Welcome

Welcome to the Falcon user manual.

Use the left navigation to open sections and jump to specific workflows.

About Falcon

Falcon is a comprehensive investigation management system (IMS) designed to support the full investigation lifecycle. All system activities are organized within a structured workflow based on Clients, Investigations, and Searches.

System Overview

  • Client — represents the entity for which the investigation is conducted
  • Investigation — a workspace where related searches and data are stored
  • Search — can only be executed within an investigation

Workflow: Client → Investigation → Search

Default Setup

  • One default Client is automatically created
  • One default Investigation is automatically created

This allows users to start running searches immediately without additional setup.

Note: A Client is required to create an Investigation, and an Investigation is required to run searches.

Login

To access Falcon, open the system URL, enter your login credentials, and then confirm access with the required Access Card code.

1
Open Falcon

Go to the system login page.

2
Enter credentials

Provide your login and password.

3
Confirm with Access Card

Enter the requested 8-digit code from the corresponding Access Card line.

4
Open Dashboard

After successful verification, the Dashboard opens automatically.

Important: Store the Access Card securely. It is required for every login.

Dashboard

The Dashboard provides a role-based overview of key system information and available actions. The set of visible sections depends on the user role.

Server Status

Displays the current status of core system servers, including Phoenix and Falcon.

License Overview License Owner only

Shows license limits and available resources, including clients, investigations, operators, and search queries.

Search Overview

Shows active searches and provides quick access to start a new search.

Investigations & Operators

Summarizes investigation activity by status and provides an overview of operator roles.

NotificationsBETA

The notification bell notification icon displays system events relevant to the user role.

Role-Based Visibility

  • License Owner — sees all events within the license.
  • Curator / Manager — see events created by users below their role.
  • Investigator — sees only their own events.

Latest Notifications

  • Up to 4 latest notifications are shown in the bell modal.
  • Unread notifications are highlighted and marked with a blue bell.
  • Read notifications are marked with a gray bell.

Behavior

  • Click an unread notification to open the related result and mark it as read.
  • Click the bell icon to mark it as read without opening the result.
  • Use All notifications to open the full Notifications page.

Example

Databases search has been completed for query "[email protected] started by investigator_4l32a9z (investigator).

AI Summary search has been completed for query "[email protected]" started by investigator_2l9ds (investigator).

Search List

The Search List page is the main workspace for monitoring existing searches, filtering them, creating new searches, archiving completed results, and removing selected records.

Default ColumnsDescription
QueryThe phrase or value that was searched.
ScopeThe source type: Databases, Logs, Documents, or Find in Investigation.
Created AtThe date and time when the search was created.
Finish AtThe date and time when the search completed.
StarterThe user who started the search.
StatusPending, In Progress, Done, Canceled, or Problem.
ActionsAvailable actions such as cancel, progress, or open results.

Available actions

  • All Searches — shows all searches available to the user
  • My Searches — filters to searches started by the current user
  • New Search — opens the search creation form
  • Archive — available only for searches in Done
  • Trash — available for selected searches except Pending and In Progress. Only License Owner can delete searches.

Table tools

  • Filters — filter by query, scope, accuracy, scheduled type, starter, status, tags, and investigation
  • Table Settings — adjust font size, column lock, and visible optional columns
  • Select all — selects all records on the current page

Search Lifecycle

Every search moves through a defined status flow from creation to completion or failure.

Pending
In Progress
Done
Pending
Canceled
Pending
In Progress
Problem

Search Results

The Search Results page displays the output of a completed search and provides tools for reviewing, filtering, analyzing, and exporting the data. Each search run generates a result set that can be explored through multiple tabs.

Header Information

Provides key details about the executed search:

Result Files

Each completed search execution is stored as a separate result file. For scheduled searches, multiple result files may be generated over time.

Result Tabs

Preview

Displays up to 500 rows from the result file. Used for quick inspection of raw data without loading the full dataset.

Export: CSV, XLSX, PDF. A one-time share link can also be generated where permitted and remains valid for 24 hours.

Finds

Shows structured data extracted from the results (Phones, Emails, Domains, IPs, Card, BTC.) with occurrence counts.

Credentials

Displays extracted credential data grouped by domain, including login-password pairs. Shows up to 500 rows.

Export: CSV, TXT.

AI Summary

Runs AI analysis on the result file data to generate a structured, human-readable summary.

Cost: 1 token per analysis.

Operators BETA

RoleMain Capabilities
License OwnerFull system access. Can manage license settings, clients, investigations, operators, and all searches within the license.
CuratorIncludes Manager permissions and can create and edit operators.
ManagerIncludes Investigator permissions and can create clients and investigations.
InvestigatorCan create searches and view their own searches.

Clients BETA

The Clients module allows users to create and manage client profiles that can be linked to investigations and searches.

Investigations list

An Investigation is a central workspace used to organize all operational activity related to a specific case. It serves as a place to store case-related information and brings together all search queries performed within the investigation.

All searches in Falcon must be created within an investigation, making it the primary container for executing searches and managing results.

Purpose

  • Store and organize case-related data (files, notes, tags)
  • Group and manage all searches related to a specific investigation
  • Provide a structured workspace for analysis and collaboration

Access Control

  • License Owner can assign users to investigations and has access to all investigations within the license
  • Curator can view all investigations and create new ones, but cannot assign operators to investigations
  • Manager can see only investigations they created
  • Investigator can see only investigations they are assigned
  • If an Investigator is not assigned to any investigation, they cannot run searches

Find in Investigation BETA

This feature helps the user locate a query inside completed search results within a selected investigation.

Purpose

Use this function when you remember that a phrase appeared in one of the investigation results, but you do not know which search contains it.

How it works

  • Select an investigation
  • Enter a query phrase
  • Run the search
  • Open the matching completed search result from the returned list
Rules: both fields are required, the query is limited to 100 characters, the | symbol is not allowed. Search show in the Search List and does not comsume tokens.

AI DetectiveBETA

AI Detective is an automated investigation workflow that performs search and analysis based on a single query. It simplifies the investigation process by automatically collecting and structuring relevant data.

How it works

Capabilities

Note: AI Detective is designed to accelerate analysis by reducing manual steps and organizing results automatically.

New AI Detective BETA

The New AI Detective page allows creating a smart investigation based on a single query. The system automatically launches multiple related searches, aggregates the data, and structures the results for analysis.

Required fields

  • Client — defines the entity for which the investigation is created
  • Query — the main value used to generate automatic searches
  • Title — name of the investigation

Optional fields

  • Description — additional context for the investigation
  • Assigned investigators — users who will have access to this investigation
  • Tags — used for categorization and filtering

How it works

  • Automatically generates and runs multiple related search queries
  • Aggregates data from all executed searches
  • Structures results into a table of frequent occurrences and a relationship graph
  • Processing time may take up to 5 days depending on data volume

Access Control

  • By default, the investigation is visible only to the creator
  • Only License Owner can assign investigators or managers
  • If no users are assigned, no one else will see the results
Note: To share AI Detective results with other users, they must be explicitly assigned to the investigation by the License Owner.

AI Detective Details BETA

The AI Detective Details page provides full information about a specific smart investigation, including its configuration, metadata, and execution status.

General Information

  • ID — unique identifier of the AI Detective investigation
  • Creator — user who created the investigation
  • Client — associated client
  • Title — investigation name
  • Query — main query used to generate automatic searches
  • Description — optional investigation details

Execution Details

  • Created at — date when the investigation was created
  • Deadline — expected completion date
  • Finish at — actual completion date (if finished)
  • Status — current state of processing

Access & Collaboration

  • Investigators — users assigned to this investigation
  • Only assigned users can view and work with this investigation

Available Actions

  • View Result — opens the AI Detective results page
  • Download Archive — downloads all related data as an archive
  • Edit — available while the investigation status is In Progress. Allows updating Description, Deadline, and Assigned Investigators
  • Back — returns to the previous page
Note: Access to this investigation depends on assignment. Only users added by the License Owner can view the details and results.

AI Detective Results BETA

The AI Detective Results page displays processed data generated by the smart investigation. It provides a structured overview of key findings and visualizes relationships between entities discovered during automated searches.

Header Information

  • Query — the original query used to generate the investigation
  • Created At — date and time when the investigation started
  • Finish Time — date and time when processing was completed
  • Investigation — related investigation name

Top Finds

Displays the most frequently identified data points extracted from all processed search results.

  • Emails — most common email addresses
  • Phone numbers — frequently occurring phone numbers
  • Domains — related domains identified in the data
  • Credit cards — detected card numbers
  • BTC wallets — identified Bitcoin wallet addresses

Search Tree

A visual relationship graph that shows connections between entities such as emails, phone numbers, and other extracted data.

  • Displays links between related data points
  • Helps identify patterns and hidden relationships
  • Built automatically based on aggregated search results

Graph Controls

  • Color by State — colors nodes based on their relevance or confidence level
  • Filters — toggle visibility of nodes:
    • Initial - the starting node based on the original query.
    • Strong — highly reliable connections found directly in the data.
    • Potential — possible connections identified through indirect matches or weaker signals.
    • Frequent — data points that appear most often across multiple search results.
  • Color by Category — colors nodes based on data type (email, domain, etc.)
Note: The results are generated by processing and aggregating multiple automatically executed search queries. The graph highlights relationships between entities to support faster analysis and investigation.

FAQ

Why is my search still in Pending?

New searches stay in Pending for up to 5 minutes before entering the processing queue. During this period, the request can still be canceled.

Why cannot I archive some searches?

Archiving is available only for searches that have already finished successfully with the Done status.

Why can’t I use OR and AND?

OR and AND query types work only when Search Accuracy is enabled (ON).

Why do I get more results with Accuracy OFF?

With partial match enabled, Falcon can find the query inside longer strings and mixed alphanumeric values.