By OSINTScan Research•Published 2026-09-20•Last updated 2026-09-27

WhatsMyName vs. Sherlock: Signature Accuracy & False-Positive Analysis

Analyzing why dual-fingerprint rules (eCode + eString + mCode + mString) reduce false positives compared to status-code-only checks.

Evaluation Methodology & Scope

Audited rule definitions across WhatsMyName (wmn-data.json) and Sherlock (data.json) against live HTTP responses from social networks, developer registries, and CDN-protected endpoints.

Sample Scope: 720 curated WhatsMyName rules vs 400+ Sherlock site rules

Technical Comparison Matrix

DimensionOSINTScan (Hybrid Engine)WhatsMyName SchemaSherlock Schema
Rule Schema StructureUnified eCode/eString + mCode/mString + WAF & soft-404 classifierFour-part schema (e_code, e_string, m_code, m_string)Single-polarity errorType (status_code, message, or response_url)
False-Positive ResistanceHigh — requires positive body signature and absence of soft-404 markersHigh — explicitly validates both existence and missing stringsModerate — status_code rules can misclassify 200 OK error shells
Platform CategorizationSocial, Coding, Gaming, Video, Music, Forum, Finance, BusinessCategorized by industry/topic in wmn-dataFlat alphabetical dictionary in standard data.json
Interactive Web Filtering & ExportLive confidence filtering, category tabs, CSV/JSON exportCommunity web mirrors vary in maintenanceCLI output only

Why Dual-Polarity Fingerprints Matter in OSINT

The most common failure mode in automated username enumeration is the 'Soft 404': a web server returns HTTP 200 OK even when an account does not exist, rendering a generic 'User not found' template or an empty JavaScript application shell. Tools that rely solely on checking whether HTTP status equals 200 will falsely report that the target username exists on dozens of platforms.

WhatsMyName pioneered the four-part rule specification: every platform defines both what a valid profile looks like (expected HTTP code e_code and expected body substring e_string) and what a missing account looks like (missing HTTP code m_code and missing body substring m_string). If a server returns HTTP 200 during a Cloudflare challenge or soft-404 page, the classifier sees that e_string is absent—or that m_string is present—and refuses to mark the account as FOUND.

How OSINTScan Combines Both Ecosystems

OSINTScan uses the four-part WhatsMyName fingerprint specification as its primary verification standard across 720 cataloged rules, while cross-validating results against Sherlock, Maigret, and Blackbird signatures. When multiple engines confirm the same canonical domain, OSINTScan merges the evidence into a single deduplicated card and elevates the match confidence.

Known Limitations & Responsible Interpretation

  • Platform HTML structures and API responses change frequently; any signature-based scanner requires continuous rule maintenance as websites update their frontend templates.
  • A positive HTTP fingerprint proves that a handle is registered on a platform, not that the account belongs to the same real-world person across platforms.
All Comparisons