command one · identity, infrastructure & archive recon

Command One — find the person, the network and the history

Command One is an open-source-intelligence (OSINT) web app for people search and infrastructure recon. You sign in with your account, enter a username, email address, phone number, real name, domain, IP address, CIDR range or ASN, and Command One runs public-source checks — 165+ platforms probed natively in-console, and up to 3,000+ once the fleet modules join in — plus subdomain, DNS, live-host, port, ASN, exposure and archived-web stages for infrastructure targets. Everything merges into one case file with sources, confidence scores and exportable PDF or CSV reports.

Google sign-in is used only to create and access your Command One account: we read your name, email address and profile picture to identify you in the console. Command One never reads your Gmail, Drive or contacts.

free registration · public sources only

what this is

One console instead of twenty terminal windows

Identity work normally means juggling a dozen open-source scripts, each with its own install, output format and quirks — and infrastructure work means a second toolchain on top. Command One replaces both with one investigation surface: enter a username, email, phone number, name, domain, IP, ASN or CIDR range, and the console plans the right modules for that target. Subdomain discovery, DNS and HTTP fingerprinting, port scanning, ASN mapping and archived-web recovery feed the same entity graph as the identity sweeps, so an account and the server behind it end up in one case file.

Everything runs against public and licensed sources — no scraping behind logins. Each result keeps the source that produced it, so any conclusion can be traced back and re-verified by someone else. Free accounts get 50 credits a day; Premium Unlimited runs every module, including new ones as they ship, for £49.99 a month.

46

enabled modules

36

enabled fleet modules

1

workers online

51,096

source checks completed

14,394

findings normalised

coverage breakdown

Which platforms sit in the in-console checks, and which arrive with the fleet modules.

how it works

From identifier to case file in four moves

01

Acquire the target

Enter whatever you have — a username, email address, phone number, real name, domain, IP address, CIDR range or ASN. Command One picks the modules that can act on that identifier.

02

Run the sweep or recon pipeline

Identity targets fan out to a parallel sweep across public sources. Infrastructure targets run as an ordered pipeline instead, each stage feeding the next; heavier tools are dispatched to your own self-hosted worker fleet.

03

Correlate

Raw hits are normalised into unified entities — accounts, identities, hosts, addresses, services, archive snapshots — and linked by typed relationships. Matching entities merge and gain confidence.

04

Report

Each investigation becomes a case file with scan logs, per-source evidence, raw payloads and an audit trail you can hand over.

infrastructure & historical recon

Target, discover, correlate — one ordered pipeline

Each stage feeds the next instead of running blind: discovered hosts become resolution input, resolved addresses become probe input, and every result is folded into one connected model of entities and relationships you can pivot from. Historical stages read the archived web, so you can see what a target looked like years before today.

  1. 01passive

    Username sweep

    Handle enumeration across hundreds of platforms — Sherlock, Maigret, Snoop, WhatsMyName, socialscan, Blackbird, marple and Sylva.

  2. 02passive

    Account & email intel

    Where an address is registered, and what its Google profile exposes — Holehe, GHunt, mosint, email2phonenumber.

  3. 03passive

    Phone intel

    Carrier, line format and account registration signals — PhoneInfoga and Ignorant.

  4. 04passive

    Social footprint

    Profile detail and public posting activity on the accounts the sweep found — Social Analyzer, snscrape, Toutatis, Osintgram, NetSoc, CupidCr4wl.

  5. 05passive

    Subdomain discovery

    Passive enumeration across certificate transparency and index providers.

  6. 06passive

    DNS resolution

    A, AAAA, CNAME, MX, NS, TXT and PTR records for every discovered host.

  7. 07passive

    Live hosts

    HTTP/HTTPS probing — status, title, server, TLS, technologies and CDN.

  8. 08authorized targets only

    Ports & services

    Authorized TCP discovery over resolved addresses.

  9. 09passive

    ASN & network

    Autonomous system, owning organization and announced prefixes.

  10. 10passive

    Shodan enrichment

    Previously observed services, products, versions and banner metadata.

  11. 11passive

    Historical web

    Archived URLs, paths, parameters and assets across time.

  12. 12passive

    Cross-source correlation

    Broad multi-source sweep that ties identity and infrastructure findings together.

modules

What you can run

Infrastructure recon

One target — domain, host, IP, CIDR range or ASN — mapped end to end by an ordered pipeline: subfinder subdomains, dnsx resolution, httpx live hosts and TLS, authorized naabu port discovery, asnmap ownership and Shodan exposure.

How subdomain discovery works

Username sweep

Native probes across 150+ platforms, plus Sherlock, Maigret, Snoop, Blackbird, socialscan and WhatsMyName on the worker fleet — all confidence scored.

How reverse username lookup works

Email recon

Mail-exchange validation, disposable-provider detection, Gravatar discovery, handle derivation and Holehe registration checks across hundreds of services.

How reverse email lookup works

Phone intelligence

E.164 normalisation, country and carrier hints, then Ignorant registration checks against messaging and consumer platforms.

Inside phone number OSINT

Archive recon

waybackurls and gau replay everything the archived web still remembers about a host: a year-bucketed timeline of URLs, paths, extensions and parameters, plus a "what changed" panel comparing the archive against today's live observation.

Domain surface

DNS records, certificate-transparency subdomains, plus theHarvester and Sublist3r passive enumeration for the full external footprint.

How the subdomain finder works

Identity expansion

Turn a real name into ranked handle candidates and sweep each one; GHunt resolves Google account artefacts from an address.

Multi-source correlation modules

New on the fleet: Sylva pivots a handle, email or phone across dozens of aggregated sources, Social Analyzer scores profile matches 0-100%, and CupidCr4wl sweeps dating-platform surfaces.

Instagram & social post intel

Toutatis and Osintgram pull Instagram account artefacts — obfuscated email and phone hints, ids, bio and follower counters — while snscrape harvests public social posts for a name or handle.

Deep email pivots

mosint aggregates multi-source email reconnaissance in one pass, and email2phonenumber recovers masked recovery-number digits from provider password-reset flows.

Verify Link Pack

Instant, native: a curated Social-Media-OSINT toolbox of manual verification links — Facebook, X, Instagram, TikTok, LinkedIn, Reddit, Telegram, WhatsApp, search dorks, Wayback, WHOIS and company registers.

CommandDeck analyst workspace

A dedicated workspace — not a panel inside a case — where any investigation becomes a pan-and-zoom relationship graph you can filter by confidence, collapse into clusters, and annotate with notes, flags, tags, manual links and private evidence. Your layout, zoom and filters are saved per case.

Inside CommandDeck

Web Intelligence bundle

The newest worker bundle: Wayback CDX rebuilds a host's archived URL history, urlscan.io returns submitted scans, page structure and observed infrastructure, and VirusTotal adds reputation, resolutions and related domains — chained as domain → IP → ASN → certificate → archived URL.

Premium data sources

Intelligence X searches leak, darknet and archive collections (20 credits), and Phone Intelligence returns carrier, line type, risk scoring and SMS gateway data (15 credits). Both run on purchased credits.

Correlation & unified findings

SpiderFoot correlation feeds the same schema as every other module: deduplicated entities, filterable facets, CSV and branded PDF case reports.

Tool credits and licences are listed on the credits page.

module roster

All 46 modules and what they cost

Native modules run the moment you hit go. Fleet modules dispatch to a self-hosted worker, and API modules call a keyed provider server-side. Modules marked are premium and draw on purchased credits — see what the premium modules do.

Native — instant, no setup

  • Username Sweep2 cr · native

    300+ platforms, per-site rules

  • Email Recon1 cr · native

    MX, disposable, Gravatar

  • Phone Recon1 cr · native

    parsing, country, line type

  • Name Expander3 cr · native

    handle candidates from a name

  • Domain Recon1 cr · native

    DNS, MX, certificate surface

  • Verify Link Pack1 cr · native

    manual verification URLs

  • Intelligence X20 cr · native

    leak, darknet and archive search

  • BreachDirectory15 cr · native

    breach exposure and hash hints

  • Phone Intelligence15 cr · native

    carrier, line type, routing

Worker fleet — open-source tools

  • Sherlock3 cr · fleet

    400+ site username hunt

  • Maigret5 cr · fleet

    3000+ site dossier

  • Snoop4 cr · fleet

    large-scale enumeration

  • WhatsMyName2 cr · fleet

    community site list

  • Blackbird1 cr · fleet

    username + email sweep

  • socialscan1 cr · fleet

    official signup endpoints

  • Holehe1 cr · fleet

    120+ email registrations

  • Ignorant1 cr · fleet

    phone-number accounts

  • GHunt4 cr · fleet

    Google account artefacts

  • Sylva3 cr · fleet

    multi-source correlation

  • Social Analyzer4 cr · fleet

    ~350 sites, match rating

  • CupidCr4wl3 cr · fleet

    dating-platform sweep

  • SpiderFoot8 cr · fleet

    200+ modules, correlation

  • theHarvester1 cr · fleet

    emails and hosts per domain

  • Sublist3r1 cr · fleet

    passive subdomains

  • Toutatis4 cr · fleet

    Instagram account artefacts

  • Osintgram4 cr · fleet

    Instagram profile intel

  • snscrape3 cr · fleet

    public social post scraping

  • mosint4 cr · fleet

    multi-source email recon

  • email2phonenumber3 cr · fleet

    masked recovery digits

  • PhoneInfoga3 cr · fleet

    phone footprint + carrier

  • marple3 cr · fleet

    search-engine username hunt

  • NetSoc OSINT2 cr · fleet

    social network sweep

  • OWASP Amass4 cr · fleet

    attack-surface mapping

  • recon-ng4 cr · fleet

    hosts and contacts framework

  • bbot4 cr · fleet

    recursive attack-surface scan

  • xnLinkFinder3 cr · fleet

    links, endpoints, parameters

  • git-hound4 cr · fleet

    public GitHub code leaks

  • ExifTool2 cr · fleet

    image and document metadata

  • sn0int4 cr · fleet

    scriptable source correlation

Infrastructure & archive pipeline

  • subfinder2 cr · fleet

    passive subdomain discovery

  • dnsx2 cr · fleet

    A, AAAA, CNAME, MX, NS, TXT

  • httpx3 cr · fleet

    live hosts, titles, tech, TLS

  • naabu5 cr · fleet

    authorized port discovery, public IPs only

  • asnmap2 cr · fleet

    ASN owner and announced prefixes

  • Shodan4 cr · api

    exposed services and banners per IP

  • waybackurls2 cr · fleet

    Wayback Machine URL history

  • gau3 cr · fleet

    archive URLs from multiple indexes

new in the console

Features beyond the run

CommandDeck workspace

Its own authenticated workspace with a case selector: pan, zoom and drag the graph, search and filter by confidence, collapse clusters, and keep the arrangement you built — layout, zoom and filter state are saved per case and restored on any device.

Analyst notes, flags & tags

Record your reasoning against the evidence itself. Notes, flags and tags persist with the case and stay private to your account; raw scan findings are never edited.

Manual links & private evidence

Draw the relationships you believe hold — rendered visually distinct from collected evidence — and attach screenshots or documents to the case in private storage.

Source provenance & confidence

Every finding keeps its module, raw payload, timestamp and confidence score, so any claim can be traced to the source that produced it and independently re-checked.

Reliable exports

PDF case reports and CSV exports save properly on the web and in the mobile apps — written to your device and handed to the system share sheet, with an honest result either way.

Watchlists

Save targets you care about and re-sweep them on a schedule; new findings surface as changes against the last run rather than a fresh pile of results.

Scan notifications

In-app alerts when a sweep finishes, plus an email summary from notify.com1.cloud so long worker jobs don't need babysitting.

Shareable case files

Generate a read-only link to a case so a colleague or client can review the findings and evidence without an account — revoke it any time.

Credits meter & billing

The header meter shows your daily allowance, its reset countdown and your purchased balance separately. Top up, review purchase history and manage your account in one place.

working the results

Filter, corroborate, export

Faceted intel feed

Slice every finding by category, module, execution mode, target type, case, confidence band or recency — with a socials-only shortcut for footprint work.

Grouping & sorting

Group results by category, module, target, case or confidence, and sort by confidence, corroboration, recency or platform.

Corroboration scoring

Independent modules that agree on the same entity merge into one record and lift its confidence; single-source hits stay flagged as leads.

Evidence trail

Each record keeps its source module, raw payload and timestamps, so anything you report can be re-verified by someone else.

Reports & sharing

Export the visible set as CSV, generate a branded PDF case file with executive summary and findings register, or hand over a revocable read-only link.

CommandDeck workspace

Open any case in the dedicated CommandDeck workspace to pan, zoom, filter, cluster and annotate the relationship graph without changing the underlying scan evidence.

Agent integration

A read-only agent endpoint lets your own AI tooling list cases and search findings under your account, secured with OAuth.

who uses it

Built for verification work

Due diligence

Verify that a counterparty, contractor or applicant is who they claim to be before you sign.

Fraud & trust and safety

Link throwaway accounts, spot recycled handles and map the infrastructure behind a scam network.

Journalism & research

Trace a public figure's footprint across platforms with citable sources for every claim.

Personal exposure audit

Run yourself as the target and see exactly what an outsider can assemble about you.

pricing

Free every day, top up when you need more

Standard modules run on your free daily allowance. Premium modules — paid data sources such as Intelligence X, BreachDirectory and Phone Intelligence — run on purchased credits.

free

£0

forever

  • 50 credits refreshed every day at 00:00 UTC
  • All standard OSINT modules
  • Unified intel feed, CSV and PDF case files
  • Watchlists and shareable read-only cases

credit top-up

£4.99

per 50 credits · one-off

  • 50 purchased credits, no daily expiry
  • Unlocks premium paid-source modules
  • Buy up to 10 packs at a time
  • 30-day money-back guarantee
Get started

premium unlimited

£49.99

per month · cancel any time

  • Every module unlocked — no credits deducted
  • New modules included as they ship
  • Paid data sources included
  • Fair use: 50 searches per day
See Premium Unlimited

Prices in GBP. Orders are processed by our reseller Paddle.com, the Merchant of Record for all orders. See our refund policy.

mobile

Take the console with you

The native app carries the same case files, credits balance and CommandDeck workspace, with pinch-to-zoom on the graph and verified PDF or CSV exports saved straight to your device.

Get it on Google Play
iOS app — coming soon

rules of engagement

Public sources, logged actions, lawful use

  • Only openly accessible sources are queried — nothing behind a login or paywall.
  • Every scan is written to an audit trail tied to the account that launched it.
  • Results are signals, not proof. Treat a hit as a lead to verify, never as a conclusion about a person.
  • Harassment, stalking and unlawful profiling are grounds for immediate account termination.