Playbook 1: Account footprint
- Start with username and email searches.
- Correlate overlaps across modules.
- Build a timeline from key events.
- Export findings for reporting.
Playbook 2: Infrastructure mapping
- Start from a domain.
- Expand to DNS, subdomains, and linked IPs.
- Analyze geolocation and hosting context.
- Track changes with monitoring alerts.
Playbook 3: Breach triage
- Search by email or username.
- Review available leak providers (plan dependent).
- Score exposure severity.
- Escalate with timeline and evidence exports.
Good practice
- Keep each case in a dedicated project.
- Add attachments and notes as evidence.
- Use monitoring to detect new signals after initial analysis.