Top 10 Best Criminal Intelligence Software of 2026

GITNUXSOFTWARE ADVICE

Public Safety Crime

Top 10 Best Criminal Intelligence Software of 2026

Top 10 criminal intelligence software ranking for case, OSINT, and analytics, with tradeoffs for CaseBuilder, Palantir Foundry, ArcGIS Hub.

28 min readUpdated AI-verified · Expert reviewed
How we ranked these tools
01Feature Verification

Core product claims cross-referenced against official documentation, changelogs, and independent technical reviews.

02Multimedia Review Aggregation

Analyzed video reviews and hundreds of written evaluations to capture real-world user experiences with each tool.

03Synthetic User Modeling

AI persona simulations modeled how different user types would experience each tool across common use cases and workflows.

04Human Editorial Review

Final rankings reviewed and approved by our editorial team with authority to override AI-generated scores based on domain expertise.

Read our full methodology →

Score: Features 40% · Ease 30% · Value 30%

Gitnux may earn a commission through links on this page — this does not influence rankings. Editorial policy

Criminal intelligence software combines data ingestion, relationship modeling, and evidence-led case workflows so analysts can turn fragmented sources into auditable leads. This ranked list targets evidence-minded teams that must compare OSINT processing, integration depth, RBAC and audit logging, and investigation throughput across public platforms and enterprise deployments.

Social Links OSINT Platform is the best fit when your priority is quickly collecting and analyzing public social, web, and blockchain clues to kick off investigations, whereas Maltego suits analyst-led link mapping and repeatable transforms before broader case workflows are built.

Editor’s top 3 picks

Three quick recommendations before you dive into the full comparison below — each one leads on a different dimension.

Editor pick
1

Social Links OSINT Platform

Account-to-account pivoting that turns social identifiers into a navigable relationship map for analyst review.

Built for fits when teams need fast social identity linkage before building broader case artifacts..

2

Maltego

Editor pick

Custom transform development for recurring entity expansion steps inside the same graph workflow.

Built for fits when intelligence teams need analyst-led link mapping and repeatable transforms before deeper case workflows..

3

IBM i2 Analyst's Notebook

Editor pick

Analyst Notebook graph workspaces let investigators build and refine typed relationship networks with rapid visual iteration.

Built for fits when intelligence teams need repeatable association analysis and explainable link reasoning for investigations..

Comparison Table

1
vertical specialist
9.3/10
Overall
2
9.0/10
Overall
3
8.7/10
Overall
4
enterprise
8.3/10
Overall
5
8.1/10
Overall
6
vertical specialist
7.8/10
Overall
7
vertical specialist
7.4/10
Overall
8
enterprise
7.1/10
Overall
9
6.8/10
Overall
10
vertical specialist
6.5/10
Overall
#1

Social Links OSINT Platform

vertical specialist

Collects and analyzes public social, web, and blockchain data for investigations.

9.3/10
Overall
Features9.2/10
Ease of Use9.1/10
Value9.6/10
Standout feature

Account-to-account pivoting that turns social identifiers into a navigable relationship map for analyst review.

Social Links OSINT Platform is used for collection planning and rapid triage by starting from a person or handle and following outward to linked accounts and profiles. The product’s core utility centers on link analysis and association review, with outputs designed to preserve analyst context for downstream reporting. A key fit signal is that the system is built around social identity linkage rather than general case management or full intelligence production tooling. That focus keeps the workflow narrow and fast for social-based leads.

The main tradeoff is limited coverage for non-social evidence sources such as document repositories, phone records, or deep geospatial layers. Social Links OSINT Platform works best when the collection plan prioritizes social network analysis and identity resolution from handles and usernames. A typical use situation is pre-case enrichment for an intelligence-led policing workflow, where analysts need linkable leads before building a full investigative narrative.

Pros
  • +Identity-first workflow that pivots from handles into connected social presence
  • +Relationship mapping that preserves analyst context across account links
  • +Automation-friendly collection runs for repeatable lead enrichment
  • +Export-ready results that fit reporting and downstream case systems
Cons
  • Narrow source coverage compared with mixed-evidence intelligence platforms
  • Deeper governance controls like RBAC and audit trails may be limited
  • Less suitable for document-centric evidence management workflows
  • Graph outputs can require manual cleanup for ambiguous identity matches
Use scenarios
  • Intelligence analysts

    Handle-led enrichment for identity linkage

    More actionable lead set

  • Investigative case teams

    Pre-case social background collection

    Faster investigative triage

Show 1 more scenario
  • Compliance and risk teams

    Monitor connections across public personas

    Reduced blind spots

    Track social identity relationships tied to known entities for investigative follow-up.

Best for: Fits when teams need fast social identity linkage before building broader case artifacts.

#2

Maltego

SMB

Transforms and connects public data for link analysis, digital investigations, and OSINT.

9.0/10
Overall
Features9.0/10
Ease of Use9.2/10
Value8.7/10
Standout feature

Custom transform development for recurring entity expansion steps inside the same graph workflow.

Analysts use Maltego by starting from a seed entity and running transforms that fetch related entities, then refining the graph with filters and manual validation steps. The graph view stays central while relationships, confidence cues, and iteration history guide where work moves next. This fit tends to work best when teams prefer explainable visual reasoning and want to drive collection from analyst-led hypotheses.

A key tradeoff is that Maltego automation hinges on using the correct transforms and modeling assumptions, so inconsistent entity inputs can produce noisy graphs. Maltego is a strong match when investigators need fast exploratory mapping of unknown relationships before handing structured findings to case management or reporting workflows.

Pros
  • +Transform-driven graph building maps unknown relationships quickly
  • +Custom transforms let teams operationalize repeatable collection logic
  • +Visual graph output supports analyst-to-reviewer explainability
  • +Export options support downstream reporting and evidence packaging
Cons
  • Graph quality depends heavily on good seed entity hygiene
  • Automation and governance require strong analyst discipline
  • Some integrations rely on transform availability and maintenance
  • Large graphs can become slow without careful scoping
Use scenarios
  • Intelligence analysts and investigators

    Hypothesis-driven relationship mapping

    Faster identification of key connections

  • Threat hunting teams

    External and internal indicator enrichment

    More actionable indicator context

Show 2 more scenarios
  • Open-source research staff

    Reusable collection pipelines

    Less variation between analysts

    Standardize research steps as transforms so entity gathering follows consistent analyst logic each run.

  • Case support teams

    Analyst output packaging for review

    Cleaner handoff to case teams

    Export selected entities and relationships into downstream formats that support case documentation.

Best for: Fits when intelligence teams need analyst-led link mapping and repeatable transforms before deeper case workflows.

#3

IBM i2 Analyst's Notebook

enterprise

Visualizes relationships among people, locations, events, communications, and organizations.

8.7/10
Overall
Features8.9/10
Ease of Use8.6/10
Value8.4/10
Standout feature

Analyst Notebook graph workspaces let investigators build and refine typed relationship networks with rapid visual iteration.

IBM i2 Analyst's Notebook centers on interactive link analysis, with visual graph editing, relationship classification, and workspace-based investigation flows. The environment is designed to connect entities, documents, and events into analyzable structures that analysts can filter and reframe as hypotheses change. Integration options matter for multi-system intelligence contexts because i2 can be paired with other i2 components and external data feeds for repeatable refresh cycles.

A key tradeoff is that deep customization often requires administrative and analyst discipline to keep relationship definitions consistent across investigations. Analyst teams succeed when they use Analyst Notebook for recurring association analysis and then standardize how results move into case working records and reporting outputs.

Pros
  • +Interactive link graph editing with relationship typing and fast visual filtering
  • +Investigation workspaces support iterative analysis across changing hypotheses
  • +Strong fit for entity-centric casework that depends on association patterns
  • +Integration paths that connect i2 analysis outputs with broader intelligence tooling
Cons
  • Advanced configuration can require analyst training to avoid inconsistent link definitions
  • Large datasets can strain responsiveness without careful workspace and filter design
  • Some workflows depend on external systems for case management and records handling
  • Extensibility choices may require technical owners to maintain integrations
Use scenarios
  • Intelligence analysts

    Person and organization association investigations

    Faster hypothesis refinement

  • Investigations managers

    Standardized analyst workflows

    More consistent outputs

Show 1 more scenario
  • Case teams in agencies

    Evidence-driven link analysis

    Clearer investigative narratives

    Teams connect documents and events into a working graph that supports investigation narrative building.

Best for: Fits when intelligence teams need repeatable association analysis and explainable link reasoning for investigations.

#4

Palantir Gotham

enterprise

Combines operational data for intelligence analysis, investigations, and mission coordination.

8.3/10
Overall
Features7.9/10
Ease of Use8.6/10
Value8.6/10
Standout feature

Gotham’s entity model and relationship linking drive investigation workflows that stay consistent across multiple cases and data sources.

Palantir Gotham combines entity-centric analysis with operational case workflows and decision support for intelligence-led policing. The system’s integration model centers on governed data connectors, ontology-driven entities, and configurable workspaces that align investigative tasks to an intelligence requirements and collection plan.

Gotham also provides automation through rules, workflows, and an API surface for synchronizing investigations, evidence links, and analyst notes across systems. Governance is handled through access control, auditing, and configuration patterns that support repeatable case setup across units.

Pros
  • +Strong entity-first model with link and association analysis in investigative workspaces
  • +Detailed access control with audit trails for investigative and evidence-related actions
  • +Automation support via workflows and rules tied to case and evidence objects
  • +API and connector ecosystem for integrating records, case data, and external feeds
Cons
  • Requires significant configuration and ongoing governance to keep case setups consistent
  • Analyst productivity depends on workspace configuration rather than out-of-box templates
  • Geospatial workflows rely on integrations rather than a dedicated crime-mapping module
  • Complex deployments can slow time-to-first-case without a mature implementation plan

Best for: Fits when agencies need governed, entity-centric investigations with API-driven integration across case systems.

#5

Siren Investigate

enterprise

Searches and analyzes connected data for investigations, intelligence, and risk analysis.

8.1/10
Overall
Features7.9/10
Ease of Use8.3/10
Value8.0/10
Standout feature

Entity-centric investigations combine link paths and evidence timelines in a single explainable workspace.

Siren Investigate ingests operational investigation data and builds link and timeline views for analyst workflows. It focuses on explainable investigation surfaces like entity-centric records, configurable case dashboards, and evidence timelines that show why items are connected.

The workflow is designed around investigation tasks that generate outputs for review, rather than only search and export. Integration depends on Siren’s connectors and its API surface, which support data synchronization and automated case updates.

Pros
  • +Entity and link views support investigation reasoning from a single workspace
  • +Configurable case dashboards reduce time spent assembling analyst views
  • +Evidence timeline ordering supports review of events and supporting artifacts
  • +Automation via API supports repeatable case updates from external systems
Cons
  • Case configuration can require analyst time to reach stable, reusable layouts
  • Automation coverage depends on connector availability for each source system
  • Some governance controls feel less granular than dedicated case management suites
  • Large graph rendering can slow down when entity volume spikes

Best for: Fits when analysts need entity-linked investigations, evidence timelines, and repeatable API-driven case updates.

#6

Fivecast ONYX

vertical specialist

Monitors open-source information for threats, persons of interest, and criminal activity.

7.8/10
Overall
Features8.0/10
Ease of Use7.6/10
Value7.6/10
Standout feature

Audit-focused case activity tracking ties user actions to case records during investigation workflow runs.

Fivecast ONYX is a case and intelligence workflow system built around operational reporting, case management, and analytical investigation. It focuses on connecting incidents, people, places, and documents into reviewable case records with audit-oriented activity tracking.

ONYX supports automation through configurable workflows and integrates external data sources through its API so teams can move intelligence artifacts between systems. The result is a controls-first environment for intelligence-led policing workflows that need consistent case handling and traceable collaboration.

Pros
  • +Configurable investigation workflows reduce manual steps during case handling
  • +API-driven integration supports bringing records in and exporting artifacts out
  • +Case-centric audit trail helps track who changed what across a case lifecycle
  • +Investigation views help analysts work across incidents, entities, and documents
Cons
  • Meaningful governance depends on consistent configuration of roles and workflows
  • Advanced analytical depth depends more on integrations than native modeling breadth

Best for: Fits when intelligence teams need case-driven workflows with audit trail and API integration.

#7

Kaseware

vertical specialist

Manages investigative cases, intelligence records, workflows, evidence, and reporting.

7.4/10
Overall
Features7.4/10
Ease of Use7.4/10
Value7.4/10
Standout feature

CaseBuilder workflow templates that enforce consistent intelligence documentation across case lifecycles.

Kaseware is an on-premises criminal intelligence and case management system built around Kaseware CaseBuilder workflows, with structured information entry and analyst-focused screens. It supports investigation work products such as cases, contacts, organizations, and documents, then ties them together with linkable records for analysis and reporting.

Kaseware’s administration layer focuses on controlled access to case objects, audit-oriented change history, and repeatable templates for consistent documentation. The tool’s distinct value is how its case-building workflow shapes data capture for intelligence-led policing tasks rather than leaving analysts to assemble everything ad hoc.

Pros
  • +Workflow-driven case building with reusable templates
  • +Link-based investigation model for connecting entities and records
  • +On-premises deployment supports controlled custody of data
  • +Change history and audit-friendly records for case documentation
Cons
  • Integration depth depends on add-ons or bespoke connector work
  • Complex intelligence workflows can require analyst training time
  • Schema flexibility can feel limited for atypical reporting needs
  • API surface coverage is narrower than general-purpose data platforms

Best for: Fits when intelligence analysts need structured case workflows and controlled access inside on-prem environments.

#8

DataWalk

enterprise

Connects investigative data across entities, events, documents, and geographic relationships.

7.1/10
Overall
Features7.1/10
Ease of Use7.2/10
Value7.0/10
Standout feature

End-to-end investigation workflow automation that turns imported evidence and links into case actions analysts can execute and explain.

DataWalk is used for intelligence-led investigations that combine graph-based link analysis with automated workflows for case development. Its core pattern is ingesting heterogeneous records, resolving entities, and producing explainable connection views that analysts can annotate and operationalize.

Administration centers on user roles, controlled access to case artifacts, and activity visibility across the investigation workspace. DataWalk also exposes integration paths through APIs and connectors so agencies can route new sources into the analytical environment and push outputs into downstream systems.

Pros
  • +Graph-driven link analysis supports analyst-friendly connection views
  • +Workflow automation reduces repetitive case assembly steps
  • +Entity resolution helps normalize identities across disparate records
  • +API surface supports integration with surrounding records and case systems
Cons
  • Best results require disciplined source normalization and data quality checks
  • Automation and governance require ongoing configuration by system owners

Best for: Fits when investigators need graph-centric case building with controlled access and workflow automation.

#9

ShadowDragon SocialNet

API-first

Maps online identities, relationships, locations, and activity across public data sources.

6.8/10
Overall
Features6.8/10
Ease of Use6.5/10
Value7.0/10
Standout feature

Relationship-centric investigation workspace that ties analytical network views directly to case context for analyst review.

ShadowDragon SocialNet ingests investigative data and builds social network analysis views for link-heavy casework. It supports entity-focused workflows that connect people, organizations, and events, then surfaces relationship patterns for analytical review.

The tool emphasizes case organization around analytical outputs and source-linked context to support an intelligence workbench. Automation and integration depend on how datasets are provided into the system and how teams standardize identifiers across feeds.

Pros
  • +Social network views make relationship density and clusters easy to spot
  • +Entity-centric workflows support repeatable investigations around the same subject
  • +Source-linked context helps preserve why a connection was recorded
  • +Case grouping keeps analysis artifacts tied to an investigative thread
Cons
  • Automation depth depends on integration approach and available connectors
  • Advanced governance controls like fine-grained RBAC are not clearly central to the workflow
  • Data quality hinges on identifier consistency across imported records
  • Large graph performance can become constrained when relationship counts scale

Best for: Fits when analysts need fast social link inspection inside structured case folders with consistent identifiers.

#10

Skopenow

vertical specialist

OSINT investigation platform for person-of-interest research and link analysis.

6.5/10
Overall
Features6.4/10
Ease of Use6.6/10
Value6.5/10
Standout feature

Configurable investigative boards for structuring case work around analyst-defined flows.

Skopenow targets criminal intelligence analysis workflows with a case-centric environment for collecting, organizing, and reviewing investigative information. It focuses on configurable investigative boards, structured notes, and link handling so analysts can move from source intake to working hypotheses without switching tools.

Teams can standardize how reports and case materials are assembled to keep work aligned across assignments. The product is a good fit when investigation speed depends on repeatable case organization rather than heavy data science tooling.

Pros
  • +Case-centric workspace reduces context switching during report drafting
  • +Configurable investigative boards support consistent investigative organization
  • +Link handling helps analysts track relationships across notes and files
  • +Structured notes support repeatable case materials and quicker reviews
Cons
  • Limited visible depth for advanced analytical engines like explainable models
  • Automation and API coverage is not strong enough for high-integration shops
  • Governance controls appear less detailed for multi-agency RBAC needs
  • Geospatial analysis features are not clearly positioned for full GIS workflows

Best for: Fits when analysts need repeatable case organization for investigations without deep analytics engineering.

Conclusion

After evaluating 10 public safety crime, Social Links OSINT Platform stands out as our overall top pick — it scored highest across our combined criteria of features, ease of use, and value, which is why it sits at #1 in the rankings above.

Our Top Pick
Social Links OSINT Platform

Use the comparison table and detailed reviews above to validate the fit against your own requirements before committing to a tool.

How to Choose the Right criminal intelligence software

Criminal intelligence software connects collection inputs to investigative workspaces so analysts can build associations, document reasoning, and keep case activity traceable. This guide covers the ten tools evaluated for intelligence-led policing workflows, including Social Links OSINT Platform, Maltego, IBM i2 Analyst's Notebook, Palantir Gotham, and ArcGIS Hub.

The coverage extends through Siren Investigate, Fivecast ONYX, Kaseware CaseBuilder, DataWalk, and ShadowDragon SocialNet, with Skopenow for teams that emphasize configurable investigative boards. The tool writeups focus on how integration depth, automation and API surface, and governance controls shape day-to-day investigation throughput and consistency.

Criminal intelligence software for intelligence-led policing workflows and governed case analysis

Criminal intelligence software supports the criminal intelligence cycle by bringing structured and unstructured inputs into link analysis and case management workflows. Tools like IBM i2 Analyst's Notebook emphasize analyst workspaces for typed relationship networks, with visual iteration and fast filtering to keep investigation reasoning explainable.

Platforms like Palantir Gotham build investigation workspaces around governed entity models and relationship linking so teams can keep case setups consistent across multiple data sources. The category also covers tools that prioritize analyst-led graph building and repeatable transformations, such as Maltego, alongside platforms that tie activity tracking to case records through workflow automation.

Evaluation criteria for criminal intelligence software

Criminal intelligence software must connect investigative inputs to usable analyst workspaces without obscuring how relationships or case actions were created. The strongest products combine focused investigation views with repeatable workflows for records, links, and evidence.

  • Social identity pivoting

    Social Links OSINT Platform pivots from account identifiers into connected social profiles and preserves analyst context between links. ShadowDragon SocialNet adds relationship-density views inside structured case folders.

  • Repeatable graph expansion

    Maltego uses custom transforms to repeat entity-expansion steps inside the same graph workflow. DataWalk extends graph work into automated case actions after evidence and links are imported.

  • Typed relationship workspaces

    IBM i2 Analyst's Notebook supports rapid visual editing of typed relationships, filtering, and changing investigative hypotheses. Siren Investigate combines link paths with evidence timelines in one workspace.

  • Governed entity and case models

    Palantir Gotham uses an entity model that keeps relationships consistent across cases and data sources, with detailed access controls for investigative actions. Fivecast ONYX ties user activity to case records through configurable workflows and API-driven transfers.

  • Case workflow templates

    Kaseware CaseBuilder uses reusable templates to enforce consistent documentation across case lifecycles and supports on-premises deployment. Skopenow uses configurable investigative boards to organize report drafting without requiring deep analytics engineering.

  • Integration and connector coverage

    Fivecast ONYX supports importing records and exporting artifacts through APIs, while Siren Investigate depends on connector availability for each source system. Kaseware integration depth can require add-ons or bespoke connector work.

Choose by investigation model, integration shape, and governance depth

The selection depends first on how analysts move from an initial identifier to a documented case. Social Links OSINT Platform and ShadowDragon SocialNet prioritize social relationship inspection, while IBM i2 Analyst's Notebook and Maltego prioritize analyst-directed graph construction.

  • Choose social pivoting or broad investigation workspaces

    Select Social Links OSINT Platform when account-to-account movement is the primary starting point for investigations. Select Palantir Gotham or Siren Investigate when investigators need entity-linked case views that combine several source types.

  • Choose analyst-built graphs or workflow-led cases

    Maltego and IBM i2 Analyst's Notebook suit teams that refine relationships directly in graph workspaces and control how hypotheses develop. Kaseware CaseBuilder and Fivecast ONYX suit teams that need predefined case stages, templates, and activity records.

  • Test the integration boundary before selecting a platform

    Fivecast ONYX supports API-based record import and artifact export, while Siren Investigate depends on connectors for individual source systems. Kaseware may require add-ons or custom connector work for systems outside its available integration path.

  • Match governance requirements to the product model

    Palantir Gotham provides detailed access controls and audit trails around investigative and evidence-related actions. ShadowDragon SocialNet and Social Links OSINT Platform place less visible emphasis on fine-grained administrative controls, so governance requirements need separate validation.

  • Decide between on-premises control and configurable cloud workflows

    Kaseware supports controlled access inside on-premises environments and uses workflow templates for case documentation. DataWalk and Skopenow focus on configurable investigation operations, but DataWalk requires stronger source normalization and Skopenow offers less visible depth in advanced analytical engines.

Teams that benefit from criminal intelligence software

Criminal intelligence software benefits teams that must connect identities, relationships, records, and analyst decisions across repeat investigations. Product fit changes according to the starting evidence, the required case structure, and the level of administrative control.

  • Open-source intelligence teams

    Social Links OSINT Platform supports fast movement from social identifiers into connected accounts. ShadowDragon SocialNet adds social network views and repeatable subject folders for relationship inspection.

  • Investigative analysis units

    IBM i2 Analyst's Notebook supports typed relationship editing and visual filtering as investigative hypotheses change. Maltego supports custom transforms for recurring entity-expansion tasks.

  • Agencies with governed multi-source investigations

    Palantir Gotham keeps entity links consistent across cases and data sources while recording access to investigative and evidence-related actions. Siren Investigate combines evidence timelines, link paths, and configurable case dashboards.

  • Case-management and intelligence operations teams

    Kaseware CaseBuilder supplies reusable documentation templates and controlled access for on-premises operations. Fivecast ONYX connects case workflows with imported records and exported investigation artifacts.

  • Teams needing graph-centric workflow automation

    DataWalk turns imported evidence and links into case actions that analysts can execute and explain. Skopenow provides configurable investigative boards for teams that need organized reporting without deep analytics engineering.

Common criminal intelligence software selection mistakes

Selection errors often occur when a graph interface is treated as proof of broad source coverage or when a case workspace is treated as a complete integration layer. The cards show meaningful differences between social collection, graph analysis, workflow automation, and administrative control.

  • Choosing a social-first tool for mixed-evidence investigations

    Social Links OSINT Platform and ShadowDragon SocialNet focus on social relationship inspection, while Palantir Gotham and Siren Investigate support broader entity-linked investigation workspaces.

  • Assuming graph automation works without clean seed data

    Maltego depends on accurate seed entities for reliable transform results, and DataWalk requires source normalization and data quality checks before automated case actions can remain useful.

  • Ignoring governance configuration during implementation planning

    Palantir Gotham provides detailed access controls and audit trails, but its case consistency still depends on configuration. Fivecast ONYX also requires consistent role and workflow settings for meaningful governance.

  • Treating API availability as complete integration coverage

    Fivecast ONYX supports record imports and artifact exports through APIs, but Siren Investigate depends on connectors for individual systems and Kaseware may require bespoke connector work.

  • Selecting a case board without checking analytical depth

    Skopenow organizes investigation work through configurable boards, but its visible coverage of advanced analytical engines is limited. IBM i2 Analyst's Notebook or Maltego provides deeper graph-oriented analysis for teams that need relationship reasoning.

How We Selected and Ranked These Tools

We evaluated criminal intelligence software across features, ease of use, and value. Features represented 40% of each ranking, while ease of use represented 30% and value represented 30%.

We compared graph behavior, case workflows, integration paths, automation, and governance controls across Social Links OSINT Platform, Maltego, IBM i2 Analyst's Notebook, Palantir Gotham, Siren Investigate, Fivecast ONYX, Kaseware CaseBuilder, DataWalk, ShadowDragon SocialNet, and Skopenow. Social Links OSINT Platform ranked first because its account-to-account pivoting, relationship mapping, high feature score, ease score, and value score gave analysts a focused path from social identifiers to connected identities.

Frequently Asked Questions About criminal intelligence software

How do API and automation differ between Palantir Gotham, Fivecast ONYX, and Siren Investigate?
Palantir Gotham provides an API surface designed to synchronize entity links, evidence associations, and analyst notes across connected case systems. Fivecast ONYX automates case-related actions through configurable workflows and routes imported intelligence artifacts using its API. Siren Investigate uses its API surface to keep entity timelines and investigation outputs updated when new records arrive.
Which tools support single sign-on and audit logging for investigator actions?
Fivecast ONYX is built around audit-oriented activity tracking that ties user actions to case records. Palantir Gotham emphasizes access control and auditing as part of governed operations across units. Kaseware includes audit-oriented change history and controlled access to case objects in its administration layer.
When is entity resolution and schema normalization a deciding factor in criminal intelligence analysis?
DataWalk resolves entities while ingesting heterogeneous records and then produces explainable connection views that analysts can operationalize. Maltego centers on entity graph expansion patterns where linkability depends on transform-driven normalization steps. ShadowDragon SocialNet relies on standardized identifiers across feeds to keep its social network analysis views consistent inside structured case folders.
What breaks if a team only needs link analysis but selects a tool optimized for case-building workflows?
Kaseware CaseBuilder workflow templates can shape data capture and documentation, but they add structure that link-heavy exploratory work may feel constrained by. DataWalk can drive investigation actions and case actions from imported evidence, but teams that only need rapid relationship mapping may spend time aligning to its operational workflow pattern. IBM i2 Analyst's Notebook supports configurable link types and visual iteration, but it may require additional integration work to fully operationalize case tasks compared with ONYX or Siren Investigate.
How do link explanation and evidence traceability differ across IBM i2 Analyst's Notebook, Siren Investigate, and Fivecast ONYX?
IBM i2 Analyst's Notebook focuses on explainable typed relationship networks inside Analyst Notebook graph workspaces. Siren Investigate pairs link paths with evidence timelines in an entity-linked workspace so analysts can review connection reasoning alongside time-ordered evidence. Fivecast ONYX ties activity tracking to case records so analysts can trace which workflow steps changed or validated investigation artifacts.
Which deployment model matters most for agencies that require on-premises administration and controlled access?
Kaseware is an on-premises criminal intelligence and case management system that provides structured entry screens and administration over case objects. DataWalk centers access control and activity visibility for the investigation workspace, and it supports integration paths for routing data into the environment. Palantir Gotham is governed around connector-based integration and access controls across connected systems, which can align with hybrid deployment patterns.
How should analysts migrate existing case notes, documents, and relationship links into a new system like Palantir Gotham or i2?
Palantir Gotham’s governed connectors and entity model are used to map existing records into consistent entities and relationship structures before building configured workspaces. IBM i2 Analyst's Notebook can ingest investigation working sets through i2 ecosystem integrations, then preserve typed link reasoning in its graph workspaces. Kaseware focuses on CaseBuilder template-driven capture, so migration usually targets converting legacy notes into structured fields and linkable case objects.
What integration gap appears when teams treat social OSINT linkage as equivalent to case intelligence link modeling?
Social Links OSINT Platform is designed to harvest and pivot social identifiers into a linkable investigative relationship map for analyst review. ShadowDragon SocialNet adds structured social network analysis views tied to case folders and consistent identifiers, so it supports network patterns inside case context. Palantir Gotham models entities and relationship linking across governed data connectors, so social pivots need mapping into its broader ontology-driven structure to support end-to-end case workflows.
How does extensibility work in Maltego compared with i2 tooling or configurable workflows in Fivecast ONYX?
Maltego supports extensibility through custom transforms that standardize repeatable collection and expansion steps inside the same graph workflow. IBM i2 Analyst's Notebook supports extensibility via i2 tools and integration options that fit intelligence-led policing workflows. Fivecast ONYX extends capability through configurable workflows that drive case activity tracking and automation around investigation reporting.

Tools reviewed

Primary sources checked during evaluation.

Referenced in the comparison table and product reviews above.

Logos provided by Logo.dev

Keep exploring

FOR SOFTWARE VENDORS

Not on this list? Let’s fix that.

Our best-of pages are how many teams discover and compare tools in this space. If you think your product belongs in this lineup, we’d like to hear from you—we’ll walk you through fit and what an editorial entry looks like.

Apply for a Listing

WHAT THIS INCLUDES

  • Where buyers compare

    Readers come to these pages to shortlist software—your product shows up in that moment, not in a random sidebar.

  • Editorial write-up

    We describe your product in our own words and check the facts before anything goes live.

  • On-page brand presence

    You appear in the roundup the same way as other tools we cover: name, positioning, and a clear next step for readers who want to learn more.

  • Kept up to date

    We refresh lists on a regular rhythm so the category page stays useful as products and pricing change.