Project Gates of Valhalla
Sign in Sign up

Project

Gates of Valhalla


A cyber security research platform focused on OSINT, forensics and timelines. We explore data, uncover truth, and build clarity through open source intelligence and rigorous analysis.

Open source intelligence: find, verify, expose

Open Source Intelligence

Find, verify, expose. Public sources, walked systematically and drawn as a graph.

Forensic analysis: extract, analyze, reconstruct

Forensic Analysis

Extract, analyse, reconstruct. Every finding keeps the raw evidence it came from.

Timelines that tell the truth

Timelines That Tell The Truth

Build context, uncover sequence, reveal the story. The next tool on the bench.

71
Sources live
105
Sources built
5
Seed entity types
18
Entity types graphed

What it does

You give it one thing you know — an email address, a username, an IP, a hostname or a domain. Every source that accepts that kind of entity runs against it. Everything those sources return becomes an entity in its own right, and the process repeats outward, hop by hop, until the map stops growing or you tell it to stop.

The graph is drawn while collection is still running. Nothing blocks: you can drag nodes, inspect findings and follow leads while the rest of the fan-out continues behind you. When you are done, the whole thing exports as a PDF intelligence report, a PNG of the graph exactly as you arranged it, or JSON and CSV for further work.

Danish first

Most OSINT tooling treats Denmark as an afterthought. This one does not. DK Hostmaster WHOIS is queried with the flags that actually return contact handles, the CVR company register is wired in for Danish legal entities and their management, Danish hosting providers and mail platforms are fingerprinted by name, and the subdomain wordlist includes the conventions Danish sites actually use. Worldwide sources are there too — they are just not the whole story.

How to read a finding

Findings are leads, not verdicts. Every one of them describes what a public source reported at the moment it was asked. Vendors disagree, registries redact, caches go stale, and scanners get blocked. Entities the platform inferred rather than observed — a person's name derived from an email address, for instance — are marked at reduced confidence and drawn with a dashed ring. Confirm anything that matters before you act on it.

What it will not do

  • It does not attempt authentication against anything, ever.
  • It does not port-scan. Only ports 80 and 443 are contacted, and only to read what a public web server volunteers about itself.
  • It does not submit anything to third parties about your target. urlscan results are read, never created.
  • It does not exploit. Vulnerability findings come from version banners in other people's indexes, and are flagged as inference.

Who built it

THUGS(red), a Danish hacking community. This is a tool for security researchers, and all we do here is dig and visualise patterns in OSINT data.

Running your own copy

71 of 105 sources need no credentials at all — DNS, WHOIS, RIR registries, certificate transparency, the Internet Archive, GeoLite2 and CVR all work out of the box, with or without an account.

The rest bill per key, so they belong to the researcher who bought them: add yours on your account page and that source is live for you from your next investigation, no restart. Nothing breaks for want of a key; you just see less. The source list shows exactly what is live for you right now.