A native macOS GUI client for sherlock-project, with first-class Chinese-platform support. 基于 sherlock-project 的 macOS 原生图形客户端,内置国内平台扩展。
Sherlockng 把命令行工具 sherlock 封装成一个 macOS 原生桌面应用(PySide6 / Qt6),把 sherlock 几乎全部命令行参数变成可视、可开关、可调的图形控件,并在其基础上扩展了 21 个国内主流平台的账号探测规则。
- 直接复用 sherlock 的探测引擎(WAF 识别、状态码/响应体/重定向三类判定),不重复造轮子。
- 守护线程承载搜索,Qt 信号流式回传,UI 不卡顿、可真实取消。
- 深色主题,结果表格按状态着色,可过滤、可导出 CSV、双击直达主页。
- 多用户名查询:支持逗号/换行分隔,
{?}自动展开_/-/.。 - 全参数图形化:代理、超时、站点选择、
--local、--nsfw、--ignore-exclusions、--json(文件/URL/PR 号)、--print-*、--browse、--dump-response、--txt/--csv/--xlsx、--output/--folderoutput。 - 国内平台扩展:见下表,规则独立存放于
app/data/china_platforms.json,运行时合并,不修改上游data.json。 - 可搜索站点选择器:从全部站点(上游 + 国内 )勾选。
- 结果区:实时表格(用户名/站点/状态/HTTP/URL/耗时/说明)、进度条、日志、"仅命中"过滤、浏览器打开、当前视图导出 CSV。
git clone https://github.com/benknam/Sherlockng.git
cd Sherlockng
python3 -m venv .venv
.venv/bin/pip install -e ./sherlock PySide6 pandas openpyxl requests requests-futures
./run.sh # 从源码运行
sherlock/目录为 vendored 的上游源码(已随仓库提交,无需单独克隆)。
./build.sh # 产物:dist/Sherlockng.app首次若被 Gatekeeper 拦截(未签名):右键 → 打开 → 仍要打开;或 xattr -dr com.apple.quarantine dist/Sherlockng.app。
sherlock 用三种 errorType 判定目标用户名在某站点是否存在:
status_code:请求 profile URL,2xx→存在,≥300/<200 或命中errorCode→不存在。message:在响应 HTML 中搜索errorMsg,命中→不存在。response_url:禁止重定向,2xx→存在,重定向/4xx→不存在。
辅助:urlProbe(独立探测端点)、request_method+request_payload(POST/GraphQL)、regexCheck(用户名格式校验,不匹配则跳过)、WAF 指纹识别(Cloudflare/AWS/PerimeterX 拦截页标记为 inconclusive)。本项目的国内平台全部采用 status_code,并对 HEAD 返回 200 的站点强制 GET。
Sherlockng/
├── app/
│ ├── main.py # 入口 + 深色主题
│ ├── core/{params,runner}.py # 参数模型 / sherlock worker
│ ├── gui/{main_window,results_model,site_picker}.py
│ └── data/china_platforms.json # 国内平台扩展规则
├── sherlock/ # vendored sherlock-project (MIT)
├── launch.py # PyInstaller 入口
├── build.sh / run.sh
└── README.md / LICENSE
- sherlock-project — 核心探测引擎,MIT License。
- PySide6 / Qt6 — GUI 框架。
MIT License © 2026 benknam。vendored 的 sherlock 保留其原始 MIT 许可(见 sherlock/LICENSE)。
Sherlockng wraps the sherlock command-line tool into a native macOS desktop app (PySide6 / Qt6). Nearly every sherlock CLI flag becomes a toggleable, adjustable GUI control, and the project adds 21 major Chinese platforms on top of the upstream site list.
- Reuses sherlock's detection engine (WAF detection, status_code / message / response_url verdicts) — no reinvented logic.
- Search runs in a daemon thread; results stream back via Qt signals. The UI stays responsive and supports real cancellation.
- Dark theme, color-coded result table, filtering, CSV export, double-click to open profile.
- Multi-username queries: comma/newline separated,
{?}expands to_/-/.. - Full parameter GUI: proxy, timeout, site selection,
--local,--nsfw,--ignore-exclusions,--json(file/URL/PR number),--print-*,--browse,--dump-response,--txt/--csv/--xlsx,--output/--folderoutput. - Chinese-platform extension: see table below. Rules live in
app/data/china_platforms.jsonand are merged at runtime — upstreamdata.jsonis left untouched. - Searchable site picker across all sites (upstream + Chinese).
- Results pane: live table (username/site/status/HTTP/URL/elapsed/note), progress bar, log, "found only" filter, open in browser, export current view to CSV.
git clone https://github.com/benknam/Sherlockng.git
cd Sherlockng
python3 -m venv .venv
.venv/bin/pip install -e ./sherlock PySide6 pandas openpyxl requests requests-futures
./run.sh # run from sourceThe
sherlock/directory is the vendored upstream source (committed, no separate clone needed).
./build.sh # output: dist/Sherlockng.appIf Gatekeeper blocks the unsigned bundle on first launch: right-click → Open → Open anyway; or xattr -dr com.apple.quarantine dist/Sherlockng.app.
sherlock decides whether a username exists on a site via three errorType strategies:
status_code: request the profile URL; 2xx→claimed, ≥300/<200 or inerrorCode→available.message: search the response HTML forerrorMsg; match→available.response_url: disable redirects; 2xx→claimed, redirect/4xx→available.
Helpers: urlProbe (alternate probe endpoint), request_method+request_payload (POST/GraphQL), regexCheck (skip if username format mismatches), and WAF fingerprinting (Cloudflare/AWS/PerimeterX challenge pages marked inconclusive). All Chinese platforms here use status_code, forcing GET where HEAD returns 200.
Sherlockng/
├── app/
│ ├── main.py # entry + dark theme
│ ├── core/{params,runner}.py # param model / sherlock worker
│ ├── gui/{main_window,results_model,site_picker}.py
│ └── data/china_platforms.json # Chinese-platform rules
├── sherlock/ # vendored sherlock-project (MIT)
├── launch.py # PyInstaller entry
├── build.sh / run.sh
└── README.md / LICENSE
- sherlock-project — the detection engine, MIT License.
- PySide6 / Qt6 — GUI toolkit.
MIT License © 2026 benknam. The vendored sherlock retains its original MIT license (see sherlock/LICENSE).