The Investigator's Stack: The Tools Every Team Should Know
- Blockchain Unmasked
- Jun 16
- 10 min read

At BlockchainUnmasked , we've spent years in this space — working alongside thousands of victims, law enforcement personnel, and Government agencies across the world to identify, trace, investigate, and freeze illicit funds. Over time investigators develop a feel for what is actually required to move a case forward and what just looks good in a screenshot.
So this week we did something simple. We sat our investigators down and asked them one question: what are the tools you can't get through a single day without? The ones that are genuinely load-bearing in a daily workflow, the ones that make an investigation complete. After a 40-minute discussion and a fair bit of friendly arguing, we pulled it together — and we're sharing that knowledge here, so you can run investigations more efficiently too.
One honest disclaimer before we start: there is nothing binary about any of this. A lot of it is conditional — it depends on the kind of network you're looking at, the volume in play, the number of nodes, and the nature of the case itself. There's no single "right" stack and "wrong" stack. Many of these tools overlap heavily, especially across the OSINT and tracing space, and the truth is that some people simply work better with one set than another. So treat this as a menu, not a mandate.
A quick note on access, because it matters throughout: some of what follows is open to any investigator, while certain steps and platforms are restricted to verified law enforcement (and in some cases, verified exchanges). We've flagged the law-enforcement-gated pieces as we go, since knowing who can pull which lever is half the battle in a time-sensitive case.
Every investigation, at its core, breaks down into three pieces:
Investigation & Tracing
Identification & OSINT
Freezing, Blacklisting & Recovery
Let's go through each.
Piece 1 — Investigation & Tracing
We all know the heavyweights: TRM Labs, Chainalysis, and likely Elliptic too. They're the default for good reason. The more interesting question is: who's the next best tracer out there, and who does our team actually prefer to graph with?
If you want to try proprietary platforms, Global Ledger and CipherOwl both deserve a serious look. Each comes with strong datasets, attribution, and functionality, while carving out its own niche. Global Ledger earns a lot of loyalty for its clean interface, node customization, and color-coding — readability matters far more than people admit when you've been staring at a graph for hours with dozens of nodes. CipherOwl stands out for letting you add counterparties directly onto the graph, which keeps you in flow rather than bouncing between tabs or manually pasting transactions rather than bouncing between tabs or manually pasting transactions — paste a node and it auto-connects to the others already on the canvas.
Worth adding to that tier is MistTrack by the SlowMist team. It carries one of the larger AML label datasets in the industry, covers a wide spread of chains, and — handy for later — includes a stablecoin blacklist lookup.
On the freemium side, if you're not working with a large budget, you can close your eyes and reach for Breadcrumbs or MetaSleuth by BlockSec . Both give you a capable graph and enough functionality to actually work the graph rather than just look at it. MistTrack also offers a free Light tier. And don't sleep on Arkham and Bubblemaps as a free attribution and clustering layer — Arkham for entity-labeled wallet intelligence, Bubblemaps for quickly seeing how a cluster of wallets relates visually. Finally, never forget the base layer that's always free: plain blockchain explorers such as Etherscan , OKLink , and mempool.space are still where half the real work happens.
Two larger institutional names that don't get mentioned enough are Crystal Intelligence and Merkle Science, both solid for cross-chain coverage and behavioral typologies if your budget reaches that far.
Bridges and cross-chain swaps
Tracing across bridges and cross-chain swaps is simply normal now. Honestly, we don't consider 80–90% of bridges to be obfuscation at all — they're everyday infrastructure, and most maintain their own dedicated explorers (Wormholescan, LayerZeroScan, the deBridge explorer, THORChain / Runescan, Mayan, and so on). You can just seacrh the names on your browser and find.
When you want a single view across many bridges at once, Range's Cross-Chain Explorer and free tools like Bridge Explorer (unbridge.xyz) are excellent for stitching a source-chain transaction to its destination leg.
Here's the piece that's becoming a genuine pain: the rising utilization of automated swaps and instant-exchange services such as FixedFloat, ChangeNOW, Changelly and SimpleSwap . They've quietly become an obfuscation layer of choice, and increasingly you'll find a human intermediary — an OTC broker/nested service — sitting between the illicit wallet and the off-ramp, which changes how you approach the case.
But it's worth saying plainly, though: several of the names above are highly cooperative with fellow investigation firms and with law enforcement.
So when it comes to actually working these, our team sometimes tries to leans on internal scripts and trusted private channels built specifically to gather intel. In a great many cases you can get surprisingly far with simple temporal and amount analysis — matching the in-leg and out-leg of a swap by timing and value, which Arkham's filtering makes quick. And for investigators and LE specifically, you can almost always reach out to the platform directly; many of these services cooperate, and there are designated private groups built for exactly this kind of outreach.
Piece 2 — Identification & OSINT
Here's the truth that humbles every investigator: tracing is only half the job. Identifying the entity — connecting an on-chain address to a physical entity, and that entity to a real person — is the hardest and most important part. You're bridging Web2 and Web3, and that's where cases are won or lost.
Pulling KYC details from exchanges is the gold standard, right up until you're dealing with a sophisticated actor who uses mixers, nested services, and privacy coins. It also depends on active participation from law enforcement, since the records sit behind legal process — and that can be slow in time-sensitive matters. This route is law-enforcement-gated. So when KYC isn't an option, how do you pivot from Web3 back to Web2?
In a huge share of fraud and scam cases — pig butchering especially — there's some thread of Web2 communication or a website/domain involved. The moment you have a domain, an email, or a mobile number, you have a starting point. So what do you do with it?
Infrastructure and domain intelligence
Run domains and websites through tools like VirusTotal, Silent Push, Shodan, Censys, and urlscan.io to pull IP, registrant, passive DNS, SSL certificate details, and other key signals. WHOIS lookups — and historical or reverse WHOIS via the likes of DomainTools or WhoisXML — help you understand the registrant and registrar. When Shodan and Censys come up short, alternative scan engines such as Netlas.io, FOFA, and ZoomEye are worth a second pass, and crt.sh is the fastest way into certificate transparency logs.
But here's the reality in 2026: a lot of domains are siloed, redacted, or sitting behind a CDN. In those cases you have to go down to the infrastructure level rather than trusting whatever a single tool returns. This is where a platform like Validin has become a genuine favorite — it lets you pivot on favicon hashes, CSS/HTML class hashes, TLS and JARM fingerprints, HTTP banners, and passive DNS history to cluster domains that look unrelated on the surface. Group multiple domains under your scope using shared certificate hashes, Google Analytics and tracking IDs (tools like BuiltWith and Wappalyzer surface the tech stack and analytics codes operators forget to scrub), and shared hosting infrastructure. One reused favicon across forty phishing pages is exactly the kind of lazy fingerprint that cracks a whole network open.
When the trail points toward a person, lean into email, username, and phone pivots — Epieos, OSINT Industries, Holehe, and similar — to move from an operational artifact toward an actual identity. And because sites are taken down mid-investigation, capture history with the Wayback Machine and archive.today before it disappears.
Reported-data and scam databases
Cross-reference everything against the open databases:
Chainabuse — reported crypto scam and fraud data
GASO (Global Anti-Scam Organization) — reported scam domains and infrastructure
Scam Sniffer and PhishDestroy — phishing and wallet-drainer intelligence
The wider phishing feeds — CryptoScamDB, ScamAdviser, URLhaus, PhishTank, and OpenPhish
Document everything
This one is less a tool than a discipline: the detail you think is irrelevant may be the one small torch you have in a dark forest later. Document everything. Obsidian and Notion keep you structured so you never lose context; Hunchly automatically captures and timestamps your web evidence as you browse (a lifesaver when a page changes or vanishes); and Maltego ties it all together as visual link analysis when a case grows too tangled for a spreadsheet. For LE teams, classic link-analysis platforms still earn their place here as well.
Labels and attribution
For labelling and attribution, Chainalysis and TRM are again the strongest. But from our team's own experience, a real shout-out goes to Nominis for being genuinely proactive in tagging and labelling entities — it's a rewarding dataset to work with. Their Shadow Intelligence feature, which connects Web3 activity back to Web2 footprints, together with their depth on terrorism-related data, makes them one of the more valuable sources available right now. Arkham, MistTrack, Nansen, and even Etherscan's own labels and comments round out the free-to-cheap attribution layer.
Piece 3 — Freezing, Blacklisting & Recovery
This is the hard one, but it's doable. With the right approach, the right connections, and a measure of proactiveness, freezing and recovery become possible. Just be clear on the split. From an investigator's workflow, you're realistically driving the reporting, blacklisting, and freezing half — and even that runs in partnership with law enforcement. The recovery itself sits with law enforcement and specialist firms such as Asset Reality and Digital Mint.
What investigators and LE can do in cases of potential freeze of funds, is give protocols and exchanges a heads-up about a threat actor's wallet based on the historical transactional pattern of that actor, or flag a live funds movement as it happens — reporting and blacklisting the illicit wallets across the right platforms and designated private groups, so that institutions can freeze funds when a reliable partner flags them.
A few channels have genuinely changed this game and belong in any crypto-crime toolkit:
Stablecoin issuer freezes. Tether.io and Circle can freeze USDT and USDC at the token level. Knowing how to route a request to the issuer — directly or through the right intermediary — is now a core skill.
T3 Financial Crime Unit (T3 FCU). The joint Tether / TRON / TRM Labs initiative has frozen hundreds of millions in illicit USDT on TRON, executing freezes within 24 hours of a request and working directly with law enforcement worldwide. Its T3+ collaborator programme brings exchanges into real-time coordination. If your case touches USDT-on-TRON, this is the channel to know.
TRM Beacon Network. A real-time communication network for collaborating to freeze stolen funds while an incident is still live. Membership is free for verified exchanges and law enforcement — speed is everything in a freeze, and this is built for it.
Exchange law-enforcement portals. Most major exchanges now run dedicated LE request channels; learn the front door for each. MistTrack's stablecoin blacklist lookup is a quick, open way to check whether an address has already been frozen or blacklisted before you spend effort chasing it.
Note: Freezes are actioned at the request of law enforcement. Some institutions may still provide a temporary restraining order on funds for one or two weeks, but this still requires active law-enforcement involvement.
Then, less for investigators and more for LE: if you work in crypto crime, platforms like Deconflict and Kodex are must-haves, and both are restricted to verified law enforcement. Deconflict tells you whether another agency is already working the wallet or case you're on — saving duplicated effort and avoiding stepping on a live operation — while Kodex lets agencies reach exchanges and institutions to make data requests in a timely, secure, and auditable way.
Final thoughts
So that's a snapshot of the tools our team uses in their regular workflows as well as look up for during certain cases. Remember what we said at the top: none of this is "use this, not that." Many of these tools overlap — the OSINT and tracing stacks especially blur into one another — and at the end of the day it comes down to what you find most natural to work with.
The best investigators we know aren't the ones holding the most expensive license or certifications. They're the ones who've built a stack that fits the way their mind works, and who document obsessively enough that no small torch ever goes out.
Did we miss something? Drop it in the comments — we'd genuinely like to know what's in your daily toolkit.
Tool directory
Every tool referenced above is mentioned below.
Tracing & analytics
TRM Labs — https://www.trmlabs.com
Chainalysis — https://www.chainalysis.com
Elliptic — https://www.elliptic.co
Global Ledger — https://globalledger.io
CipherOwl — https://www.cipherowl.ai
MistTrack (SlowMist) — https://misttrack.io
Breadcrumbs — https://www.breadcrumbs.app
MetaSleuth (BlockSec) — https://metasleuth.io
Arkham Intelligence — https://www.arkm.com
Bubblemaps — https://bubblemaps.io
Crystal Intelligence — https://crystalintelligence.com
Merkle Science — https://www.merklescience.com
Nansen — https://www.nansen.ai
Explorers (base layer)
Etherscan — https://etherscan.io
OKLink — https://www.oklink.com
Bridges & cross-chain
Range Cross-Chain Explorer — https://www.range.org
Bridge Explorer (unbridge) — https://unbridge.xyz
Wormholescan — https://wormholescan.io
LayerZeroScan — https://layerzeroscan.com
deBridge Explorer — https://explorer.debridge.finance
THORChain Explorer / Runescan — https://thorchain.net · https://runescan.io
Mayan Explorer — https://explorer.mayan.finance
Allbridge — https://allbridge.io
Instant swaps / exchanges
FixedFloat — https://fixedfloat.com
ChangeNOW — https://changenow.io
Changelly — https://changelly.com
SimpleSwap — https://simpleswap.io
Infrastructure & domain OSINT
VirusTotal — https://www.virustotal.com
Silent Push — https://www.silentpush.com
Shodan — https://www.shodan.io
Censys — https://censys.com
URLScan — https://urlscan.io
DomainTools — https://www.domaintools.com
WhoisXML API — https://www.whoisxmlapi.com
Netlas — https://netlas.io
FOFA — https://fofa.info
ZoomEye — https://www.zoomeye.ai
crt.sh (certificate transparency) — https://crt.sh
Validin — https://www.validin.com
BuiltWith — https://builtwith.com
Wappalyzer — https://www.wappalyzer.com
Person-level pivots
Epieos — https://epieos.com
OSINT Industries — https://www.osint.industries
Holehe — https://github.com/megadose/holehe
Site history / preservation
Wayback Machine — https://web.archive.org
Reported-data & scam databases
Chainabuse — https://www.chainabuse.com
GASO (Global Anti-Scam Org) — https://www.globalantiscam.org
Scam Sniffer — https://www.scamsniffer.io
PhishDestroy — https://phishdestroy.io
CryptoScamDB — https://cryptoscamdb.org
ScamAdviser — https://www.scamadviser.com
URLhaus — https://urlhaus.abuse.ch
PhishTank — https://phishtank.org
OpenPhish — https://openphish.com
Documentation & link analysis
Obsidian — https://obsidian.md
Notion — https://www.notion.com
Hunchly — https://www.hunch.ly
Maltego — https://www.maltego.com
Attribution & labels
Nominis — https://nominis.io
(See also Arkham, MistTrack, Nansen, Etherscan above)
Freezing, blacklisting & recovery
Asset Reality — https://www.assetreality.com
DigitalMint — https://digitalmint.io
Tether (USDT issuer freeze — LE request only) — https://tether.to
Circle (USDC issuer freeze — LE request only) — https://www.circle.com
T3 Financial Crime Unit (freezes at LE request) — https://t3fcu.org
TRM Beacon Network (verified LE & exchanges) — https://www.trmlabs.com
Deconflict (verified LE only) — https://deconflict.com
Kodex (verified LE / institutions) — https://www.kodexglobal.com


