Solutions · For Investigators

Run the whole investigation in one place.

Researchers and security teams piece together explorers, spreadsheets, and screenshots today. VikingIntel gives you the trace, the entity picture, the case record, and the evidence bundle — with every claim labeled for what it is.

Workflow
Trace → Correlate → Attribute → Report
Evidence
Typed claims, SHA-256-verified exports
After the report
Monitoring keeps the case live
What you get

Built around how investigations actually proceed.

Start from a signature or an address, expand to the surrounding structure, attribute what the evidence supports, preserve it, and keep watching.

Fund tracing

Forward and backward multi-hop traces that stop at known exchanges, bridges, and mixers — and say so when they truncate instead of implying an answer.

Wallet & entity analysis

Full behavioral profiles: funding lineage, counterparties, execution fingerprints, related wallets with the basis for each link, and composite risk scores with per-component evidence.

Bulk triage

Paste up to 1,000 addresses — a heist’s cashout set, a suspicious distribution — and rank them by exchange proximity with per-address hit detail. Pro plan (100 addresses/day).

Private labels

Your own researcher labels ride alongside the shared registry inside your traces — your attribution knowledge compounds instead of living in a spreadsheet.

Cases & evidence

Every wallet, note, decision, and finding under one case. Typed findings with provenance, append-only decisions, versioned reports, and snapshots — structured for review.

OSINT enrichment

Enrich an investigation with public-source evidence from project websites, domain infrastructure, repositories, and public identities — each piece carrying its source, timestamp, and confidence.

Monitoring

Keep watching the wallets that matter after the report ships. New movement raises webhook alerts tied to the same case file.

Correlation

Structure without false merges.

Known infrastructure is discounted rather than clustered, so a shared deposit address doesn’t collapse hundreds of unrelated wallets into one suspect group. Relationships are labeled with the basis for the link — you decide what holds.

Evidence

Conclusions that survive review.

Findings carry observed, derived, attributed, or inferred labels; deterministic facts outrank inference. Reports are stamped with the methodology version and a hash, so what you concluded is checkable later — by you or by anyone else.

Evidence Report
Cluster sybil-cluster-0192
Verified
Investigation ID
inv_8f3a2c
Cluster ID
sybil-cluster-0192
Wallet count
41
Classification
Coordinated
Confidence
High
Evidence families
3 / 4
Entity exclusions
1 (Binance Hot Wallet)
Generated
2026-08-04T14:36:11Z
Report hash
sha256:9a41…e02c

Illustrative example — mock cluster, report hash, and Verified badge.

Incident
incident-014
treasury compromise
Attacker wallet
8qLm…2kDe
identified by evidence
Watchlist
+1 address
added in one click
New movement
0.4 SOL · 2 events
detected 14:47:02Z
Alert raised
webhook + evidence
same case file

The loop closes. The attacker stays on the watchlist. New movement raises a webhook alert with the evidence attached — the investigation continues from the same case file, not from zero.

Monitor

The case file is ready when the money moves again.

Put the actor’s wallets under watch. New movement raises a webhook alert with the evidence attached — pick up from the same case file, no restart from zero.

Give your next investigation a head start.

Free accounts include tracing quota, screening, cases, and the full investigator loop.