πŸ›°οΈ One username, email or phone β€” everything public about it, one report, every line sourced

Everything public about one person, one network and one history β€” one case file where every line names its source :compass:

You are holding one fragment about one person β€” a username, an email address, a phone number, a real name. You want to know what it connects to.

Command One is one console that works that fragment through the public sources for you, then hands back a single case file: the accounts it is registered on, the servers and domains behind it, and what the target looked like years ago. Every line prints the source that produced it, so anyone you show the file to can check the same line themselves.

:star: The first move is on yourself. Type one of your own usernames, watch every place it is registered come back, then go close the ones you forgot about. Two minutes, nothing installed, no card asked for.

:link: com1.cloud β€” free account Β· 50 credits a day Β· public sources only

What one identifier turns into

username    β†’  every site it is registered on          165 probed in-console
email       β†’  where it is signed up Β· disposable? Β· Gravatar
phone       β†’  country Β· line type Β· the apps that use it
real name   β†’  ranked guesses at the handles behind it
domain      β†’  subdomains Β· DNS Β· live hosts Β· TLS
IP address  β†’  live hosts Β· services Β· the network owner
CIDR range  β†’  the same picture across a whole block
ASN         β†’  the owner and the address ranges it announces

Three families, one case file

digraph Case { rankdir=LR; bgcolor="#fbfcfc"; node [shape=box, style="rounded,filled", fillcolor="#eef2f5", color="#1f3a52", fontcolor="#1f3a52", fontname="Helvetica"]; edge [color="#6f8f7a", penwidth=1.4]; ident [label="one identifier\nusername Β· email Β· phone\nname Β· domain Β· IP Β· ASN", fillcolor="#1f3a52", fontcolor="#ffffff"]; idm [label="identity sweep\n165 platforms in-console\n+ 3,000+ via the fleet"]; infra [label="infrastructure\n12 ordered stages\nsubdomains β†’ DNS β†’ live hosts β†’ ASN"]; hist [label="archived web\nwhat the target\nlooked like before"]; casef [label="one case file\nevery line names\nits source", fillcolor="#6f8f7a", fontcolor="#ffffff"]; ident -> idm; ident -> infra; ident -> hist; idm -> casef; infra -> casef; hist -> casef; }

Matching hits from independent modules merge and lift in confidence; a lone hit stays flagged as a lead instead of being quietly dressed up as a fact. Export the whole file as a PDF case report or CSV, or hand someone a revocable read-only link.

What it checks β€” the eight targets you can type
You type What fires What you hold afterwards
username the native sweep across 165 platforms, then the fleet catalogue every site the handle is registered on
email mail-record lookup, disposable check, Gravatar, registration checks the services that address signed up to
phone number format, country, line type, registration checks the country, the carrier and the apps using it
real name handle ranking plus public profile artefacts ranked candidates for the handles behind a name
domain subdomains, DNS records, live hosts, TLS, technologies the estate standing behind one domain
IP address live hosts, services, network ownership what answers on an address, and who owns it
CIDR range the same checks across a whole block the reachable surface of a netblock
ASN owner and announced address ranges a network’s footprint

Native checks answer straight away; heavier fleet tools are dispatched to a worker and land in the same case file.

What runs under it β€” the free tools it is built on

The console is a front end, not a black box. Its worker fleet runs these open-source projects, each under its own licence, and the native sweeps are informed by them:

Every one of them runs free on your own machine. What the console adds is the wiring β€” one target, one output format, one case file, with the source kept on each line. Command One does not redistribute their code.

Identity sweep β€” what comes back

One handle or one address, and the sweep returns the accounts it can tie together:

  • Registered accounts β€” the platform, the profile URL, and the module that found it
  • Email signals β€” where the address is signed up, whether the domain is disposable, and the Gravatar behind it
  • Phone signals β€” country, number format, line type and the services that use it
  • Social footprint β€” public profile detail and posting activity on the accounts the sweep turned up
  • Ranked handles β€” candidate usernames behind a real name, strongest first

Findings from different modules that describe the same entity are merged into one record and scored together. Single-source hits stay visible as leads, never mixed in with the corroborated ones. Every record keeps the raw payload, the module it came from and the time it was collected.

Infrastructure + archived web β€” the 12 ordered stages

A domain, a host, an address block or an ASN runs as a pipeline where each stage feeds the next, instead of firing blind:

01  username sweep        handles across the platforms
02  account & email       where an address is registered
03  phone intel           carrier Β· line format Β· registration signals
04  social footprint      public profile detail and activity
05  subdomain discovery   passive, across certificate logs and indexes
06  DNS resolution        A Β· AAAA Β· CNAME Β· MX Β· NS Β· TXT Β· PTR
07  live hosts            status Β· title Β· server Β· TLS Β· tech Β· CDN
08  ports & services      authorised targets only
09  ASN & network         owner and announced prefixes
10  Shodan enrichment     previously observed services and versions
11  historical web        archived URLs Β· paths Β· parameters Β· assets
12  cross-source          identity and infrastructure tied together

Discovered hosts become resolution input, resolved addresses become probe input, and everything lands in one connected model you can pivot around. Stage 11 reads the archived web, so a domain shows what it used to be long before today.

Free vs paid β€” the real numbers
Free account Premium Unlimited
Cost :white_check_mark: Β£0 Β£49.99 per month
Daily allowance :white_check_mark: 50 credits a day, refreshed daily every module, 50 searches a day fair use
Modules the native checks and the standard fleet every module, including the paid data sources
Future modules added over time :white_check_mark: included the day each one ships
Exports :white_check_mark: PDF case report and CSV :white_check_mark: PDF case report and CSV
Card required :white_check_mark: none monthly subscription, cancel anytime

A handful of premium data sources bill in gold credits instead of the daily allowance: 50 gold credits for Β£4.99, and they stay on your account rather than resetting each day.

:link: com1.cloud/premium-unlimited β€” what the subscription covers

Run it on yourself β€” the two-minute footprint audit
  1. Sign in with Google β€” it creates the account only, using your name, email and picture
  2. Drop in a username you use
  3. Read the case file: every site that handle is registered on
  4. Run it again with your main email address
  5. Open the accounts you had forgotten about β€” and close or tidy the ones you no longer want

The same two minutes tell you exactly what a stranger can assemble about you from public sources, which is the part most people never get to see.

The lines that keep it honest

  • Public sources only β€” nothing behind a login, no paid data brokers, no archives sold on the side
  • Google sign-in creates your account and nothing else: your name, your email, your picture. The console never reads your mail, your files or your contacts
  • Every scan is written to an audit trail on your own account
  • Results are leads β€” check them before you rely on them. Harassment and unlawful profiling end an account

One box, every answer carrying its source β€” the twenty terminal windows were never the point.

11 Likes

Excellent tool set thank you

:rocket: Command One β€” Major Update

26 OSINT Modules β€’ 3,000+ Platforms β€’ Intel Maps β€’ Watchlists

Command One has grown considerably since the original release.

What started as a unified people-search console has now expanded into a full OSINT investigation workspace β€” combining native modules, open-source tools, API feeds, correlation, visual intelligence, case sharing and scheduled monitoring.

:globe_with_meridians: Launch Command One

FREE DAILY ALLOWANCE 26 MODULES 3,000+ PLATFORMS PUBLIC SOURCES


:satellite: What’s New?

πŸ†• 26 Investigation Modules

Command One now has 26 live modules across three execution types:

Native β€” instant

  • Username Sweep
  • Email Recon
  • Phone Recon
  • Name Expander
  • Domain Recon
  • Verify Link Pack
  • DeHashed
  • Intelligence X
  • Phone Intelligence

Worker Fleet

  • Sherlock
  • Maigret
  • Snoop
  • WhatsMyName
  • Blackbird
  • socialscan
  • Holehe
  • Ignorant
  • GHunt
  • Sylva
  • Social Analyzer
  • CupidCr4wl
  • SpiderFoot
  • theHarvester
  • Sublist3r

API Feeds

Native modules run immediately, while fleet tools are dispatched to the self-hosted worker infrastructure.


🌐 3,000+ Platforms Across Username Modules

Username investigations have been expanded significantly.

Command One now reaches 3,000+ platforms across its username modules, combining native platform probing with tools such as Maigret, Sherlock, Snoop, WhatsMyName and other specialised integrations.

Results are brought back into the same unified findings system and confidence scored.


πŸ—ΊοΈ Interactive Intelligence Map

Cases can now be viewed as an interactive relationship graph.

The target sits at the centre while related intelligence is displayed as connected nodes.

You can:

  • Drag findings and hubs
  • Rearrange the graph
  • Follow relationships
  • View confidence visually
  • Inspect source details
  • Reset the layout
  • Switch between list and map views

The map also follows the filters applied to the investigation results.


πŸ”— Multi-Source Correlation

Command One now goes further than simply collecting results.

Independent modules can corroborate the same entity and merge their findings into a unified record.

Corroborated findings increase in confidence, while single-source results remain identifiable as leads.

New correlation tooling includes:

  • Sylva
  • Social Analyzer
  • CupidCr4wl
  • SpiderFoot

πŸ”Ž Verify Link Pack

A new native verification toolbox provides quick access to manual verification resources.

It includes links for:

  • Facebook
  • X
  • Instagram
  • TikTok
  • LinkedIn
  • Reddit
  • Telegram
  • WhatsApp
  • Search dorks
  • Wayback Machine
  • WHOIS
  • Company registers

The idea is simple: automate the discovery where possible, then make manual verification easy when required.


πŸ‘οΈ Premium Intelligence Sources

Command One now supports additional paid-source intelligence through purchased credits.

Intelligence X

Search leak, darknet and archive collections.

Phone Intelligence

Provides additional phone intelligence including:

  • Carrier information
  • Line type
  • Risk scoring
  • SMS gateway data

Premium sources consume purchased credits rather than the standard daily allowance.


πŸ‘€ Watchlists & Scheduled Monitoring

You can now save targets that you want to monitor.

Watchlists can re-sweep targets on a schedule and surface new findings as changes against the previous investigation.

Instead of repeatedly checking the same target manually, Command One can highlight what has changed.


πŸ”” Scan Notifications

Long-running investigations no longer need to be watched manually.

Command One now provides:

  • In-app completion notifications
  • Email summaries
  • Worker-job notifications

Start a scan and come back when it’s finished.


πŸ”— Shareable Case Files

Cases can now be shared using a read-only link.

A colleague or client can review the investigation and evidence without needing their own Command One account.

Links can also be revoked when access is no longer required.


πŸ€– AI Agent Integration

Command One includes a read-only OAuth-secured agent endpoint.

Your own AI tooling can:

  • List cases
  • Search findings
  • Access investigation data under your account

This allows Command One to become part of a larger AI-assisted investigation workflow without giving the agent unrestricted access.


πŸ“Š Better Investigation Results

The investigation feed now supports extensive filtering, grouping and sorting.

Filter by:

  • Category
  • Module
  • Execution mode
  • Target type
  • Case
  • Confidence
  • Recency

Group by:

  • Category
  • Module
  • Target
  • Case
  • Confidence

Sort by:

  • Confidence
  • Corroboration
  • Recency
  • Platform

πŸ“„ Reports, Evidence & Sharing

Every finding retains its source module, raw payload and timestamps.

Investigations can be exported as:

CSV

Export the visible findings set.

PDF

Generate a branded case file containing an executive summary and findings register.

Shareable Case

Create a revocable read-only case link for handover or review.


:credit_card: New Credit System

Command One is now free to use every day with a daily allowance.

:free_button: Free

$0 β€” Forever

  • 50 credits refreshed every day
  • Standard OSINT modules
  • Unified intelligence feed
  • CSV exports
  • PDF case files
  • Watchlists
  • Shareable read-only cases

:money_bag: Credit Top-Up

$5 / 50 credits

  • One-off purchase
  • Credits do not expire daily
  • Unlocks premium paid-source modules
  • Up to 10 packs can be purchased at once
  • 30-day money-back guarantee

A premium monthly tier is also planned.


:gear: The Core Workflow

01 β€” Acquire

Enter a username, email, phone number, real name or domain.

02 β€” Run

Command One selects the modules capable of working with the identifier.

03 β€” Correlate

Raw results are normalised into accounts, identities, infrastructure and media.

04 β€” Investigate

Filter, group, sort, corroborate and explore the relationship map.

05 β€” Report

Export the investigation as PDF, CSV or a shareable read-only case.


:shield: Public Sources & Responsible Use

Command One is designed around publicly accessible intelligence.

No:

  • Breach dumps
  • Paid data brokers
  • Scraping behind logins
  • Authentication bypass

Every scan is tied to the account that launched it and written to an audit trail.

Results are signals, not proof. A finding should be treated as a lead and independently verified before being relied upon.

Harassment, stalking and unlawful profiling are prohibited.


:chart_increasing: Current Platform

Live Modules 26
Username Platforms 3,000+
Native Modules 9
Fleet Tools 15
API Feeds 2
Findings Schema 1 Unified Format
Reports PDF + CSV
Case Sharing Read-only Links
Monitoring Watchlists
Visualisation Interactive Intel Map

:rocket: Try Command One

Create a free account and start with the daily allowance.

:globe_with_meridians: Open Command One

OSINT β€’ PEOPLE SEARCH β€’ DUE DILIGENCE β€’ FRAUD RESEARCH β€’ JOURNALISM β€’ SECURITY RESEARCH


:speech_balloon: Feedback

Command One is actively being developed.

If you’ve used the platform, I’d be interested in hearing what modules, integrations or investigation features you’d like to see next.

3 Likes

Nice update

:rocket: Command One β€” Major Update: OSINT Investigation Workspace

A major update to Command One since the original post.

Command One has evolved from a simple people-search console into a full OSINT identity, infrastructure and historical investigation workspace.

:globe_with_meridians: Command One: https://www.com1.cloud/


:new_button: What’s New

:person: Identity & People Investigation

Command One now accepts multiple starting points:

  • Username
  • Email
  • Phone number
  • Real name
  • Domain
  • IP address
  • CIDR range
  • ASN

Results from multiple investigation modules are brought back into one workspace and can be correlated within the same case.

Username investigations can now reach 3,000+ platforms through the worker fleet, with 165 platforms probed directly.


:magnifying_glass_tilted_right: 47 Live Investigation Modules

Command One now combines native modules, API intelligence and a worker fleet.

Native

  • Username Sweep
  • Email Recon
  • Phone Recon
  • Name Expander
  • Domain Recon
  • Verify Link Pack
  • Intelligence X
  • BreachDirectory
  • Phone Intelligence

OSINT Worker Fleet

  • Sherlock
  • Maigret
  • Snoop
  • WhatsMyName
  • Blackbird
  • socialscan
  • Holehe
  • Ignorant
  • GHunt
  • Sylva
  • Social Analyzer
  • CupidCr4wl
  • SpiderFoot
  • theHarvester
  • Sublist3r
  • Toutatis
  • Osintgram
  • snscrape
  • mosint
  • email2phonenumber
  • PhoneInfoga
  • marple
  • NetSoc OSINT
  • OWASP Amass
  • recon-ng
  • bbot
  • xnLinkFinder
  • git-hound
  • ExifTool
  • sn0int

Infrastructure & Historical Recon

  • subfinder
  • dnsx
  • httpx
  • naabu
  • asnmap
  • Shodan
  • waybackurls
  • gau

:globe_with_meridians: Infrastructure Recon

Command One now goes beyond people and usernames.

The infrastructure workflow can move through:

Domain β†’ Subdomains β†’ DNS β†’ Live Hosts β†’ Ports/Services β†’ ASN β†’ Shodan β†’ Historical Web

It can investigate:

  • Subdomains
  • DNS records
  • Live hosts
  • Ports and services
  • ASN / network ownership
  • Internet exposure
  • Shodan enrichment
  • Historical URLs
  • Archived endpoints
  • Paths and parameters

The aim is to keep the infrastructure investigation inside the same case rather than jumping between separate tools.


:mantelpiece_clock: Historical Web Intelligence

Command One now includes historical web reconnaissance using:

Wayback + gau

Investigate previously indexed URLs, including:

  • Old URLs
  • Paths
  • Extensions
  • Parameters
  • Archived endpoints
  • Historical changes

This adds the history layer alongside identity and infrastructure.


:brain: Cross-Source Correlation

Results from different modules are normalised into a unified findings structure.

Command One can correlate information across sources and highlight:

  • Related entities
  • Supporting sources
  • Corroborated findings
  • Confidence
  • Evidence
  • Source provenance

The goal is not simply to return more results, but to make the relationships between results easier to investigate.


:world_map: Interactive Intelligence Map

Investigations can be explored through an interactive relationship graph.

Entities can include:

  • People
  • Accounts
  • Usernames
  • Emails
  • Phones
  • Domains
  • Hosts
  • Infrastructure
  • Related findings

Move from an initial identifier into the wider network of connected information.


:eyes: Watchlists & Monitoring

Targets can now be added to watchlists.

Command One can re-sweep targets and surface changes against previous investigations.

Useful for:

  • Ongoing research
  • Due diligence
  • Infrastructure monitoring
  • Security research
  • Tracking changes to public footprints

:bell: Notifications

Long-running investigations no longer require you to keep the console open.

Command One supports investigation/job notifications including:

  • In-app notifications
  • Email summaries
  • Worker-job notifications

:file_folder: Cases, Evidence & Reports

Investigations can be saved as cases with an audit trail.

Findings retain information such as:

  • Source module
  • Source information
  • Raw payload
  • Timestamp
  • Confidence
  • Corroboration

Cases can be exported as:

PDF β€” investigation reports

CSV β€” investigation data

Shareable Case β€” read-only case sharing for review or collaboration


:robot: AI Agent Integration

Command One now includes a read-only OAuth-protected agent endpoint.

This allows authorised AI tooling to work with Command One investigation data, including:

  • Listing cases
  • Searching findings
  • Retrieving investigation data

The endpoint is read-only and tied to the user’s authorised account.


:magnifying_glass_tilted_right: Investigation Feed

The investigation feed has also been expanded with filtering, grouping and sorting across areas such as:

  • Category
  • Module
  • Execution mode
  • Target type
  • Case
  • Confidence
  • Recency
  • Corroboration
  • Platform

This makes larger investigations easier to navigate.


:free_button: Free Access

Command One remains available with a free daily allowance for standard OSINT modules.

The current free allowance provides 50 credits refreshed daily.

Standard modules can be run directly from the investigation workspace without needing separate installations or command-line setup.


:shield: Responsible OSINT

Command One is designed around lawful investigation using publicly accessible sources.

The platform is not intended for:

  • Harassment
  • Stalking
  • Unlawful profiling
  • Circumventing authentication
  • Accessing private accounts
  • Obtaining breach dumps

Results should be treated as leads and signals, not proof, and important findings should be independently verified.


:bar_chart: Current Platform

Feature Current
Live modules 47
Platforms probed directly 165
Platforms reachable via fleet 3,000+
Unified findings :white_check_mark:
Interactive intelligence map :white_check_mark:
Infrastructure recon :white_check_mark:
Historical web recon :white_check_mark:
Watchlists :white_check_mark:
Notifications :white_check_mark:
PDF reports :white_check_mark:
CSV export :white_check_mark:
Shareable cases :white_check_mark:
AI agent endpoint :white_check_mark:

:bullseye: The Direction

The original idea was:

One search box instead of twenty terminal windows.

That is still the goal.

But Command One is now becoming a complete investigation workspace:

Find the person.

Map the network.

Recover the history.

Correlate the evidence.

Monitor what changes.

Keep the investigation in one case.


:rocket: Try Command One

Command One is free to use for standard OSINT investigations.

:globe_with_meridians: https://www.com1.cloud/

Feedback, feature requests and suggestions for additional tools/integrations are welcome.

The project is actively being developed.

2 Likes

Thanks dude

Fire

Fire tools bro

What you can run today β€” one identifier in, one sourced case file out :receipt:

For anyone who already has the console open: this is the part to put to work now, in five moves.

1. Sign in at com1.cloud β€” Google sign-in creates the account and nothing else.
2. Drop in one identifier: a username, an email address, a phone number, a real name, a domain, an address or an ASN.
3. Pick the modules. The native checks answer straight away; the heavier fleet tools are dispatched to a worker and land in the same case.
4. Read the case file β€” every line carries the module that found it, the raw payload and the time it was collected.
5. Export a PDF case report or CSV, or hand someone a revocable read-only link.

:link: com1.cloud β€” open the console
:link: com1.cloud/auth β€” create the free account

What you can run today β€” modules and what each fires
Family What it fires What lands in the case
Username the native sweep across 165 platforms, then the fleet catalogue every site the handle is registered on
Email mail records, disposable check, Gravatar, registration checks the services that address signed up to
Phone format, country, line type, registration checks the country, the carrier and the apps using it
Name handle ranking and public profile artefacts ranked candidates for the handles behind a name
Domain subdomains, DNS records, live hosts, TLS the estate standing behind the domain
IP / CIDR live hosts, services, network ownership the reachable surface of a netblock
ASN owner and announced address ranges a network’s footprint
Archive + correlation archived URLs and the cross-source sweep the target over time, all in one graph

Matching hits from independent modules merge and lift in confidence; a lone hit stays flagged as a lead. Each record keeps the module it came from, so any single finding can be checked on its own.

Costs β€” free tier, gold credits, Premium Unlimited
Free account Premium Unlimited
Cost :white_check_mark: Β£0 Β£49.99 per month
Runs :white_check_mark: 50 credits a day, refreshed daily every module, 50 searches a day fair use
Premium data sources metered in gold credits :white_check_mark: included
Future modules added over time :white_check_mark: included the day each one ships
Exports :white_check_mark: PDF case report and CSV :white_check_mark: PDF case report and CSV
Cancel β€” anytime, access runs to the end of the paid period

Gold credits: 50 for Β£4.99, and they stay on the account instead of resetting each day. They are what the handful of premium data sources bill against.

Results are leads β€” check them before you rely on them, because every line already tells you where it came from.

Drop one identifier, keep the case file, and let each source answer for itself.

:up_arrow: The Core-Community team has rebuilt the topic above β€” one plain front door: what the console takes, what comes back, and every source named on the line it produced.