Forensic Evidence vs. Research Documentation
In the web capture space, two distinct categories of tools exist: forensic evidence capture platforms and OSINT (Open Source Intelligence) research tools. Understanding the difference can save your team time and prevent evidence challenges.
OSINT Research Tools
OSINT tools are typically browser extensions designed for investigators, law enforcement, and journalists. They work by quietly capturing every page visited during a research session, building an automatic audit trail of the investigation.
OSINT tools excel at:
- Continuous background capture while you browse
- Automatic timeline creation for research sessions
- Keyword tracking across captured pages
- Tagging and organizing captured data
- Deletion monitoring (alerting when captured pages disappear)
- SHA-256 hashing for data integrity
Typical limitations:
- Browser-only (extension model)
- Designed for research documentation, not formal evidence packaging
- No blockchain timestamping
- No branded chain of custody reports
- No e-Discovery load file export
- Investigator manages their own chain of custody
AEGIS: Built for Forensic Evidence Capture
AEGIS is a dedicated forensic capture platform designed to produce structured, verifiable evidence packages. Rather than passively capturing pages as you browse, AEGIS performs deliberate, documented captures with full cryptographic verification.
AEGIS excels at:
- Producing 10-file evidence packages per capture
- SHA-256 hash manifests + RSA-2048 digital signatures
- Bitcoin blockchain timestamping (immutable time proof)
- TLS/SSL certificate attestation
- Branded chain of custody reports
- e-Discovery load files (.dat/.opt) for litigation review platforms
- MHTML archive + raw HTML + extracted text
- 33-language support with custom agency branding
Feature Comparison
| Feature | AEGIS | Typical OSINT Tool |
|---|---|---|
| Primary Use | Forensic evidence capture | Research documentation |
| Capture Style | Deliberate, per-target | Continuous background capture |
| SHA-256 Hashing | ✅ Full manifest | ✅ Per-page hashing |
| Digital Signatures | ✅ RSA-2048 | GPG signing (varies) |
| Blockchain Timestamps | ✅ Bitcoin / OpenTimestamps | Rarely available |
| TLS Certificate Attestation | ✅ Full SSL documentation | Rarely available |
| Chain of Custody Report | ✅ Branded HTML report | Audit trail / timeline |
| e-Discovery Load Files | ✅ .dat/.opt included | Rarely available |
| Evidence Package | 10 structured files | Page captures + attachments |
| Keyword Tracking | Not primary function | ✅ Common feature |
| Deletion Monitoring | Not primary function | ✅ Common feature |
| Custom Branding | ✅ White-label reports | Rarely available |
| Pricing | One-time $497 (Founder) | Annual subscription (varies) |
Key Differentiator: Evidence Depth
The core difference is evidence depth. OSINT tools capture breadth (many pages, continuous documentation). AEGIS captures depth (one target, maximum cryptographic verification).
An AEGIS capture produces a complete forensic package: hashed files, signed manifests, blockchain-anchored timestamps, TLS attestation, and e-Discovery-ready load files. This level of documentation is designed for scenarios where evidence provenance will be scrutinized.
An OSINT research session produces a documented timeline of your entire investigation — invaluable for briefings and analysis, but structured differently than a formal evidence package.
When to Use Each Type of Tool
Use AEGIS when:
- You need a single, high-stakes evidence capture with maximum cryptographic backing
- You need e-Discovery-ready output for litigation review platforms
- You want blockchain-verified timestamps for immutable time proof
- You need branded, client-ready chain of custody reports
- You’re building an evidence package for regulatory or legal proceedings
Use an OSINT tool when:
- You’re conducting broad online research across many pages
- You need continuous background capture during an investigation
- You want automatic keyword tracking and deletion monitoring
- You’re building a research timeline for internal briefings
Can You Use Both?
Yes — and many investigative teams do exactly that. Use OSINT tools during the research and discovery phase to document your investigation broadly. When you identify specific pages that need to be preserved as formal evidence, use AEGIS to create a full forensic capture package with blockchain timestamps and e-Discovery export.
n Wolf Pak Capturen