CSINT / Open working record

See CSINT on one screen.

This map explains what the site is for, where its tools run, and how an investigation becomes evidence. Every node represents a real step in the work.

01 / Understand

Break down a question.

A file, web page, APK, claim, or public feed becomes one bounded starting question.

02 / Inspect

Choose the right desk.

Each tool states what it accepts, what it produces, and where it processes data.

03 / Connect

Do not lose the evidence.

Keep findings, sources, time, and relationships in one working flow instead of scattered notes.

04 / Share

Hand it over clearly.

Leave a readable report, evidence log, or delivery package that another person can follow.

Working model

Why does one node connect to another?

CSINT is more than a directory. It is a working order: bound the question, choose the inspection, attach the evidence, and turn it into a readable result when needed.

The connections are not a mandatory workflow. They are a simple order for moving forward without losing context.

Product relationships

Each product has a different job. They work together.

This graph does not turn every tool into a complicated diagram. A node is one work area. A line shows how the output of one step can be useful in the next. Select a node to see what it takes, what it gives back, and its boundary.

Tool and research area Evidence and workspace Product or service

Lines do not mean a mandatory integration or automatic data transfer. They show how context created in one step can be used in the next.

Data boundaries

Every tool card answers the same question.

Where is the input processed? What output is produced? These labels make the boundary visible before you choose a tool. Read the individual page before entering sensitive data.

In browser

Stays on your device

The file, note, or evidence record is processed in the browser. This category is designed for local work.

Server query

The stated value is sent

A URL, domain, IP, or bounded research question passes through a server for a controlled query.

Public feed

Public records are followed

These cards do not require user input. They organize public threat and source feeds.

Mixed flow

Local file, permitted query

Media is inspected on the device. An optional permitted URL request is described separately.

Live tool catalogue

29 tools, eight working areas.

Instead of a name list, every card says what it does and what kind of output it creates. Filter by processing boundary or search by name.

Showing 29 tools.

01 / AI Intelligence

1 tool
  • 01.01

    Browser

    AI Agent Surface Map

    Maps agent instructions, MCP connections, CI permissions, and powerful tool surfaces in a repository archive without running code.

    Output: Surface map and JSON/Markdown evidence pack.

02 / File and visual inspection

7 tools
  • 02.01

    Browser

    Mobile Exposure Graph

    Shows APK permissions, code, and infrastructure traces in an evidence-linked graph. It can compare two versions.

    Output: Findings graph, version diff, and evidence ZIP.

  • 02.02

    Browser

    CSINT Mobile Behavior Diff

    Matches the same mobile journey across controlled conditions and APK versions, then links behavior changes to an evidence bundle.

    Output: Scenario diff, contract result, graph, and raw evidence.

  • 02.03

    Browser

    File and document sandbox

    Builds an identity, structure, embedded-link, and IOC report from one file.

    Output: Inspection report and relationship graph.

  • 02.04

    Browser

    Version comparison

    Extracts structural differences between two versions of a file.

    Output: Difference list and assessment.

  • 02.05

    Browser

    Container image inspection

    Inspects the layers of an exported container image.

    Output: Layer and content report.

  • 02.06

    Mixed

    Shadow Trace

    Shows frame, pixel, movement, and audio events in images, video, and audio on a timeline.

    Output: Timeline and downloadable ZIP report.

  • 02.07

    Browser

    Visual and video evidence lab

    Inspects image and video files for evidence assessment.

    Output: Metadata and investigation notes.

03 / Web and domain research

7 tools
  • 03.01

    Server

    OSINT Runbook Builder

    Turns a research question into bounded, scheduled public-source checks.

    Output: Tracking record and downloadable runbook.

  • 03.02

    Server

    Web evidence recorder

    Records a page as evidence with its date context.

    Output: Dated evidence record.

  • 03.03

    Server

    Redirect chain

    Shows the steps an address takes before it reaches its destination.

    Output: Step-by-step redirect list.

  • 03.04

    Server

    Web supply chain inspection

    Lists the third-party dependencies loaded by a page.

    Output: Dependency list.

  • 03.05

    Server

    Web change monitoring

    Compares what changed between versions of a page.

    Output: Version-to-version change report.

  • 03.06

    Server

    Internet exposure

    Summarizes how assets you own appear from the public internet.

    Output: Passive visibility summary.

  • 03.07

    Browser

    Shadow verification

    Evaluates a suspicious account or claim through a checklist.

    Output: Verification assessment.

04 / Email and IOC inspection

1 tool
  • 04.01

    Server

    IOC lookup

    Compares an indicator with public records.

    Output: Source-by-source reputation summary.

05 / Threat Intelligence

7 tools
  • 05.01

    Public feed

    CTI desk

    Brings CVE, IOC, and ransomware feeds together in one view.

    Output: Live threat desk.

  • 05.02

    Public feed

    CVE tracking

    Follows vulnerability records that are actively exploited.

    Output: Current CVE list.

  • 05.03

    Public feed

    Ransomware monitoring

    Follows public announcements from ransomware groups.

    Output: Group and victim feed.

  • 05.04

    Public feed

    Threat actors

    Lists profiles of tracked threat actors.

    Output: Actor profiles.

  • 05.05

    Public feed

    Dark web signal analysis

    Collects and summarizes public signals associated with dark-web sources.

    Output: Signal summary.

  • 05.06

    Public feed

    Daily briefing

    Presents the day’s threat records as a short briefing.

    Output: Daily briefing text.

  • 05.07

    Public feed

    Detection pack

    Prepares detection content from current threat records.

    Output: Downloadable detection content.

06 / Archive and change tracking

2 tools
  • 06.01

    Server

    Web archive desk

    Shows archived versions of an address on a timeline.

    Output: Archived-version timeline.

  • 06.02

    Public feed

    Source changes

    Records changes in monitored sources.

    Output: Change log.

07 / Android and malware inspection

1 tool
  • 07.01

    Public feed

    Android threats

    Collects Android-focused threat and vulnerability records.

    Output: Threat records.

08 / Reporting and evidence preparation

3 tools
  • 08.01

    Browser

    Report builder

    Turns verified findings into a shareable report.

    Output: Shareable report.

  • 08.02

    Browser

    Evidence log

    Keeps evidence in order with source and date context.

    Output: Ordered evidence list.

  • 08.03

    Browser

    Case correlation desk

    Builds relationships between event and asset records.

    Output: Relationship graph.

Products and services

Work that is separate from a tool.

The free catalogue describes browser-based tools. These areas are human-led review, monitoring, or collaborative ways of working.

Open

ReleaseGuard / Handoff Desk

A client delivery record for n8n agencies and freelance automation developers. It frames scope, change, risk path, and a SHA-256 manifest as a readable package.

Review the service
Open

AI Automation Security

A security review centre for n8n agencies, automation teams, and people operating their own workflows.

Open the centre
Pro pilot

n8n Workflow Security Monitoring

Makes packages in an n8n file visible, checks known security issues, and helps monitor meaningful changes.

Review monitoring
Invitation-only pilot

OSINT Evidence Workspace

A team workspace for case areas, source and claim records, evidence packages, client review links, and an audit log.

Review the workspace

Working spaces

Desks that organize an investigation.

These spaces are less about one tool and more about keeping the question and evidence together. Each explains its own data boundary on its page.

Event verification

Helps organize a claim, its sources, and verification steps into a small case flow.

Open Event Desk

Inquiry Room

A workspace for following a research question, public-source checks, and notes more systematically.

Open Inquiry Room

Incident Lab

A learning space for safe incident-analysis practice, case studies, and method notes.

Open Incident Lab

Now and later

Keep the status clear.

A product name does not mean a capability is ready. This page separates live tools, open products, and pilot areas. Planned work has its own roadmap.

Now

29 live tools

The eight catalogue groups state their input, output, and processing boundary.

In progress

Pilots and workspaces

Pro and invitation-only pilots keep their actual status. They are not written as ready-made products.

Later

Roadmap

Unpublished work stays separate. It moves into the live list only after it has been verified and released.

Open roadmap

First step

Start in one place.

You do not need to learn everything at once. Identify what you have, see the boundary, then organize your notes or evidence.

  1. Start with file inspection if you have a file, document, or APK.
  2. Open the web evidence recorder if you need to verify a page.
  3. Go to the CTI desk if you need a current threat feed.
  4. Use Event Desk when you have several sources and claims to connect.