01 / Understand
Break down a question.
A file, web page, APK, claim, or public feed becomes one bounded starting question.
CSINT / Open working record
This map explains what the site is for, where its tools run, and how an investigation becomes evidence. Every node represents a real step in the work.
01 / Understand
A file, web page, APK, claim, or public feed becomes one bounded starting question.
02 / Inspect
Each tool states what it accepts, what it produces, and where it processes data.
03 / Connect
Keep findings, sources, time, and relationships in one working flow instead of scattered notes.
04 / Share
Leave a readable report, evidence log, or delivery package that another person can follow.
Working model
CSINT is more than a directory. It is a working order: bound the question, choose the inspection, attach the evidence, and turn it into a readable result when needed.
The connections are not a mandatory workflow. They are a simple order for moving forward without losing context.
Product relationships
This graph does not turn every tool into a complicated diagram. A node is one work area. A line shows how the output of one step can be useful in the next. Select a node to see what it takes, what it gives back, and its boundary.
Lines do not mean a mandatory integration or automatic data transfer. They show how context created in one step can be used in the next.
Data boundaries
Where is the input processed? What output is produced? These labels make the boundary visible before you choose a tool. Read the individual page before entering sensitive data.
The file, note, or evidence record is processed in the browser. This category is designed for local work.
A URL, domain, IP, or bounded research question passes through a server for a controlled query.
These cards do not require user input. They organize public threat and source feeds.
Media is inspected on the device. An optional permitted URL request is described separately.
Live tool catalogue
Instead of a name list, every card says what it does and what kind of output it creates. Filter by processing boundary or search by name.
Showing 29 tools.
01.01
BrowserMaps agent instructions, MCP connections, CI permissions, and powerful tool surfaces in a repository archive without running code.
Output: Surface map and JSON/Markdown evidence pack.
02.01
BrowserShows APK permissions, code, and infrastructure traces in an evidence-linked graph. It can compare two versions.
Output: Findings graph, version diff, and evidence ZIP.
02.02
BrowserMatches the same mobile journey across controlled conditions and APK versions, then links behavior changes to an evidence bundle.
Output: Scenario diff, contract result, graph, and raw evidence.
02.03
BrowserBuilds an identity, structure, embedded-link, and IOC report from one file.
Output: Inspection report and relationship graph.
02.04
BrowserExtracts structural differences between two versions of a file.
Output: Difference list and assessment.
02.05
BrowserInspects the layers of an exported container image.
Output: Layer and content report.
02.06
MixedShows frame, pixel, movement, and audio events in images, video, and audio on a timeline.
Output: Timeline and downloadable ZIP report.
02.07
BrowserInspects image and video files for evidence assessment.
Output: Metadata and investigation notes.
03.01
ServerTurns a research question into bounded, scheduled public-source checks.
Output: Tracking record and downloadable runbook.
03.02
ServerRecords a page as evidence with its date context.
Output: Dated evidence record.
03.03
ServerShows the steps an address takes before it reaches its destination.
Output: Step-by-step redirect list.
03.04
ServerLists the third-party dependencies loaded by a page.
Output: Dependency list.
03.05
ServerCompares what changed between versions of a page.
Output: Version-to-version change report.
03.06
ServerSummarizes how assets you own appear from the public internet.
Output: Passive visibility summary.
03.07
BrowserEvaluates a suspicious account or claim through a checklist.
Output: Verification assessment.
04.01
ServerCompares an indicator with public records.
Output: Source-by-source reputation summary.
05.01
Public feedBrings CVE, IOC, and ransomware feeds together in one view.
Output: Live threat desk.
05.02
Public feedFollows vulnerability records that are actively exploited.
Output: Current CVE list.
05.03
Public feedFollows public announcements from ransomware groups.
Output: Group and victim feed.
05.04
Public feedLists profiles of tracked threat actors.
Output: Actor profiles.
05.05
Public feedCollects and summarizes public signals associated with dark-web sources.
Output: Signal summary.
05.06
Public feedPresents the day’s threat records as a short briefing.
Output: Daily briefing text.
05.07
Public feedPrepares detection content from current threat records.
Output: Downloadable detection content.
06.01
ServerShows archived versions of an address on a timeline.
Output: Archived-version timeline.
06.02
Public feedRecords changes in monitored sources.
Output: Change log.
07.01
Public feedCollects Android-focused threat and vulnerability records.
Output: Threat records.
08.01
BrowserTurns verified findings into a shareable report.
Output: Shareable report.
08.02
BrowserKeeps evidence in order with source and date context.
Output: Ordered evidence list.
08.03
BrowserBuilds relationships between event and asset records.
Output: Relationship graph.
Products and services
The free catalogue describes browser-based tools. These areas are human-led review, monitoring, or collaborative ways of working.
A client delivery record for n8n agencies and freelance automation developers. It frames scope, change, risk path, and a SHA-256 manifest as a readable package.
Review the serviceA security review centre for n8n agencies, automation teams, and people operating their own workflows.
Open the centreMakes packages in an n8n file visible, checks known security issues, and helps monitor meaningful changes.
Review monitoringA team workspace for case areas, source and claim records, evidence packages, client review links, and an audit log.
Review the workspaceWorking spaces
These spaces are less about one tool and more about keeping the question and evidence together. Each explains its own data boundary on its page.
Helps organize a claim, its sources, and verification steps into a small case flow.
Open Event DeskA workspace for following a research question, public-source checks, and notes more systematically.
Open Inquiry RoomA learning space for safe incident-analysis practice, case studies, and method notes.
Open Incident LabNow and later
A product name does not mean a capability is ready. This page separates live tools, open products, and pilot areas. Planned work has its own roadmap.
Now
The eight catalogue groups state their input, output, and processing boundary.
In progress
Pro and invitation-only pilots keep their actual status. They are not written as ready-made products.
Later
Unpublished work stays separate. It moves into the live list only after it has been verified and released.
Open roadmapFirst step
You do not need to learn everything at once. Identify what you have, see the boundary, then organize your notes or evidence.