Phantom Helix

Resources
SIERRA invoker panel and results connected to an investigation graph

Investigation resources

Resources for investigation work.

Review how Phantom Agent handles evidence and providers. Then explore independent tools that extend SIERRA.

Review investigation guidanceRead the SIERRA invoker guide

SIERRA ecosystem safety

Read the source and its install path.

These are independent projects. Phantom Helix does not audit or maintain them. Review code, dependencies, and commands before using them on a working machine.

Investigation practice

Review the working boundaries.

Start here to review evidence, provider disclosures, lawful use, and the current Phantom Agent workflow.

See an example investigation

See how Phantom Agent researches a question, shows what it found, and flags what still needs checking.

Understand provider and data destinations

See where data can go and why an external source may receive the minimum query data needed.

Check authorization and responsible-use boundaries

Review the use restrictions that apply before an investigation or source check begins.

Review current privacy practices

See how we handle investigation content, support access, analytics, retention, and data requests.

Selected projects

Choose by the job.

This is a short directory, not a security endorsement. Start with the source repository and decide whether the project fits your environment.

Addon loader

01

SieLoader

By Vladhog Security

Combines SIERRA addon files into one loadable invoker. It can also run the installation commands supplied by each addon.

Loads addons from a shared folder

Runs addon install.txt commands

Optional repository client for remote addons

Loader repository

Repository client

Development framework

02

Sierra Dev

By Xsyncio

A Python framework for building SIERRA invokers. It provides typed handlers and uses annotations for configuration.

Automatic YAML generation

Typed result handlers

Examples and development documentation

Examples

03

Invoker Starter Pack

By Runtime Terror

Sample invoker scripts for learning SIERRA's extension format. They also show common automation patterns.

Ready-to-read example scripts

Common OSINT and reconnaissance patterns

A starting point for your own invokers

Contribute

Built something useful for SIERRA?

Share an invoker, development tool, or framework with the community. Include source, setup instructions, and the risks a user should understand.

Discuss it on Discord

Phantom Helix

In silence, patterns emerge.

Investigation tools for professional teams that need to keep the sources, reasoning, and next steps together.

Phantom Agent

OverviewHow access worksRequest accessSign in

© 2026 Phantom Helix · Operated by Danny Jian · ABN 52 512 969 796

Built in Melbourne for professional investigation work.