IntelMind Documentation

How to use IntelMind’s OSINT tools

Documentation built for the three profiles we serve: private investigators, SOC/CSIRT teams, and M&A due diligence. Each module comes with a step-by-step guide and interpretation criteria.

IntelMind brings together six OSINT tools in a unified interface: email, IP, domain, phone, social media and forensic image. Each module has its own scope, sources and signals — here you’ll find what it does, what it returns, and how to interpret its results so every query has real value.

It works both as an OSINT manual for beginners and a quick reference for experienced analysts, with a focus on traceability and a signed PDF with RFC 3161 digital chain of custody.

Quick access

Jump directly to the module you’re interested in.

Documentation by tool

Expand each block to see what it analyzes, what it returns, and how to interpret the result.

Email analysis · 5 credits

What it does: evaluates an email address from an OSINT and technical perspective with anti-fraud scoring.

What it analyzes: public identity of the owner, exposure in breaches (Have I Been Pwned) and stealer logs (HudsonRock Cavalier), SMTP/MX validity and deliverability (Hunter.io, MailboxLayer), domain authentication (SPF, DMARC, DKIM, MTA-STS, BIMI), disposable email (72,710+ domain DB), and platform presence (Holehe + Maigret cross-confirmed).

What it returns: 4D risk scoring, executive verdict, technical data, a two-part AI professional summary, and a signed PDF with RFC 3161 chain of custody.

How to interpret it: a positive signal doesn’t 100% confirm that an email exists; the result should be read as a set of indications and technical context, not an absolute ruling.

Open the email tool →

IP analysis · 8 credits

What it does: analyzes an IP address and returns relevant technical context, cross-referenced reputation, and geography.

What it analyzes: cross-referenced reputation (AbuseIPDB, VirusTotal, GreyNoise, AlienVault OTX, IPsum, CINS, Feodo, Spamhaus DROP), BGP/RPKI validation with exact prefix, ports and CVEs (Shodan InternetDB), network type via ASN, cloud attribution (AWS/GCP/Azure/Cloudflare), domain co-hosting, historical passive DNS, and Tor exits.

What it returns: 4D scoring (technical/reputation/context/exposure), a 3-line actionable executive verdict, deterministic anomalies and recommendations, an AI professional summary, and a signed PDF.

How to interpret it: an IP can reflect a provider, VPN, cloud, or shared infrastructure — don’t assume direct attribution without more context.

Open the IP tool →

Domain analysis · 12 credits

What it does: analyzes a domain from public records, legal identity and technical signals.

What it analyzes: owner’s legal identity (legal notice/Impressum, company name, business registry), WHOIS/RDAP and age, reputation (VirusTotal, DNS blacklists and a 2.25M malicious-domain database), typosquatting, TLS certificates and Certificate Transparency (crt.sh), DNS and email (SPF/DKIM/DMARC/CAA), Shodan, WhatWeb.

What it returns: risk scoring, summarized technical context, detailed results, an AI summary, and a signed PDF with custody.

How to interpret it: useful for triage, initial review, technical investigation, and supporting other modules like email.

Open the domain tool →

Phone analysis · 7 credits

What it does: investigates a number in depth — who’s behind it when public, whether it’s spam or a scam, and its technical profile.

What it analyzes: identity in global leaks and open web; presence on WhatsApp, Telegram, Instagram; reputation (FTC, Tellows, SpamCalls, responderono.es); triple technical validation, real portability, VOIP/premium status, and OFAC sanctions.

What it returns: identity with evidentiary source when it exists (or an honest disclaimer if not), a 0–100 score, a professional summary, and a PDF with chain of custody.

How to interpret it: scope depends on the type of number and data availability across the sources queried.

Open the phone tool →

Social media analysis · 20 credits

What it does: locates profiles, mentions, and public activity linked to a user or social identity.

What it analyzes: platform presence (Sherlock, Maigret, Nexfil), verified own profiles (GitHub API, YouTube API, Keybase, Lichess, Chess.com), avatars via pHash and reverse search, cross-confirmed real name, PGP/SSH cryptography, OFAC sanctions, breach exposure, historical Wayback, and dorks.

What it returns: findings linked to avatar and real name when convergence occurs, a consolidated persona, scoring, and a signed PDF.

How to interpret it: a support to analysis, not sole proof; special attention to noise (echoed handles, SEO bios, default avatars) that the engine filters automatically.

Open the social media tool →

Forensic image analysis · 30 credits

What it does: analyzes visual information and explores context from images using forensic techniques.

What it analyzes: manipulation and synthetic or deepfake images (ELA, PRNU, double compression), EXIF metadata with GPS, copies found online with their metadata, global reverse search (Google Vision, SauceNAO, TinEye, Yandex), author identity (ID document, profiles, facial biometrics, Maigret across 24 platforms) and Wayback.

What it returns: a complete forensic report, RFC 3161 chain of custody, useful visual context, and expanded findings.

How to interpret it: real value usually increases when combined with other indicators (email, phone, domain) from the same case.

Open the image tool →

Best practices

Simple recommendations to get more value from the platform in every case.

Start with the strongest data point

If you have several indicators, start with the one that has the most reliability or best initial context.

Cross-check tools

The best results come from combining several modules (email + domain, phone + social) rather than relying on a single query.

Don’t assume immediate attribution

IntelMind provides signals and context, but the final interpretation always depends on the analyst’s judgment.

Document your findings

Export the signed PDF with RFC 3161 chain of custody for traceability, archiving, and delivery to a client or regulator.

Limits and interpretation. IntelMind doesn’t turn a signal into absolute certainty. The platform centralizes, correlates and interprets, but final validation always depends on the case, the data queried, and cross-referencing with more context.

Some sources may vary in availability, scope or depth depending on when the query is made. The PDF’s evidentiary value (SHA-256 hash + RFC 3161 FreeTSA timestamp + public verification URL) is, however, constant and defensible.

Frequently asked questions

What OSINT tools does IntelMind include?

IntelMind includes six analysis modules: email, social media, phone, IP addresses, domains and images. Each tool operates independently and can be combined with others within the same investigation.

How many credits does each IntelMind tool use?

5 credits: email. 7: phone. 8: IP. 12: domain. 20: social media. 30: forensic image analysis. Monthly plan credits renew each billing period.

How should I interpret the results of an OSINT analysis?

IntelMind presents results with technical context, a professional summary, and signals classified by relevance. The result should be read as a set of indications and context, not absolute certainty: final validation always depends on the analyst’s judgment.

Can I export the analysis results?

Yes. The main modules let you export results as a signed PDF with RFC 3161 chain of custody. The report includes the professional summary, technical data, and the most relevant evidence, ready to share, archive, or deliver to a client.

What limitations does IntelMind have when analyzing public data?

IntelMind works exclusively with public sources available at the time of the query. Data availability and depth can vary depending on the indicator type and active sources. The result is a support to analysis, not a definitive ruling.

What public sources does each module query?

Email: Hunter.io, MailboxLayer, Holehe, DNS, RDAP, blacklists. IP: IPinfo, AbuseIPDB, VirusTotal, GreyNoise, AlienVault OTX, Shodan, DNS blacklists. Domains: WHOIS/RDAP and WHOIS:43, site legal identity (legal notice/Impressum), VirusTotal, DNS blacklists, a 2.25M malicious-domain database, Certificate Transparency (crt.sh), Shodan, WhatWeb. Social: Sherlock, Maigret, Nexfil, GitHub API, YouTube API, dorks. Images: Hive, computer vision, reverse search (Google Vision, SauceNAO, TinEye, Yandex) and Wayback.

What limitations does IP geolocation have?

IP geolocation is approximate (city or region), not an exact location. Only the ISP has precise data, and only provides it under a court order. Dynamic IPs, VPNs, and proxies add uncertainty. The result should be interpreted as context, not proof of location.

How should I interpret the professional summary?

The professional summary synthesizes the main signals in plain language, but it’s not a ruling. It explains what the technical data indicates and suggests lines of action, but the final interpretation depends on your investigation’s context. Use it as a starting point, not a conclusion.

What part of the result is evidence, and what part is interpretation?

Technical data (DNS, records, dates, scores, detections) is direct evidence from public sources. The risk scoring and the professional summary are interpretations based on that data. The executive verdict is an indicative recommendation. Always cross-check the signals with your own judgment.

Does IntelMind store my searches?

Queries are processed to generate the analysis and are not permanently stored in a way accessible to third parties. Results are kept temporarily for PDF export. Query data isn’t shared with external services beyond the OSINT sources needed for each analysis.

Where can I find a free OSINT course online to complement IntelMind?

As a free OSINT course to get started, combine three resources: the OSINT Framework as an interactive tool index, Bellingcat’s How-tos for applied methodology, and SANS OSINT papers for theoretical framing. IntelMind fits in as the operational layer: you run, on the platform, the examples these resources explain conceptually.

Start investigating with rigor

Try the OSINT suite free for 14 days, or request your first Cyber DD M&A report for free. No card required.