4 client case studies

SOCIAL LINKS OSINT CASE BOOK

get case study

Publicly attributed cyber actors often leave behind far more digital evidence than what appears in a wanted notice or media report. While investigators may begin with nothing more than a name, photograph, or nationality, the real challenge lies in expanding those limited identifiers into a broader understanding of the subject's online presence, technical communities, historical activity, and potential infrastructure. Doing so requires more than conventional OSINT searches. Analysts must validate identities across platforms, correlate historical records, and uncover connections hidden within leaks, social networks, and communication platforms.

This case study follows the profiling of a publicly identified cyber actor using SL Crimewall. Starting with only a limited set of public identifiers, investigators progressively expand the investigation through conference material, GitHub repositories, X profiles, historical leak data, phone number enrichment, Telegram analysis, facial recognition, and name-based searches. Each discovery creates a new investigative pivot, allowing the team to validate identities, uncover technical communities, identify additional digital artifacts, and build a structured intelligence profile. How these investigative leads were developed—and how each Crimewall capability contributed to the workflow—is explored step by step throughout this case study.