case Full case
/case [target] Run the full case pipeline inside the CTI workspace for the supplied target.
- [target]
- Public identifier to investigate within the approved boundary.
Outcome: Cited findings, subject graph, confidence and coverage notes, and saved Markdown plus DOCX reports when conversion tools are available.
/case example.com sweep Multi-vector sweep
/sweep [target] Collect broad public records and observations for any target type.
- [target]
- Identifier to collect leads for before choosing pivots.
Outcome: Raw leads with collection method, source, confidence, and collection gaps recorded.
/sweep @username query Operator queries
/query [subject] Generate advanced search-operator queries for public-source collection.
- [subject]
- Domain, name, handle, organization, or other subject to query.
Outcome: A query set ready for acquire-stage collection, with uncertainty and source limits preserved.
/query example.com flow Guided flow
/flow [type] Start the first-time guided workflow for a target category.
- [type]
- Workflow such as person, domain, email, or quick.
Outcome: Step-by-step prompts that keep purpose, sources, confidence, and safety checks explicit.
/flow person progress Progress
/progress Show the current case phase and what remains pending.
Outcome: Current acquire, enrich, assess, or deliver status with pending work.
/progress validate Validate findings
/validate Audit case quality and evidence completeness; it is a workflow check, not proof that every claim is true.
Outcome: Quality score and issues to revisit before final delivery.
/validate coverage Coverage matrix
/coverage List sources, target areas, and blind spots that were or were not covered.
Outcome: Coverage matrix with collection gaps recorded as limitations.
/coverage brief Brief
/brief Produce a plain-language summary for non-technical readers.
Outcome: Concise cited brief, saved as Markdown and DOCX when conversion tools are available.
/brief report Report export
/report [brief|json|csv|legal|journalist|ioc] Export the case in the selected report format.
- [brief|json|csv|legal|journalist|ioc]
- Optional output style. Omit for the formal structured intelligence report.
Outcome: Selected report artifact with citations, confidence, contradictions, and unresolved gaps. Markdown and DOCX are saved for narrative reports; machine exports are separate.
/report legal render Render view
/render <entities|timeline|risk|network|threat-path|attack-surface> Render a portable ASCII relationship, timeline, risk, network, threat-path, or attack-surface view unless Mermaid is explicitly requested.
- <entities|timeline|risk|network|threat-path|attack-surface>
- Visualization to render from current case data.
Outcome: ASCII visualization suitable for Markdown and DOCX reports.
/render entities workspace Workspace
/workspace <save|open|list|diff> [name] Save, resume, list, or compare CTI case workspaces.
- <save|open|list|diff>
- Workspace operation to run.
- [name]
- Case workspace name or pair of names for diff.
Outcome: Case state is saved, resumed, listed, or compared without changing the evidence requirements.
/workspace save mycase