👤 Person / Name
A named individual — the subject of identity resolution and profiling.
Identity
🔧 Native workbench
🔗 Analyst pivots
🔍 Lookup
📜 Playbook — Person / Name exploitation
- Direction — frame the requirement for Person / Name: what decision does this support, by when?
- Collection — pull the 0 mapped sources (0 free) and the native workbench (open); capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
✨ Enrichment pathways
🎫 Person / Name
A person data point represents a natural individual identified by name and associated biographical attributes (aliases, DOB, nationality, roles, affiliations). It anchors identity-centric investigations, letting analysts consolidate scattered selectors (emails, phones, accounts) into a single resolved human entity for attribution, due diligence, and sanctions screening.
Format: Free-text full name with optional structured attributes (given/family name, DOB YYYY-MM-DD, place of birth, nationality ISO-3166). No canonical validation; requires transliteration/romanization handling and alias normalization.
📡 How it is collected
- Public records and corporate registries (directors, UBOs)
- Leaked/breach datasets correlating names to selectors
- Social media profiles and about pages
- News, court filings, and litigation records
- Sanctions, PEP, and watchlist entries
- HUMINT / interview-derived attribution
📚 Enrichment & validation sources
🔗 Pivot to
🧩 Analysis & hunting techniques
- Name disambiguation and entity resolution across sources
- Alias/transliteration expansion (soundex, phonetic matching)
- PEP and adverse-media screening
- Corporate network / UBO graph traversal
- Selector-to-identity clustering
- Timeline reconstruction of roles and affiliations
- Fuzzy matching against sanctions lists with scoring
- Cross-jurisdiction record correlation
🔧 Tools
- Maltego
- OpenRefine
- SpiderFoot
- Aleph
- OCCRP Data
- Dedupe.io
- Neo4j
- Pipl-style resolution frameworks
⚡ Workbench actions
- Screen against sanctions and PEP lists
- Run adverse-media sweep
- Resolve aliases and transliterations
- Map corporate/UBO network
- Link known selectors to the identity
- Build affiliation timeline
- Score identity-match confidence
- Export entity graph to link analysis
📊 Dashboard KPIs
Number of resolved selectors linkedSanctions/PEP match countAdverse-media hit countIdentity-confidence scoreDistinct jurisdictions with records
📂 Open
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron