Skip to main content

onionscout

onionscout

onionscout is a lightweight CLI tool for auditing Tor hidden services (.onion) for common security misconfigurations, clearnet dependencies, metadata leaks, fingerprinting indicators, and basic de-anonymization risks.

It is designed as a first-pass audit helper, not a full penetration-testing framework.

Use only against systems you own or are authorized to assess.

Features

Network and origin handling

  • Tor SOCKS5h support
  • onion v3 hostname sanity check
  • smart HTTP/HTTPS origin selection
  • .onion-safe redirect policy
  • initial clearnet URL blocking for policy-managed fetches
  • cross-onion redirect blocking
  • redirect leak detection to clearnet
  • retry handling for common onion/Tor network errors
  • separate HTTP, SSH, and TLS timeouts

Web fingerprinting

  • web server header detection
  • default error-page fingerprinting
  • favicon discovery and Shodan-compatible favicon hash
  • ETag extraction and Shodan query helper
  • TLS reachability, TLS version, cipher, certificate SHA256, issuer, subject, and validity

Leak and de-anonymization checks

  • clearnet redirects
  • external active resources
  • external links
  • CSP / CSP-Report-Only external allowances
  • Report-To / NEL / Link header leakage
  • canonical / alternate / OpenGraph / Twitter metadata leaks
  • protocol-relative external links
  • meta-refresh redirects
  • clearnet form actions
  • clearnet WebSocket endpoints
  • Onion-Location header
  • optional clearnet mirror Onion-Location validation with --clearnet-url
  • proxy-related headers
  • common fingerprinting headers
  • baseline security headers
  • CORS misconfiguration classification
  • JavaScript URL, IP, source-map, and secret-candidate leak checks
  • lightweight image metadata sniffing for EXIF/XMP-style markers, URLs, IPs, and GPS hints

Hidden-service hygiene checks

  • Apache mod_status
  • Apache mod_info
  • nginx stub_status
  • WebDAV exposure
  • HTTP method exposure checks, including TRACE, PUT, DELETE, PATCH, PROPFIND, and MKCOL
  • common sensitive files and paths
  • directory listing detection
  • .well-known/* endpoints
  • robots.txt
  • sitemap.xml
  • clearnet URL detection inside robots.txt and sitemap.xml
  • security.txt at root and .well-known
  • basic security.txt Expires, Canonical, and clearnet URL review
  • CAPTCHA-related external resource leakage
  • Set-Cookie attributes:
    • Secure
    • HttpOnly
    • SameSite
    • Domain

Content indicators

  • minimal same-host crawler
  • email extraction
  • obfuscated email extraction, for example name(at)domain(dot)tld
  • placeholder email separation, for example example.com
  • BTC / ETH / XMR address indicators
  • HTML comments review
  • comment-based IP, URL, JWT, private key, and secret-candidate detection

Output

  • human-readable Rich table
  • JSON output for automation
  • optional report file export

Requirements

  • Python 3.10+
  • Tor SOCKS proxy:
    • Tor daemon: 127.0.0.1:9050
    • Tor Browser: 127.0.0.1:9150
    • Whonix Gateway example: 10.152.152.10:9050

Installation

From PyPI

pipx install onionscout

From GitHub

pipx install git+https://github.com/h0ek/onionscout.git

For local development:

git clone https://github.com/h0ek/onionscout.git
cd onionscout
python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install -U pip
python3 -m pip install -e .
python3 onionscout.py -u <ONION_URL> --skip-tor-check

Usage

onionscout -u <ONION_URL>

Example:

onionscout -u http://exampleonionaddress.onion --skip-tor-check

Use Tor Browser SOCKS:

onionscout -u http://exampleonionaddress.onion --socks 127.0.0.1:9150 --skip-tor-check

Force HTTP:

onionscout -u exampleonionaddress.onion --scheme http

Force HTTPS:

onionscout -u exampleonionaddress.onion --scheme https --insecure-https

Validate a clearnet mirror Onion-Location header against the target onion:

onionscout -u exampleonionaddress.onion --clearnet-url https://mirror.example

Save TXT report:

onionscout -u exampleonionaddress.onion -o report.txt

Save JSON report:

onionscout -u exampleonionaddress.onion --json -o report.json

Disable crawler:

onionscout -u exampleonionaddress.onion --no-crawl

Tune crawler:

onionscout -u exampleonionaddress.onion --max-urls 150 --depth 2

Tune timeouts:

onionscout -u exampleonionaddress.onion --http-timeout 20 --ssh-timeout 8 --tls-timeout 12

Authenticated scans

Some onion services require an authenticated session. You can pass a raw HTTP Cookie header with --cookie. The cookie is scoped by onionscout to the selected target onion host and is not sent to the Tor connectivity check or blocked off-target URLs.

Example:

onionscout -u http://exampleonionaddress.onion --cookie 'access=abcd1234'

For multiple cookies, use the normal HTTP header format:

onionscout -u http://exampleonionaddress.onion --cookie 'access=VALUE; session=VALUE2; csrftoken=VALUE3'

How to get the cookie value from a browser:

  1. Log in to the target service.
  2. Open Developer Tools.
  3. Go to Storage / Cookies.
  4. Select the target onion domain.
  5. Copy the cookie name and value.
  6. Pass it as name=value.

Do not share session cookies. They are equivalent to temporary access tokens for your logged-in session.

Options

-u, --url              Target .onion URL
--scheme              Origin scheme mode: auto, http, https
--socks               SOCKS5h proxy, default 127.0.0.1:9050
--skip-tor-check      Skip check.torproject.org connectivity check
--http-timeout        HTTP timeout
--ssh-timeout         SSH timeout
--tls-timeout         TLS timeout
--ssh-port            SSH port for fingerprint check
--retries             Retries for transient onion/Tor errors
--cookie              Raw HTTP Cookie header, e.g. 'access=VALUE; session=VALUE2'
--clearnet-url        Optional clearnet mirror URL for Onion-Location validation
--insecure-https      Disable HTTPS certificate verification for HTTP requests
--no-crawl            Disable crawler-based checks
--max-urls            Crawler URL limit
--depth               Crawler depth
--json                Output JSON
-o, --output          Save report to file

Notes

  • Most onion services use plain HTTP internally; HTTPS is supported when present.
  • In auto mode, onionscout tests available origins and chooses a working HTTP or HTTPS origin.
  • Redirects are followed only when they stay on the selected target onion host; clearnet and cross-onion redirects are reported instead of being fetched.
  • Some findings are context-dependent. For example, public social links may be intentional, while active clearnet scripts are usually more relevant for anonymity risk.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

onionscout-0.2.0.tar.gz (29.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

onionscout-0.2.0-py3-none-any.whl (29.8 kB view details)

Uploaded Python 3

File details

Details for the file onionscout-0.2.0.tar.gz.

File metadata

  • Download URL: onionscout-0.2.0.tar.gz
  • Upload date:
  • Size: 29.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for onionscout-0.2.0.tar.gz
Algorithm Hash digest
SHA256 94272b3d0c967f0647b4c9f35a2abb822dea92f9b0f4824875969676b7dd3926
MD5 c5ddf8599f8aead9a78f698a6286f5d9
BLAKE2b-256 59ecb3bee36d86f60432412286715df66bc562a93300c1ce8aabbeedb51158e2

See more details on using hashes here.

Provenance

The following attestation bundles were made for onionscout-0.2.0.tar.gz:

Publisher: release.yml on h0ek/onionscout

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file onionscout-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: onionscout-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 29.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for onionscout-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 8b28f05e84cbe2116527a71e2a53d877602f3ab925e55dc9ffa16adcd738306b
MD5 f5dfc89cad7d39e27fb2a756081912aa
BLAKE2b-256 3b19c28735bb2ba8a7798aa5e2421575f924f0746238aa258eb606d47b460ca9

See more details on using hashes here.

Provenance

The following attestation bundles were made for onionscout-0.2.0-py3-none-any.whl:

Publisher: release.yml on h0ek/onionscout

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page