X-Ray Search Beyond LinkedIn: Google Strings for GitHub, Kaggle, Dribbble and 9 More Sites

X-ray search, often called Google X-ray, is a Google or Bing query locked to one website with the site: operator, so every result is a page from that site, such as a GitHub profile, a Kaggle profile or a conference speaker page. Recruiters use it to find people on sites that have weak or no people search of their own. It costs nothing and needs no account on the site you search.

The reason to bother: in Gem's 2026 benchmarks, sourced candidates are nearly 8 times more likely to be hired than inbound applicants. Many engineers, designers and data scientists show more of their work on GitHub, Dribbble or Kaggle than on LinkedIn. GitHub alone reports 225M+ developers.

This guide covers X-ray search beyond LinkedIn: which operators still work, 30 strings for 12 sites, the rules you have to respect, and how to get from a results page to a shortlist. LinkedIn has its own page: our LinkedIn X-ray search guide has 15 strings and the LinkedIn rules. Full disclosure: I run The Cognitive, which replaces the string with a plain-English brief. Every outside fact here comes from the source's own page, read on 4 October 2026.

What is X-ray search, and why do recruiters use it?

X-ray search means searching one site's public pages through a general search engine. You type site:github.com plus a few words into Google, and Google returns only GitHub pages that match. The name comes from seeing inside a site from the outside.

Recruiters use it for 3 reasons. Many sites have no people search, or one that hides locations and skills behind a login. Google reads the whole public page, including the bio and the README, so it can match words a site's own search ignores. And one string can be reused across a dozen sites by changing a single operator. That is why X-ray stays a core skill for any talent sourcer, and one channel among many in candidate sourcing.

It is also what most people mean by Boolean search for finding people online. Boolean is the logic (quotes, OR, minus, brackets); X-ray is that logic aimed at one site. There is no separate Boolean search engine to sign up for. Google and Bing are the engines, and the generators simply write the string for you. Our free Boolean generator writes one Google X-ray string and a GitHub query for an engineering role, with no sign-up.

Which search operators still work for X-ray search in 2026?

Fewer than most tutorials claim. Google's own help page lists 6 operators today, and Bing documents more. Here is what each engine says on its own pages, read on 4 October 2026:

OperatorWhat it doesGoogle documents it?Bing documents it?Use it for
site:Limits results to a domain, URL or URL prefixYesYes, up to 2 directory levels deepEvery X-ray string
"quotes"Exact word or phraseYesYesTitles, skills, cities
- (minus)Excludes a wordYesYes, as NOT or -Removing jobs, tutorials, project pages
OREither termNot on its help page todayYes, in capitalsTitle and skill synonyms
intitle:Word in the page titleNoYes, one term eachProfile page titles
inurl:Word in the URLNoNoExcluding paths like /shots/
filetype:PDFs and other file typesYesYesResumes and speaker decks
before: / after:Pages last updated before or after a dateYesNoDropping stale pages
inbody: / loc:Word in the body / countryNoYesBing-only strings

"Not documented" means Google makes no promise. OR, intitle: and inurl: still appear in nearly every sourcing string, but neither Google's help page nor its Advanced Search form explains them today. Test each one on your own query before you build on it, and always write OR in capitals, which Bing requires.

Both engines share one formatting rule. Google puts it this way: "Do not put spaces between the operator and your search term." site:github.com works; site: github.com does not.

What has Google removed or never supported?

Drop these 4 from old strings:

Bing adds a limit of its own that matters for long strings: "Only the first 10 terms are used to get search results." A 14-term Bing string quietly ignores the last 4.

How do you X-ray search a site, step by step?

The method is the same on every site. The step most people skip is the first one: find the URL pattern of a profile page before you write a word of the string.

  1. Open 3 real profiles on the site and read their URLs. Dev.to puts profiles at dev.to/name; Doximity uses doximity.com/pub/name-md. If profiles share a prefix, put the prefix in site:. If they do not, you need exclusions instead.
  2. Check the site's robots.txt. If the profile path is disallowed, Google is not crawling those pages and your string will come back thin or empty. Wellfound's profile path is the example below.
  3. Find a word that only profile pages carry. Dev.to profiles show the labels "Location" and "Joined"; Sessionize titles end in "Speaker Profile". That word separates people from posts.
  4. Add 1 skill and 1 place in quotes, with synonyms joined by OR inside brackets.
  5. Read page 1, then subtract noise with a minus. Change one thing per rerun so you know what moved the results.

Here is the map I used for the strings below. I checked each site's robots.txt and a sample page on 4 October 2026:

SiteWho you findProfile URL patternProfile pages open to crawlers?Word that marks a profile
GitHubSoftware engineersgithub.com/nameYes; contributor and stargazer lists are blocked"followers" "following"
Stack OverflowEngineers by tagstackoverflow.com/users/id/nameYes in the 10 Sept 2026 copy; our live check was blocked"reputation", "top tags"
KaggleData scientistskaggle.com/nameCould not read todayTier names such as "Grandmaster"
DribbbleProduct and brand designersdribbble.com/nameYesExclude /shots/
BehanceVisual and motion designersbehance.net/nameYesExclude /gallery/
MediumEngineers and managers who writemedium.com/@nameYesThe /@ prefix
DEV (dev.to)Developers who writedev.to/nameYes"Location", "Joined"
DoximityUS physicians, NPs, PAs, pharmacistsdoximity.com/pub/name-mdYesThe /pub/ prefix
SessionizeConference speakerssessionize.com/nameYes"Speaker Profile" in the title
MeetupOrganisers and speakersGroup and event pagesMember pages ask you to log in"organizer"
WellfoundFounders and startup teamswellfound.com/company/name/peopleCompany pages yes; /u/ profiles blocked"Founder, Leadership"
University sitesAlumni by degree and yearVaries by schoolVaries"alumni", "class of"

30 X-ray search strings for sites beyond LinkedIn

Every string uses only the operators in the table above. I wrote them against URL patterns and page words I confirmed on 4 October 2026, but I have not run them in a logged-out browser for this article, so judge the results yourself. Swap the skill and city for your role. For more role-by-role strings, see our Boolean search string examples; for the logic itself, the Boolean operators guide.

GitHub X-ray search (strings 1 to 5)

GitHub is the site recruiters X-ray most, and the hardest to aim. Profiles sit at github.com/name with no shared prefix, so a plain site:github.com string returns repositories, issues and docs as well as people. The fix is a pair of words only a profile page shows.

1. Go engineers in Berlin, profiles only.

site:github.com "followers" "following" ("Go" OR "Golang") "Berlin" -tutorial -awesome

"followers" and "following" appear on user profiles, which pushes repository pages down. -awesome removes the link-list repositories that swamp every skill keyword.

2. Android engineers in Portugal.

site:github.com "followers" "following" "Kotlin" "Android" ("Lisbon" OR "Porto" OR "Portugal")

People write a city, a country or both in the location field. Cover all 3.

3. GitHub's own user search, which beats Google for location.

type:user location:berlin language:go followers:>10

Run this in GitHub's search bar, not Google. GitHub documents location:, language: and followers:, and language: means "the languages of repositories they own", which is a stronger signal than a word in a bio.

4. Experienced Rust developers, by account age.

type:user language:rust location:"san francisco" repos:>5 created:<2019-01-01

created: filters on when the account opened. An account from before 2019 with 5 or more Rust repositories is a decent proxy for years in the language.

5. Personal sites hosted on GitHub Pages.

site:github.io ("resume" OR "CV") "data engineer" ("Airflow" OR "dbt")

Many engineers publish a resume at name.github.io, sometimes with an email they chose to share. Leave contributor lists alone: GitHub's robots.txt blocks crawlers from /contributors and /stargazers pages, so Google cannot see them.

Stack Overflow X-ray search (strings 6 to 8)

Stack Overflow profiles sit under a clean prefix, stackoverflow.com/users/, which makes it one of the easiest sites to aim at. The archived 10 September 2026 copy of its robots.txt left profile pages open while blocking activity and filter views. Location is optional, so expect gaps.

6. Go answerers in Berlin.

site:stackoverflow.com/users "Berlin" ("go" OR "golang") "top tags"

"top tags" sits on the profile itself, so this skips question pages.

7. Android specialists in London.

site:stackoverflow.com/users "London" ("kotlin" OR "android") "reputation"

Reputation is earned by answers other people voted up. A high number tells you the person explains things well in public.

8. Database specialists on a sister site.

site:dba.stackexchange.com/users "PostgreSQL" ("Amsterdam" OR "Netherlands")

Stack Exchange runs dozens of topic sites with the same /users/ path. Swap the subdomain for the niche: dba for databases, serverfault for operations, security for security engineers.

Kaggle X-ray search for data scientists (strings 9 to 11)

Kaggle ranks members in 5 tiers: Novice, Contributor, Expert, Master and Grandmaster. The tier word is the filter recruiters lean on. Kaggle served our checks a captcha today, so I could not read its robots.txt; treat these strings as ones to test.

9. Kaggle Masters and Grandmasters in London.

site:kaggle.com ("Grandmaster" OR "Master") "London" -competitions -datasets -discussion

The minus terms push competition, dataset and forum pages out, leaving more profiles.

10. Computer vision Experts in Bengaluru.

site:kaggle.com "Expert" "computer vision" ("Bengaluru" OR "Bangalore")

Use both spellings for any city that changed its name.

11. Kaggle people who also code in public.

site:github.com "followers" "following" "kaggle.com" "Toronto"

This finds GitHub profiles that link to a Kaggle account, so you get competition results and production code for the same person.

Dribbble and Behance X-ray search for designers (strings 12 to 15)

Both sites mix profiles with project pages. Dribbble project posts live under /shots/ and Behance projects under /gallery/, so exclude those paths and profiles rise.

12. Product designers in Germany, Dribbble.

site:dribbble.com "product designer" ("Berlin" OR "Germany") -inurl:shots -jobs

inurl: is undocumented on Google, so if it misbehaves, drop it and add -"shot" instead.

13. Illustrators in Toronto, Dribbble.

site:dribbble.com "illustrator" "Toronto" -inurl:shots -inurl:tags

Tag pages are blocked in Dribbble's robots.txt anyway; the exclusion just keeps stray ones out.

14. UX designers in Lisbon, Behance.

site:behance.net "UX designer" "Lisbon" -inurl:gallery

Project pages repeat the designer's name, so excluding /gallery/ is what turns this into a people search.

15. Motion designers by tool, Behance.

site:behance.net "motion designer" ("After Effects" OR "Cinema 4D") "London" -inurl:gallery -jobs

Designers name their tools more reliably than their seniority, so the tool group carries this string.

Medium and DEV X-ray search for engineers who write (strings 16 to 19)

People who write about their work are easier to assess and often easier to approach, because you can open with something they wrote.

16. Staff engineers who write about Kubernetes, Medium.

site:medium.com/@ "staff engineer" "Kubernetes"

Medium author pages sit under /@name, so the /@ prefix favours authors over publications.

17. Engineering managers writing about scaling teams, Medium.

site:medium.com "engineering manager" ("hiring" OR "onboarding") "platform team" after:2025

after: keeps it to pages Google holds as updated since 2025, which cuts the 2017 thought pieces.

18. TypeScript developers in Lagos, DEV.

site:dev.to "Location" "Joined" "Lagos" ("TypeScript" OR "React")

"Location" and "Joined" are profile labels on DEV, so posts drop away.

19. Rust developers who list an employer, DEV.

site:dev.to "Work" "Joined" "Rust" ("Berlin" OR "Munich")

DEV profiles carry a "Work" line when the person filled it in. It is the closest thing to a current title on the site.

Healthcare directories: Doximity and the NPI Registry (strings 20 to 22)

Healthcare is where X-ray needs the most care. Doximity's public directory covers US physicians, nurse practitioners, physician assistants and pharmacists, and its profile pages are open to crawlers. Its Terms of Service, effective 20 July 2026, ban scripts, robots and crawlers that access or scrape the service. Read results by hand; never automate it. For tools built around clinical hiring, see our healthcare recruiting software list.

20. Cardiologists in Nashville, Doximity.

site:doximity.com/pub "Cardiology" "Nashville"

Doximity profile titles carry the name, credential, city, state and specialty, so 2 quoted words go a long way.

21. Family nurse practitioners in Ohio, Doximity.

site:doximity.com/pub ("nurse practitioner" OR "NP") "family medicine" "OH"

Profiles use the 2-letter state code in the title. Try the full state name on a second run.

22. The NPI Registry, searched directly.

https://npiregistry.cms.hhs.gov/api/?version=2.1&taxonomy_description=cardiology&state=TN&limit=50

This is the US government's public provider registry, with an open API. It returns the practice address, a practice phone number and credentials. Use it to confirm that someone you found is a licensed provider in the state you need. The phone number rings the practice, not the person.

Conference speaker lists and Sessionize (strings 23 to 25)

Speakers are a filtered pool: someone already judged them good enough to put on a stage.

23. Kubernetes speakers in Germany, Sessionize.

site:sessionize.com intitle:"Speaker Profile" "Kubernetes" "Germany"

Sessionize titles speaker pages "Name's Speaker Profile @ Sessionize", which makes intitle: unusually precise here.

24. Data engineering conference speaker pages.

intitle:speakers "data engineering" ("conference" OR "summit") after:2025 -jobs

No site: at all: this finds speaker pages on any conference site. Open each page and note the names with a role you need.

25. Speaker decks as PDFs.

filetype:pdf "product management" ("keynote" OR "talk") "speaker" after:2025

Slide decks often carry the speaker's name and employer on slide 1.

Meetup and Wellfound (strings 26 to 28)

Both sites need a workaround. A Meetup member page asked us to log in when we checked, so aim at group and event pages, where organisers are named. Wellfound's robots.txt (August 2026 copy) disallows /u/, its candidate profile path, so X-ray its company team pages instead.

26. Python meetup organisers in Austin.

site:meetup.com "Python" "Austin" ("organizer" OR "organized by")

An organiser of a local tech group knows half the people you want to hire, so talk to them even if they are not the candidate.

27. Speakers at local events.

site:meetup.com "Rust" "Berlin" ("speaker" OR "talk by")

Event pages name the speaker in the description. Note the name, then find the person on GitHub.

28. Fintech founders and early teams, Wellfound.

site:wellfound.com intitle:"Founder, Leadership" "fintech" "London"

Wellfound titles company people pages "Company: Founder, Leadership & Team". Use it to find early employees at startups that just closed or shrank.

University alumni pages (strings 29 and 30)

Universities publish alumni spotlights, award lists and class notes, all public and often detailed about degree and year. If you hire graduates every year, our campus recruiting software guide covers the tools for it.

29. US alumni in software, by class year.

site:edu "alumni" ("class of 2018" OR "class of 2019") "software engineer"

site:edu matches every .edu domain. Add one school's domain instead, such as site:yourschool.edu, when the role calls for a specific program.

30. UK chemical engineering graduates, on Bing.

site:ac.uk "alumni" "chemical engineering" inbody:graduated loc:GB

Bing documents inbody: and loc:, and takes 1 term per inbody:. Keep Bing strings to 10 terms or fewer.

What are the limits and ethics of X-ray search?

This section is practical guidance, not legal advice. Talk to your counsel about your own process, especially for candidates in the EU or UK.

Terms of service

Typing a query into Google and reading a public page is ordinary searching. What sites restrict is automation and reuse. GitHub's Acceptable Use Policies forbid using information from GitHub for spam, including unsolicited emails and selling personal information "such as to recruiters, headhunters, and job boards". They also require you to respond to "do not contact" requests. Doximity bans scrapers and crawlers outright. So search by hand, contact people one at a time with a real reason, and stop when asked.

robots.txt

robots.txt tells crawlers which paths they may fetch. It shapes what Google can show you: Wellfound's /u/ profiles and GitHub's contributor lists are blocked, so strings aimed at them return little. It is also a clear signal of what a site does not want collected. Do not point a scraper at a path the site has disallowed.

GDPR and legitimate interest

For EU candidates, recruiters usually rely on legitimate interest under Article 6(1)(f) of the GDPR. That lets you process personal data unless the person's rights override your interest, which is why a balancing test is worth writing down. Article 14 then requires you to tell people you collected their data from elsewhere. You must do it within a reasonable period and at the latest within 1 month, or at your first message if you contact them. A short privacy line in your first email covers most of it.

Data accuracy

Google shows its copy of a page, and Google confirmed the cache: operator is gone, so you cannot check what it saw. A GitHub location may be 4 years old. A Kaggle tier says nothing about current employment. Confirm the current role on the person's own site or a recent post before you write to them.

Result caps

Google is explicit that site: "doesn't necessarily return all the URLs that are indexed under the prefix". Its operators are "bound by indexing and retrieval limits", and pages now come 10 results at a time since num=100 stopped working. Bing reads only the first 10 terms of a query. The answer is narrower strings and more of them, by city, by synonym and by site.

How do you turn X-ray results into a shortlist?

Results pages are a list of URLs. A shortlist is people you have checked against the role, and most of them will be the passive people our passive candidate sourcing guide writes about. The steps that close the gap:

  1. Write down the must-haves first, 2 or 3 of them, before you open a single result. Everything else is a preference.
  2. Open each result and score it against those must-haves only. A spreadsheet with name, URL, the evidence for each must-have and a yes or no is enough.
  3. Cross-check on a second site. A GitHub profile plus a Stack Overflow profile or a talk tells you more than either alone.
  4. Confirm the current employer and location on the newest source you can find.
  5. Record where and when you found each person, which Article 14 makes you disclose anyway.

How do you find contact details legally?

Start with what the person published for that purpose: an email on their personal site, a GitHub Pages resume, or a contact form on their blog. Then use a contact finder that tells you where its data comes from (our email and phone finders for recruiters list compares them), and send one relevant message rather than a sequence. In the EU or UK, include who you are, why you are writing and how to opt out. Do not harvest emails from commit metadata or code: GitHub's policy names recruiters when it bans using its data for unsolicited email.

How do you skip the manual X-ray?

X-ray is free, but it costs time: each string gets rerun 3 or 4 times before the results go into a spreadsheet. The Cognitive replaces that loop with one sentence.

The Cognitive is AI recruiting software that searches ~900M public profiles from a plain-English brief. I tested it with "Senior backend engineer with 5+ years of Go who has built payments systems, Remote EU". The app read that into editable filters, including "Remote EU" read as Germany plus 7 other countries. You fix any filter that reads you wrong and run it again.

While it searches, it shows 2 phases: "Reading your brief and finding relevant candidates", then "Ranking candidates based on your requirements". Every person found is judged against the must-haves in your brief. Anyone who misses one drops below the people who meet them, so the top of the list is the shortlist you would have built by hand. Each card opens with a "Why this match" line, 1 or 2 reasons traced to the profile, such as "Go listed in skills".

The contact step is built in. You can reveal verified emails and phone numbers, enriched from 30+ sources. Costs are published: 1 credit per candidate a search returns, 5 to reveal an email and 10 to reveal a phone number, and a reveal is charged only when a value comes back. Everyone you find stays with the role, and later searches skip people you have already seen.

AI Sourcing starts at $49/month, cancel anytime. Email and SMS outreach sequences need the Sourcing Pro plan and go out from platform mailboxes. There is no Chrome extension, so it does not read GitHub or Dribbble pages as you browse them.

There is a free trial with 100 sourcing credits.

Type the brief instead of the string One sentence, read into editable filters and ranked against your must-haves across ~900M public profiles. Start free

Who is The Cognitive built for?

The Cognitive is built for the recruiter who X-rays 4 sites for every hard role and still ends up with a spreadsheet to sort. It suits in-house teams and small agencies that want a ranked shortlist, contact reveals and a live AI video interview in one self-serve account. Keep what already works:

To start, take the hardest open role you have, write it as 1 sentence with 2 or 3 must-haves, and run it both ways: as one of the strings above and as a brief. Count the people you would actually contact. If you would rather have strings written for you, our free Boolean search generator writes them from a short brief, and the same page compares it with the other free generators.

Run your hardest role as a brief, not 30 strings Describe it once, see who meets every must-have, then reveal verified contacts for the people you pick. Start free

Sources

Frequently Asked Questions

What is Google X-ray search?

Google X-ray search is a Google or Bing query restricted to one website with the site: operator, so every result is a page from that site, such as a GitHub or Kaggle profile. Recruiters use it to search sites that have weak or no people search of their own. It is free and needs no account on the site. The Cognitive replaces the string with a plain-English brief searched across ~900M public profiles.

How do I do an X-ray search on Google?

Type site: followed by the site's profile path, then add a skill and a location in quotes, for example site:stackoverflow.com/users "Berlin" "golang" "top tags". First open 3 real profiles to learn the URL pattern, check the site's robots.txt, and find a word only profile pages carry. Then read page 1 and remove noise with a minus sign, changing one thing per rerun.

Which Google search operators still work in 2026?

Google's help page, read on 4 October 2026, documents quotes, site:, minus, filetype:, before: and after:. OR, intitle: and inurl: are widely used but not documented by Google today, so test them on your query. Google retired the + operator in 2011, confirmed in September 2024 that cache: no longer works, and stopped honouring &num=100 in September 2025. Bing documents OR, intitle:, inbody: and loc:.

How do I X-ray search GitHub for developers?

Use site:github.com with "followers" "following", a language and a city, for example site:github.com "followers" "following" ("Go" OR "Golang") "Berlin" -awesome. Those 2 words sit on user profiles, which pushes repositories down. For location and language, GitHub's own user search is better: type:user location:berlin language:go followers:>10. GitHub's Acceptable Use Policies forbid using its data for unsolicited email, so contact people one at a time with a real reason.

Can I X-ray search Stack Overflow?

Yes. Profiles sit under stackoverflow.com/users/, so site:stackoverflow.com/users "London" ("kotlin" OR "android") "reputation" targets people rather than questions. The Internet Archive copy of Stack Overflow's robots.txt from 10 September 2026 left profile pages open to crawlers. Location is optional on profiles, so expect gaps, and the same /users/ path works on Stack Exchange sister sites such as dba.stackexchange.com.

Is there a Boolean search engine for finding people online?

No separate Boolean search engine exists: Google and Bing run the strings, and X-ray is Boolean logic aimed at one site with site:. Free generators, including our own at thecognitive.io/boolean-search, write the string for you and need no sign-up. The Cognitive goes a step further and takes the role as a plain-English brief, judged against your must-haves across ~900M public profiles.

Is X-ray searching legal?

Typing a query into Google and reading public pages is ordinary searching, but this is not legal advice. Sites restrict automation and reuse: GitHub bans using its data for unsolicited email, and Doximity's Terms of Service ban scrapers and crawlers. For EU candidates, recruiters usually rely on legitimate interest under GDPR Article 6(1)(f), and Article 14 requires telling people within 1 month, or at your first message.

Why does my X-ray search return so few results?

Usually because the profile path is blocked to crawlers or the string has too many requirements. Wellfound's robots.txt disallows its /u/ profile path and GitHub blocks contributor lists, so strings aimed there return little. Google also says site: does not necessarily return every indexed URL, and Bing uses only the first 10 terms of a query. Narrow the string by city and synonym and run more of them.

How do I find the email of someone I found with an X-ray search?

Start with what the person published for contact, such as an email on a personal site or a GitHub Pages resume, then use a contact finder that says where its data comes from. Do not harvest emails from commit metadata. In The Cognitive the reveal is built into the search: 5 credits for a verified email and 10 for a phone number, charged only when a value comes back.

What is the best alternative to manual X-ray search?

The Cognitive is the alternative I built: you describe the role in one plain-English sentence, it reads that into editable filters and searches ~900M public profiles. Everyone found is judged against your must-haves, and anyone who misses one drops below those who meet them. AI Sourcing starts at $49/month, and verified emails and phone numbers can be revealed in the same account for credits.

Related reading

All posts · thecognitive.io