> For the complete documentation index, see [llms.txt](https://tools.osintnewsletter.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://tools.osintnewsletter.com/osint-tools/sierra.md).

# SIERRA

| **SIERRA**       | **Quick Overview**                                                                                                                                               |
| ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| URL              | <https://phantomhelix.com/download>                                                                                                                              |
| What it does     | Keeps investigation notes, screenshots, entities, relationships, time metadata, and tool output together in a local graph workspace.                             |
| How to use it    | Download the desktop app, create a case graph, add entities/notes/images, connect relationships, attach time metadata, and run local/cloud invokers when needed. |
| Cost             | Free desktop app with optional paid cloud execution plans.                                                                                                       |
| Account required | No for local desktop use. Yes for optional Cloud Invoker features.                                                                                               |
| Cookies          | SIERRA desktop has no telemetry for local use.                                                                                                                   |
| Ownership        | Built and operated by Phantom Helix Intelligence, founded by Danny Jian in Melbourne, Australia.                                                                 |
| Use in Reporting | Useful from the early exploratory stage of an investigation through to review and report preparation.                                                            |

### What does SIERRA do?

SIERRA is a local-first desktop investigation workspace for live OSINT and cyber investigations. It helps investigators keep notes, evidence, entities, relationships, time metadata, screenshots, and tool output in one graph-based case board.

Instead of spreading investigation work across browser tabs, text notes, spreadsheets, folders, and separate graphing tools, SIERRA gives investigators one working case graph where context and chronology stay attached as the case evolves.

It also supports local invokers and optional cloud invokers, allowing repeatable tool output to be added back into the investigation workspace.

### How to Use:

**1. Download and install the SIERRA desktop app for Windows, macOS, or Linux and begin by creating a new investigation graph.**

<img src="/files/zd9fIlYpfAHBitVT7jBc" alt="" height="324" width="602">

**2. Add entities (by right-clicking in the graph space), notes, screenshots, or other evidence items as nodes, and connect related items with edges to preserve relationships and reasoning.**

<img src="/files/0ZMjs2E5l3SxJjtNUOEj" alt="" height="423" width="602">

**3. Add dates or time ranges (by hovering over each entity) to nodes and edges where chronology matters and yse local invokers to run repeatable tools near the investigation workspace You can view the Dev guide at** [**https://phantomhelix.com/doc/invoker** ](https://phantomhelix.com/doc/invoker)

<img src="/files/pBN4YYo7i2UGfNicbBfy" alt="" height="353" width="602">

**4. Use the graph as a working case board for review, follow-up and reporting and optionally connect to SIERRA Cloud to run cloud invokers when remote execution is needed.**

### Cost

* [ ] Free
* [x] Partially Free
* [ ] Paid

Free desktop app with optional paid cloud execution plans.

## Data Processing

### Account Required:

* [x] Yes
* [x] No

No for local desktop use. Yes for optional Cloud Invoker features.

### Cookies:&#x20;

The desktop app does not collect personal data, investigation data, usage analytics, telemetry, or usage statistics during local use. The PhantomHelix website does not use tracking or third-party advertising cookies. Browser storage is used for authentication flows. Website analytics are anonymous and processed in the EU. Cloud Invokers are opt-in and send only the inputs the user explicitly provides for that invocation. More on <https://phantomhelix.com/privacy>

### Use in Reporting

Typical investigation and reporting uses include:

* Quickly mapping early leads before the investigation direction is clear.
* Preserving a rough working network of people, accounts, domains, images, claims, sources, and follow-up questions.
* Keeping weak leads, assumptions, and unverified links visible without treating them as final conclusions.
* Expanding or pruning the investigation network as new information is found.
* Reviewing how a messy set of leads developed into stronger findings.
* Preparing handover notes for another analyst or reviewer.
* Turning the working graph into a clearer structure before writing the final report.
* Identifying which findings are supported, which remain uncertain, and which require further verification.

**Example workflow:**

An analyst investigating an online persona, scam cluster, suspicious domain, image lead, or incident-related trail can use SIERRA to quickly build a rough investigation network as leads appear. As the case develops, the analyst can refine the graph, remove dead ends, mark uncertainties, and use the remaining structure to prepare a report, handover, or follow-up plan.

No formal public case study has been published yet.

| **Capabilities**                                                                            | **Limitations**                                                                                       |
| ------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- |
| Local-first desktop investigation workspace.                                                | Not a data provider by itself.                                                                        |
| Graph-based case board for entities, evidence, notes, files, and screenshots.               | Does not replace source verification/analyst judgement.                                               |
| Relationship mapping between investigation items.                                           | Cloud invokers require explicit user action & may involve third-party services.                       |
| Date and time-range metadata on nodes and edges.                                            | Investigators remain responsible for legal and ethical use of tools, scripts, APIs, and data sources. |
| Local invokers for repeatable tool workflows. Optional cloud invokers for remote execution. | Local-first workflows require users to manage their own case files and operational security.          |
| <p><br></p>                                                                                 | Some advanced workflows may require users to configure local invokers/external tools.                 |

### Summary

SIERRA is best used as a local-first investigation workspace rather than a single-purpose lookup tool. Its main strength is keeping evidence, entities, notes, relationships, timelines, and tool output together in one working case graph.

### Ownership

SIERRA is owned and operated by Phantom Helix Intelligence, an independent OSINT software company founded by [Danny Jian](https://www.linkedin.com/in/401unauthorized/) in Melbourne, Australia.

Danny is a software engineer with a background in cybersecurity, OSINT, and investigation tooling. SIERRA has been developed as a solo-built project over the past three years, with more than 1,100 hours invested in building a local-first workspace for organizing evidence, entities, relationships, timelines, and repeatable tool workflows.

The tool is independently developed and maintained by Phantom Helix Intelligence.

### Ethical Considerations

* Use only within applicable laws and platform terms.
* Do not use for harassment, stalking, doxing, unauthorized access, or unlawful surveillance.
* Avoid collecting or sharing unnecessary personal data.
* Treat screenshots and identity-related findings as sensitive investigation material.
* Verify findings through multiple sources before drawing conclusions.
* Be careful when using cloud invokers, as selected inputs may be sent to remote or third-party services.
* Maintain appropriate consent, authority, and chain-of-custody practices where required.

### Related Tools:

* [Maltego](/osint-tools/maltego.md)
* IBM i2 Analyst's Notebook
* Obsidian
* SpiderFoot

#### Sources

<https://phantomhelix.com/download>&#x20;

<https://www.linkedin.com/in/401unauthorized/>&#x20;

*With thanks to Danny Jian for submitting this tool to the OSINT Tool Library.*

<br>
