More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
kipi turns any document—PDF, screenshot, spreadsheet or pasted notes—into a live, typed entity graph and then drives an autonomous investigator across WHOIS, DNS, certificates and live sites without you writing a single query. You drop in a report or image, approve the proposed schema with one click, and watch as consolidation, typing, correlation, scoring and graph analytics happen step by step. At any point you can confirm, correct or reject each node, edge or finding. Every fact carries its source and an evidence grade from A (DNS record) to lead-level reads by the analyst.
In a 75-second demo, two seed domains (trumpfundus.com and trumpstake.us) blossom into a Russian-language affiliate fraud network running fake crypto casinos. The backend operates through a shell company in Reykjavík, set up just after Brian Krebs exposed its predecessor. The network spans 20,000+ affiliates, siphoning 60–80% of stolen deposits in crypto. A Musk-branded phishing clone sits in the same community cluster. When the investigation finishes, kipi writes a brief with every claim linked to its source and graded for evidence strength.
You install it locally via git clone and a one-step install script. The only required key is ANTHROPIC_API_KEY—for entity classification, schema proposal and report writing. All other OSINT lookups (VirusTotal, Censys, Etherscan, etc.) work if you add their keys; core pivots like whois, DNS, RDAP, Shodan InternetDB and BTC wallet mapping run keylessly. It’s Python, SQLite and Tesseract under the hood, Elastic License 2.0. Use it for paid investigations, fork it, self-host it—just don’t repackage kipi itself or resell it as a service.
Questions about this article
No questions yet.