Pick almost any username and it leaves a shadow across the web: forums, game platforms, code hosts, social networks. Nexfil, written by thewhiteh4t, is a compact open source OSINT tool built around one well-defined job: given a username, check it against hundreds of platforms and report where profiles exist. The README sets two goals, speed and precision, and the numbers back the ambition. A lookup can finish in under twenty seconds, and the tool ships 328 platform definitions inside a single JSON store, each paired with a strategy for telling a real profile from a dead end.
The engineering is where this project gets interesting. Rather than treating every website the same, nexfil encodes nine different detection approaches: plain HEAD requests, body-marker checks, redirect probes, JSON API lookups, alternate-URL checks, subdomain comparisons, tldextract-based URL analysis, GET-versus-404 fallbacks, and a headless Chrome path for sites that hide behind JavaScript or Cloudflare. All of them run concurrently on asyncio with aiohttp, share one progress counter, and funnel hits into the same colored terminal output and the same text report. It is a small codebase, but every file has exactly one job.
As with every tool in this series, this is an educational tour of source code, not a manual for digging into private individuals. Username enumeration is powerful and easy to abuse, so treat nexfil the way its license and community intend: for research, authorized investigations, and understanding your own digital footprint. The author’s README positions the tool for OSINT work, and responsible use means respecting platform terms and the privacy of real people while you study how the detection machinery works.
Nexfil at a glance: one CLI, one async core, nine detection tests, and a shared hit bucket feeding colored output and a text report.
Reading the overview from left to right:
- The run starts at src/nexfil/cli.py, which parses -u, -f, -l, timeout, and proxy flags, then validates the input mode.
- src/nexfil/url_store.json holds the 328 platform blocks, each with a URL template, a test name, and optional data.
- The async core in src/nexfil/cli.py builds one aiohttp session, one headless driver, and one asyncio task per platform.
- src/nexfil/method.py, src/nexfil/string_case.py, src/nexfil/redirect.py, src/nexfil/api.py, and src/nexfil/headless.py implement the detection strategies.
- src/nexfil/share.py holds the found, timedout, and error buckets plus a global progress counter.
- src/nexfil/printer.py turns every confirmed hit into a colored URL line.
- Back in cli.py, the autosave routine writes the session report to a timestamped text file.
Why You Need This
The first reason is recon literacy. Username correlation is one of the foundational moves in open-source intelligence, and nexfil shows what that actually means at the HTTP level: there is no magic database behind it, just hundreds of careful decisions about how each site signals that a profile exists. Reading the URL store alone is an education, because every entry documents one site’s quirk, whether that is a JSON endpoint that returns an empty array for missing users or a redirect that only fires for real accounts.
The second reason is that nexfil is a masterclass in low false-positive engineering. The naive version of this tool marks any non-404 as a hit and drowns you in soft-404 pages and anti-bot interstitials. Nexfil instead matches a test type to each platform’s actual behavior: some sites get a marker-string check where the hit is declared only when the not-found text is absent, others get a redirect comparison, others get a JSON field inspection, and the hardest ones get a real browser session. The result is a report you can actually trust without re-verifying every line.
The third reason is defensive relevance. If you pick usernames casually, this tool shows exactly how quickly those choices connect your identities across platforms. Running it against your own handles, or simply reading the store to see how many services are enumerated, is a fast way to appreciate why security guides recommend distinct usernames for sensitive accounts. Awareness here is practical, not theoretical.
How It Works
Inside nexfil: the CLI modes, the aiohttp task fan-out, all nine tests, and the shared buckets behind the report.
Understanding the Architecture
A CLI with three input modes and an update check. The entrypoint builds an argparse parser with the username flag, a file flag, a comma-separated list flag, a timeout that defaults to ten seconds, and four proxy options covering mode, protocol, host, and port. With the -U flag the same file takes a detour into chk_update, which fetches a metadata JSON from the project’s repository and compares versions using the packaging library. Input validation is blunt and effective: no username anywhere produces a usage hint, and a list without a comma is rejected outright. On Windows the code sets the selector event loop policy and treats the working directory as home, which keeps paths working outside Unix conventions.
One store of 328 platform definitions. The url_store.json file is the heart of the project: a flat list of blocks, each carrying a URL template with a placeholder for the username, a test name that selects the detection strategy, and optional data such as a marker string or an XPath pair. At startup the CLI loads the store and prints the count. The distribution tells the design story: 204 platforms use the plain default HEAD check, 64 use body markers, 21 use redirect probes, 18 need the headless browser, 8 use JSON APIs, 7 use the GET method test, 4 use URL analysis, and one each use subdomain and alternate-URL tests.
An async core that fans out hundreds of tasks. The main routine creates an aiohttp ClientSession with a TCPConnector that skips SSL verification, a Chrome-style user agent, and connect and read timeouts from the -t flag. Detection then proceeds in parallel: for every block, the URL template is formatted with the username and an asyncio task is created, and one gather call waits for all of them. Before the requests fly, the code tries to start undetected_chromedriver in headless mode with the eager page-load strategy, and if the module or Chrome itself is missing it downgrades gracefully, warning that some sites will be skipped rather than failing the whole run.
A dispatcher that matches site behavior to test type. The query coroutine is the fork in the road. For blocks without a test name it sends a HEAD request with redirects allowed and declares a hit when the status lands in the accepted set of 200, 301, 302, 405, and 418. A 404 on a method-tagged platform triggers a full GET recheck, and any other unexpected status lands in the error bucket. The named tests each get their own module and their own tolerance for site quirks, while every coroutine increments the shared counter so the progress line keeps ticking even when platforms time out.
Nine strategies for nine kinds of websites. The method test GETs the profile URL and calls it a hit whenever the response is not a 404. The string test goes further: it accepts a small set of status codes and declares a hit only when the platform’s not-found marker text is absent from the body, which is exactly the kind of asymmetry that filters soft-404s. The redirect test disables redirects and compares the Location header against the original URL, treating a missing header as a hit. The api test requests a JSON endpoint and scans for non-empty results, users, or username fields; the alt test probes an alternate URL and expects a 200. The url test uses tldextract to compare the final URL against the site’s registered domain, catching platforms that silently land you on a search page, and the subdomain test simply checks whether the response URL stayed on the expected subdomain.
A real browser for the stubborn sites. For the 18 headless-tagged platforms, the driver visits the URL and headless.py waits with selenium’s WebDriverWait on an any-of condition matching either the found or the not-found XPath from the store. There is explicit Cloudflare awareness: if the page title reads like an interstitial, the code waits it out, and if the attempt fails it checks the page source for a Ray ID before logging that the bypass failed. This is the difference between a tool that works on modern sites and one that quietly lies about them.
Shared state, colored output, and one honest report. Every hit funnels through clout in printer.py, which highlights the domain in yellow, prints the URL, and appends it to the shared found list. Timeouts and client errors land in their own buckets with details appended to an exceptions log through a small logging wrapper. When the gather finishes, the CLI prints elapsed time and the three totals, and autosave writes a timestamped text file into the dumps directory containing the username, start and end times, hit and timeout counts, and every found URL. Nothing found is lost and nothing is exaggerated.
End to end. One command loads 328 definitions, formats each URL, fans out concurrent tasks across nine strategies, and merges everything into a colored terminal stream and a single text report. The design is a flat flow of independent checks with shared accounting, which is why a codebase this small can cover this much ground without becoming fragile.
Advantages
- Genuinely fast. Hundreds of concurrent aiohttp requests finish a full sweep in seconds, matching the README’s under-twenty-seconds claim for a lookup.
- Nine detection strategies. Matching the test type to each platform’s behavior keeps false positives low instead of treating every non-404 as a profile.
- Graceful degradation. A missing Chrome or driver module only disables headless checks; the other 300-plus platforms still run.
- Shared accounting. Hits, timeouts, and errors are counted separately, so the final report distinguishes absence from failure.
- Zero-config batch mode. Single usernames, comma lists, and files all work through the same core, and every session autosaves to disk.
- Transparent definitions. The entire platform catalog is a readable JSON file you can inspect, extend, or prune yourself.
Benefits
- Map your own exposure. Checking your handles shows in seconds how many platforms tie those names to you.
- Learn async Python patterns. Task fan-out, shared counters, timeout buckets, and graceful driver fallbacks are all textbook-quality asyncio practice.
- Understand anti-false-positive design. Marker-absence checks, redirect comparisons, and JSON field probes are reusable techniques for any presence-testing tool.
- See modern OSINT honestly. The store makes explicit how much of username enumeration is patient, per-site protocol work rather than magic.
- Reuse the store format. The url, test, and data block schema is a clean template for your own platform lists.
- Small enough to audit. MIT-licensed and compact, the whole detection engine fits in a dozen short files.
Usage
Installation follows the README:
pip install nexfil
Single usernames, comma-separated lists, and username files all use the same engine:
nexfil -u username
nexfil -l "user1,user2"
nexfil -f users.txt
Timeout and proxy behavior are controlled with flags, and -U checks for a newer release:
nexfil -u username -t 5
nexfil -u username -pm single -proto http -ph 127.0.0.1 -pp 8080
nexfil -U
Results print live with highlighted domains and are written to a timestamped text file in the nexfil dumps directory under your local share path.
Conclusion
Nexfil proves that a focused tool with honest engineering beats a sprawling one every time. Its entire intelligence lives in 328 declarative platform blocks, its entire speed comes from unglamorous asyncio fan-out, and its accuracy comes from matching nine small detection strategies to how real websites actually behave. The architecture is easy to hold in your head, the code is easy to audit, and the report is easy to trust, which is a rare combination in this space. Study it for the async patterns, borrow the store format for your own tooling, and use it, as the author intends, for legitimate OSINT work on targets you are authorized to investigate.
Links:
Enjoyed this post? Never miss out on future posts by following us