The Greyline Verification Standard

Disciplines

OSINT, SOCMINT, cyber threat intelligence, entity resolution, identity intelligence, behavioural analysis, network and link analysis, digital forensics, and dark web intelligence.

Method · Disciplines

OSINT, SOCMINT, cyber threat intelligence, entity resolution, identity intelligence, behavioural analysis, network and link analysis, digital forensics, dark web intelligence.


Disciplines, Not Defaults

Every Greyline engagement draws on a defined set of intelligence disciplines, combined according to what the specific question requires. Which disciplines apply is set out in the written scope, not assumed.

A personal relationship verification draws on a different combination than a corporate insider-threat investigation. The scope says which, and the report says how they were applied.


OSINT: Open-Source Intelligence

Collection and analysis of information from publicly available sources: public records, corporate registries, media archives, academic databases, and the open web.

When applied: Background research, asset tracing, reputation verification, historical pattern analysis.

What it produces: Sourced, dated statements of fact drawn from public record; timeline construction; gap analysis where expected records are absent.

Limitation: OSINT is only as good as the sources that exist. A subject with minimal digital footprint or one who has deliberately obscured their trail may yield thin results. We report this absence rather than fill the gap with inference.


SOCMINT: Social Media Intelligence

Platform-native analysis of public posts, networks, and behaviour across social media platforms.

When applied: Lifestyle verification, behavioural consistency checks, network mapping, timeline corroboration, sentiment and activity pattern analysis.

What it produces: Screenshots with metadata, network relationship maps, activity timelines, behavioural pattern assessments.

Limitation: We analyse only publicly available material. We do not bypass privacy settings, use fake accounts to access restricted content, or scrape data in breach of platform terms of service. Where a subject’s accounts are private or dormant, we report that constraint explicitly.


Cyber Threat Intelligence

Tracking threat-actor infrastructure, tooling, and behaviour relevant to a client’s exposure.

When applied: Corporate security assessments, pre-transactional due diligence, executive protection, brand and reputation threat monitoring.

What it produces: Threat-actor attribution assessments (where feasible), infrastructure mapping, exposure gap analysis, actionable mitigation recommendations.

Limitation: Attribution in cyberspace is probabilistic. We grade our confidence explicitly and do not overstate certainty where the evidence supports only a range of possibilities.


Entity Resolution

Determining whether records, aliases, or accounts across disparate sources refer to the same real-world individual or organisation.

When applied: Complex investigations involving multiple jurisdictions, shell structures, alias use, or deliberately fragmented identity presentation.

What it produces: Entity relationship maps, confidence-graded linkages, disambiguation of false positives.

Method: Cross-referencing of identifiers (name variants, dates, locations, account handles, behavioural signatures) across sources, with each link graded for strength and independence.


Identity Intelligence

Verifying claimed identity against documentary and open-source evidence.

When applied: Pre-relationship verification, employment screening, fraud investigation, witness credibility assessment.

What it produces: Document authenticity assessment (where within our capability), consistency checks between claimed identity and observed behaviour, discrepancy reports.

Limitation: We are not a credit reference agency or a government identity verifier. We verify against available evidence; we do not issue identity credentials.


Behavioural Analysis

Assessing patterns of activity, communication, and lifestyle signal for consistency and anomaly.

When applied: Fraud investigation, insider threat assessment, relationship verification, due diligence where declared behaviour does not match observed behaviour.

What it produces: Pattern consistency reports, anomaly flagging, timeline correlation between claimed and observed activity.

Method: Structured observation against a baseline, not subjective impression. The analyst documents what was observed, when, and how it deviates from the expected pattern.


Mapping relationships between people, entities, and accounts to surface hidden connections.

When applied: Corporate ownership investigations, fraud network mapping, influence mapping, supply chain integrity checks.

What it produces: Network visualisations, link strength assessments, path analysis between entities, hidden connection surfacing.

Method: Relationship mapping based on corroborated evidence, shared addresses, overlapping directorships, financial flows, communication patterns, not on proximity or assumption.


Digital Forensics

Forensically sound acquisition and analysis of digital evidence from devices and accounts.

When applied: Litigation support, internal investigation, evidence preservation, breach response.

What it produces: Forensic images with hash verification, contemporaneous acquisition logs, reproducible analysis, chain-of-custody documentation.

Standard: ACPO Principles for Digital Evidence. Original data is never altered. The audit trail is reproducible by an independent third party.


Dark Web Intelligence

Structured, analyst-led investigation of dark web markets, forums, and threat-actor channels.

When applied: Data breach assessment, credential exposure checks, threat-actor monitoring, illicit market surveillance.

What it produces: Exposure reports, threat-actor capability assessment, credential compromise notifications, contextual risk analysis.

Limitation: Dark web intelligence is inherently fragmentary. We do not claim comprehensive coverage of all dark web activity. We report what we find, how we found it, and what we cannot see.


How Disciplines Combine

No engagement uses all nine. The written scope defines the relevant subset, and the report explains how they were applied. A typical personal verification might draw on OSINT, SOCMINT, and identity intelligence. A complex corporate investigation might add entity resolution, network analysis, and dark web intelligence.

The combination is deliberate, documented, and justified, not a kitchen-sink approach.

See the Standard Applied

Explore the rest of our method.