By OSINTScan Research•Published 2026-09-20•Last updated 2026-09-27

Sherlock vs. Maigret: Username Enumeration Architecture & Accuracy Comparison

First-party technical evaluation comparing Python CLI username scanners (Sherlock and Maigret) with browser-based multi-engine verification.

Evaluation Methodology & Scope

Evaluated using 10 test handles (5 existing multi-platform accounts, 3 mixed-case handles, and 2 non-existent random control strings) across public social, developer, and community endpoints.

Sample Scope: 10 test handles evaluated across public HTTP endpoints

Technical Comparison Matrix

DimensionOSINTScan (Web)Sherlock CLIMaigret CLI
Execution EnvironmentWeb browser (Server-Sent Events streaming)Python 3 CLI (local terminal)Python 3 CLI (local terminal)
Primary Detection MechanismHTTP status + positive/negative body signatures + soft-404 title filterstatus_code, message, or response_url per rulePresence/absence strings + recursive profile link extraction
Case-Sensitivity HandlingAutomatic lowercase normalization with exact-case fallbackPasses raw CLI argument unless manually re-runPasses raw CLI argument unless manually re-run
Single-Page Application (SPA) Soft-404 ProtectionExplicit mString & page title soft-404 suppressionSusceptible on status_code-only rulesModerated by presence string checks
Additional Identifier SupportUsername, Email Lookup, Email Breach, Phone LookupUsername onlyUsername and recursive profile tags
Report Export FormatsCSV and JSON in-browser exportTXT, CSV, JSON via CLI flagsHTML, PDF, XMind, TXT, JSON via CLI flags

How Sherlock and Maigret Differ Architecturally

Sherlock is designed as a lightweight, single-pass Python CLI utility that checks approximately 400+ public websites using three primary error-detection modes: HTTP status code (e.g. 200 vs 404), error message substring matching, and redirect URL inspection. Because many rules rely solely on HTTP 200 status codes, modern React and Next.js single-page applications (SPAs) that return HTTP 200 for missing profiles can produce false positives when run from datacenter or residential connections behind Cloudflare.

Maigret began as a fork of Sherlock and expanded the database to over 2,500 sites while introducing two major capabilities: dual presence/absence string verification (presenseStrs and absenceStrs) and profile metadata scraping (extracting links to other accounts directly from a found profile page). However, Maigret's larger site catalog increases scan duration and triggers rate limiting (HTTP 429) or WAF challenges on unproxied connections.

Where Browser-Based Multi-Engine Correlation Fits

Running Sherlock or Maigret requires installing Python, managing virtual environments, and keeping JSON rule definitions updated locally. OSINTScan executes curated rule sets from WhatsMyName, Sherlock, Maigret, and Blackbird concurrently in memory, deduplicating platform matches by canonical domain and applying strict soft-404 filtering before presenting results in a mobile-friendly web interface.

In our 10-handle test suite, mixed-case inputs (such as PascalCase usernames) caused standard CLI runs to miss oEmbed endpoints like TikTok that enforce lowercase handle URLs. Normalizing queries to lowercase first—and falling back to exact casing only when needed—eliminated casing discrepancies across all tested endpoints.

Known Limitations & Responsible Interpretation

  • CLI tools allow users to supply custom Tor/SOCKS5 proxies or authenticated session cookies locally, which a public zero-log web application does not accept for privacy and security reasons.
  • Sites protected by interactive CAPTCHAs or strict login walls cannot be verified automatically by any unauthenticated scanner and require manual browser verification.
All Comparisons