBP. Orders are processed by our reseller Paddle.com, the Merchant of Record for all orders. See our refund policy.
mobile
The native app carries the same case files, credits balance and CommandDeck workspace, with pinch-to-zoom on the graph and verified PDF or CSV exports saved straight to your device.
rules of engagement