Project Gates of Valhalla
Sign in Sign up

Guide

Getting started

What this platform is, what a finding means, and the five minutes before your first investigation.

The short version

  1. Type a seed — a domain, email, username, IP, phone number or address — and press Investigate.
  2. Everything that comes back becomes a node that is itself queried. That is the fan-out.
  3. Sign in if you want to keep the work, share it, or use sources that need your own API key.
  4. Read findings as leads, never as verdicts. The platform is careful to say which is which; be careful to keep reading it that way.

What this is

Gates of Valhalla is an OSINT platform. You give it one thing you know — a domain, an email address, a username, an IP, a phone number, a street address — and it asks every source that accepts that kind of thing. Everything those sources return becomes an entity, and each of those gets asked about too. The result is a graph that grows outward from your seed, drawn live as it arrives.

Around that sit five more tools: a timeline builder, a forensic file analyser, a vulnerability scanner, a leak collector, and a security quiz. They share accounts, organisations and an audit trail, and they are otherwise independent — you can use any one of them without the others.

Findings are leads, not verdicts

This is the idea the whole platform is built around, and it is the one thing worth reading twice.

When a source says two things are connected, that is that source's claim, made at a particular moment, for reasons of its own. It is not a fact this platform is vouching for. The interface works quite hard to keep that distinction visible:

  • Inferred entities carry reduced confidence. If the platform worked something out rather than being told it, the graph says so.
  • A source that could not answer is reported as unknown, never as an absence. Blocked, rate-limited, out of quota and "nothing found" are four different answers, and only the last one means anything about your subject.
  • Anything you supply is marked as yours. An entity you added by hand gets a dashed cyan halo on the canvas and an "added by the analyst" line in the report, permanently. A report that cannot separate what was found from what was assumed is not worth much in front of anybody who matters.
  • A cached answer says it was cached. The activity ticker and the task record both flag a replayed source. A report must never imply a source was queried when it was not.

The failure mode this guards against is simple and common: a graph looks authoritative because it is a graph. Two nodes joined by a line read as a fact. Very often it is one API's guess. Click the edge, read what claimed it, and decide for yourself.

And silence is not evidence either

The other half of the same rule. If you narrow the source selection — which you should — the sources you left out returned neither a finding nor an absence of one. They were never asked. The PDF report says so explicitly, in its own limitation line, but only when the selection was actually narrowed, because a warning that is always on stops being read.

The same applies to the timeline, where the gaps get a section of their own, and to the leak collector, where a crawl that found nothing tells you which of four reasons applies rather than reporting "no files".

Your first investigation

  1. Go to the research tool.
  2. Look at the source group control next to the Investigate button. It says Starter by default. Leave it there for now — see why the default is narrow.
  3. Type a seed. If you have nothing in mind, click one of the Try chips underneath — each one is a different kind of entity, so you can watch the tool answer a different sort of question.
  4. Press Investigate. The graph starts drawing within a second or two.
  5. When it settles, right-click a node. That menu is where the tool actually lives; the research guide goes through every item on it.

Do you need an account?

No, and that is deliberate — the front page is the tool, and making a stranger sign up before they can look anything up would defeat it. An anonymous visitor can run investigations, build timelines, export reports and play the quiz.

What an account adds:

  • Your work is kept and listed. Anonymous investigations are reachable only by their link.
  • Your own API keys. Roughly a quarter of the sources here need one — Shodan, HIBP, Censys and friends. Keys live encrypted on your account and are spent by you, because those services bill per key and one researcher's quota should not fund another's work.
  • Sharing. Private, organisation-wide, or anyone with the link.
  • Organisations. A shared view of your team's research and its own audit trail.
  • The rest of the tools. Forensics and above want an accountable actor behind them.

Roles, and how to get one

Four roles. Each is placed by how much trust it needs, not by seniority — which is why forensics sits above sharing, and why the leak collector sits above both.

Security Analyst The default for a new account. Runs investigations, builds timelines, reads what the organisation can see, holds their own API keys, and runs the vulnerability scanner against domains they have proved they control.
Security Researcher Adds publishing an investigation to anyone with the link, and forensic analysis — which points parsers with a CVE history at bytes somebody else chose, so it is a real trust step.
Security Specialist Runs the organisation. Also holds the two largest grants: building a custom source, which chooses a URL this server will then call, and the leak collector, which fetches other people's documents onto this server's disk.
Administrator The platform: accounts, organisations, integrations, the full audit log.

Every web sign-up is an Analyst, including the first one. To move up, ping Kawaiipantsu on Discord and say what you are trying to do — that is more useful than naming the permission you think you need, because half the time there is a lower-privilege way to get there.

What the platform records about you

Reads and writes both go in an audit trail — who looked, at what, when. That is the point of it: the record of who looked outlives what they found, and on a platform that handles other people's personal data it is the thing that makes the handling defensible.

Files you upload are transient by design. The timeline keeps the events it extracted and the text it read; the original upload is scaffolding and gets pruned. If you need a file to persist, put it on filio.dk and import it by link — then the durable copy is yours, on a service built for it, and this platform holds only a reference and a SHA-256.

See the privacy page for the full account.