Pre-Investigation OPSEC Workflow
10 stepsInvestigator OPSEC & Sock Puppets1. Audit your current fingerprint with Cover Your Tracks + CreepJS. Document the baseline.
2. Decide OPSEC level: Low (normal browser + VPN), Medium (Mullvad Browser + VPN), High (Whonix gateway + Workstation VM).
3. Create an isolated research identity: dedicated email, no reuse of personal identity elements.
4. For sensitive investigations: use Tails OS on a bootable USB, no persistence.
5. Rotate identity periodically (every 30–90 days for long-running investigations).
6. Never mix identities: each sock puppet lives in its own browser profile / VM.
7. Network hygiene: trusted VPN + DNS over HTTPS. Do not use ISP DNS.
8. Metadata strip: MAT2 or ExifTool before uploading any file.
9. Communications: Signal or Session for source contact. Not personal WhatsApp.
10. Document OPSEC decisions in the final report: what level was used, why, what was done if something failed.
🔒 Your progress and notes are saved only in this browser.