Pivot map
Pivot from here
Outputs from Keybase can become inputs for the next tool. These are the most relevant follow-on pivots in the library.
Lookup email addresses and mailing addresses with reverse email search to identify people and organizations in OSINT investigations.
Addresses.com provides US residential address lookups, reverse phone searches, and people finder tools for locating individuals.
Ancestry search provides access to billions of historical records including census data, vital records, immigration documents, and family trees.
Canada411 is Canada's people directory for finding individuals by name, providing addresses and phone numbers for OSINT investigations.
AccountKiller provides direct deletion links and step-by-step instructions for removing accounts on hundreds of websites and social platforms.
Lookup email addresses and mailing addresses with reverse email search to identify people and organizations in OSINT investigations.
Addresses.com provides US residential address lookups, reverse phone searches, and people finder tools for locating individuals.
Algo VPN automates deployment of a personal WireGuard or IKEv2 VPN server in the cloud for private, secure OPSEC browsing.
Investigator Use
Keybase is a cryptographic identity and secure communication platform that links cryptographic keys to verifiable online identities across social media platforms. Users prove they control specific online accounts (Twitter, GitHub, Reddit, websites) by publishing signed proofs, creating a verified cross-platform identity network.
For OSINT investigators, Keybase's identity verification system is valuable for confirming that accounts across different platforms belong to the same person and for verifying the authenticity of public-key holders. When a subject claims to be the same person on multiple platforms, Keybase proofs provide cryptographic evidence of that cross-platform identity claim.
The public key infrastructure on Keybase allows investigators to associate PGP keys found during investigation with verified online identities. If a PGP key retrieved from a dark web forum or encrypted communication matches a Keybase profile, that profile's linked accounts provide additional intelligence about the key's owner.
Cross-platform identity verification through Keybase proofs is particularly useful for investigating pseudonymous individuals who have verified their cross-platform identity for reputation reasons — a common practice in the security research community, cryptocurrency space, and open-source software development. These voluntary verifications create investigative links between pseudonymous online personas and verifiable platform accounts.
Keybase team features allow investigation of organizational communication — teams on Keybase may reveal membership connections between individuals that are not evident from their individual profiles.
For encrypted evidence handling, understanding Keybase's cryptographic architecture helps investigators assess the reliability of identity claims based on cryptographic verification versus self-reported association.
Keybase profiles are publicly accessible without account registration. The public API allows programmatic queries for user data and key lookups.
Document any Keybase profiles queried, linked platform verifications found, public keys retrieved, and query timestamps for investigation records.
Before You Pivot
Capture the target, search terms, and why this source is relevant before you leave the page.
Archive volatile pages, save screenshots, and keep timestamps for anything that may change.
Treat one tool as a lead source. Confirm important findings with independent sources.
Related tools
AccountKiller provides direct deletion links and step-by-step instructions for removing accounts on hundreds of websites and social platforms.
Algo VPN automates deployment of a personal WireGuard or IKEv2 VPN server in the cloud for private, secure OPSEC browsing.
Keep all your devices protected with Blokada content filtering and encryption.
Canarytokens creates tracking traps that alert investigators when accessed, revealing attacker IP, time, and origin when planted.
crt.sh searches certificate transparency logs to uncover domains, subdomains, and infrastructure from TLS certificate data.
EFF Cover Your Tracks reveals how ad trackers and fingerprinters see your browser to help investigators strengthen OPSEC and anonymity.