Save media into global archive buckets reusable across cases, stand up bucket indexes (face/semantic/image/audio/ask) with the archive setup wizard, and run "does this match anything I've archived?" checks from inside any case.
Map a target's internet-exposed hosts and services with the shodan source, capture host reports, brief the exposure, and optionally stand up a monitor for newly exposed services.
Same recording, surfaced again — fingerprint audio into a local audio-fp index, then match a query clip against it (or clip-to-clip) with time-offset alignment, gate out sped-up re-uploads with a margin, and escalate a fingerprint miss to a CLAP semantic pass.
Be on the lookout — stand up a standing face/image watchlist: register a reference face, point a monitor at incoming feeds, auto-match every new item against the reference, and surface hits as a triage queue + alert so a match announces itself.
Same camera shot these — pull EXIF device fingerprints (make/model/lens/serial) off every case image and video, roll them up by camera with devices, and tell a strong serial link from a weak make+model+lens one, feeding the connections into the graph and the map.
Canvass the cameras near a location — resolve a street address (or accept a raw lat,lng) to a point, fan the OSM fixed-camera and live public-webcam sources around it at a radius, and plot every hit on one map to triage which cameras could overlook the scene. A leads generator, not a guaranteed complete camera…
String the board — build the case knowledge graph, read its hubs (shared media, targets, device fingerprints, places, typed entities), focus the neighborhood around a node, optionally run the opt-in LLM entity pass, and promote real connections into evidence via findings.
Hunt re-uploads and reskins of original video content across X / YouTube / TikTok — escalate from cheap metadata triage to frame/face/transcript matching and produce citable copycat findings.
Turn a case into a visual evidence board — materialize face and object crops, link the same person across clips, connect themes, and render the corkboard as a CSI brief plus a live monitor wall.
Google-dork a target domain for exposed documents, directory listings, login portals, and misconfigurations using the dork source (real Google operators), then capture the result pages and produce a cited exposure brief.
Make unreadable footage legible — denoise/upscale a marked moment, re-run OCR and detection on the enhanced output, and record what was recovered with honest provenance (interpolation is a lead, not proof).
Follow the money trail — register a blockchain address (chain) or an SEC EDGAR filer (edgar) as an OSINT source, scan the public transaction / filing history into cited scan records, connect the flow-of-funds and counterparties on the case graph, and promote a movement or filing to a finding on a line of…
Install and configure overcast for this harness: install the CLI, verify the system ffmpeg, and configure reusable provider profiles. Use once per machine/profile before driving the overcast skill.
Build a persistent local face database out of case media — the mugshot book — then run a suspect photo through it to identify who they are and where else they appear, with cited similarity scores.
Read foreign-language text off an image or video frame, translate it, and re-search in the SOURCE language — OCR a sign/screen/poster with see --ocr, translate it yourself, then scan the open web (and dork) with native-language queries, and cite what the text revealed.
Trace a suspicious or viral clip back to its earliest appearance and originator — reverse-image-search distinctive frames, sweep sources with no recency floor, and return a cited origin verdict.
Listen to the police scanner — register a dispatch (CAD / calls-for-service) feed on the Socrata SODA API, validate with one scan, then monitor it on an interval, plot the geolocated calls on a map, and triage call-types against the case's lines of investigation.
Work out where a photo or clip was taken — check embedded EXIF/GPS first, then pull signage, landmarks, and terrain clues, reverse-image-search the strongest ones, and corroborate to a location with cited evidence.