Before an analyst registers a research persona on a criminal forum, what do you agree with counsel?
answer
- who carries the risk, and who signs
- written policy before anything is registered
- found credentials are still unauthorised access
- attribution-free egress, devices and funding
- build, buy, or decline entirely
basics
~20 sA written, counsel-approved collection policy: never authenticate to systems you do not own, never buy stolen data, never fund a sanctioned party, and use an invented identity on infrastructure and funding that do not trace back to the company.
solid answer
~50 sGet a written collection policy signed by counsel before anything is registered. The hard limits: no authenticating to systems you do not own, even with credentials found in a dump - that is unauthorised access however you obtained them; no purchase of stolen data, access or tooling; no payment that could reach a sanctioned party; and an agreed procedure for material that is illegal to possess when it arrives unbidden. The persona: an invented identity impersonating no real person, on infrastructure and funding that do not trace back - a corporate card defeats the whole exercise. No soliciting an offence, and a named owner for the terms-of-service risk. The analyst must not be personally linkable to the persona. Then ask the real question: with one analyst and no research infrastructure, buying this access from a vendor who already runs personas is usually the better call.
go deeper
Know that logging into anything you do not own, even with leaked credentials, is unauthorised access, and that creating a research persona is never an individual decision.
Explain the practical hygiene: an invented identity, separate infrastructure and funding, and the difference between observing a forum and interacting with the people on it.
Show how the collection stays defensible - what is recorded, what is refused, what happens when illegal material arrives, and how you keep the analyst unlinkable to the persona.
Own the whole call: the written policy, who signs it, whether the capability is funded at all, and the willingness to conclude that buying the access or declining it beats running a persona badly.
## Why this is a leadership decision, not an analyst's A research persona in a criminal forum is the one collection activity where the risk is not primarily to the investigation. It is legal risk to the company, personal risk to the analyst, and reputational risk if the arrangement is ever described in public or in a deposition. None of those are risks an analyst can accept on the organisation's behalf, which is why the conversation happens with in-house counsel first and produces a written document rather than a verbal blessing. ## The hard limits These are the lines that convert research into an offence, and they should be written as absolutes because judgement under pressure at 02:00 is not reliable. - **No authentication to systems you do not own.** Credentials found in a dump are still credentials; using them to log into a victim's mailbox, a panel, or an exposed service is unauthorised access under computer-misuse law in most jurisdictions, and the fact that the account was leaked publicly is not a defence. This is the single most common way well-meaning research becomes a crime. - **No purchase.** Buying stolen data, access, or tooling funds the offence and can constitute handling stolen property. The frequent justification - *we only bought it to confirm our own data was in it* - does not fix the transaction. - **No payment that could reach a sanctioned party.** Payments to criminal marketplaces carry sanctions and anti-money-laundering exposure, and the compliance consequences land on the company, not the analyst. - **A procedure for illegal material.** Criminal forums host content that is unlawful to possess. Agree in advance what an analyst does when it arrives: stop, do not download further, preserve the record of what happened, escalate to counsel. Deleting quietly is the wrong instinct - it destroys the record that shows what was collected and why. - **No solicitation or inducement.** Asking an actor to commit an offence, or steering one, is a different activity from observing, and it has consequences in any later proceeding. ## The persona itself - **The identity must be invented.** Impersonating a real, identifiable person creates a separate liability and can harm somebody who never consented. - **The infrastructure must not trace back.** Separate egress, separate devices, a separate tenant and mail domain. Registering a persona from corporate address space undoes the whole exercise, exactly as touching adversary infrastructure from the office network does. - **The funding must not trace back either.** A corporate credit card leaves a payment trail with the company's name on it, and creates the sanctions problem in the same stroke. If the only available funding is the company card, that is a finding, not a workaround. - **The analyst must not be linkable.** Retaliation against named researchers is real. Persona hygiene protects a person, not only an investigation, and there must be an agreed response if the link is made anyway. ## The things people forget **Terms of service.** Registering under a false identity breaches most platforms' terms; on some it has legal weight beyond contract. This is a business risk somebody accepts by name, not an inconvenience the analyst assumes away. **Law-enforcement collision.** Your persona may sit inside an active investigation. Agree who your contact is and what you report, so that your collection does not damage a case or make your analyst a witness by accident. **Records and retention.** If anything collected ever supports a claim, its provenance must survive scrutiny - what was collected, when, by which persona, and under what authorisation. Personal data collected about identifiable people also carries data-protection obligations that do not pause because the source is a criminal forum. ## The judgement call Having written all that down, the decision often reverses itself. A one-analyst team with no non-attributable egress, no separate tenant and no funding channel cannot run a persona safely, and running one badly is worse than not running one: it produces intelligence nobody can act on, exposes an employee, and creates a legal question you did not need to ask. The alternatives are usually stronger for the money. Vendors and sharing communities already run this collection under their own legal frameworks and sell or share the product. An information-sharing group gives peer reporting from organisations that look like yours. And in almost every one-analyst team, the marginal hour is worth more spent on the estate's own telemetry, where the same adversary leaves records you are unambiguously entitled to read. Say that out loud in the interview. The strongest answer here is not a list of tradecraft techniques; it is knowing what capability the activity presupposes, naming who has to sign, and being willing to conclude *not us, not yet*.
- Counsel refuses. What do you get instead?Vendor-provided access from providers who already run this collection under their own legal framework, peer reporting through a sharing community, and a hard reallocation of the analyst's time to the estate's own telemetry. That last one usually answers more of the actual intelligence requirements than a forum persona would.
- An analyst has already created a persona on their own initiative. What now?Stop further collection, do not delete anything, and disclose to counsel with a record of what was accessed, acquired and paid for. Deletion looks like concealment and destroys the evidence that the activity stayed within bounds. Then decide whether the persona is retired or brought under the written policy.
- Why is a corporate credit card specifically a problem?It ties the persona to the company by name through a traceable payment trail, so a single subscription burns the identity. It simultaneously creates sanctions and anti-money-laundering exposure for a payment into a criminal marketplace, and it leaves an accounting record that will be read later by people who were not in the room.
saying these in an interview costs you the question
- Says using credentials from a public dump is fine because they leaked
- Buys a data sample to confirm the company was breached
- Treats a VPN as the whole of persona tradecraft
- Funds the persona on a corporate card
- Lets the analyst accept the terms-of-service and legal risk personally
- Never considers buying the access from a vendor instead