> For the complete documentation index, see [llms.txt](https://knowledge.whiteintel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://knowledge.whiteintel.io/search-and-investigation/investigation+.md).

# Investigation+

Investigation+ is an AI-assisted identity investigation tool. Given an email address or username, it correlates the identity across infostealer records and assembles a consolidated profile of the devices, accounts, applications, and credentials associated with it.

**Availability:** Threat Intelligence subscription, or an add-on to Enterprise. Usage is rate limited.

<figure><img src="/files/yDEbGHwK9kdgquDLWrzu" alt=""><figcaption></figcaption></figure>

### Starting an investigation

1. Enter an email address or username in the search field and run the analysis.
2. The platform queues an analysis job and processes it in stages. Progress is shown per component while the job runs.
3. When the job completes, the consolidated results are displayed.

Each analysis is recorded in your **Analysis History**, so a previous investigation can be reopened without re-running it.

### Usage limits and accuracy

Investigation+ is AI-assisted and may contain inaccuracies. Usage is capped per hour and per day. The applicable limits are shown on the landing view, and the platform reports a clear message if a limit is reached.

### Results

When an identity is found, the results are organized into tabs:

* **Results** — a Known Assets panel and an Applications footprint.
  * **Known Assets** groups the device-level attributes correlated with the identity: computer names, operating systems, IP addresses, countries, related accounts discovered on the same compromised devices, and recovered passwords.
  * **Applications footprint** lists the applications and services associated with the identity.
* **Graph** — a visual relationship map between the identity and the correlated entities.
* **Credentials** — the exposed credential records tied to the identity.
* **AI Insights** — a generated narrative analysis of the findings.

<figure><img src="/files/8pXEZidHT8WSaRfPauri" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/eeLsUlUuVmyTGhpkR4dN" alt=""><figcaption></figcaption></figure>

### Exporting findings

The assembled asset data can be exported as a structured file for offline analysis or inclusion in a report.

<figure><img src="/files/haGxTy24kaG9WEBI8JkY" alt=""><figcaption></figcaption></figure>

### No results

If the analysis completes but no matching infostealer records are found, the platform states this explicitly and offers to return to the search so you can investigate a different identity.
