I Tested 7 AI OSINT Agents on My Own Digital Footprint - Here's What They Found in 4 Minutes
I Tested 7 AI OSINT Agents on My Own Digital Footprint - Here’s What They Found in 4 Minutes
我测试了 7 款 AI 开源情报(OSINT)工具来“人肉”我自己——4 分钟后,结果让我不寒而栗
I thought I had good opsec. I was adorably wrong. 我一直以为自己的网络安全意识(Opsec)还不错。现在看来,我当时的想法真是天真得可爱。
The Setup 测试准备 I decided to do the digital equivalent of Googling yourself at 2am after 3 glasses of wine, but with better tools and less self-pity. I took 7 of the most hyped AI OSINT agents - the ones that promise to “uncover anyone in seconds” on Product Hunt and shady Telegram ads - and pointed them at the one target I can legally stalk without a restraining order: myself. No fake names. No burner emails. Just my real name, my main email, and one profile photo. The same breadcrumbs I leave everywhere. I gave each tool exactly 4 minutes. Not because I’m scientific. Because that’s how long my anxiety can handle watching a progress bar that says “SCANNING DARK WEB…” This is what happened. 我决定做一件数字化的“深夜酒后搜索自己”的事,只不过这次我用了更专业的工具,且少了些自怜自艾。我挑选了 7 款在 Product Hunt 和 Telegram 灰色广告中被吹捧得最厉害的 AI 开源情报(OSINT)工具——它们都号称能“在几秒钟内扒出任何人的底细”——并将它们指向了一个我可以合法“跟踪”且不会收到限制令的目标:我自己。没有假名,没有一次性邮箱,只有我的真实姓名、主邮箱和一张头像。这些就是我留在互联网各处的“面包屑”。我给每款工具整整 4 分钟的时间。这不是因为我有多严谨,而是因为看着进度条上显示“正在扫描暗网……”时,我的焦虑感最多只能支撑 4 分钟。以下就是测试结果。
Ground Rules & Disclaimer: 基本准则与免责声明: This is self-OSINT. I have explicit consent from my target (me). Don’t be creepy. Don’t use these tools to harass, dox, or stalk people. This is about auditing your own attack surface, not becoming the main character in a true crime podcast. 这是一次自我 OSINT 测试。我已获得目标(我自己)的明确同意。请不要做变态的事。不要利用这些工具去骚扰、人肉或跟踪他人。这次测试的目的是审计你自己的攻击面,而不是让你成为犯罪纪录片里的主角。
The Lineup 测试阵容 I didn’t pick random tools. I picked the categories everyone is actually using in 2026: 我没有随机挑选工具,而是选择了 2026 年大家都在使用的几类主流工具:
-
Epieos - The Email Bloodhound: You give it an email, it tells you where that email has been. Google accounts, social profiles, data breaches.
-
Epieos - 邮箱猎犬: 输入邮箱,它就能告诉你这个邮箱去过哪里,包括关联的谷歌账号、社交资料和数据泄露记录。
-
IntelX.io - The Breach Archaeologist: Searches breaches, leaks, pastebins, and the dark web archives. It’s like Ancestry.com but for your passwords.
-
IntelX.io - 泄露考古学家: 搜索数据泄露、外泄信息、Pastebin 和暗网存档。它就像是密码界的“家谱网”(Ancestry.com)。
-
OSINT Industries - The Pay-To-Creep Powerhouse: The one the TikTok investigators use. Email, phone, name, username - it correlates everything into a scary-neat profile.
-
OSINT Industries - 付费跟踪神器: TikTok 上的“调查员”都在用这个。无论是邮箱、电话、姓名还是用户名,它都能将所有信息关联成一份令人毛骨悚然的详细档案。
-
Social Searcher / Sherlock-style AI - The Username Hydra: You put in one username, it checks 400+ platforms. Your embarrassing 2012 Reddit account? Found.
-
Social Searcher / Sherlock 类 AI - 用户名九头蛇: 输入一个用户名,它会检查 400 多个平台。你 2012 年那些尴尬的 Reddit 账号?全被找出来了。
-
PimEyes / FaceCheck.ID - The Face That Launched a Thousand Lawsuits: Reverse facial recognition. Upload one photo, find every place your face appears on the public web. Yes, it still works. No, it’s not comfortable.
-
PimEyes / FaceCheck.ID - 引发无数诉讼的“脸”: 反向人脸识别。上传一张照片,就能找到你的脸在公共网络上出现的所有位置。没错,它依然有效,而且让人很不舒服。
-
SpiderFoot + GPT Wrapper - The OG Turned AI: Classic OSINT automation framework, now with an LLM layer that actually explains the findings instead of just dumping JSON like it’s 2019.
-
SpiderFoot + GPT 封装版 - 进化后的元老: 经典的 OSINT 自动化框架,现在加入了大语言模型层,它能直接解释调查结果,而不是像 2019 年那样只丢给你一堆 JSON 数据。
-
Maltego + OpenAI Plugin - The Pretty Graph That Judges You: Maps relationships. It doesn’t just find data, it connects it. “You worked with X, who lives near Y, who posted Z.” Beautiful. Terrifying.
-
Maltego + OpenAI 插件 - 审视你的精美图谱: 绘制关系图。它不仅能找到数据,还能将它们串联起来:“你曾与 X 共事,X 住在 Y 附近,而 Y 发布了 Z。”既精美,又恐怖。
The 4-Minute Autopsy: What They Found 4 分钟的“尸检”:它们发现了什么 I hit start on all 7. Made coffee. By the time the Keurig stopped wheezing: 我启动了所有 7 款工具,然后去煮咖啡。等咖啡机停止运作时:
In Under 60 Seconds: 60 秒内:
- My current address, with 87% confidence, from a data broker opt-out page I thought I had removed myself from.
- 我当前的住址(置信度 87%),来自一个我以为已经退订的数据经纪人页面。
- My old MySpace username. I had suppressed that memory for a reason.
- 我以前的 MySpace 用户名。我刻意封存这段记忆是有原因的。
- 3 data breaches I didn’t know about, including one with a plaintext-adjacent password I reused in 2018. I know. I know.
- 3 起我不知道的数据泄露事件,其中一个包含我在 2018 年重复使用的明文密码。我知道,我知道(别骂我)。
- My LinkedIn, GitHub, Medium, Instagram, and a forgotten Flickr account with photos of my dog wearing sunglasses.
- 我的 LinkedIn、GitHub、Medium、Instagram,以及一个被遗忘的 Flickr 账号,里面有我给狗戴墨镜拍的照片。
By Minute 2: 第 2 分钟:
- PimEyes found 12 photos of me. Two were from a conference talk in 2022. One was from a local newspaper article I did for a charity run. One was… my Venmo profile pic cropped by someone else. Cool.
- PimEyes 找到了 12 张我的照片。两张来自 2022 年的会议演讲,一张来自我参加慈善跑的当地报纸报道,还有一张……是我被别人裁剪过的 Venmo 头像。真棒。
- IntelX linked my main email to a breach that included my old phone number, which OSINT Industries then used to pull my carrier info and a list of “possible associates.” One was my mom. One was a guy I bought a couch from on Facebook Marketplace in 2020. The algorithm thinks we’re close.
- IntelX 将我的主邮箱与一次泄露事件关联,其中包含我的旧手机号;OSINT Industries 随后利用该号码提取了我的运营商信息和一份“可能关联的人员”名单。其中一个是我的母亲,另一个是我 2020 年在 Facebook Marketplace 上买沙发时联系过的人。算法认为我们关系密切。
- The username hydra found my Chess.com account. My ELO is now public record. The shame is permanent.
- 用户名九头蛇找到了我的 Chess.com 账号。我的积分现在成了公开记录。这种羞耻感是永久的。
By Minute 4: 第 4 分钟: The full picture assembled itself, without me helping at all. Full Name + DOB + Current & 2 Previous Addresses + Phone Number + 6 Personal Emails + Employer History + University + 47 Photos + 12 Social Profiles + Breach Passwords + Amazon Wishlist (why is this public?) + Political Donation Record. 完整的画像自动拼凑而成,我根本没帮任何忙。全名 + 出生日期 + 当前及过去两个住址 + 电话号码 + 6 个个人邮箱 + 雇主历史 + 大学信息 + 47 张照片 + 12 个社交资料 + 泄露的密码 + 亚马逊愿望清单(为什么这玩意儿是公开的?)+ 政治捐款记录。
Total cost to an attacker to get this: $0 to $47, depending on the tool. Total effort: Less than ordering a burrito. 攻击者获取这些信息的总成本:0 到 47 美元不等(取决于工具)。总耗时:比点一份墨西哥卷饼还快。
I have 2FA on everything now. I use a password manager. I consider myself “privacy-aware.” I’m still a walking data buffet. 我现在给所有账号都开了双重验证(2FA),也用了密码管理器。我自认为“隐私意识很强”。但我依然是一个行走的“数据自助餐”。
The Scoreboard Nobody Asked For 没人要求的排行榜
| Tool | Scariest Feature | Accuracy | Price | My Uncomfortable Rating |
|---|---|---|---|---|
| Epieos | Finds Google ID, Maps reviews, even your Google Calendar photo | 9/10 | Free / $ | 8/10 - Clinical |
| IntelX | Breach timeline | 10/10 | Freemium | 9/10 - Existential |
| OSINT Industries | Name -> Everything | 9.5/10 | $$$$ | 10/10 - Call your lawyer |
| Username Searchers | Finds forgotten accounts | 7/10 | Free | 7/10 - Cringe |
| PimEyes | Face -> Location -> Event | 8.5/10 | $ | 11/10 - Black Mirror |
| SpiderFoot AI | Auto-summarizes your vulnerabilities | 8/10 | Free/Open | 8/10 - Nerd terrifying |
| Maltego | Visualizes your entire social graph | 9/10 | $$ | 9/10 - Pretty terrifying |
| 工具 | 最可怕的功能 | 准确度 | 价格 | 我的不适指数 |
|---|---|---|---|---|
| Epieos | 查找 Google ID、地图评论,甚至你的谷歌日历头像 | 9/10 | 免费/$ | 8/10 - 冷冰冰的精准 |
| IntelX | 泄露时间线 | 10/10 | 免费增值 | 9/10 - 存在主义危机 |
| OSINT Industries | 姓名 -> 一切 | 9.5/10 | $$$$ | 10/10 - 快找律师吧 |
| 用户名搜索器 | 找回被遗忘的账号 | 7/10 | 免费 | 7/10 - 尴尬 |
| PimEyes | 脸 -> 位置 -> 事件 | 8.5/10 | $ | 11/10 - 黑镜级别 |
| SpiderFoot AI | 自动总结你的漏洞 | 8/10 | 免费/开源 | 8/10 - 技术性恐怖 |
| Maltego | 可视化你的整个社交图谱 | 9/10 | $$ | 9/10 - 相当恐怖 |
Winner for pure horror? PimEyes. It’s one thing to know your data is out there. It’s another to see your face on a website in Estonia you never visited. 纯粹的恐怖赢家?PimEyes。知道自己的数据在网上是一回事,但在一个你从未访问过的爱沙尼亚网站上看到自己的脸,又是另一回事。
Winner for most actionable? IntelX + Epieos. Free, fast, and tells you exactly what to burn. 最具实操性的赢家?IntelX + Epieos。免费、快速,且能准确告诉你该“烧毁”哪些信息。
So What? The 3 Things You Should Actually Do 那又怎样?你真正应该做的 3 件事 I did this as a stunt. But here’s the part where I turn into a responsible adult for 30 seconds: 我做这个测试是为了博眼球。但现在,我要花 30 秒变回一个负责任的成年人:
-
You don’t have a privacy problem. You have a correlation problem. One leak is nothing. AI OSINT is dangerous because it correlates 10 boring leaks into one interesting profile. Your Strava + your LinkedIn + your breached email = your home address and when you’re not there.
-
你面临的不是隐私问题,而是关联性问题。 一次泄露不算什么。AI OSINT 的危险之处在于它能将 10 个无聊的泄露信息关联成一份有趣的个人档案。你的 Strava 运动轨迹 + LinkedIn 职业信息 + 泄露的邮箱 = 你的家庭住址以及你不在家的时间。
-
Delete is a lie. Reduce is real. You can’t delete yourself from the internet. You can make yourself expensive to find. Remove data brokers [DeleteMe / Optery / manual opt-outs], nuke old accounts with JustDeleteMe, and turn off public Venmo/Amazon lists. Make the low-hanging fruit slightly higher.
-
“删除”是个谎言,“减少”才是现实。 你无法从互联网上彻底抹除自己,但你可以增加别人找到你的成本。通过 DeleteMe/Optery 或手动方式退出数据经纪人名单,用 JustDeleteMe 注销旧账号,并关闭 Venmo/Amazon 的公开列表。把那些“低垂的果实”挂得高一点。
-
Audit yourself quarterly. Set a calendar event: “Stalk Myself.” 15 minutes. Run Epieos on your email. Run PimEyes on your face. Check haveibeenpwned. If you find something you hate, fix it then. Future you, applying for a job / date / mortgage, will thank you.
-
每季度审计一次自己。 在日历上设个提醒:“人肉我自己”。花 15 分钟,用 Epieos 查邮箱,用 PimEyes 查人脸,去 haveibeenpwned 查泄露。如果发现讨厌的信息,立刻修复它。未来的你,在申请工作、约会或贷款时,会感谢现在的你。