Project Gates of Valhalla
Sign in Sign up

Documentation

Help & guides

One guide per tool. Each starts with the short version — the four or five steps that are usually all you need — and then goes into how to actually use the thing in an investigation.

If you read one of these, read Getting started. It is the short one, and it covers the thing every other guide assumes: what a finding on this platform means, and what it deliberately does not mean.

What this platform is, what a finding means, and the five minutes before your first investigation.

The short version

  1. Type a seed — a domain, email, username, IP, phone number or address — and press Investigate.
  2. Everything that comes back becomes a node that is itself queried. That is the fan-out.
  3. Sign in if you want to keep the work, share it, or use sources that need your own API key.
  4. Read findings as leads, never as verdicts. The platform is careful to say which is which; be careful to keep reading it that way.

The main tool. Seed, fan-out, and the right-click menu that turns a picture into an investigation.

The short version

  1. Pick a source group before you search — it decides what gets spent, and the default is deliberately narrow.
  2. Type a seed and press Investigate. The graph draws itself as answers arrive.
  3. Right-click any node. That menu is the tool: add a relation you already know, scan that one entity with one named source, stop the fan-out going somewhere useless, or prune noise.
  4. Press f to fit, g to cycle layouts, / to jump to the search box.
  5. Export a PDF, PNG, JSON or CSV from the masthead. Those are links — they survive being pasted into a ticket.

Paste what you have, get a dated chronology that states its own precision and shows you the gaps.

The short version

  1. Create a timeline, then paste a source — an email thread, a report, a chat log, a note you wrote.
  2. Events are extracted with a date, a precision and a confidence. Nothing is fetched on your behalf.
  3. Add files for machine data: nine thousand log lines become one span with the outliers called out, not nine thousand dots.
  4. Add events by hand for what you know. They are marked as yours, permanently and visibly.
  5. Export the PDF — it prints every event with its source and precision, and gives the gaps their own section.
Read the full guide Needs Security Analyst. Ask Kawaiipantsu on Discord.

Forensics: what a file really is

Security Researcher

Static analysis of a file you already hold. Nothing is executed, and nothing is sent to a third party.

The short version

  1. Upload a file, or import one from a filio.dk share. Uploading runs nothing.
  2. Press Analyse. That is a separate, deliberate act, because the parsers behind it have a CVE history.
  3. Read the type verdict first: the extension is the least reliable thing about a file.
  4. Check the personal-data section before you forward anything to anybody.
  5. Delete the file when you are done. Its report goes with it, on purpose.
Read the full guide Needs Security Researcher. Ask Kawaiipantsu on Discord.

Vulnerability scanner

Security Researcher

The only tool here that sends traffic at a host. Prove you control the domain, then choose how loud to be.

The short version

  1. Type the domain. The page gives you a TXT record to publish at _valhalla.<domain>.
  2. Publish it, then press Check. The proof is read from the zone’s own nameservers, never a cache.
  3. Pick a pack. Heimdall is safe against anything you own; Ragnarök is loud and says so.
  4. Watch it run. Stop is a real stop — about a second from the button to a dead scanner.
  5. The PDF states how ownership was established. A reader can tell consent from an unsolicited scan.
Read the full guide Needs Security Researcher. Ask Kawaiipantsu on Discord.

Leak Collector

Security Specialist

Read a leak site’s file listing over Tor or the clearnet, tick what you need, take it away as one packed archive.

The short version

  1. Paste the address of the file listing — not the site’s front page.
  2. Wait for the crawl. It reads index pages and downloads nothing.
  3. Read the list, tick what you actually need, and tick Forensics beside anything you want analysed.
  4. Press Retrieve. Up to five files come down at once, with a progress bar each.
  5. Download the pack. One zip per run, with a manifest naming the source and SHA-256 of every file.
Read the full guide Needs Security Specialist. Ask Kawaiipantsu on Discord.

What the hundred connectors are, why some are greyed out, and how to point the platform at an API of your own.

The short version

  1. A greyed-out source is missing a key, not broken. Keys live on your account and are spent by you.
  2. Source groups decide what runs. A narrow group is not a lesser investigation, it is a cheaper one.
  3. A source that could not answer is reported as unknown, never as an absence. Read the difference.
  4. Specialists can build a custom source: point it at an API, make one real call, and pick the values off the response.

The one part of this platform that teaches rather than investigates. Open to strangers, on purpose.

The short version

  1. Pick a round. Twelve presets, twenty-three disciplines, 444 questions.
  2. Answer once per question — the set is dealt at the start and there is no going back.
  3. Read the explanation, especially when you got it wrong. The explanation is the point; the score is the hook.
  4. No account needed. Close the tab and come back tomorrow; the round is still there.

Still stuck

Ping Kawaiipantsu on Discord. That is also how you ask for a role: the higher grants here are given to people, not applied for through a form, and being told what you want to do is more useful than being told which permission you think you need.