💬 Messaging Handle
An identity on a messaging platform (Telegram, Signal, Discord) used for coordination and sales.
Communications
Sources
0
0 no-auth
Disciplines
0
that use it
Mission domains
0
reach
Workbench
—
native tool
🔗 Analyst pivots
🔍 Lookup
📜 Playbook — Messaging Handle exploitation
- Direction — frame the requirement for Messaging Handle: what decision does this support, by when?
- Collection — pull the 0 mapped sources (0 free) and the native workbench; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
✨ Enrichment pathways
🎫 Messaging Handle
An account identifier on a messaging platform (Telegram/Signal/WhatsApp/Discord/Session), such as a @username, user ID, or registered phone number. It matters for SOCMINT, tracking threat-actor communications, mapping communities/channels, and linking pseudonymous personas to real identities.
Format: Telegram @username (5-32 chars, a-z0-9_) or numeric user_id; WhatsApp/Signal keyed to E.164 phone; Discord snowflake (18-19 digit int) + legacy user#discriminator; Session 66-char hex account ID.
📡 How it is collected
- Channel/group member enumeration
- Message metadata and forwarded-from headers
- Public directory and username search
- Contact-discovery via phone import
- Invite links and t.me/discord.gg resolution
- Bot API lookups of public entities
📚 Enrichment & validation sources
🔗 Pivot to
🧩 Analysis & hunting techniques
- Channel/community membership mapping
- Persona correlation across platforms by username reuse
- Forward-graph and mention-network analysis
- Snowflake timestamp decoding (account age)
- Phone-to-handle pivoting via contact import
- Language/stylometry attribution of messages
- Bot-vs-human behavioral profiling
🔧 Tools
- Telethon
- TGStat
- Discord.py / snowflake decoder
- Maltego
- sherlock (username hunt)
- spiderfoot
⚡ Workbench actions
- Resolve handle to phone/email
- Enumerate shared channels/groups
- Decode ID timestamp (account age)
- Build forward/mention graph
- Cross-platform username sweep
- Screen against breach/leak datasets
- Monitor handle for activity
📊 Dashboard KPIs
Number of shared channelsAccount age (days)Cross-platform matchesBreach appearance countMessage activity rate
📂 Open
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron