Arsenly_OSINTby XowiaLabs

Pre-Investigation OPSEC Workflow

10 stepsInvestigator OPSEC & Sock Puppets
0/10 steps complete
  1. 1. Audit your current fingerprint with Cover Your Tracks + CreepJS. Document the baseline.

  2. 2. Decide OPSEC level: Low (normal browser + VPN), Medium (Mullvad Browser + VPN), High (Whonix gateway + Workstation VM).

  3. 3. Create an isolated research identity: dedicated email, no reuse of personal identity elements.

  4. 4. For sensitive investigations: use Tails OS on a bootable USB, no persistence.

  5. 5. Rotate identity periodically (every 30–90 days for long-running investigations).

  6. 6. Never mix identities: each sock puppet lives in its own browser profile / VM.

  7. 7. Network hygiene: trusted VPN + DNS over HTTPS. Do not use ISP DNS.

  8. 8. Metadata strip: MAT2 or ExifTool before uploading any file.

  9. 9. Communications: Signal or Session for source contact. Not personal WhatsApp.

  10. 10. Document OPSEC decisions in the final report: what level was used, why, what was done if something failed.

🔒 Your progress and notes are saved only in this browser.