Welcome
Welcome to the Falcon user manual.
Use the left navigation to open sections and jump to specific workflows.
About Falcon
Falcon is a comprehensive investigation management system (IMS) designed to support the full investigation lifecycle.
All system activities are organized within a structured workflow based on Clients, Investigations, and Searches.
System Overview
- Client — represents the entity for which the investigation is conducted
- Investigation — a workspace where related searches and data are stored
- Search — can only be executed within an investigation
Workflow: Client → Investigation → Search
Default Setup
- One default Client is automatically created
- One default Investigation is automatically created
This allows users to start running searches immediately without additional setup.
Note: A Client is required to create an Investigation, and an Investigation is required to run searches.
Login
To access Falcon, open the system URL, enter your login credentials, and then confirm access with the required Access Card code.
1Open FalconGo to the system login page.
2Enter credentialsProvide your login and password.
3Confirm with Access CardEnter the requested 8-digit code from the corresponding Access Card line.
4Open DashboardAfter successful verification, the Dashboard opens automatically.
Important: Store the Access Card securely. It is required for every login.
Dashboard
The Dashboard provides a role-based overview of key system information and available actions.
The set of visible sections depends on the user role.
Server Status
Displays the current status of core system servers, including Phoenix and Falcon.
License Overview
License Owner only
Shows license limits and available resources, including clients, investigations, operators, and search queries.
Search Overview
Shows active searches and provides quick access to start a new search.
Investigations & Operators
Summarizes investigation activity by status and provides an overview of operator roles.
NotificationsBETA
The notification bell
displays system events relevant to the user role.
Role-Based Visibility
- License Owner — sees all events within the license.
- Curator / Manager — see events created by users below their role.
- Investigator — sees only their own events.
Latest Notifications
- Up to 4 latest notifications are shown in the bell modal.
- Unread notifications are highlighted and marked with a blue bell.
- Read notifications are marked with a gray bell.
Behavior
- Click an unread notification to open the related result and mark it as read.
- Click the bell icon to mark it as read without opening the result.
- Use All notifications to open the full Notifications page.
Example
Databases search has been completed for query "[email protected] started by
investigator_4l32a9z (investigator).
AI Summary search has been completed for query "[email protected]" started by
investigator_2l9ds (investigator).
Search List
The Search List page is the main workspace for monitoring existing searches, filtering them, creating new searches, archiving completed results, and removing selected records.
| Default Columns | Description |
| Query | The phrase or value that was searched. |
| Scope | The source type: Databases, Logs, Documents, or Find in Investigation. |
| Created At | The date and time when the search was created. |
| Finish At | The date and time when the search completed. |
| Starter | The user who started the search. |
| Status | Pending, In Progress, Done, Canceled, or Problem. |
| Actions | Available actions such as cancel, progress, or open results. |
Available actions
- All Searches — shows all searches available to the user
- My Searches — filters to searches started by the current user
- New Search — opens the search creation form
- Archive — available only for searches in Done
- Trash — available for selected searches except Pending and In Progress. Only License Owner can delete searches.
Table tools
- Filters — filter by query, scope, accuracy, scheduled type, starter, status, tags, and investigation
- Table Settings — adjust font size, column lock, and visible optional columns
- Select all — selects all records on the current page
Search Lifecycle
Every search moves through a defined status flow from creation to completion or failure.
Pending
→
In Progress
→
Done
Pending
→
In Progress
→
Problem
- New searches remain in Pending for up to 5 minutes.
-
During Pending, the search can be canceled.
In that case, the status becomes Canceled, and tokens allocated for the search are refunded.
- After the waiting period, the search enters the queue and starts in In Progress.
- When completed successfully, the status becomes Done.
- If the search fails, the status becomes Problem.
New Search
The New Search page allows users to create and execute search queries within an investigation.
All searches are performed within the context of a specific investigation, which serves as a container for related queries and results.
Required Fields
To start a search, the following fields must be completed:
-
Investigation — defines the investigation in which the search will be executed and where results will be stored.
-
Search Queries — the value or phrase to be searched.
-
Search Scope — defines the data source where the search will be performed.
Search Query
Falcon supports multiple query types depending on the required search logic.
Each type defines how the system processes and matches the provided query.
| Query Type |
Description |
| Single |
The primary query type used for searching a single value or phrase.
Available across all Search Scope types.
The matching mode (exact or partial) is controlled by the Search Accuracy setting.
|
| OR |
Max three phrases combined using the OR operator.
Returns results where each result row contains at least one of the specified phrases.
Available only for Search Scope: Databases and requires Search Accuracy: ON.
|
| AND |
Two or three phrases combined using the AND operator with a defined distance ( from 1 to 300 characters).
All specified phrases must appear in each result row within the defined character distance.
The distance parameter sets the maximum allowed number of characters between phrases and applies to all specified phrases.
Example: [apple] [tree] [green leaves] [75]
→ Returns results where all phrases appear within 1–75 characters of each other, in any order like as: "The apple tree in the garden has bright green leaves during spring.".
Available only for Search Scope: Databases and requires Search Accuracy: ON.
|
Search Scope
| Search Scope |
Description * |
| Databases |
Searches across database leak data.
Standard search supports all query variations, including usernames and free-form queries.
Usernames: @username, username These are different queries with different results.
Quick search is supported for the following data types:
- Phone numbers:
+972553456787 or 972553456787
0553456787
These are different queries with different results.
- Emails:
[email protected]
- Domain names:
Example.com
- Credit cards:
4567675412344567
- BTC addresses:
bc1qt3tyrjkzke5q5glzsvfufpslj5ak76ump3kck6
- IP addresses:
1.1.1.1
|
| Logs |
Searches across leaked system and personal device snapshots.
Capabilities:
- Standard search supports all query variations
- Average execution time: ~10 hours
|
| Documents |
Searches across OSINT-collected documents and files.
Supported query formats:
- Space-separated words
- Date formats:
DD.MM.YYYY, MM/DD/YYYY
- Alphanumeric values (e.g.
AB123CD)
- Numeric values (up to 9 digits)
Advanced query types (OR / AND) are not supported.
|
Wildcard Search
Wildcard search allows partial matching using the * symbol.
* matches any single character or digit
5345**67*87 — matches variations of numeric values (e.g. phone numbers)
S**[email protected] — matches variations of the email username
Wildcard Behavior
- In phone numbers,
* replaces digits only
- In email addresses,
* works only in the part before @
Note: Wildcard search works only with the Single query type
and is supported only for Search Scope: Databases, Logs.
Additional Settings
Search Accuracy
Search Accuracy controls how precisely Falcon matches the provided query.
-
ON — Exact Match
Returns only exact matches of the specified query, without additional characters before or after it.
The match must be bounded by delimiters such as:
[ ], space, tab, or punctuation characters (e.g. ! " # $ % & ( ) , / : ; < = > ? \ ^ { | } ~ +).
Examples:
-
OFF — Partial Match
Returns results where the query appears as part of a larger string.
Examples:
-
[email protected] → may return:
-
3331234567 → may return:
+393331234567
abc3331234567xyz
8q037569ey580008877676755433333123456713489774hjfjjfj
3331234567
Note: When Search Accuracy is enabled, the system performs exact matching of the specified phrase.
When disabled, partial matches are included as well.
Schedule
The Schedule setting defines when the search will be executed.
| Option |
Behavior |
| Now |
Runs immediately after submission. |
| Pick Date & Time |
Runs once at the selected date and time. |
| Daily |
Runs immediately, then every day at 00:00 UTC. |
| Weekly |
Runs immediately, then every Monday at 01:00 UTC. |
| Monthly |
Runs immediately, then on the 1st day of each month at 02:00 UTC. |
Important: Tokens are charged for each search execution.
The first charge occurs immediately after the search is created, and additional tokens are deducted according to the selected schedule.
Bulk Query Upload (.txt)
The Upload a ".txt" file button allows you to import multiple search queries at once instead of entering them manually.
- Supports up to 50 queries per file
- Each query is treated as a separate search request
Supported separators:
- New line (each query on a new line)
- Comma (
,)
- Semicolon (
;)
- Vertical bar (
|)
Behavior:
- After upload, queries are automatically added to the search form
Example:
john smith
jane doe
[email protected], +1 234 567 890
company name; username123
passport number | tax id
Search Results
The Search Results page displays the output of a completed search and provides tools for reviewing, filtering, analyzing, and exporting the data.
Each search run generates a result set that can be explored through multiple tabs.
Header Information
Provides key details about the executed search:
- Query — the searched value or phrase
- Search Scope — data source used (Databases, Logs, Documents)
- Search Accuracy — matching mode (Exact or Partial)
- Created At / Finish At — execution timestamps
- Investigation — investigation where the search was performed
Result Files
Each completed search execution is stored as a separate result file.
For scheduled searches, multiple result files may be generated over time.
Result Tabs
Preview
Displays up to 500 rows from the result file.
Used for quick inspection of raw data without loading the full dataset.
Export: CSV, XLSX, PDF.
A one-time share link can also be generated where permitted and remains valid for 24 hours.
Finds
Shows structured data extracted from the results (Phones, Emails, Domains, IPs, Card, BTC.)
with occurrence counts.
Credentials
Displays extracted credential data grouped by domain, including login-password pairs.
Shows up to 500 rows.
Export: CSV, TXT.
AI Summary
Runs AI analysis on the result file data to generate a structured, human-readable summary.
Cost: 1 token per analysis.
Operators BETA
| Role | Main Capabilities |
| License Owner | Full system access. Can manage license settings, clients, investigations, operators, and all searches within the license. |
| Curator | Includes Manager permissions and can create and edit operators. |
| Manager | Includes Investigator permissions and can create clients and investigations. |
| Investigator | Can create searches and view their own searches. |
Clients BETA
The Clients module allows users to create and manage client profiles that can be linked to investigations and searches.
Investigations list
An Investigation is a central workspace used to organize all operational activity related to a specific case.
It serves as a place to store case-related information and brings together all search queries performed within the investigation.
All searches in Falcon must be created within an investigation, making it the primary container for executing searches and managing results.
Purpose
- Store and organize case-related data (files, notes, tags)
- Group and manage all searches related to a specific investigation
- Provide a structured workspace for analysis and collaboration
Access Control
- License Owner can assign users to investigations and has access to all investigations within the license
- Curator can view all investigations and create new ones, but cannot assign operators to investigations
- Manager can see only investigations they created
- Investigator can see only investigations they are assigned
- If an Investigator is not assigned to any investigation, they cannot run searches
Find in Investigation BETA
This feature helps the user locate a query inside completed search results within a selected investigation.
Purpose
Use this function when you remember that a phrase appeared in one of the investigation results, but you do not know which search contains it.
How it works
- Select an investigation
- Enter a query phrase
- Run the search
- Open the matching completed search result from the returned list
Rules: both fields are required, the query is limited to 100 characters, the | symbol is not allowed. Search show in the Search List and does not comsume tokens.
AI DetectiveBETA
AI Detective is an automated investigation workflow that performs search and analysis based on a single query.
It simplifies the investigation process by automatically collecting and structuring relevant data.
How it works
- A single query is used as the starting point
- The system automatically launches searches across database sources
- Results are processed and structured into a table of frequent occurrences and a relationship graph, providing a clear view of key data and connections.
Capabilities
- Automated search execution
- Data aggregation from multiple search queries executed automatically.
- Structured presentation of findings
- Reduced need for manual analysis
Note: AI Detective is designed to accelerate analysis by reducing manual steps and organizing results automatically.
New AI Detective BETA
The New AI Detective page allows creating a smart investigation based on a single query.
The system automatically launches multiple related searches, aggregates the data, and structures the results for analysis.
Required fields
- Client — defines the entity for which the investigation is created
- Query — the main value used to generate automatic searches
- Title — name of the investigation
Optional fields
- Description — additional context for the investigation
- Assigned investigators — users who will have access to this investigation
- Tags — used for categorization and filtering
How it works
- Automatically generates and runs multiple related search queries
- Aggregates data from all executed searches
- Structures results into a table of frequent occurrences and a relationship graph
- Processing time may take up to 5 days depending on data volume
Access Control
- By default, the investigation is visible only to the creator
- Only License Owner can assign investigators or managers
- If no users are assigned, no one else will see the results
Note: To share AI Detective results with other users, they must be explicitly assigned to the investigation by the License Owner.
AI Detective Details BETA
The AI Detective Details page provides full information about a specific smart investigation,
including its configuration, metadata, and execution status.
General Information
- ID — unique identifier of the AI Detective investigation
- Creator — user who created the investigation
- Client — associated client
- Title — investigation name
- Query — main query used to generate automatic searches
- Description — optional investigation details
Execution Details
- Created at — date when the investigation was created
- Deadline — expected completion date
- Finish at — actual completion date (if finished)
- Status — current state of processing
Access & Collaboration
- Investigators — users assigned to this investigation
- Only assigned users can view and work with this investigation
Available Actions
- View Result — opens the AI Detective results page
- Download Archive — downloads all related data as an archive
- Edit — available while the investigation status is In Progress. Allows updating Description, Deadline, and Assigned Investigators
- Back — returns to the previous page
Note: Access to this investigation depends on assignment.
Only users added by the License Owner can view the details and results.
AI Detective Results BETA
The AI Detective Results page displays processed data generated by the smart investigation.
It provides a structured overview of key findings and visualizes relationships between entities discovered during automated searches.
Header Information
- Query — the original query used to generate the investigation
- Created At — date and time when the investigation started
- Finish Time — date and time when processing was completed
- Investigation — related investigation name
Top Finds
Displays the most frequently identified data points extracted from all processed search results.
- Emails — most common email addresses
- Phone numbers — frequently occurring phone numbers
- Domains — related domains identified in the data
- Credit cards — detected card numbers
- BTC wallets — identified Bitcoin wallet addresses
Search Tree
A visual relationship graph that shows connections between entities such as emails, phone numbers, and other extracted data.
- Displays links between related data points
- Helps identify patterns and hidden relationships
- Built automatically based on aggregated search results
Graph Controls
- Color by State — colors nodes based on their relevance or confidence level
- Filters — toggle visibility of nodes:
- Initial - the starting node based on the original query.
- Strong — highly reliable connections found directly in the data.
- Potential — possible connections identified through indirect matches or weaker signals.
- Frequent — data points that appear most often across multiple search results.
- Color by Category — colors nodes based on data type (email, domain, etc.)
Note: The results are generated by processing and aggregating multiple automatically executed search queries.
The graph highlights relationships between entities to support faster analysis and investigation.
FAQ
Why is my search still in Pending?
New searches stay in Pending for up to 5 minutes before entering the processing queue. During this period, the request can still be canceled.
Why cannot I archive some searches?
Archiving is available only for searches that have already finished successfully with the Done status.
Why can’t I use OR and AND?
OR and AND query types work only when Search Accuracy is enabled (ON).
Why do I get more results with Accuracy OFF?
With partial match enabled, Falcon can find the query inside longer strings and mixed alphanumeric values.