Written scope
Question, authorized subject or assets, permitted sources, time window, excluded data, stop date, and approving authority.
DIGITAL EVIDENCE // OPEN-SOURCE INTELLIGENCE
A complete path from curious beginner to ethical investigator: scientific method, chain of custody, OSINT, DFIR, Maltego, open-source tools, and the suites used in professional laboratories.
00 // BEFORE THE FIRST TOOL
A professional can explain what they were authorized to do, what they collected, what changed, how they know, what could be wrong, and whether another examiner can reproduce the result.
Question, authorized subject or assets, permitted sources, time window, excluded data, stop date, and approving authority.
Preserve the original, work from a copy, calculate cryptographic hashes, and record tools, versions, timestamps, and errors.
Automated output is a lead. Confirm important facts with an independent source, another parser, or the native data.
Collect only what is necessary. Relatives, coworkers, bystanders, and namesakes are not acceptable collateral damage.
Actively seek evidence that would disprove your hypothesis. Keep observations, inferences, and unknowns separate in the report.
Encrypt case files, restrict access, set a retention period, and dispose of data properly when the case closes.
Pause: consult legal counsel, a privacy officer, an editor, or the engagement lead.
Method references: NIST SP 800-86, SWGDE — forensic acquisition, Berkeley Protocol, CNIL — OSINT and privacy and French Criminal Code, Art. 323-1. This guide is educational, not legal advice.
01 // ZERO-TO-OPERATOR BOOTCAMP
This sprint builds safe, independent habits before specialization. Budget 8–10 focused hours per week: 2 hours of theory, 5 hours of lab work, 1 hour of notes, and 1–2 hours of review. Paid software is optional; every required exercise has a free path.
START HERE
OPERATING RHYTHM
DO NOT SKIP
Learn filesystems, processes, logs, hexadecimal, UTC, hashing, artifacts, provenance, and chain of custody.
OUTPUTExplain twelve core terms in your own words and hash five files with two tools.
Create, patch, snapshot, and document Windows and Linux VMs. Separate personal, evidence, OSINT, and malware contexts.
OUTPUTNetwork diagram, asset list, clean snapshot hashes, and recovery test.
Practice evidence intake, imaging, write blocking, verification, working copies, and acquisition logs on a lab USB drive.
OUTPUTE01 plus raw image, matching SHA-256 values, chain of custody, and error log.
Study MFT, USN Journal, Registry, EVTX, Prefetch, LNK, Jump Lists, Amcache, SRUM, and Recycle Bin semantics.
OUTPUTTen reconstructed actions, each tied to a native artifact and parser output.
Normalize time zones, clock offsets, file timestamps, browser history, downloads, cache, and SQLite records.
OUTPUTA twenty-event timeline with confidence, conflicts, and three independently validated events.
Identify processes, sockets, persistence clues, DNS, HTTP, TLS metadata, PCAP limitations, and live-collection side effects.
OUTPUTCorrelate one synthetic RAM image and PCAP into a defensible incident narrative.
Turn an intelligence requirement into a source plan. Use advanced search, archives, WARC, screenshots, hashes, and source logs.
OUTPUTA preserved source package and a claim-to-source matrix with no circular corroboration.
Practice entity resolution across usernames, registries, RDAP, DNS, certificates, and public code while accounting for namesakes.
OUTPUTA fictional identity map with two rejected matches and explicit stopping criteria.
Extract metadata and keyframes, perform reverse search, compare terrain and shadows, and distinguish a clue from proof.
OUTPUTLocation and time-window assessment with alternatives, uncertainty, and preserved media.
Model entities, run narrow Transforms, label edge provenance, avoid false merges, and reduce a graph for an audience.
OUTPUTA readable fictional fraud graph plus a source register and five explained relationships.
Parse supplied Android/iOS and cloud exports, inspect SQLite manually, state collection gaps, then audit your own public exposure.
OUTPUTA focused mobile finding and a completed anti-OSINT remediation plan.
Combine disk, memory, network, web, and graph evidence. Answer one precise question without exceeding scope.
OUTPUTCase brief, notes, exhibits, timeline, report, executive summary, and reproducibility package.
Have a peer challenge authority, collection, timestamps, attribution, alternative hypotheses, and every high-confidence statement.
PASS CONDITIONThe peer reproduces five key findings from your package. Correct the failures, version the report, and record what changed.
90-DAY EXIT CHECK
Your progress is saved only in this browser.
0/6 exit conditions completed.
02 // 12-MONTH PROGRESSION
Durations assume 7–10 focused hours each week. Do not advance because you watched a course. Advance when you can produce the stated evidence of competence without following a walkthrough.
LEVEL 00 // SHARED FOUNDATION
Learn Linux and Windows, NTFS/ext4/APFS, processes, the Windows Registry, event logs, TCP/IP, DNS, HTTP, SQL/SQLite, JSON, regular expressions, Python/PowerShell/Bash, UTC, and time-zone handling.
LEVEL 01 // EVIDENCE
Study legal authority, scene photography, order of volatility, write blockers, bitstream imaging versus targeted collection, SHA-256, chain of custody, working copies, clock drift, and contemporaneous notes.
LEVEL 02A // DFIR
Master the MFT and USN Journal, Registry, Event Logs, Prefetch, LNK files, Jump Lists, Amcache, Shimcache, SRUM, Recycle Bin, browser artifacts, and deleted files. Build a super-timeline and explain what each timestamp actually means.
LEVEL 02B // OSINT
Define an intelligence requirement and collection plan. Learn search operators, archives, username and domain research, mapping, image and video verification, company registers, and source evaluation. Preserve the URL, UTC time, context, original file, and provenance.
LEVEL 03 // CORRELATION
Analyze RAM and processes, PCAPs, network logs, lawfully acquired Android/iOS artifacts, SQLite databases, cloud audit logs, entities, and relationships. Learn the blind spots of every collection method.
LEVEL 04 // EXAMINER
Develop an examination strategy, validate tools, keep reproducible notes, conduct peer review, write technical and executive reports, disclose limitations, and defend your work under questioning.
LEVEL 05 // SPECIALIST
Specialize in Windows incident response, macOS/iOS, mobile, malware and memory, cloud, fraud, crypto-assets, geolocation, media verification, threat intelligence, or public-interest investigations.
03 // THE TWO INVESTIGATION LOOPS
Define the question, authority or consent, scope, safety risks, equipment, roles, and reference clock.
Identify potential sources and order of volatility. Collect network state and RAM before shutdown only when the scenario, authority, and procedure support live collection.
Isolate without destroying data, photograph the scene, label and seal each item, and open a chain-of-custody record.
Choose physical, logical, targeted, or live acquisition. Record tool and version, settings, operator, start/end time, errors, and SHA-256.
Index and parse a verified working copy. Do not let a suite decide by itself what is relevant or accurate.
Build timelines and competing hypotheses. Account for artifact semantics, time zones, clock drift, missing telemetry, and anti-forensics.
Use a second tool, hex or SQLite view, native source, vendor documentation, test image, or controlled lab reproduction.
Separate observations, inferences, and limitations. Cite exhibits, complete peer review, control access, and follow retention and authorized disposal rules.
Write a precise intelligence requirement, intended decision, success threshold, exclusions, and deadline.
Assess potential harm to subjects, analysts, and third parties; sensitive data; research identities; source exposure; and no-contact rules.
Start with the least intrusive and most authoritative sources. Record dependencies so mirrored claims are not mistaken for independent confirmation.
Capture URL, UTC timestamp, page context, WARC when appropriate, original media, metadata, and cryptographic hash.
Source reliability is not the same as information credibility. Detect circular reporting, satire, outdated pages, manipulated context, and synthetic content.
Resolve entities, map relationships, normalize time and geography, compare hypotheses, and identify missing information.
Seek genuinely independent sources and trace claims to the earliest available original instead of counting republications.
Deliver a proportionate answer with explicit confidence, minimized third-party data, handling markings, retention, and documented purge.
ANALYTIC LANGUAGE
04 // FIELD-READY PROCEDURES
Adapt these templates to your organization, jurisdiction, and validated tools. They are training baselines—not substitutes for legal authority, laboratory policy, or device-specific guidance.
COPY THIS FORMAT
CASE / EXHIBIT / DATE-TIME UTC / OPERATOR / AUTHORITY / SOURCE / ACTION / TOOL + VERSION / SETTINGS / INPUT HASH / OUTPUT HASH / RESULT / ERROR OR DEVIATION / NEXT STEPWrite notes while working. Never silently rewrite history: append corrections with author, time, reason, and the previous value preserved.
| ID | Claim | Direct evidence | Corroboration | Alternative | Confidence | Limitation |
|---|---|---|---|---|---|---|
| F-01 | Precise statement that answers part of the case question | Exhibit and artifact, with location | Independent source or native validation | Strongest competing explanation | Low / moderate / high with rationale | Missing data, parser scope, clock, attribution, or collection gap |
MASTERY RUBRIC
| Domain | Beginner | Junior | Practitioner | Professional |
|---|---|---|---|---|
| Preservation | Can hash a file. | Images training media from a checklist. | Chooses and justifies a collection method. | Handles exceptions, validates the process, and survives custody review. |
| Artifact analysis | Reads parser output. | Explains common artifacts. | Correlates artifacts and validates critical fields. | Recognizes version-dependent semantics, parser failure, and anti-forensics. |
| OSINT | Finds public pages. | Archives sources and records provenance. | Resolves entities and tests alternatives. | Runs proportionate collection, protects people, and detects dependency between sources. |
| Reporting | Lists observations. | Links findings to exhibits. | Separates facts, inference, confidence, and limitations. | Produces concise work that a peer can reproduce and a nontechnical decision-maker can understand. |
| Judgment | Follows steps. | Recognizes obvious uncertainty. | Knows when to stop, escalate, or lower confidence. | Defends decisions, corrects errors transparently, and improves the SOP. |
05 // YOUR LABORATORY
Do not mix personal activity, web collection, malware analysis, and evidence processing. Professional Windows suites and open-source Linux workflows complement each other.
PRIMARY DFIR WORKSTATION
Best compatibility with AXIOM, EnCase, FTK, X-Ways, Cellebrite, MSAB, Oxygen, Belkasoft, and Zimmerman tools.
OPEN-SOURCE ANALYSIS
File-system, timeline, memory, network, and scripting workflows in a free, reproducible, well-documented DFIR distribution.
MALWARE
Use two disposable, isolated VMs: Linux for artifacts and network behavior, Windows for reverse engineering. Never bridge them to evidence storage or the production LAN.
OSINT RESEARCH
A separate browser profile and encrypted case vault are often enough. Qubes/Whonix or Tails address specific threat models; they are not costumes or automatic anonymity.
06 // PUBLICLY DOCUMENTED TOOL ECOSYSTEM
No static list can contain “every tool used by police.” Tooling varies by country, agency, unit, budget, case type, and procedure; some capabilities are export-controlled or restricted to eligible organizations. This catalog covers the major publicly documented ecosystems. Knowing a product name grants neither a license, legal authority, nor examiner competence.
Free forensic preview and acquisition; useful for Windows disk images and memory captures.
Exterro ↗FREEFast Linux imager for raw, EWF/E01, and AFF formats, with integrity verification.
Official site ↗OPEN SOURCECommand-line acquisition and image handling. Powerful tools that require tested procedures and validation.
libewf ↗OPEN SOURCEOpen-source platform for disk, file, timeline, keyword, and module-based analysis.
Autopsy ↗OPEN SOURCEMulti-source recovery, analysis, and reporting across computers, mobile devices, cloud data, and vehicles.
Magnet ↗PROLong-established suite for collection, triage, examination, and reporting in laboratories and enterprises.
OpenText ↗PROIndexing, processing, and review of large data volumes, with laboratory and enterprise editions.
Exterro ↗PROPortable, fast, granular environment derived from WinHex and valued for low-level analysis.
X-Ways ↗PROComputer, RAM, mobile, cloud, vehicle, and drone suite. Its Forensic edition is marketed to government customers.
Belkasoft ↗RESTRICTEDHardware write blockers and imagers (TX1, Falcon-NEO, TaskForce) for controlled acquisition at scale.
Tableau ↗HARDWARETargeted collection and processing through targets and modules; ideal for reproducible triage.
Kroll ↗FREERegistry Explorer, EvtxECmd, MFTECmd, RECmd, LECmd, JLECmd, PECmd, AmcacheParser, and other Windows parsers.
Official index ↗FREEPlugin-based extraction of artifacts from Windows Registry hives.
GitHub ↗OPEN SOURCEFast hunting across EVTX files and logs with Sigma rules; alerts must be interpreted in context.
Hayabusa ↗OPEN SOURCEAggregates many timestamped sources into a super-timeline.
Documentation ↗OPEN SOURCECollaborative timeline analysis with search, views, tags, and notebooks.
Official site ↗OPEN SOURCEChromium data parser for history, downloads, cookies, caches, and extensions.
GitHub ↗OPEN SOURCERead-only remote access to disks, RAM, and cloud data for existing forensic tools.
F-Response ↗PROOpen-source memory-forensics framework for Windows, Linux, and macOS.
Documentation ↗OPEN SOURCEExposes memory as a virtual file system and provides APIs, plugins, and live or offline analysis.
GitHub ↗OPEN SOURCERAM acquisition for Windows, cloud Linux, and Linux kernels. Every live capture changes the system, so document its footprint.
WinPmem ↗OPEN SOURCEEndpoint collection, hunting, and response at scale using VQL and auditable artifacts.
Documentation ↗OPEN SOURCERemote response, state querying, and Unix collection; integrate them into authorization and retention procedures.
GRR ↗OPEN SOURCEPacket capture and protocol inspection. Preserve the original PCAP and filter a working copy.
Wireshark ↗OPEN SOURCENetwork metadata, sessions, extraction, and exploration of large PCAPs; Suricata adds signature-based detection.
Zeek ↗OPEN SOURCELinux and Windows malware-analysis environments designed for isolated, resettable labs.
REMnux ↗OPEN SOURCEDisassembly, decompilation, and debugging. Editions and licenses differ; start with Ghidra.
Ghidra ↗MIXEDClassification, capability identification, obfuscated strings, and data transformations. Always verify the output.
capa ↗OPEN SOURCEMobile acquisition and analysis through Physical Analyzer; Pathfinder correlates large datasets. Access, capabilities, and lawful use are controlled.
Cellebrite ↗RESTRICTEDAdvanced mobile access for eligible customers, plus consent-based or enterprise extraction depending on the product. Not a consumer tool.
Magnet ↗RESTRICTEDXRY extracts; XAMN searches, visualizes, analyzes, and reports. Some capabilities are dual-use and export controlled.
MSAB ↗RESTRICTEDAcquisition and analysis of mobile devices, cloud data, backups, drones, and applications with relationship views.
Oxygen ↗PROiOS acquisition and analysis; Phone Breaker and Distributed Password Recovery cover backups, cloud sources, and authorized recovery.
Elcomsoft ↗PROLogical or physical acquisition where supported, app decoding, review, and mobile reporting.
MOBILedit ↗PROOpen Android and iOS artifact parsers, plus Mobile Verification Toolkit for identifying traces of compromise.
ALEAPP ↗OPEN SOURCEmacOS artifact analysis and a collection of SQLite queries and indicators for Apple devices.
mac_apt ↗OPEN SOURCENative eDiscovery and audit sources. Preserve exports, manifests, time range, collector identity, and API limitations.
Microsoft ↗CLOUDAcquisition and analysis of infotainment systems and drone data. A specialist domain where vendor support and validation are critical.
Berla ↗PROConversion, enhancement, and scientific image or video analysis with an operation history.
Amped ↗PROProprietary CCTV video, enhancement, and large-scale media review, depending on specialty.
iNPUT-ACE ↗PROMetadata, controlled transcoding, and stream inspection. Always preserve the original media.
ExifTool ↗OPEN SOURCEKeyframes, reverse-image search, metadata, and verification of signed provenance information.
InVID ↗FREEReplayable WARC capture of dynamic web content. Complements screenshots and contemporaneous notes.
ArchiveWeb.page ↗OPEN SOURCEWeb collection with logging, traceability, and investigation- or litigation-oriented exports.
Hunchly ↗PROTriage of suspicious Office and PDF documents; analyze only in an isolated environment.
oletools ↗OPEN SOURCELarge-scale processing, review, exhibit management, and collaboration. Guardian and Magnet Review/Automate also occupy this layer.
Nuix ↗INSTITUTIONUse complementary engines, operators, caches, and local languages. Preserve the source page; a search snippet is not evidence.
Advanced search ↗PUBLICHistorical versions and web corpora. Archive.today can complement them; record who archived what, when, and what is missing.
Wayback ↗PUBLICCategory-based resource directories. They are maps, not guarantees of reliability.
Bellingcat ↗INDEXUsername discovery. A shared handle does not prove a shared identity; compare content, dates, and context.
WhatsMyName ↗MIXEDExposure checks and alerts without revealing plaintext passwords. The first choice for self-auditing.
HIBP ↗DEFENSIVEEmail enrichment, accounts, timelines, breaches, and infostealer logs. Use only with authority and strict minimization.
IntelBase ↗SENSITIVESearch and monitoring for exposed identities and infrastructure. Some plans advertise unredacted passwords: do not access them without an explicit legal basis.
OSINTLeak ↗SENSITIVEUnified search platform for breaches, identities, and activity. This is likely the service meant by “oatnhet.com”; the verified domain is oathnet.org.
OathNet ↗SENSITIVEExposure and archive search engines. Treat results as sensitive leads that may be incomplete or misattributed.
Intelligence X ↗SENSITIVEInstitutional platforms for investigations, identity, social networks, and risk. Some functions are restricted and highly intrusive.
SocialNet ↗INSTITUTIONRegistration, delegation, resolvers, and MX/TXT/NS records. Privacy-protected WHOIS is not suspicious by default.
ICANN ↗PUBLICPublic certificate history and hostname discovery; account for third-party and retired assets.
crt.sh ↗PUBLICIndexes of exposed services and certificates. Viewing an index never authorizes connecting to or testing a target.
Censys ↗MIXEDHistorical WHOIS and DNS, pivots, and mapping. Distinguish co-hosting, control, and simple correlation.
SecurityTrails ↗MIXEDReputation, relationships, rendered pages, and indicators. Never submit a confidential file or URL to a public service.
VirusTotal ↗MIXEDSearch public web code and technologies. GitHub and code search can reveal already exposed secrets that should be reported responsibly.
PublicWWW ↗MIXEDAutomated collection and correlation. Restrict modules to scope and verify false positives.
SpiderFoot ↗OPEN SOURCEThreat intelligence, underground forums, and risk monitoring for authorized teams. Searchlight Cyber and Intel 471 serve the same segment.
Recorded Future ↗ENTERPRISEStructured, controlled sharing of indicators and CTI knowledge; taxonomies, markings, and dissemination matter as much as ingestion.
OpenCTI ↗OPEN SOURCETerrain, buildings, roads, and street-level imagery. Bing Maps and KartaView provide different dates and coverage.
Google Earth ↗PUBLICMulti-date satellite imagery and environmental layers. Document resolution, date, cloud cover, and processing.
Copernicus ↗PUBLICSun and shadow geometry, terrain, and geographic clues. Use them to test a hypothesis, never as isolated proof.
SunCalc ↗PUBLICReverse-image search and earliest-known appearance. Compare crops, mirrors, dates, and the original page.
TinEye ↗PUBLICVisual aids for compression and pixel analysis. They cannot determine by themselves whether an image is “real” or “fake.”
Forensically ↗FREEFacial search and recognition carry high risks of false positives and rights violations. Clearview is institutional; every match requires human review and a lawful basis.
Clearview AI ↗HIGH RISKAircraft and vessel positions or histories where coverage exists. Gaps, delays, and filtering are common.
ADS-B Exchange ↗MIXEDInstitutional video analysis and management. Analytics can prioritize review but never replace the examiner.
BriefCam ↗INSTITUTIONOfficers, entities, and filings. Prefer the national registry, SEC EDGAR, Companies House, INPI/Data INPI, or Pappers as an interface.
OpenCorporates ↗PUBLICSanctions, politically exposed persons, archives, and offshore structures. Verify identity before drawing conclusions.
OpenSanctions ↗MIXEDPublic procurement, corporate filings, and open data. Reuse terms and data-protection law still apply.
TED ↗PUBLICTransaction explorers and graphs. An address is not an identity without corroborated attribution.
GraphSense ↗MIXEDInstitutional blockchain investigation, attribution, and risk scoring. Heuristics must be explainable and open to challenge.
Chainalysis ↗PROCollection, pivots, and graph visualization. A graph edge shows a data relationship, not necessarily a human relationship.
Maltego ↗MIXEDLink analysis, data fusion, and institutional intelligence. Access and datasets depend on the organization.
IBM i2 ↗INSTITUTIONPublic-record and identity aggregation for authorized organizations, particularly in the United States.
Accurint ↗INSTITUTIONNo tools match this search.
07 // MALTEGO WITHOUT THE MYTH
Maltego becomes powerful when context stays visible: entity, provenance, date, confidence, and the reason for each edge. Transforms accelerate pivots; they do not prove that two nodes represent the same person.
Record the question, scope, authorized identifiers, date, and stopping criteria.
Create one entity per fact and attach a source, timestamp, and note immediately.
Choose the pivot that answers the question. Avoid “run all” and uncontrolled collection.
Mark it observed, declared, calculated, or assumed, with confidence and an expiry date.
A shared name, avatar, IP address, or postal address is not enough.
Provide a reduced graph, timeline, sources, limitations, and answer—not a spaghetti wall.
08 // PRACTICE WITHOUT VICTIMS
Create E01 and raw acquisitions, hash them, recover files, build a timeline, and compare Autopsy/X-Ways or Autopsy/TSK.
Deliverables:Fictional authority, chain of custody, notes, report, and limitations.
Use synthetic Windows disk, RAM, and PCAP evidence. Reconstruct initial access, execution, persistence, and actions.
Deliverables:Super-timeline, five exhibits, an alternative hypothesis, and detection rules.
Find the earliest publication, probable location, time window, and file transformations.
Deliverables:WARC and captures, independent sources, confidence, and error risk.
Use registries, domains, certificates, documents, and a Maltego graph without real personal data.
Deliverables:Entity resolution, provenance, timeline, and a minimization record.
Analyze a supplied training extraction; bypass no lock. Compare ALEAPP/iLEAPP with a forensic suite.
Deliverables:SQLite artifacts, time-zone handling, manual validation, and a focused report.
A peer acts as counsel, privacy officer, or manager and challenges five conclusions.
Deliverables:Source-backed answers, accepted corrections, and a newly signed version.
Trace Labs involves missing people: follow its rules strictly, contact nobody, and publish no personal data. In every exercise, use synthetic identities and redact sensitive data from your portfolio.
09 // BECOME EMPLOYABLE
A certification can structure learning or pass an HR filter. It cannot replace reproducible casework, clear writing, or judgment.
Acquisition, triage, inventory, data quality, and procedures.
Computer, Windows artifact, mobile, or media examination; defensible reports and review.
Endpoints, memory, network, cloud, containment, and detection.
Lawful acquisition, decoding, SQLite validation, and device-specific limitations.
Collection planning, verification, graphs, briefing, and source protection.
SOPs, validation, QA, testimony, mentoring, budget, and laboratory governance.
Official learning paths: GIAC DFIR, IACIS, Cellebrite Training and Magnet Certifications. Check prerequisites, current content, cost, and local recognition before paying.
10 // DEFEND AGAINST OSINT
A poorly managed specialist OS protects less than a mainstream system that is patched, encrypted, and compartmentalized. Anti-OSINT does not erase the past; it reduces new links and limits the blast radius.
| Profilee | Recommended system | Why | Critical limitation |
|---|---|---|---|
| Everyday use | Maintained Windows 11, macOS, Fedora, or Ubuntu | Updates, BitLocker/FileVault/LUKS, separate profiles, and broad compatibility | The OS cannot fix identity reuse or what you publish. |
| Hardened mobile | Current iPhone or GrapheneOS on an officially supported device | Encryption, sandboxing, and profiles; iPhone Lockdown Mode for targeted threats | The phone number, contacts, SIM, and accounts remain correlatable. |
| Sensitive research | Qubes OS with separate qubes; Whonix for Tor traffic | Strong compartmentalization, disposable VMs, and network/USB isolation | Requires compatible hardware and discipline; one personal login can link contexts. |
| Ephemeral session | Tails sur USB | Amnesic by default, traffic over Tor, and metadata tools | Not magic: metadata, behavior, compromised hardware, and correlation remain possible. |
0/6 checks completed on this device.
Read the documentation before installation: Qubes OS, Tails warnings, Whonix/Tor limitations and supported GrapheneOS devices.
11 // AI, AUTOMATION, AND ERROR
Translate or summarize authorized material, suggest queries, prioritize human review, generate lab scripts, and propose hypotheses.
Preserve the input, model/version/date, parameters, raw output, human validation, and primary source for every finding.
“The model says it is them,” an unvalidated facial score, AI-image detection treated as a verdict, a nonexistent citation, or attribution without evidence.
CONCLUSION // THE HUMAN WEAKNESS
A VPN, Tor, Tails, Qubes, or a disposable username makes nobody invisible. A posting time, writing habit, reused avatar, talkative relative, payment, recovery account, or background detail can connect years of compartmentalized activity.
The largest exposure surface is often human: convenience, urgency, repetition, and trust. The realistic objective is not “absolute anonymity.” It is to reduce links, minimize data, separate contexts, verify before acting, and know what to do when separation fails.
The best investigator questions the tool. The best defense questions its habits.
Capabilities, licenses, URLs, and rules change. Always check official documentation, security advisories, available NIST tests, and the law in your jurisdiction. Last reviewed: August 8, 2026.