🚀 Maximize your product's SEO. Submit to 240+ directories in 1-click with DirSubmit. Launch Now
flowsint logo

flowsint

Visual graph investigations for cybersecurity analysts.

2026-09-14

Product Introduction

  1. Definition: Flowsint is a graph-based intelligence and investigation platform (OSINT platform) built on a durable graph database core. It functions as a visual workflow automation and data enrichment engine specifically designed for connecting disparate data points.
  2. Core Value Proposition: It exists to solve the problem of tool fragility and data silos in open-source intelligence (OSINT) and cybersecurity investigations. Flowsint provides a stable, extensible graph foundation where investigations remain intact even as individual data sources, APIs, and enrichment tools (treated as plug-and-play extensions) evolve or are replaced.

Main Features

  1. Interactive Graph Exploration UI: A central, visual interface for exploring entities (like IP addresses, domains, persons, organizations) and their relationships. Users can interactively navigate, edit, and expand the graph, providing a clear spatial representation of complex connections that is superior to tabular data or isolated reports.
  2. Dynamic Schema & Flexible Entity Modeling: Unlike rigid databases, Flowsint uses dynamic schemas with strong type safety, allowing investigators to define custom entity types (e.g., "ThreatActor," "Campaign," "Vulnerability") and properties on the fly. This supports schema evolution, meaning data models can adapt over time without corrupting existing investigation data, which is critical for long-running cases.
  3. Pluggable Enricher System via Webhooks: The platform's extensibility is technicalized through a simple REST API and Python webhook system. Any external tool or service (e.g., virusTotal API, Shodan, custom Python script) can be integrated as an "enricher." These enrichers can be run manually on selected graph entities or chained into automated enrichment flows, centralizing functionality within the graph interface.
  4. Native n8n Workflow Automation Integration: Flowsint can act as a trigger or action node within the n8n workflow automation platform. This unlocks connectivity to over 500 external services (Slack, Google Sheets, Telegram, etc.), enabling sophisticated automated OSINT pipelines. For example, automatically enriching new entities, triggering alerts, or generating reports when the graph reaches a certain state.

Problems Solved

  1. Pain Point: The "toolchain treadmill" where investigators juggle numerous fragile, siloed scripts and SaaS tools. This leads to broken workflows when APIs change, tools are deprecated, or data cannot be easily correlated between systems, causing loss of investigative context and continuity.
  2. Target Audience: Primary users are Cybersecurity Threat Analysts, OSINT Researchers, and Digital Forensics Investigators. Secondary users include Investigative Journalists, Corporate Intelligence Analysts, and Fraud Investigators—any professional who needs to map and analyze complex relationships from diverse data sources.
  3. Use Cases: Threat Actor Attribution: Mapping infrastructure, aliases, and tactics of a cyber threat group. Data Breach Investigation: Connecting exposed credentials, IP addresses, and related domains to understand the scope of a breach. Due Diligence & Corporate Intelligence: Visualizing relationships between companies, executives, and financial holdings.

Unique Advantages

  1. Differentiation: Unlike all-in-one OSINT suites or isolated command-line tools, Flowsint decouples the durable investigation graph (the core asset) from the transient enrichment tools. This avoids vendor lock-in and provides agnosticism towards data sources, whereas competitors often bundle proprietary data with their platform.
  2. Key Innovation: The conceptual shift from a "tool-centric" to a "graph-centric" investigation model. The graph is the persistent, primary artifact. Tools are treated as disposable, replaceable components that feed into and query this central graph. This is enabled by its API-first, webhook-driven architecture and dynamic data modeling.

Frequently Asked Questions (FAQ)

  1. What is Flowsint used for? Flowsint is used for visual, graph-based open-source intelligence (OSINT) and cybersecurity investigations, enabling analysts to connect data from disparate sources, automate enrichment workflows, and uncover hidden relationships in complex datasets.
  2. How does Flowsint handle data integration and enrichment? Flowsint integrates data via a plug-and-play webhook system (REST/Python), allowing any external API or script to be connected as an enricher. It also offers deep integration with n8n for advanced, multi-service workflow automation, centralizing all enriched data within its persistent graph database.
  3. Is Flowsint suitable for collaborative investigations? Yes, the platform is built around a centralized graph database core, which acts as a single source of truth. This architecture is inherently suited for team collaboration, allowing multiple analysts to work on the same investigation graph, see real-time updates, and maintain a continuous, intact investigative record.
  4. Can I define my own data types and relationships in Flowsint? Absolutely. Flowsint's core feature is dynamic schema and flexible entity modeling, allowing users to create custom entity types (like "BitcoinWallet" or "PhoneNumber") with specific properties and define complex relationship types between them, adapting the platform to highly specialized investigation domains.
  5. What is the difference between Flowsint and traditional threat intelligence platforms (TIPs)? While both manage data, traditional TIPs often focus on ingestion and correlation of standardized threat feeds (like STIX/TAXII). Flowsint is more foundational and flexible, focusing on a visual, user-extensible graph for any investigation, with planned STIX support to complement, not replace, its core graph model.

Submit to 240+ Directories with 1-Click

Maximize your product's SEO and drive massive traffic by automatically submitting it to over 240 curated startup directories using DirSubmit.

Related Products

Subscribe to Our Newsletter

Get weekly curated tool recommendations and stay updated with the latest product news