For the complete documentation index, see llms.txt. This page is also available as Markdown.

Zen

Tool Description : Finds email addresses of GitHub users.

Zen

Quick Overview

What it does

Takes an email address and investigates GitHub for accounts, activity, and public repositories associated with it.

How to use it

Run the tool from the command line with a target email.

Cost

Free.

Account required

No.

Cookies

None (runs locally in your environment).

Ownership

Developed by Somdev Sangwan (s0md3v), a well-known security researcher and developer from India.

Use in Reporting

Ideal for linking emails to GitHub accounts, profiling suspicious users, and documenting malicious activity for investigative reports.

What does Zen do?

Zen automates email-based OSINT on GitHub. Instead of manually searching for a suspicious email across GitHub, it quickly reveals accounts, repositories, and activity linked to that email, making research faster and more accurate.

The lowdown: It’s a fast, free OSINT tool for linking emails to GitHub accounts and activity.

How to Use:

1. Clone the Zen repository from GitHub.

2. Install required dependencies.

3. Run the tool with a target email address and review the output for GitHub usernames, public repos, and activity.

Example command to find email address of a user:

python zen.py username

You can view our detailed guide to Zen in The OSINT Newsletter here.

Cost

Data Processing

Account Required:

Cookies:

None (runs locally in your environment).

Use in Reporting

Zen can be used to:

  • Link email addresses to GitHub accounts.

  • Identify suspicious or malicious users.

  • Gather evidence of activity for investigations.

  • Enrich OSINT profiles with verified GitHub data.

  • Document findings in cybersecurity or international crime reports.

You can view some detailed use cases via The OSINT Newsletter here.

Capabilities

Limitations

Email-based GitHub account discovery.

Only works for GitHub accounts linked to an email.

Public repository and activity monitoring.

Cannot access private/unlinked accounts.

Quick identification of suspicious users.

CLI-based so requires command-line knowledge.

Fast, automated workflow.

Possible false positives so results need verification.

Limited to GitHub - doesn’t cover other platforms.

Summary

Zen is best used in the analysis and enrichment stage of the OSINT workflow, particularly useful for investigating malicious actors, documenting suspicious behavior, and enriching OSINT profiles in cybersecurity or international crime research.

Ownership

Developed by Somdev Sangwan (s0md3v), a well-known security researcher and developer from India.

Ethical Considerations

  • Only investigate emails you are authorized to research.

  • Avoid harassing or doxxing users.

  • Use findings responsibly in investigations or reporting.

  • Respect privacy and legal boundaries when documenting accounts.

  • Sherlock

  • TruffleHog

  • SpiderFoot

Sources

https://github.com/s0md3v/Zen

https://osintnewsletter.com/p/zen

https://github.com/s0md3v

https://www.linkedin.com/in/s0md3v/

https://x.com/s0md3v

Last updated

Was this helpful?