← Back to overview
Capability explained
Evidence workbench and security checks
The evidence workbench separates and documents technical artefacts such as text fragments, hashes, links and identifiers.
What can be examined?
- Domains, IPs, e-mail addresses, URLs, hashes and crypto addresses
- URL, Base64, hexadecimal and supported encodings
- Tracking parameters and external loading targets
- Timestamps from supported platform links
- Password exposure through a k-anonymous prefix check
- Lawful query preparation for public dark-web indexes
What can you find out?
- Which useful identifiers are present in text
- What plain text an encoding contains
- Which parameters may track a reader
- Whether a password hash prefix occurs in known breaches without sending the password
- How to document a sensitive search with source and time
Example from journalistic work
A chat record is separated into domains, IPs, wallets and hashes. Each item can then be checked with the right tool without sending the entire conversation to a third party.
What does the result not prove?
- Decoding is not decryption.
- Dark-web research remains limited to lawful purposes and permitted indexes.
- A breach match calls for a password change but may not identify the affected service.
Evidence and privacy
Only tools actually used and their inputs are recorded. Results, sources, timestamps, hashes and embedded evidence remain attributable. External services are only contacted where the tool expressly states this.