Describe the purpose
Open Cases (/cases) and create a case. Provide a clear title, purpose and basis. Record the incident date and time zone: an address's current holder can differ from its holder at the incident time.
Add identifiers and files
Add relevant IPs, domains, URLs and other objects. Upload documents and correspondence related to the purpose. Wait for processing to finish: originals and extracted fragments are different views. Parser errors or unsupported formats need attention; the file cannot be treated as successfully read.
Review results
Choose sources suitable for the identifier and run checks. A completed search consumes a platform credit. Results show source availability, errors and skipped checks. Compare original findings, retrieval dates and incident-time information. No finding or a zero risk score does not establish safety.