What problem does it solve? Investigators need to examine domains, IPs, URLs, file hashes, documents, email headers, and public GitHub history without tipping off targets, contaminating evidence, or overstating what technical signals actually prove. ## Core Features & Use Cases - Passive Indicator Triage: Classify domains, IPs, URLs, and file hashes using passive records and public APIs, capturing provider labels as dated observations rather than verdicts. - Infrastructure History Reconstruction: Build dated timelines from passive DNS, certificate transparency, RDAP/WHOIS, and web archives without scanning or probing live hosts. - Document and Email Forensics: Extract metadata from local files and parse raw email headers, treating SPF/DKIM/DMARC results as server assertions rather than identity proof. - Verified Indicator Export: Export fact-checked indicators (IPv4, domains, hashes, crypto addresses) to JSON, CSV, or STIX only after Gate 1 verification. - Use Case: A journalist receives a suspicious email linking to an unknown domain. Use this Skill to passively triage the domain, reconstruct its DNS and certificate history, analyze the raw email headers, and export only the indicators that survive fact-checking. ## Quick Start Use the technical-investigation skill to passively triage the domain in this phishing email and reconstruct its infrastructure history without contacting the live host.