SocialIntel Analyzer
Social media and public data intelligence.
- Cross-platform OSINT social monitoring
- Fake profile & botnet network detection
- Public threat & misinformation tracking
Overview
TrustShield OSINT works with information that is already public or already lawfully held by you. It watches for accounts impersonating your people and brand, and it establishes whether records held in different places describe the same person, so an investigator starts with a picture rather than a pile of tabs.
The information needed to understand a person or an incident is usually available already. The difficulty is that it sits in many places, none of which talk to each other, and an analyst spends most of their time gathering it rather than thinking about it.
TrustShield OSINT does the gathering. It watches public channels for accounts impersonating your executives or your brand, and for activity that looks coordinated rather than genuine. Separately, it works out whether records held across the sources you are entitled to use describe one person or several, and shows how they connect.
What comes back is a starting point rather than a verdict. Connections are presented with the reasons they were drawn, so an analyst can follow them, discard the ones that do not hold, and record what they concluded. The work of judging is left where it belongs.
2
Products across public information intelligence
Public and authorised
Works only with information you may lawfully use
Analyst led
Findings are examined by a person, not acted on automatically
In this category
One product watches what is being said and posted in public. The other establishes whether records in different systems describe the same person. Both hand their findings to an analyst with the reasoning attached.
Social media and public data intelligence.
Cross-platform identity resolution and linkage.
How it works
Nothing here reaches for information you are not entitled to. The value is in assembling what is already available and showing how the pieces relate.
Two questions
Connections are presented with the reasons behind them for an analyst to follow, test and discard, never acted on automatically.
Name the people, brands or subjects that matter, and the sources you are entitled to draw on. That boundary is set at the start and the work stays inside it.
Public channels are monitored for impersonation and for activity that looks organised rather than genuine. Records across your authorised sources are collected together for the subject in question.
Records that appear to describe the same person are brought together, and the connections between them are shown along with the reasons they were drawn, so a weak link is visible as a weak link.
The picture is handed over for a person to examine, follow and challenge. What they conclude is recorded with the material that supported it, in a form suitable for a case file, an escalation or a review.
Use cases
Wherever the answer is already public but scattered. These are the situations teams bring to the category most often.
Establish whether applications and accounts held in different systems belong to the same person, and give an investigator the connections behind that view rather than a list of possible matches.
Find accounts impersonating your senior people or your brand while they are still being set up, and keep a record of each one for a takedown request or legal follow up.
Assemble the publicly available picture around a subject or an incident quickly, with every connection traceable back to what it was drawn from.
Understand whether apparently unrelated claims connect back to the same people, which is difficult to see when each claim is assessed on its own.
Distinguish coordinated activity from genuine public reaction, so enforcement is aimed at organised behaviour rather than at people who happen to agree with each other.
Build the public picture of a counterparty before a deal, and hand a reviewer the reasoning rather than a conclusion they have to take on trust.
FAQ
Answered the way an analyst, a security lead or a privacy officer asks them.
TrustShield OSINT is FaceOff's suite for turning information that is already public or already lawfully held into something an investigator can work with. It monitors public channels for accounts impersonating your people and brand and for activity that appears coordinated, and it establishes whether records held across your authorised sources describe the same person. Findings are handed to an analyst with the reasoning attached.
From channels that are already public, and from sources your organisation is entitled to use. The boundary is set when the work is configured and the suite stays inside it. Nothing here obtains information by accessing accounts, systems or material you have no right to, and the sources behind any finding are shown so a reviewer can check where it came from.
No. It produces leads for a person to examine, not conclusions to act on. Connections are presented together with the reasons they were drawn, precisely so an analyst can test them and discard the ones that do not hold. Decisions about people should be made by people who can be asked to justify them, and the suite is built on that assumption rather than around it.
By looking at how accounts and activity relate to one another rather than at what any single account says. Genuine reaction tends to be untidy and independent; organised activity tends to share patterns that individual accounts do not reveal on their own. The distinction is presented as a finding with its supporting material, because getting it wrong means acting against ordinary people.
Findings are prepared to be examined. Each connection is traceable back to the material it was drawn from, and what an analyst concluded is recorded alongside the evidence that supported it, so the reasoning can be followed by a colleague, a regulator or a court rather than having to be reconstructed from memory later.
TrustShield OSINT is used by financial crime teams resolving whether records describe the same person, corporate security teams protecting executives and brands from impersonation, law enforcement assembling the public picture around a subject, insurers looking for connections between claims, trust and safety teams separating coordinated activity from genuine reaction, and diligence teams researching counterparties.
Yes, and the suite is designed on that basis. A connection between records is a reason to look more closely rather than proof that two records describe one person, and public information is frequently incomplete or out of date. That is why every finding carries the reasoning behind it and why the analyst, not the system, reaches the conclusion.
The rest of the line
Bring a subject you are researching or an impersonation problem you are dealing with. We will walk through what comes back and how an analyst would work with it.