Data Points

🚫 Sanction / Watchlist Entry

An entry on a sanctions list, watchlist, or PEP database.
Financial

Sources

9
8 no-auth

Disciplines

3
that use it

Mission domains

5
reach

Workbench

native tool

🔌 Sources that yield Sanction / Watchlist Entry (9)

SourceCategoryAuthFormat
EU Financial Sanctions (FSF)
EU consolidated financial sanctions.
SanctionsNONExmlhome↗ api↗
OFAC Consolidated (non-SDN)
OFAC consolidated non-SDN lists.
SanctionsNONEcsvhome↗ api↗
OFAC Sanctioned Crypto Addresses (0xB10C)
Machine-readable OFAC-designated wallet lists per chain.
Crypto SanctionsNONEtexthome↗ api↗
OFAC SDN
US Treasury Specially Designated Nationals list.
SanctionsNONEcsvhome↗ api↗
OpenSanctions
Consolidated sanctions, PEPs & watchlists.
SANCINTNONEjsonhome↗ api↗
OpenSanctions (default)
Consolidated sanctions, PEPs, watchlists (FollowTheMoney).
Sanctions/PEPNONEjsonhome↗ api↗
UK OFSI Consolidated List
UK financial sanctions targets.
SanctionsNONEcsvhome↗ api↗
UN Security Council Consolidated List
UN consolidated sanctions list.
SanctionsNONExmlhome↗ api↗
Sanctions.io
Aggregated sanctions & PEP screening API.
Sanctions/PEPKEYjsonhome↗ api↗

🔍 Lookup

📜 Playbook — Sanction / Watchlist Entry exploitation

  1. Direction — frame the requirement for Sanction / Watchlist Entry: what decision does this support, by when?
  2. Collection — pull the 9 mapped sources (8 free) and the native workbench (open); capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎫 Sanction / Watchlist Entry

A sanction or watchlist entry is a named individual, entity, vessel, aircraft, or address designated by a government or multilateral body as restricted from trade, finance, or travel. It matters because a positive match halts transactions, exposes counterparty risk, and often anchors an entire illicit-finance network worth mapping.

Format: Structured record: legal name + aliases, program code (e.g. SDGT, IRAN-EO13846), listing ID (OFAC SDN Unique ID, EU logical/regulation ref, UN permanent reference number QDi.xxxx), listing date, and identifiers (DOB, passport, tax ID, crypto/BIC).

📡 How it is collected

  • Screening a name/entity against consolidated designation lists
  • Bulk ingest of OFAC SDN, EU, UN, HMT/OFSI, DFAT files
  • Adverse-media and enforcement-action monitoring
  • Corporate registry and UBO cross-referencing
  • Transaction/payment filter alerts from screening engines
  • Regulatory press releases and Federal Register notices

🧩 Analysis & hunting techniques

  • Fuzzy name matching (Jaro-Winkler, Levenshtein, phonetic/Soundex)
  • Alias and transliteration normalization
  • Entity resolution across multiple lists
  • 50% Rule ownership aggregation for indirect exposure
  • Network expansion to co-designated entities
  • False-positive tuning with DOB/ID disambiguation
  • Delta monitoring for new/updated designations
  • Secondary-sanctions exposure modeling

🔧 Tools

  • OpenSanctions yente
  • OpenSanctions FollowTheMoney
  • Elasticsearch
  • OpenRefine
  • Neo4j
  • sanctions-search CLI
  • Maltego
  • Aleph

⚡ Workbench actions

  • Screen against sanctions lists
  • Aggregate 50% ownership exposure
  • Resolve aliases and transliterations
  • Expand co-designated network
  • Diff against previous list version
  • Score match confidence
  • Export SAR-ready evidence pack
  • Pivot to linked accounts and addresses

📊 Dashboard KPIs

Match confidence scoreNumber of lists hitDays since designationCount of linked designated entitiesFalse-positive rate on tuned filter
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php