Examine records or other types of data to investigate criminal activities
Most of the output can be produced by software today.
An agent can find, read and summarise the sources this work depends on, and it can cover far more of them than a person would ever open. What it does not do is decide which sources deserve trust, or what the findings mean for your situation.
| How automatable | Mostly automatable |
|---|---|
| Kind of work | Research and retrieval work |
| Jobs that do it | 5 occupations |
| Tool categories that apply | Web, data and docs, Generalist agents |
| O*NET activity | Getting Information (4.A.1.a.1) |
What this looks like on the job
Not our paraphrase. These are real task statements recorded against this activity, spread across the 5 occupations that perform it.
- Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis.
- Analyze log files or other digital information to identify the perpetrators of network intrusions.
- Examine records and governmental agency files to find identifying data about suspects.
- Predict future gang, organized crime, or terrorist activity, using analyses of intelligence data.
- Search computer databases, credit reports, public records, tax or legal filings, or other resources to locate persons or to compile information for investigations.
- Perform file signature analysis to verify files on storage media or discover potential hidden files.
- Analyze completed police reports to determine what additional information and investigative work is needed.
- Evaluate records of communications, such as telephone calls, to plot activity and determine the size and location of criminal groups and members.
- Obtain and analyze information on suspects, crimes, or disturbances to solve cases, to identify criminal activity, or to gather information for court cases.
- Perform forensic investigations of operating or file systems.
- Obtain and verify evidence by interviewing and observing suspects and witnesses or by analyzing records.
- Gather intelligence information by field observation, confidential information sources, or public records.
- Perform web service network traffic analysis or waveform analysis to detect anomalies, such as unusual events or trends.
- Examine records to locate links in chains of evidence or information.
- Gather, analyze, correlate, or evaluate information from a variety of resources, such as law enforcement databases.
- Validate known intelligence with data from other sources.
- Analyze intelligence data to identify patterns and trends in criminal activity.
- Identify gaps in information.
What we would actually use
One recommendation rather than a shortlist, because a shortlist is just your problem handed back. This is what we would buy for research and retrieval work, and what it costs.
Research is the one shape of work that needs no integration at all, so a single $20 assistant with browsing is the whole stack. Add a crawler only once you are pulling hundreds of pages on a schedule rather than reading a few.
Chosen for the cheapest thing that does the job, not the best funded. Nothing on this site is sponsored, and the full landscape is there when you want to disagree with us.
The rest of the category
Context, not alternatives to weigh up. We name the layer rather than promise a named product does your specific task.
Generalist agents
Matched from the kind of work, not from vendor marketing. Check any of them can reach the system your records actually live in — that connection, not the model, is where these projects stall.
How people actually do it
No workflow names this activity yet, but these automate the same kind of work, with the prompts to paste and what to keep for yourself.
Who does this work
5 occupations in the O*NET database perform this activity. Each one has a full breakdown of its other tasks.
Work that goes with it
O*NET groups these under “Investigate criminal or legal matters”. In practice they tend to be done by the same person, in the same sitting.
Method. The activity, its taxonomy placement and the occupations that perform it come straight from the public-domain O*NET 30.3 database. The automatability band is ours: we map each of O*NET’s 41 generalized work activities to how much of its output current software can produce, assuming a person still reviews and owns the result. It is a coarse three-way judgment on purpose. A precise-looking percentage here would be invented.