Intelligence Resources

The discipline behind the discovery.

Good intelligence work is a craft with rules — about how information is collected, how identity is resolved, how sources are weighed and how uncertainty is expressed. This hub explains the concepts and tradecraft that underpin an Intelis investigation, in plain terms. It is educational background, not a claim about any particular subject or engagement.

Tradecraft Analysis Provenance

Core disciplines

How intelligence is built, source by source.

Each discipline below contributes a different layer to a structured picture. In practice they overlap — an identity lead informs an infrastructure query, which surfaces a corporate connection — but each rests on the same principles: lawful, authorised sources, documented provenance and explicit confidence.

Tradecraft

OSINT tradecraft

Open-source intelligence is the disciplined collection and analysis of information that is publicly and lawfully available — records, registries, web content, technical footprints and published documents. Good tradecraft is not about finding more data; it is about collecting it methodically, documenting where each item came from, and separating what a source actually says from what an analyst infers. The rigour lives in the process, not the volume.

Correlation

Entity resolution

Entity resolution is the work of deciding when two records — two names, two accounts, two companies — refer to the same real-world thing. Names are shared, spellings drift, and identifiers are reused, so a match is a judgement supported by evidence rather than a certainty. Done well, it keeps distinct entities apart and merges genuine duplicates while preserving the reasoning behind every decision.

Infrastructure

Infrastructure & domain intelligence

Digital infrastructure leaves a connectable trail. Domains, hosting, name servers and TLS certificates create relationships that recur across seemingly separate operations. Studying registration records, DNS history and certificate data can reveal that unrelated-looking sites share an origin — but shared hosting is common, so analysts must distinguish confirmed overlap from coincidental co-location.

Identity

Digital identity & aliases

People present fragmented identities online: usernames, email addresses, handles and reused identifiers spread across platforms. Correlating these fragments can reconstruct a coherent identity picture, but reuse of a common handle is weak evidence on its own. The discipline is to cluster identifiers, weigh how distinctive each one is, and keep probable associations clearly separate from verified ones.

Reputation

Adverse media analysis

Adverse media analysis reviews public reporting, court records and other published sources for material that bears on a subject’s reputation or risk. The value is in context and corroboration: a single unverified article is a lead, not a finding, and allegations must be distinguished from established outcomes. Careful analysis records the source, its date and its reliability alongside every claim.

Blockchain

Digital-asset & blockchain research

Public blockchains record transactions in an openly readable ledger, which makes address activity, flows and counterparties researchable. Analysis clusters addresses, follows public transaction paths and correlates on-chain indicators with off-chain context. It is research on publicly available data — it does not identify a person from an address by itself, and it does not recover, seize or move assets.

Evidence

Evidence provenance & integrity

Provenance is the documented history of an item of evidence: where it originated, when and how it was collected, and whether it has remained unchanged since. Integrity is often demonstrated with cryptographic hashes and preserved timestamps. Without provenance, even accurate information is hard to rely on later, because no one can show that what is being reviewed is what was originally found.

Assessment

Source evaluation & confidence

Not all sources deserve equal weight. Evaluation considers a source’s reliability and the credibility of the specific information it provides, and expresses the result as an explicit confidence level rather than a false binary. Independent corroboration raises confidence; conflicting sources lower it and are flagged rather than silently reconciled. Making uncertainty visible is a feature, not a weakness.

Corporate

Corporate ownership structures

Ownership rarely sits in a single record. Holding companies, nominee arrangements and cross-border structures can separate the entity on a filing from the parties who actually control it. Mapping directors, shareholders and connected entities across registries builds a structural picture — while noting that public filings can be incomplete, outdated or deliberately opaque.

Monitoring

Continuous monitoring

Intelligence has a shelf life. Directors change, domains move, new certificates appear and fresh associations emerge after a report is delivered. Continuous monitoring watches selected entities, identities and infrastructure for material change and surfaces it in the context of the original investigation — so an update is a meaningful signal, not a contextless alert.

Glossary

The language of intelligence.

A concise reference to terms used across this site and in intelligence reporting generally. Definitions are educational and deliberately general.

OSINT
Open-source intelligence — intelligence derived from publicly and lawfully available information.
HUMINT
Human intelligence — information gathered from and through people, as distinct from technical or open sources.
Entity resolution
Determining whether separate records refer to the same real-world person, organisation or object.
Pivoting
Using one confirmed data point (an email, a domain, an identifier) to discover new, connected leads.
Provenance
The documented origin and collection history of an item of evidence.
Corroboration
Independent support for a finding from more than one reliable source.
Attribution
Associating activity, infrastructure or content with a specific actor — always expressed with a confidence level.
Passive DNS
Historical records of how domain names have resolved to addresses over time, used to study infrastructure change.
Certificate transparency
Public logs of issued TLS certificates that can reveal domains and relationships between hosts.
Adverse media
Negative or risk-relevant public reporting about a subject, weighed for source and recency.
Chain of custody
The unbroken, documented record of who handled evidence and when, preserving its integrity.
Watchlist
A defined set of entities, identities or infrastructure kept under active monitoring for material change.

Confidential briefing

Turn method into a clear intelligence picture.

Describe the objective and context. We assess fit and scope before any collection begins — no obligation, no platform sign-up.