Arsenly_OSINTby Xowia Technologies

Professional Templates & Deliverables

2026 Expansion
Browse the interactive, filterable tools for this domainOpen tools →

45.1 Intelligence Information Report (IIR) — NATO/OSINT Adapted Format

The IIR is the atomic deliverable: one question, one source, one time, one evaluation. It is not a dossier (that is the Target Package). The IIR feeds a dossier.

====================================================================
INTELLIGENCE INFORMATION REPORT (IIR)
====================================================================

--- HEADER ---
REPORT NUMBER:        [ORG]-IIR-[YYYY]-[NNNN]
CLASSIFICATION:       UNCLASSIFIED // FOR OFFICIAL USE ONLY
SUBJECT COUNTRY:      [Country ISO 3166-1 alpha-3]
PREPARED BY:          [Analyst name or team]
REPORT DATE:          [ISO 8601: YYYY-MM-DDThh:mmZ]
PERIOD OF REPORT:     [Start date → End date]
REQUESTING OFFICE:    [Team/Department that requested the analysis]

--- SOURCE EVALUATION (NATO A-F / 1-6 system) ---
SOURCE RELIABILITY:   [A/B/C/D/E/F]
  A=Confirmed · B=Usually reliable · C=Fairly reliable
  D=Not usually reliable · E=Unreliable · F=Cannot be judged
INFO CREDIBILITY:     [1/2/3/4/5/6]
  1=Confirmed by others · 2=Probably true
  3=Possibly true · 4=Doubtfully true · 5=Improbable
  6=Cannot be judged
SOURCE DESCRIPTION:   [One line, do not expose sensitive source]
SOURCE ACCESS:        [Public / Aggregated / Paid / Provided by third party]

--- CONFIDENCE LEVEL (ICD 203) ---
CONFIDENCE:           [HIGH / MODERATE / LOW]
JUSTIFICATION:        [2-3 lines. High = corroborated by ≥2 independent sources
                       with solid causal logic. Moderate = 1 reliable or 2 moderate.
                       Low = single or weak source]
KEY ASSUMPTIONS:      [List of assumptions that, if broken, lower confidence]

--- BODY ---
BLUF (Bottom Line Up Front):
   [1-3 sentences. The reader must understand the critical finding from this alone.]

KEY FINDINGS (numbered, max 5):
   1. [Critical finding #1]
   2. [Critical finding #2]
   3. [Critical finding #3]

EVIDENCE (each finding with support):
   - Finding #1:
       * Sources: [URL + capture date]
       * Capture: [SHA-256 of original document / screenshot]
       * Archive: [archive.org snapshot URL if applicable]

ANALYSIS (interpretation, not evidence):
   [What it means, what it implies, what it does not imply. Apply SATs from Appendix B]

KNOWLEDGE GAPS (what you DO NOT know):
   - [Gap 1]
   - [Gap 2]

RECOMMENDATIONS (prioritized next steps):
   1. [Action — who, what, when]
   2. [Action]
   3. [Action]

--- ANNEXES ---
A. Sources list (URLs, dates, hashes)
B. Charts/maps/graphs (ownership diagram, timeline, geo)
C. Raw data (PDFs, screenshots, exports)
D. Methodology note (which SATs were applied)
E. Chain of Custody log (see 45.5)

--- DISTRIBUTION ---
TO:    [Nominal list]
CC:    [Nominal list]
NOFORN: [Y/N]

--- REVISION HISTORY ---
| Rev | Date       | Author              | Changes                       |
|-----|------------|---------------------|-------------------------------|
| 0.1 | 2026-07-19 | A. Senior           | Initial draft                 |
| 1.0 | 2026-07-20 | A. Senior+Reviewer  | Peer review, approval         |
====================================================================

45.2 Target Package (Person) Template — 20 Fields

# Field Typical Source
1 Full canonical name + aliases LinkedIn, civil registry
2 Date and place of birth Adverse media, public records
3 Nationality(ies) Public visas, public records
4 Official identifiers (RFC/CURP/CPF/CUIT/DNI) Public registry
5 Reference photo(s) (min. 1 frontal) LinkedIn, press
6 Chronological professional bio LinkedIn, OCCRP Aleph
7 Current positions LinkedIn, corporate registry
8 Relevant historical positions (10 years) OpenCorporates, EDGAR
9 Key personal relationships LittleSis, adverse media
10 Corporate relationships (UBO/director) OpenOwnership, OpenCorporates
11 PEP status + since when + level OpenSanctions PEP
12 Sanctions status + designation date OpenSanctions aggregator
13 Adverse media (3-5 incidents) Google News, OCCRP, ICIJ
14 Litigation (civil/criminal/admin) PACER, local judicial registry
15 Digital footprint (email/phone/domains) Maigret, HIBP, WhoisXML
16 Real estate footprint Property registry
17 Declared net worth (if PEP) Asset declaration
18 Travel and residences (5 years) Press, Instagram geotags
19 Identified associated risks Output of analysis
20 Analytic confidence + gap list

45.3 Executive Briefing Template (1 Page)

┌──────────────────────────────────────────────────────────────────┐
│ EXECUTIVE BRIEFING — [Topic]                                      │
│ Classification: CONFIDENTIAL // C-Suite only    Date: YYYY-MM-DD │
├──────────────────────────────────────────────────────────────────┤
│                                                                   │
│ BLUF (Bottom Line Up Front):                                      │
│ [2-3 sentences, no jargon]                                        │
│                                                                   │
│ Confidence: HIGH ▓▓▓ / MODERATE ▓▓░ / LOW ▓░░                     │
│                                                                   │
├──────────────────────────────────────────────────────────────────┤
│ 1. CONTEXT (what was investigated and why)          [3-4 lines]  │
│                                                                   │
│ 2. KEY FINDING                                      [4-6 lines]  │
│    - Central fact                                                 │
│    - Source(s)                                                    │
│    - Implication for the organization                             │
│                                                                   │
│ 3. RISK AND IMPACT (financial/reputational/operational/legal)    │
│    [2x2 table or list; A/B/C marks by severity/probability]     │
│                                                                   │
│ 4. RECOMMENDATIONS (3, prioritized)                              │
│    1. [Immediate action — 24-72h]                                │
│    2. [30-day action]                                             │
│    3. [90-day action]                                             │
│                                                                   │
│ 5. NEXT STEPS / KNOWLEDGE GAPS                                    │
│    - What is missing and how to close it (cost/effort estimate)   │
│                                                                   │
├──────────────────────────────────────────────────────────────────┤
│ Full annex: [link to full IIR / Target Package]                   │
│ Analyst contact: [name, email, phone]                            │
└──────────────────────────────────────────────────────────────────┘

45.4 Fact-Check Report Template (Journalism)

FACT-CHECK REPORT
=================

1. CLAIM (the verified statement)
   Literal text: "..."
   Claim source: [URL + date + capture]
   Who said it: [person/entity + position]

2. VERIFICATION DATE: YYYY-MM-DD
3. VERIFIER(S): [name(s)]
4. VERIFICATION STATUS:
   [ ] True        [ ] Mostly true
   [ ] Misleading  [ ] Mostly false
   [ ] False       [ ] Unverifiable

5. EVIDENCE COLLECTED
   5.1 Source 1: [type, URL, date, hash]
   5.2 Source 2: ...
   5.3 Source 3: ...

6. ANALYSIS (what weighs more and why)

7. OMITTED CONTEXT (what the claim does not say)

8. CONTACT WITH ORIGINAL SOURCE
   Was the claimant contacted? Yes/No · Response: [...]

9. REFERENCES [verifiable URLs]

10. POST-PUBLICATION CORRECTIONS [log]

11. LICENSE AND REUSE

45.5 Digital Chain of Custody Checklist — 12 Steps

Before capturing:

  • 1. Synchronise the device clock with NTP (difference <1s).
  • 2. Verify the browser is clean (no logged-in session that biases served content).
  • 3. Log pre-capture: exact URL, date/time with explicit timezone, public IP, access method (direct/VPN/Tor).

During capture:

  • 4. Capture with visible timestamp on screen.
  • 5. Save original format: complete HTML ("Save Page As → Webpage, Complete") + uncropped PNG screenshot.
  • 6. Generate a snapshot on archive.org / archive.today and save the returned URL.
  • 7. For video: download with yt-dlp preserving original metadata; do not re-encode.

Immediately after:

  • 8. Compute SHA-256 of the original file and log: filename, hash, size, UTC capture date.
  • 9. For JS-heavy captures: also save HAR file (Network → Save All as HAR) and WARC if using wpull or archiveweb.
  • 10. Rename files with convention {YYYYMMDDTHHMMZ}_{slug}.{ext} (no spaces or accents).

Storage:

  • 11. Store in an append-only repository (git with tags or WORM system). Never overwrite, only version. Second offline repository recommended.
  • 12. Maintain a master CSV/JSON log with columns: case_id · filename · sha256 · capture_url · capture_timestamp_utc · capture_method · analyst · notes. One master file per case.

45.6 Verified Templates & Deliverables Tools

Tool URL Function
Obsidian https://obsidian.md Linked notes with graphs
TimelineJS https://timeline.knightlab.com Interactive timelines
Aeon Timeline https://www.aeontimeline.com Complex timelines
Draw.io / diagrams.net https://www.diagrams.net Diagrams and flows
Zotero https://www.zotero.org Reference management
CryptPad https://cryptpad.fr Encrypted collaboration
Standard Notes https://standardnotes.com E2E encrypted notes
VeraCrypt https://www.veracrypt.fr Container encryption
MAT2 https://0xacab.org/jvoisin/mat2 Metadata stripping
ExifTool https://exiftool.org Metadata extraction
OpenTimestamps https://opentimestamps.org Blockchain timestamping
Hunchly https://www.hunchly.com Web capture with OPSEC ($129/yr)
archive.org Wayback https://web.archive.org Historical web archive
Archive.today https://archive.today Wayback alternative
Maltego https://www.maltego.com Link analysis and visualization
Datasette https://datasette.io Explore CSV/SQLite
Gephi https://gephi.org Graph analysis
RAWGraphs https://rawgraphs.io Charts from CSV
Datawrapper https://www.datawrapper.de Visualization for reports
QGIS https://qgis.org Desktop GIS
Mapillary https://www.mapillary.com Crowdsourced street-view
Atlos https://www.atlos.org Collaborative investigation
Auto-Archiver (Bellingcat) https://github.com/bellingcat/auto-archiver Automatic archiving
4CAT https://github.com/digitalmethodsinitiative/4cat Social data analysis
Pinpoint (Google Journalist Studio) https://journaliststudio.google.com/pinpoint/ Document analysis

45.7 Common Errors in OSINT Deliverables

  1. BLUF absent or buried. The executive reader has no time. If the critical finding is on page 7, it does not exist.
  2. Confusing fact with inference. "Company X is owned by Y" (fact) vs. "probably controlled by Y" (inference). Use markers [FACT] vs [ANALYSIS].
  3. No chain of custody. A screenshot without URL, date and hash is anecdotal.
  4. Overloading with tools. The C-Suite does not care which tools you used, only the findings.
  5. Not declaring knowledge gaps. A senior declares what they do not know; a junior hides it.
  6. Unjustified confidence. "High Confidence" without justification = suspicious.
  7. Wrong format scaling. A 30-page IIR to a CFO = won't be read. A 1-page executive briefing to an auditor = useless.
  8. No versioning. Without revision history, no one knows if they are reading version 0.1 or 1.4.