Data Points

👤 Person / Name

A named individual — the subject of identity resolution and profiling.
Identity

Sources

0
0 no-auth

Disciplines

0
that use it

Mission domains

0
reach

Workbench

native tool

🔍 Lookup

📜 Playbook — Person / Name exploitation

  1. Direction — frame the requirement for Person / Name: what decision does this support, by when?
  2. Collection — pull the 0 mapped sources (0 free) and the native workbench (open); capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎫 Person / Name

A person data point represents a natural individual identified by name and associated biographical attributes (aliases, DOB, nationality, roles, affiliations). It anchors identity-centric investigations, letting analysts consolidate scattered selectors (emails, phones, accounts) into a single resolved human entity for attribution, due diligence, and sanctions screening.

Format: Free-text full name with optional structured attributes (given/family name, DOB YYYY-MM-DD, place of birth, nationality ISO-3166). No canonical validation; requires transliteration/romanization handling and alias normalization.

📡 How it is collected

  • Public records and corporate registries (directors, UBOs)
  • Leaked/breach datasets correlating names to selectors
  • Social media profiles and about pages
  • News, court filings, and litigation records
  • Sanctions, PEP, and watchlist entries
  • HUMINT / interview-derived attribution

🧩 Analysis & hunting techniques

  • Name disambiguation and entity resolution across sources
  • Alias/transliteration expansion (soundex, phonetic matching)
  • PEP and adverse-media screening
  • Corporate network / UBO graph traversal
  • Selector-to-identity clustering
  • Timeline reconstruction of roles and affiliations
  • Fuzzy matching against sanctions lists with scoring
  • Cross-jurisdiction record correlation

🔧 Tools

  • Maltego
  • OpenRefine
  • SpiderFoot
  • Aleph
  • OCCRP Data
  • Dedupe.io
  • Neo4j
  • Pipl-style resolution frameworks

⚡ Workbench actions

  • Screen against sanctions and PEP lists
  • Run adverse-media sweep
  • Resolve aliases and transliterations
  • Map corporate/UBO network
  • Link known selectors to the identity
  • Build affiliation timeline
  • Score identity-match confidence
  • Export entity graph to link analysis

📊 Dashboard KPIs

Number of resolved selectors linkedSanctions/PEP match countAdverse-media hit countIdentity-confidence scoreDistinct jurisdictions with records
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php