WhatsMyName vs. Sherlock: Signature Accuracy & False-Positive Analysis
Analyzing why dual-fingerprint rules (eCode + eString + mCode + mString) reduce false positives compared to status-code-only checks.
Evaluation Methodology & Scope
Audited rule definitions across WhatsMyName (wmn-data.json) and Sherlock (data.json) against live HTTP responses from social networks, developer registries, and CDN-protected endpoints.
Sample Scope: 720 curated WhatsMyName rules vs 400+ Sherlock site rules
Technical Comparison Matrix
| Dimension | OSINTScan (Hybrid Engine) | WhatsMyName Schema | Sherlock Schema |
|---|---|---|---|
| Rule Schema Structure | Unified eCode/eString + mCode/mString + WAF & soft-404 classifier | Four-part schema (e_code, e_string, m_code, m_string) | Single-polarity errorType (status_code, message, or response_url) |
| False-Positive Resistance | High — requires positive body signature and absence of soft-404 markers | High — explicitly validates both existence and missing strings | Moderate — status_code rules can misclassify 200 OK error shells |
| Platform Categorization | Social, Coding, Gaming, Video, Music, Forum, Finance, Business | Categorized by industry/topic in wmn-data | Flat alphabetical dictionary in standard data.json |
| Interactive Web Filtering & Export | Live confidence filtering, category tabs, CSV/JSON export | Community web mirrors vary in maintenance | CLI output only |
Why Dual-Polarity Fingerprints Matter in OSINT
The most common failure mode in automated username enumeration is the 'Soft 404': a web server returns HTTP 200 OK even when an account does not exist, rendering a generic 'User not found' template or an empty JavaScript application shell. Tools that rely solely on checking whether HTTP status equals 200 will falsely report that the target username exists on dozens of platforms.
WhatsMyName pioneered the four-part rule specification: every platform defines both what a valid profile looks like (expected HTTP code e_code and expected body substring e_string) and what a missing account looks like (missing HTTP code m_code and missing body substring m_string). If a server returns HTTP 200 during a Cloudflare challenge or soft-404 page, the classifier sees that e_string is absent—or that m_string is present—and refuses to mark the account as FOUND.
How OSINTScan Combines Both Ecosystems
OSINTScan uses the four-part WhatsMyName fingerprint specification as its primary verification standard across 720 cataloged rules, while cross-validating results against Sherlock, Maigret, and Blackbird signatures. When multiple engines confirm the same canonical domain, OSINTScan merges the evidence into a single deduplicated card and elevates the match confidence.
Known Limitations & Responsible Interpretation
- Platform HTML structures and API responses change frequently; any signature-based scanner requires continuous rule maintenance as websites update their frontend templates.
- A positive HTTP fingerprint proves that a handle is registered on a platform, not that the account belongs to the same real-world person across platforms.