Identity Intelligence Engine
Give it a phone number, an email address or a name, and it automatically discovers, cross-checks and confirms the digital identities connected to it — in real time, from public sources. Several investigation methods run at the same time rather than one after another, and only the connections the platform can confirm reach the analyst
What it is
A research assistant that checks its own findings
The Identity Forensic Module is a software tool that helps investigators and analysts figure out who a person really is online, starting from just one small clue — a phone number, an email address, or a name. It automatically searches many public sources at once, checks whether the results actually belong to the same person, and presents only the connections it is confident about.
Think of it as a research assistant that, given a single lead, fans out across the internet, gathers everything publicly discoverable about that lead, double-checks its own findings against each other, and hands the analyst a short, verified list of identity connections instead of a messy pile of unconfirmed search results.
Traditional investigation work often means manually searching one tool at a time — checking a username on one site, an email on another, then trying to remember whether two unrelated-looking results actually describe the same person. This module removes that manual burden by running several investigation methods simultaneously and automatically deciding which results genuinely match. From a single starting point it can start from minimal information, search in parallel, stream results live, cross-verify matches, and deliver a verified dashboard rather than a wall of raw, unfiltered search results.
One lead in. Cross-checked on the way. Only confirmed connections out.
- A phone number, an email address or a name — any one of these is enough to begin an investigation
3 inputs
A phone number, an email address or a name — any one of these is enough to begin an investigation
- Sherlock, Telegram intelligence and Google Dorking, each an independent module running at the same time
3 modules
Sherlock, Telegram intelligence and Google Dorking, each an independent module running at the same time
- One search path, from the analyst's single lead to the verified connections on screen
7 stages
One search path, from the analyst's single lead to the verified connections on screen
- Backend, real-time updates, modules, database, dashboard and analyst access — all inside the organization's own environment
6 steps
Backend, real-time updates, modules, database, dashboard and analyst access — all inside the organization's own environment
How it works
From a single lead to verified connections, step by step
01
Start the search
A phone number, an email address, or a name
02
Contact discovery
Digital footprints identified across the public web
03
Parallel OSINT modules
Sherlock, Telegram intel and Google Dorking at once
04
Real-time streaming
Findings appear live on screen over SSE
05
Aggregation
Every module's findings pulled into one data set
06
Cross-verification
Matching data checked to confirm real connections
07
Verified connections
Confirmed identity links in a unified dashboard
It mirrors how a skilled human investigator would work — just automated, and much faster.
Product exclusiveness
Ranked high to low, by business impact
Cascading Intelligence Engine
Instead of running one search and stopping, the platform automatically lets each new discovery trigger further, deeper searches — similar to a chain reaction. An analyst starting with just a name can end up with a much fuller picture without having to manually restart the search after every new clue.
Flagship capability · each discovery triggers the next search
Automatic Cross-Referencing
The platform doesn't just list results — it automatically checks whether findings from different sources actually describe the same person before showing them. This saves analysts from the time-consuming and error-prone job of manually comparing results by eye.
Findings compared against each other before display
Verified Identity Connections
The final output isn't a pile of raw search hits; it's a short list of identity links the system has already confirmed with reasonable confidence, so analysts can trust what they see and focus their attention where it matters.
A short, confirmed list — not raw hits
Real-Time SSE Streaming
Findings appear on screen the instant they're discovered, rather than only after an entire batch process finishes. For time-sensitive investigations, this can shave significant time off an analyst's workflow.
Server-Sent Events · no page refresh, no batch wait
Sherlock Integration
The platform has a built-in connection to Sherlock, a widely used, well-respected tool for finding where a username has been registered across hundreds of websites — meaning this capability doesn't need to be run or maintained separately.
Username registration across hundreds of websites
Telegram Intelligence
The platform can surface publicly available Telegram-related intelligence relevant to the investigation, a capability many general-purpose OSINT tools don't offer natively.
Publicly available Telegram intelligence, built in
Google Dorking
The platform automates advanced search-engine query techniques — commonly called “Google Dorking” — that skilled analysts otherwise have to construct manually to surface hard-to-find public information.
Advanced search queries, constructed automatically
Market research comparison
How the module compares to the tools it is benchmarked against
Runs multiple search methods in parallel from one input
- Maltego / Social Links
- Partly — Partial — manual chaining
- SpiderFoot / Intelligence X
- Partly — Partial
- This platform
- Yes — Yes
Automatically cross-verifies matches before display
- Maltego / Social Links
- Partly — Limited
- SpiderFoot / Intelligence X
- No — No
- This platform
- Yes — Yes
Live, real-time results streaming (no waiting for batch jobs)
- Maltego / Social Links
- No — No
- SpiderFoot / Intelligence X
- No — No
- This platform
- Yes — Yes
Built-in username enumeration (Sherlock-style)
- Maltego / Social Links
- Partly — Add-on dependent
- SpiderFoot / Intelligence X
- Partly — Limited
- This platform
- Yes — Yes
Built-in Telegram intelligence
- Maltego / Social Links
- No — No
- SpiderFoot / Intelligence X
- No — No
- This platform
- Yes — Yes
The architecture
One lead, three modules — nothing shown until it is cross-checked
The cascade is a loop, and the whole platform sits inside one boundary
Step 01 · start the search
One lead
A phone number, an email address, or a name
- SherlockUsername enumeration
- TelegramMessaging-app intelligence
- Google DorkingSearch-engine techniques
Running in parallel · public sources only
Steps 05–06 · aggregation & cross-verification
Checked before it is shown
- Findings pulled together
- Compared against one another
- Same-identity checks
- Unconfirmed hits held back
Cascading intelligence — each new discovery triggers a deeper search
Backend API, modules, database and dashboard — all deployed in-house.
- Verified connectionsConfirmed identity links only
- Unified dashboardUpdating live as findings arrive
The parallel modules
Three investigation methods, running at the same time
- A widely used tool that checks whether a given username has been registered across hundreds of websites
Sherlock
A widely used tool that checks whether a given username has been registered across hundreds of websites
- Gathering publicly available information related to Telegram, a popular messaging app, relevant to an investigation
Telegram
Gathering publicly available information related to Telegram, a popular messaging app, relevant to an investigation
- Advanced, precisely-crafted search-engine queries that surface public information a normal search would miss
Google Dorking
Advanced, precisely-crafted search-engine queries that surface public information a normal search would miss
Each intelligence method runs as an independent module, meaning individual modules can be updated, replaced or extended without disrupting the rest of the platform.
Deployment strategy
Six steps, all inside the organization's own environment
Deploy the backend API
The core service that powers all searches and logic is installed on a server.
Configure real-time updates (SSE)
The live-streaming feature is switched on, so results appear on screen the moment they're found rather than after a long wait.
Deploy the investigation modules
The individual search methods — Sherlock (username lookups), Telethon (Telegram intelligence) and SeleniumBase (automated web searching used for Google Dorking) — are installed and connected to the backend.
Set up the database
A storage layer is configured to hold discovered data and verified connections securely within the organization's own environment.
Deploy the frontend dashboard
The visual, browser-based interface analysts use day-to-day is installed and connected to the backend.
Grant analyst access
Investigators are given secure logins to the dashboard, and the platform is ready for use.
Market position
Where the gap is widest
Most alternatives return a list of raw hits and leave the analyst to manually decide what's real. This module combines cascading OSINT workflows with automated, built-in verification instead.
- Against Maltego / Social Links
- Running several methods from one input is partial and depends on manual chaining, cross-verification before display is limited, and there is no live result streaming. Username enumeration is add-on dependent, and Telegram intelligence is not offered.
- Against SpiderFoot / Intelligence X
- Parallel search from a single input is partial, there is no automatic cross-verification before display, and results do not stream live. Username enumeration is limited, and there is no built-in Telegram intelligence.
- Against working the sources by hand
- Checking a username on one site, an email on another, then trying to remember whether two unrelated-looking results describe the same person is the manual burden this module removes — by running the methods simultaneously and deciding which results genuinely match.
- Against a vendor's cloud
- Every component — backend, modules, database and dashboard — is deployed inside the organization's own environment, so IT and security teams retain full control over data access, retention and compliance, with no dependency on an outside vendor's cloud infrastructure.
Frequently Asked Questions
A phone number, an email address, or a name — any one of these is enough to begin an investigation.
It verifies. Rather than presenting a raw list of hits, the platform automatically cross-matches findings from different sources and only presents connections it can confirm belong to the same identity.
Results appear live. The platform uses a real-time streaming technology (Server-Sent Events) so new findings show up on screen as they're discovered, rather than only after a full search finishes.
Yes. Each intelligence method — Sherlock, Telegram intelligence and Google Dorking — runs as an independent module, meaning individual modules can be updated, replaced or extended without disrupting the rest of the platform.
No. The platform gathers information that is already publicly discoverable — the same category of information a skilled human investigator could find manually using public search techniques. It does not bypass privacy settings or access non-public data.
Discovered data and verified connections are stored in a database deployed within the organization's own environment, keeping data under the organization's existing IT and security controls.
No. The platform automates discovery and cross-verification to save time, but the analyst remains responsible for interpreting findings and making final investigative decisions.
The rest of the line
More in TrustShield OSINT
One lead in. Verified identity connections out
Have a solutions engineer walk your team through a search — the parallel modules, the live stream and the cross-verification that decides what reaches the analyst.
