Dashboard
Evidence collection overview
Collection
Collect messages from public Telegram groups and channels
Collection Mode
Import
Import from Telegram, Discord, Reddit, or generic CSV/JSON
Drop CSV or JSON here
Supports: TeleTrace, DiscordChatExporter, Reddit JSON, generic CSV
Collections
Messages
Browse, search, filter, and tag evidence
Links
Extracted URLs from all messages
Top Domains
Suspects
Profiles, timelines, evidence
Keywords
Monitor keywords across all data
Active Keywords
Username Scanner
Search for a username across 25+ platforms
Scan Username
Scan History
Web Recon
Scrape any URL for emails, phones, social handles, crypto, and links
Scrape URL
Recon History
Dark Web Intel
.onion link tracking, Tor recon, sender correlation
Tor Connection
Scan Existing Data
Scan all collected messages for .onion links. Run this after importing data or collecting from new groups.
Tracked .onion Addresses
Top Sharers
Invite Link Hunter
Find private group doors, shadow groups, and bridge contacts
Analyze Existing Data
Scans all your collected messages for private invite links (t.me/+ and t.me/joinchat/), maps unknown groups from forwarded messages, and identifies bridge contacts who link public and private worlds.
Paste Site Scanner
Search DuckDuckGo for Telegram invite links leaked on paste sites, forums, and the open web. Enter keywords related to your targets.
Tracked Invite Links
Shadow Groups
Bridge Contacts
Code Word Engine
Detect coded language, slang, and known abuse terminology across all messages
Add Code Word
lov* matches "loving", "lover", etc. Check Regex for advanced patterns. Terms are case-insensitive.Scan Messages
Hits
Defined Terms
Top Flagged Senders
Bot Code Tracker
Track file bot codes used to distribute abuse content via FilePan, ShowFilesBot, 文件解码器, and other Telegram bots
Stats
Scan & Import
Tracked Codes
By Bot
Top Sharers
Entity Extractor & Public Records
Extract names, organizations, locations. Generate public records search links.
Extract Entities
Scans all messages for names (First Last pattern), organizations, and locations. Deduplicates and counts occurrences.
Public Records Search
Enter any name or entity to generate search links across 13+ public databases including court records, corporate registries, offshore leaks, political donations, and more.
Extracted Entities
Network Map
Interactive network visualization
Top Shared Invite Links
Political Finance
Search FEC, OpenSecrets, and political finance databases worldwide
Search
Auto-Search Entities
Run FEC searches for all names extracted from your message data.
Search History
Topic Investigation (Reverse Lookup)
Search political databases by topic (not name). Extracts every person/org connected to that topic, then auto-checks them against your TeleTrace data for matches.
Cross-References
Auto-link suspects to entities, bot codes, bridge contacts, and code word hits
Results by Suspect
Reports
Generate formatted evidence reports for law enforcement
Full Investigation Report
Complete summary of all collections, suspects, code word detections, and network intelligence. Opens as a printable HTML page that can be saved as PDF.
Individual Suspect Reports
Detailed evidence package for a single suspect. Includes tagged evidence, activity patterns, code word matches, username scans, web recon, cross-references, and integrity hash.
Activity Pattern Analysis
Analyze posting times, estimate timezones, and identify activity patterns for all suspects.
Payment Trail Mapper
Extract cryptocurrency addresses, PayPal, CashApp, WeChat Pay, Alipay, and other payment links from messages
Extract Payment Addresses
Scans all collected messages for crypto wallet addresses (BTC, ETH, XMR, LTC, TRX), payment platform links (PayPal, CashApp, Venmo, Ko-fi, Patreon), and Chinese payment methods (WeChat Pay, Alipay).
Found Addresses
Blockchain Explorer
Query Bitcoin, Ethereum, and Tron/USDT balances, transaction history, and counterparty networks
Single Address Lookup
Tron/USDT Deep Analysis
Deep analysis of a TRC-20 address: maps counterparties, calculates total USDT volume, identifies largest transactions. This is where Chinese abuse networks move money.
Batch Scan All Extracted Crypto
Queries blockchain explorers for every crypto address found by the Payment Trail Mapper.
WHOIS Lookup
Domain registration data for links found in messages
Bulk WHOIS Scan
Runs WHOIS queries on domains from shared links. Reveals registrant names, emails, organizations, and hosting details.
Single Lookup
Results
Sanctions Screening
Check names against international sanctions and watchlists via OpenSanctions
Single Check
Batch Screening
Screens all suspects and top entities against OpenSanctions (UN, EU, US OFAC, UK, Interpol, and 30+ other sanctions lists).
Results
Corporate Registry
Search OpenCorporates for shell companies, directorships, and corporate connections
Company Search
Batch Suspect Lookup
Search OpenCorporates for all suspect names to find corporate connections.
Chinese Network Investigation
Company registries, social media lookups, and Tron/USDT tracking for Chinese-language abuse networks
Search Chinese/Asian Company Registries
Deep links to company registries across China, Hong Kong, Singapore, Taiwan, and offshore jurisdictions. Use for identifying shell companies and corporate connections.
Chinese Social Media Username Search
Generate search links for usernames across Weibo, Douyin, Xiaohongshu, Zhihu, Bilibili, Baidu Tieba, QQ, Twitter, and GitHub.
Batch Username Lookup
Lists all unique senders and extracted usernames from your data. Click to generate social media search links for each.
Temporal Correlation
Find suspects with overlapping posting patterns suggesting coordination or shared timezones
Run Correlation Analysis
Compares posting hour patterns between all suspects. High overlap suggests same timezone or coordinated activity. Run Activity Analysis on the Reports page first.
Media Evidence Collector
Download, hash, and fingerprint media for evidence reports
Collected Media Overview
Media detected in your collected messages. Use Download below to grab files for evidence hashing.
Download from Channel/Bot
Downloads media files from a Telegram channel or bot for evidence preservation. Files are SHA-256 hashed and perceptually fingerprinted for duplicate detection. Uses your TG credentials from the Collection page.
Hash Local Files
Hash any media already in the media_evidence/ folder that isn't yet in the database.
Duplicate Detection
Username Harvester
Extract usernames from collected Telegram data and cross-reference against LOVCAT forum users.
Evidence Library
Bastion Secure Comms
Self-hosted, invite-only, zero third-party dependencies. Select a channel or DM to start.
Investigation Forum
Discuss leads, cases, and findings with your team
New Thread
Team Messages
Private messages between team members
Send Message
Inbox
Sent
Activity Feed
Team activity log
Admin Panel
User management and invite codes
Generate Invite Code
Invite Codes
Users
Change Password
Investigations
Per-channel stats, case folders, and cross-reference harvesting
Channels by Collection
Username Harvesting
Extract senders from collected messages, pull live member lists, and cross-reference against forum usernames.
Cases
Export
Download data and evidence packages
All Links
All Intel (Recon)
Dark Web / .onion Intel
Formatted Reports
Printable HTML reports with integrity hashes. Save as PDF from your browser's print dialog.
Suspect Evidence Packages
Tagged messages, links, username scans, web recon, SHA-256 hash.
Archives
Save, restore, and manage investigation snapshots
Create Snapshot
Saves a complete copy of the database. All messages, suspects, links, intel, keywords, forum posts, and team data.
Upload Archive
Upload a previously downloaded .db archive file.
Saved Archives
Clear My Archives
Deletes all of your saved snapshots. Does not affect the investigation database or other team members' archives.