User Guide

Operator handbook

Everything you need to run CARIO INTEL — from sign-in to signed PDF dossiers.

What is CARIO INTEL?

CARIO INTEL is an OSINT (Open-Source Intelligence) workstation. You enter a target — email, domain, IP, wallet, username, phone, or organisation — and the platform fans out across dozens of lawful public collectors in parallel to build a complete intelligence dossier with risk scoring, entity graphs, timelines, and a tamper-evident chain of custody.

Every action you take is recorded against a case file. Cases hold evidence, analyst notes, custody events, and exportable PDF reports.

Signing in & requesting access

1
Visit /login and sign in with your operator credentials.
2
If you don't have an account, click Request access and submit your details. An admin will review and provision a login.
3
Administrators provision operators and role-based invitations from /admin. New self-registered accounts receive the baseline analyst role unless an active invitation grants another role.

Roles: admin manages operators and access requests; analyst uses every investigative module.

Command — running a scan

1
Go to /dashboard.
2
Type your target in the command bar (email, domain, IP, wallet 0x…, username, phone, org name).
3
Click Run investigation or press Enter.
4
The backend fans out 60+ public collectors in parallel (with per-source timeouts so one slow source never blocks the run). Watch the pipeline bar. When it completes, every tab (Overview, Network, Timeline, Findings, Infrastructure, Dossier) populates with real data.
5
A case is automatically created (or updated) for the target. The top 5 findings are written as evidence, and an analyst note records the run metadata.

What runs against each target type:

  • Domain / email: DNS-over-HTTPS (A/AAAA/MX/TXT/NS/SOA/CAA/SRV/DMARC/DKIM/MTA-STS), RDAP, crt.sh certificate transparency, HTTP headers + tech fingerprint, robots.txt / security.txt / sitemap.xml / humans.txt / ads.txt, Wayback availability + CDX snapshot count, urlscan.io public, Mozilla HTTP Observatory, HackerTarget hostsearch / dnslookup / reverseiplookup / aslookup / geoip / httpheaders, GDELT news, OpenCorporates, Wikipedia + Wikidata, Hacker News Algolia, Reddit, GitHub repo mentions, DuckDuckGo Instant, Common Crawl, OpenSanctions.
  • IP: RDAP-IP, ip-api.com geo, ipwho.is, BGPView (ASN + prefixes), Shodan InternetDB, GreyNoise community, HackerTarget reverse-IP + geoip.
  • Username: GitHub, GitLab, Bitbucket, Keybase, DEV.to, StackExchange, Hacker News profile, Reddit profile, Mastodon, plus Sherlock-style probes across Twitch, YouTube, Instagram, TikTok, Pinterest, Medium, Spotify, SoundCloud, Steam, Vimeo, Patreon, Behance, Dribbble, Flickr, Lobsters, ProductHunt, Telegram, Twitter/X, Threads, Bluesky, Replit, CodePen.
  • Email: XposedOrNot breach analytics, Gravatar, disposable-provider heuristic, GitHub login search, plus the first 12 Sherlock probes on the local part.
  • Wallet (ETH): Ethplorer, ENS reverse, Blockchair. (BTC): Blockstream Esplora, Blockchair.
  • Phone: country-code classification + GDELT news mentions.
  • Organization: Wikipedia, OpenCorporates, GDELT news, HN, Reddit, GitHub.
  • Universal (every target): DuckDuckGo Instant, Wikidata, Common Crawl, OpenSanctions, GDELT, and a 13-link investigator pivot bundle (Google / Bing / Yandex, Archive.org + archive.today, Google dorks, Have-I-Been-Trained, IntelX, Shodan, Censys, FOFA).

Investigations & case management

The /investigate module is the workspace for active cases.

1
Click New to create a case manually (title, target, classification).
2
Select any case in the left rail to load its tabs: Evidence, Analyst Notes, Chain of Custody, Case Summary.
3
Use the search box to filter cases by ID, target, title, or tag.
4
Change a case's status (Active / Pending review / Closed / Archived) from the status dropdown in the case header.

All cases are also browsable as a flat index at /cases with evidence and note counts.

Evidence & analyst notes

1
In a case, open the Evidence tab and click Add evidence.
2
Choose a kind (URL, IOC, screenshot, transcript, doc, file), label it, cite the source, and paste the content.
3
Each evidence item gets a deterministic fingerprint hash and a collection timestamp.
4
Add tags with the tag button. Tags are searchable.
5
Open the Analyst Notes tab to write free-form analytical narrative. Pin notes you want at the top.

Chain of custody

Every mutation (case created, evidence added/tagged/deleted, note added, status changed, scan run, export) appends a custody event. Each event is hashed against the previous one, forming a tamper-evident chain.

The case header shows a CHAIN VERIFIED or CHAIN BROKEN badge. The full ledger is in the Chain of Custody tab.

Relationship graph

/graph renders all entities discovered for the current scan as an interactive node-link diagram. Click any node to inspect it on the dashboard's right rail.

Every stored case also has its own investigation graph. Open a case from the Scan Vault and switch to the Graph view to add entities manually, search for entities close to the one you investigated, and ask the graph AI assistant to expand a node or explain a cluster.

Scan Vault & investigation workspace

Every scan you run is stored permanently against your account in the Scan Vault — nothing is lost when you close the tab, and cases sync across devices.

1
Open /vault and pick any past investigation to reopen it in full.
2
Inside a case you get notes, evidence, screenshots, tasks, bookmarks, hypotheses, file attachments and AI summaries — all RLS-protected and private to you.
3
Each case shows the workspace profile it was run under, so you can tell a competitor-intel scan from a fraud or compliance run at a glance.
4
Continue chatting with the AI about any stored case — the chat history is persisted with the scan.

Choose your default workspace profile (9 industry presets) in /settings.

AI Investigation Copilot

The copilot does more than answer questions — it investigates. In any case chat it synthesises the collected evidence, proposes the next pivots, and tells you when a line of enquiry is a dead end.

1
Open a case and use the chat panel on the right.
2
Ask it to broaden the search — it can trigger additional collection on entities it considers promising.
3
Open the Reasoning tab to read the step-by-step trace of how it connected entities and why it discarded others.

Claims are labelled as hypothesis vs. corroborated fact. AI messages consume credits from your plan; extra credit packs can be bought at /pricing.

AI Identity resolution

One person may hold a dozen usernames, several emails, multiple companies, wallets and domains. Identity resolution clusters everything a case discovered into canonical identities.

Each cluster shows a verdict (same identity, likely same, uncertain), a confidence score, the supporting evidence, and any conflicts that argue against the merge. Entities that can't be attributed are listed as ungrouped.

Contradiction detection

Cross-checks self-reported claims against primary records and flags field-level conflicts — for example a profile claiming "CEO" when the official registry shows a directorship resigned three years ago.

Each contradiction lists both sources, the conflicting values, and a severity so you know which ones actually matter.

Trust score, risk score & confidence — how they are calculated

Trust score (0–100, higher is better) is simply 100 − risk score. It is the single headline number on a subject profile and answers: "how much adverse public evidence exists about this subject?" It is not a credit score, a legal judgment or a prediction of behaviour.

Risk score (0–100, higher is worse) starts from a clean baseline of 3 and only rises when a source returns an actual hit. A collector that simply ran successfully, or returned zero results, adds nothing. That is why a clean subject stays in the very high nineties on trust.

Points come from five capped categories, each with diminishing returns so one noisy category can never dominate:

  • Sanctions & watchlists (max 55) — OpenSanctions PEP/sanctions matches, OFAC SDN, EU consolidated list, UK HMT, FBI Wanted notices. Only counted when the match array is non-empty.
  • Malware & phishing infrastructure (max 30) — URLhaus malicious URLs on the host, PhishStats records, AlienVault OTX threat pulses, confirmed Tor exit nodes.
  • Credential exposure (max 25) — HaveIBeenPwned breach records, with extra weight when leaked data classes include passwords and when a breach is HIBP-verified.
  • Adverse media, criminal record & legal signals (max 48) — every retrieved article, court record and encyclopaedic entry is screened in full, and only documents that explicitly name the target count. Mentions are graded in three tiers: tier A (conviction, guilty plea, sentencing, imprisonment, violent or trafficking offences), tier B (indictment, charges, arrest, prosecution, fraud, laundering, bribery, sanctions, lawsuits) and tier C (investigations, allegations, fines, regulatory action). Each tier is weighted per independent publisher, so one outlet reporting a conviction counts heavily and nine reprints add only a little.
  • Court & regulatory filings (max 16) — CourtListener dockets and GovInfo publications naming the target.
  • Infrastructure hygiene (max 8) — weak Mozilla Observatory grades (D/F) and DNS blocklist hits.

Severity floors. Adverse evidence also sets a minimum risk, so a documented criminal record can never be diluted by clean infrastructure: corroborated tier-A coverage forces risk to at least 72 (trust ≤ 28), tier B to at least 48, tier C to at least 22.

The same collector output always produces the same score — the model never invents the number. Every subject profile shows a "How this score was calculated" strip listing each scoring category, the points it cost and the exact evidence line behind it, so any figure can be traced back to a source.

Confidence (0–100%) is a separate question: not "is this subject risky?" but "are we sure these findings are about this subject, and can we rely on them?" It combines four sub-scores shown in the confidence panel:

  • Identity — how uniquely the query pins one real entity. Direct identifiers (email, domain, IP, wallet, phone) start near-certain; common personal names start low and rise with each narrowing criterion you supply and each independent corroborating source. Multiple plausible identity candidates lower it.
  • Sources — number of independent publisher domains, not raw links. Ten sites re-running one wire story count once; the surplus is penalised as syndication.
  • Evidence — depth of structured collector payloads, minus failed collectors and unresolved contradictions between sources.
  • Name-match evidence — how much of the retrieved coverage actually contains the target's full name. If none of the returned documents name them, identity confidence is cut sharply and the panel says so outright.
  • Match — composite of the three above, weighted towards identity.

Before the search runs, very common names ("John Smith") and generic handles are detected deterministically and the console asks for narrowing details — city, employer, birth year, a known email — rather than producing a dossier that blends several people. You can always proceed anyway; the resulting confidence will reflect the ambiguity.

Findings also carry a verification tier: confirmed (primary source), supported (3+ independent sources), likely (2), possible (1 or inference), unverified, or contradicted. A high trust score with low confidence means "we found little bad — but we are also not certain we found the right person": narrow the search with DOB, location, employer or contact details before drawing conclusions.

Digital footprint score

A 300–850 exposure score for the subject, graded across five categories: breach exposure, social presence, infrastructure, financial signals and metadata leakage.

Each category comes with the evidence behind the grade and concrete remediation advice.

Organization intelligence

Paste a company name to generate a one-click dossier: ownership graph, subsidiaries, executives and board, lawsuits, patents, sanctions exposure, suppliers, technology stack, acquisitions and hiring trends.

Business Intel filters let you narrow by industry, geography, ownership/UBO and board or C-suite role to find chairmen and key people fast. Dossiers export as Markdown or into the case PDF.

Threat simulation

/threat-simulation answers "what is this company's biggest cyber risk?" using only passive public sources.

It evaluates exposed services, leaked credentials, attack surface, vulnerable technologies and public infrastructure, then returns a ranked defensive assessment with severity, confidence, evidence, coverage gaps and next steps. It is defensive only — no active probing is performed.

Predictive intelligence

Probabilistic forward assessments — bankruptcy risk, exit-scam probability, phishing-campaign likelihood, account-takeover and infrastructure-abandonment risk.

Each assessment states a probability, a confidence level, a time horizon, the supporting and counter evidence, assumptions and watch indicators. These are estimates, not certainties — treat them as leads, never conclusions.

Image intelligence (IMINT)

1
Go to /imagery and upload an image.
2
The analyser extracts landmarks, logos, OCR text, EXIF metadata and GPS coordinates where present, and infers a possible location.
3
Use the reverse-search pivots to look for the same image elsewhere on the web.

Results can be pushed into the active case and appear in the one-click Case Brief with evidence strength, confidence gaps and recommended next steps.

Intelligence canvas

An infinite visual workspace inside each case. Drag people, companies, phones, domains, wallets, screenshots, PDFs and notes onto the board and connect them into a link chart.

Anything you drop is hashed and recorded with provenance, so canvas artifacts count as real evidence rather than sketches.

Evidence integrity center

Every artifact — uploaded, collected or canvas-dropped — carries a SHA-256 hash, a collection timestamp, its source, the collection method and a full audit history.

Run a verification pass at any time to confirm nothing has been altered since collection. Results feed the case's chain-of-custody badge and the signed PDF dossier.

Relationship heatmap

Where the graph shows structure, the heatmap shows strength. Connections are banded from coincidental through weak to very likely connected, with a percentage on each pair so you can prioritise the links worth chasing.

Timeline

/timeline shows every dated event the collectors surfaced — breach dates, registration dates, on-chain activity, archived snapshots — in chronological order, colour-coded by severity.

Threat Center

/threats aggregates severity-ranked findings across all active cases.

Live monitoring

/monitor streams the public-source firehose (Hacker News, Wikipedia recent changes, GitHub public events) plus collector health probes. Use the Pause button to freeze the feed for review.

You can also put specific targets under watch — email, company, domain, wallet, phone, person or username. An hourly sweep re-probes each target with free public sources and notifies you on change: new breach, new company role, sanctions listing, lawsuit, new domain, GitHub leak or media mention. The number of watched targets is capped by your plan.

GEOINT

/geo plots geolocation data from the most recent scan (IP geo, ASN regions, organisational addresses).

Source registry

/sources lists every collector with its current health, latency, and HTTP status. Toggle a source to scope it out of future scans.

Reports & PDF export

Three places can export a signed PDF dossier:

1
Command / DashboardExport PDF emits a scan dossier with findings, entities, timeline, and collector telemetry.
2
InvestigationsExport dossier on a case emits a full case file (evidence ledger, notes, custody chain).
3
Reports (/reports) → Export PDF emits the active case dossier.

PDFs are generated locally from structured data — they do not leave your browser until you save them, and they render correctly regardless of theme.

AI analyst

/assistant is a conversational copilot trained on the current case context. Ask it to summarise findings, draft narrative paragraphs, or suggest next collection steps.

Analysts

/team lists the operators who have access to this workspace.

Admin control room

Users with the administrator role get an /admin link in the sidebar to:

  • Provision new operator logins directly.
  • Review pending access requests and approve or reject them.
  • Delete user accounts.

Settings

/settings holds workspace preferences and integration toggles.

Troubleshooting

  • PDF didn't download — make sure pop-up / download blockers aren't intercepting browser saves. The browser console will log the underlying error if any.
  • Scan returned errors for some sources — public collectors rate-limit, time out, or block edge worker IPs. Each source has a 4.5s timeout and runs in parallel so one bad source can never kill the run. Re-run after a minute, or open /sources and re-probe.
  • Can't find a case — cases are listed in three places: the left rail in /investigate, the flat index at /cases, and inside any export filename (INV-YYYY-####).
  • Stuck on a blank screen after login — hard refresh (Cmd/Ctrl + Shift + R). The app auto-clears cached chunks on next load.