Skip to content
Osintpro

OSINT for Law Enforcement, Investigators and Fraud Analysts

Investigation output gets challenged. That is the difference between this work and most analysis: somebody with an interest in the answer being wrong will read it carefully, and the question they ask first is where each claim came from and when.

Everything here is authorized, consent-backed entity work on organizations and infrastructure. Never speculative profiling of a private individual.

See pricing
  • Authorized use only.
  • Domains only, never a person.
  • Every finding sourced and timestamped.
  • Passive collection only.

Write for the person who wants you to be wrong.

A screenshot in a case file is an assertion. It has no retrieval timestamp, no record of which server answered, and it can be cropped. Registration data, DNS answers and certificates all change, which means an undated claim about any of them cannot be verified later, including by you.

The test to apply to every line of an investigation report: can a hostile reader re-run this and reach the same result. If yes, the finding survives. If no, it will be attacked at exactly the moment it matters most.

Meeting that test costs nothing at collection time and is nearly impossible to retrofit, which is why it has to be the default rather than something applied to the findings that turned out to matter.

OSINT for law enforcement and public-sector investigators.

The evidence discipline is the same whoever is applying it, and public-sector work is where it is tested hardest, because the report has to survive disclosure and a defense reading it looking for the gap. A finding that carries the record, the endpoint that answered and the UTC moment of retrieval can be re-run by the other side and reach the same result, which is the whole point.

What we are is narrow, and it is worth being exact about it: a public-record collection and reporting tool. Collection is passive, so nothing here touches a target system. There is no covert capability, no interception, no undercover persona tooling and no lawful-intercept function, and the demo accepts a domain rather than a person by design. Whether a given collection is lawful, and whether the output is admissible, turns on your jurisdiction, your authorization and your force policy, not on the tool. Nothing on this page is legal advice.

In practice the fit is entity and infrastructure work: the domain behind a fraudulent invoice, a lookalike registration used in a phishing campaign, the public footprint of a company under investigation. The same osint techniques apply, with the scope declared first, and the osint report structure carries over unchanged.

Where public-record work carries an investigation.

Invoice and payment-redirection fraud

Registration age of the domain the invoice arrived from, its mail posture, and whether it is a lookalike of a real counterparty. Frequently answered inside ten minutes, and dated.

Counterparty verification in AML work

Whether the entity behind a transaction has infrastructure consistent with the business it claims. Corroborates registry work rather than replacing it.

Marketplace and platform trust and safety

Seller and merchant infrastructure checks at volume, with a repeatable artifact per case rather than an analyst's recollection.

Insurance and claims investigation

Entity checks on suppliers and claimants that are organizations, with the collection dated against the events in the claim.

Brand abuse and phishing response

Enumerating lookalike registrations with the evidence attached, which is what a registrar complaint or a UDRP filing needs to go anywhere.

Internal investigations touching a company

Where the subject is a supplier or a related entity rather than a person, with the scope and basis recorded before collection.

The discipline that makes a case file hold.

  1. Step 1

    Scope declared before collection

    Subject, requester, purpose, basis, and what is explicitly out of bounds. Chronology is the point: written first it constrains the work, written afterwards it is a justification and reads as one.

  2. Step 2

    Every finding carries its own evidence

    The raw record exactly as returned, the endpoint that answered, and the UTC moment of retrieval. Not most findings. Every one, including the ones you are sure about.

  3. Step 3

    Negative findings kept, not dropped

    What you looked for and did not find, dated the same way. "No adverse record was found at the time of retrieval" is defensible. "There are none" is a claim you cannot support.

  4. Step 4

    Confidence stated per finding

    High from a direct record, medium from a single indirect indicator, low from a weak pivot such as shared cloud infrastructure. A reader who can tell what you know from what you suspect will trust both.

  5. Step 5

    Limitations written down

    Redacted registration data, a registry that is not public, a log that proves issuance rather than deployment. A limitations section makes a report stronger, not weaker.

Work a subject domain and read the evidence chain.

Declare the purpose, tick the authorization box, run the domain. Hover any finding to reveal the source endpoint and the UTC retrieval time. Domains only, never a person.

  • It runs in your browser. Queries go to public DNS and RDAP endpoints, not through us.

  • Nothing reaches the subject. The domain you enter is never contacted, probed or scanned.

  • A domain, never a person. There is no input on this panel that accepts an individual.

  • Findings carry their evidence. Raw record, source endpoint and the UTC moment of retrieval.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

What we will not help with, stated plainly.

The refusals are what make this usable inside a regulated organization.

No monitoring, profiling or locating of a private individual without a lawful basis. No consumer background checks under FCRA-regulated conditions. No circumvention of platform terms or authentication. No collection intended to harass, intimidate or retaliate. The demo has no input that accepts a person, which is structural rather than promised.

Investigators are the audience most likely to be asked to cross that line by a client, and a published boundary is something you can point at. The full list is on social media OSINT, and the report template is free to use whether or not you use the product.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.