Skip to content

ZeroTrace OSINT

Workbench basics

How the ZeroTrace OSINT window is laid out, how a tool page works end to end, and how a typical investigation flows through the command palette, the results panel, and history.

Workbench basics

ZeroTrace OSINT is built to be lived in during an investigation. The window is deliberately quiet: one workspace with a floating sidebar for navigation and a header for the tool you're on, so results have room to breathe.

Finding a tool

Every tool has its own page. The sidebar groups the whole library into a handful of collapsible categories, matching the Tools reference on this site — each group remembers whether you last left it open or closed, so the sidebar stays a map instead of a permanent scroll. The fastest way to reach any tool, though, is the command palette: open it, start typing, and OSINT fuzzy-matches across the whole library by name. Type a few letters of what you want and pick it from the list.

Running a tool

  1. Give it an input

    Most tools take a single thing to look into — an IP address, a domain, a hash, a username, a file, or a small set of options for a command builder. The page's form tells you what it expects, with required fields marked and sensible defaults filled in.

  2. Run it

    Start the lookup or analysis. A tool that reaches out to the network shows that it's working while the request is in flight; a local tool returns almost immediately.

  3. Read the results

    Results come back laid out for the subject, not as raw text — a table for a list of records, a labeled card for a single lookup, a diff view for a comparison, a ready command line for a builder — so you can scan them and see what matters.

  4. Follow a pivot, or save what matters

    Where the result surfaces another identifier worth checking, a next-step chip opens the right follow-up tool with that value already filled in. When something is worth keeping, send it into an open case so it becomes part of your investigation instead of scrolling away.

The results panel

A result renders in whatever shape fits its data: a labeled field card for a single-subject lookup (WHOIS, a decoded token, a user profile), a scannable table for a list (DNS records, platform checks, breach entries), or a side-by-side diff for a comparison. Long fields and large lists collapse behind a "show more" so the page stays readable at a glance, with the full detail one click away.

Local, network, and live

Every tool states its data source before you run it — Local, Network, Live, or Mixed — so you know whether it will stay entirely on your machine, ask a third party about your target, or contact the target itself. See Local, network, and live for the full model and what each label means for your footprint.

Keyboard-first

OSINT is designed to be driven from the keyboard. The command palette, moving between tools, and running a lookup are all a keystroke away, so you keep your hands on the keys and your attention on the work.

Command Palette

Search for a command to run...