Trace a username across platforms
Find every account using a handle, then separate the ones that really belong to the same person.
- Starts with
- Username
- Useful for
- Threat actors, harassers, sock puppets, verifying someone's online identity.
- Time
- 30–90 minutes
- Progress
- 0 of 6 steps ·
Type a value into any step and every step of the same type fills in, with direct search links. Values stay in this tab and are not saved; only which steps you ticked is remembered, in your browser.
1. Sweep hundreds of sites
Why: People reuse handles. A broad sweep shows where to look closer.
Do: Run the username through two or three enumeration tools. They check different site lists, so combine the results.
Look for:- Accounts on niche sites, which are more likely to be the same person than common ones
- Accounts that exist on nearly every site, which suggests a common word rather than a person
2. Confirm the matches are one person
Why: A handle match alone proves nothing. Different people often share a username.
Do: Open each hit and compare profile photos, bios, locations, writing style, linked accounts and active hours.
Look for:- The same profile photo (reverse-search it in step 3)
- Links from one profile to another
- The same real name, city or employer
3. Reverse-search the profile photos
Why: A reused photo links accounts under different names, and a stock photo exposes a fake profile.
Do: Copy each profile photo's image address and search it.
Look for:- The same photo on accounts with other usernames
- The photo appearing on stock sites or someone else's profile
4. Dig into platform-specific history
Why: Some platforms keep history that reveals past names, deleted posts or activity patterns.
Do: Use the tools for the platforms where you found accounts.
Look for:- Previous usernames and display names
- Deleted Reddit posts and comments
- Posting times that suggest a time zone
5. Check criminal forums and marketplaces
Why: For threat-actor investigations, the same handle on underground forums links activity across them.
Do: Search the handle in threat-actor username data.
Look for:- The forums where the handle is active and since when
6. Pivot on what the profiles reveal
Why: Profiles often expose an email, website or real name that opens a new line of enquiry.
Do: Collect any email, domain or name you found and run the matching playbook.
Look for:- Contact emails in bios or GitHub commits
- Personal websites or domains