Social Media Profile Detection Scanner

This scanner detects social media profile links present in web assets across twenty-six platforms including LinkedIn, Instagram, X, Facebook, YouTube, TikTok, and others. It identifies profile URLs embedded in page markup, JSON-LD structured data, and meta tags across the target web application. Detecting linked social media profiles helps organizations audit their publicly visible social presence and identify accounts that may expose organizational or individual information to adversaries.

Short Info


Level

Informational

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

26 days

Scan only one

Domain, IPv4, Subdomain

Toolbox

Web applications routinely include links to their social media profiles as part of brand communication, community engagement, and customer support strategies. Platforms such as LinkedIn, Instagram, X, Facebook, YouTube, and TikTok are used by organizations of all sizes to publish announcements, engage with audiences, and direct web visitors toward their wider digital presence. Social media links appear most commonly in website footers, about pages, contact pages, and press sections, and are often shared across multiple pages through global layout templates. In addition to official corporate accounts, individual employee profiles on platforms such as LinkedIn, GitHub, and Medium are sometimes linked from team pages or author bios. The breadth of platforms in active use has expanded significantly, with newer networks such as Bluesky, Threads, and Mastodon now appearing alongside established platforms in organizational web properties. Mapping all social media references from a web application provides a comprehensive picture of an organization's external digital footprint and the individual accounts connected to it.

Social media profile detection refers to the automated identification of links to social networking platforms that are embedded within a web application's publicly accessible pages. While these links are typically published intentionally, the enumeration of all linked accounts across platforms can reveal information that the organization did not consciously consider when publishing each individual link. Profile links disclose usernames, handle identifiers, and account names that can be used to build a comprehensive OSINT profile of the organization and its employees across multiple platforms. Personal staff profiles linked from team or about pages expose the individual's full professional history, connections, activity patterns, and in some cases personal contact details to anyone who discovers the link. Accounts on platforms such as Discord, Telegram, and WhatsApp that are linked from a web page may provide direct communication channels to staff that bypass formal identity verification processes. The aggregation of social profiles across twenty-six platforms in a single automated pass gives adversaries a consolidated view of the organization's social surface that would otherwise require significant manual effort to compile.

The scanner fetches the root page of the target asset via a headless browser with a fallback to a plain HTTP request, then crawls up to two additional same-domain pages identified through keyword-matched anchor tags including contact, iletisim, hakkimizda, about, and about-us. On each collected HTML document, three extraction strategies are applied in parallel. The first strategy scans all href attribute values against a registry of twenty-six compiled regular expression patterns, one per platform, covering LinkedIn, Instagram, X/Twitter, Facebook, YouTube, TikTok, Pinterest, WhatsApp, Telegram, GitHub, Medium, Behance, Dribbble, Vimeo, Reddit, Discord, Twitch, Snapchat, SoundCloud, Spotify, Xing, SlideShare, Flickr, Mastodon, Bluesky, and Threads. The second strategy parses JSON-LD script blocks and recursively walks the object graph collecting URLs listed under the sameAs property. The third strategy extracts values from meta tags including og:url, og:see_also, and twitter:site, converting Twitter handle values into full profile URLs before matching. A noise filter suppresses known share, embed, CDN, and intent endpoints to prevent widget and sharing button URLs from being reported as profile links. Results are labelled with the platform name and sorted alphabetically by platform then URL.

Discovery of personal employee LinkedIn profiles enables adversaries to map the organizational hierarchy, identify individuals in sensitive roles such as IT, finance, and executive leadership, and craft highly targeted spear-phishing messages that reference the victim's employment history and connections. GitHub profiles linked from team pages expose the developer's personal repositories, contribution history, and starred projects, which may reveal internal tooling, unreleased features, or accidentally committed credentials in personal side projects. Communication platform links such as Discord invite URLs, Telegram channel handles, and WhatsApp numbers provide direct contact channels to staff or community moderators that attackers can exploit for social engineering or to inject malicious content into community spaces. Accounts on platforms with public activity feeds, such as X, Reddit, and Medium, allow adversaries to monitor the organization's employees in near real time, identifying upcoming product launches, infrastructure changes, or internal frustrations that can be weaponized in targeted attacks. Aggregated social profiles across multiple platforms enable the construction of detailed behavioral profiles of key staff, including their working hours, communication style, and professional relationships, which significantly increases the effectiveness of impersonation attacks. Inactive or abandoned accounts on platforms such as SlideShare, Flickr, or SoundCloud may present account takeover opportunities if the associated email addresses are no longer monitored, allowing attackers to claim the handle and impersonate the organization.

Get started to protecting your digital assets